Internet Last Mile Outage Detection Using IP Routing Clusters

By generating network models and identifying the lowest public ancestor nodes, the problem of difficulty in detecting small-scale interrupts in IPv4 and IPv6 environments in the prior art is solved, and efficient detection of last-mile interrupts is achieved.

CN116057901BActive Publication Date: 2025-07-29CISCO TECHNOLOGY INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180056708.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-11-17
Filing Date
2021-07-14
Publication Date
2025-07-29
Estimated Expiration
2041-07-14

AI Technical Summary

Technical Problem

The prior art is difficult to efficiently detect smaller scale internet interrupts, especially in IPv6 environments, where existing systems fail to identify last mile interrupts, and existing detection methods are compute-intensive and inefficient in IPv4 environments.

Method used

By generating a network model, monitoring multiple network nodes using network devices, detecting node disconnection, and determining interrupt sources by identifying the lowest common ancestor node, interrupt detection of IPv4 and IPv6 environments is realized.

Benefits of technology

Efficient detection of smaller scale Internet interrupts is achieved, enabling identification of last-mile interrupts, improving detection efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116057901B_ABST
    Figure CN116057901B_ABST
Patent Text Reader

Abstract

Techniques for Internet last mile outage detection are disclosed. The techniques include methods for: monitoring, by a network device associated with a network, a plurality of network nodes; detecting, by the network device, that a network node among the plurality of network nodes has become disconnected from the network in the last mile of the network; overlaying, by the network device, the network node onto a network model for at least a portion of the network including the network node to generate a model overlay; and determining, by the network device, a last mile outage source associated with the disconnection of the network node by identifying a lowest common ancestor node of the network node from the model overlay. Systems and computer-readable media are also provided.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims the benefit and priority of U.S. Non - Provisional Patent Application No. 16 / 950,472, filed on November 17, 2020, which claims the benefit of U.S. Provisional Patent Application No. 63 / 061,445, filed on August 5, 2020, the respective contents of which are incorporated herein by reference in their entireties. Technical Field

[0003] This technology relates to using an IP routing cluster to detect last - mile outages. Background Art

[0004] Most organizations require reliable Internet access. When an outage occurs, tracking down the cause of the problem can be time - consuming. This is especially true when the infrastructure causing the outage is outside the control of the organization experiencing the problem. Large Internet outages at the city or entire Internet Service Provider (ISP) scale can be detected. However, these large - scale outages are rare. More common are outages that affect a neighborhood or a specific Internet route. These smaller - scale outages are difficult to detect. Brief Description of the Drawings

[0005] To describe the manner in which the various advantages and features of the present disclosure can be obtained, a more specific description of the principles briefly described above will be presented by reference to specific embodiments illustrated in the accompanying drawings. It should be understood that these drawings only depict exemplary embodiments of the present disclosure and should not be considered as limiting its scope. The principles herein are described and explained with additional features and details by using the drawings, wherein:

[0006] Figure 1 An example network environment is shown according to some examples;

[0007] Figure 2 An example method for generating a network model is shown according to some examples;

[0008] Figure 3 An example tree data structure is shown according to some examples;

[0009] Figure 4 An example method for generating an example tree data structure is shown according to some examples;

[0010] Figure 5A An example network environment with an outage is shown according to some examples;

[0011] Figure 5B An example tree data structure with an outage is shown according to some examples;

[0012] Figure 6 illustrates an example method for detecting an interruption in a network environment according to some examples;

[0013] Figure 7 illustrates an example network device according to some examples; and

[0014] Figure 8 illustrates an example computing device according to some examples. DETAILED DESCRIPTION

[0015] Various embodiments of the present disclosure are discussed in detail below. Although specific implementations are discussed, it should be understood that this is done for illustrative purposes only. Those skilled in the relevant art will recognize that other components and configurations can be used without departing from the spirit and scope of the present disclosure. Additional features and advantages of the present disclosure will be set forth in the following description, and will be partially apparent from the description, or can be learned by practicing the principles disclosed herein. The features and advantages of the present disclosure can be realized and obtained by the instruments and combinations particularly pointed out in the appended claims. These and other features of the present disclosure will become more apparent from the following description and the appended claims, or can be learned by practicing the principles set forth herein.

[0016] OVERVIEW

[0017] Systems, methods, and computer-readable media for interruption detection in a networking environment are disclosed herein.

[0018] According to at least one example, a computer-implemented method for generating a network model is provided. The method can include: sending, by a first network node, a network data packet to a second network node, the network data packet including a route associating the first network node as a source node and the second network node as a destination node; updating, by a third network node, the route when the network data packet traverses through the third network node; receiving, by the second network node, the network data packet; sending, by the second network node, the network data packet to a network device; and generating, by the network device, a network model based on the route of the network data packet.

[0019] According to at least one other example, a computer-implemented method for detecting an Internet interruption is also provided. The method can include: monitoring, by a network device of a network, a plurality of network nodes in real time; detecting, by the network device, that at least one network node among the plurality of network nodes has been disconnected from the network; overlaying, by the network device, the at least one network node on a network model; and determining, by the network device, a source of interruption of the at least one network node by identifying a lowest common ancestor node of the at least one network node.

[0020] According to at least one other example, a system is provided. The system includes one or more processors and one or more memories storing computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform the method according to any one of the preceding claims.

[0021] This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in isolation to determine the scope of the claimed subject matter. The subject matter should be understood by reference to the appropriate portions of the entire specification of this application, any or all of the drawings, and each claim.

[0022] The foregoing, together with other features and embodiments, will become more apparent when referring to the following specification, claims, and drawings.

[0023] Description

[0024] Most organizations require reliable Internet access. As described above, smaller-scale outages are more common and more difficult to detect compared to large-scale outages such as city-wide or entire Internet service provider (ISP) outages. For example, an outage affecting a neighborhood or a specific Internet route may include a particular device being misconfigured, a power outage between networks, or some other local issue. These outages occur with higher frequency, and existing systems are not equipped to detect these types of outages. In addition, existing systems may not be sufficient to identify these issues in the IPv6 world because the IPv6 environment includes far more available IP addresses, many of which may be unused. In other words, active probing of the IPv6 environment will not work because IP addresses are less densely utilized compared to the IPv4 environment. Therefore, sending packets to each IP address and waiting for a response would be incredibly computationally intensive and inefficient. In addition, ISPs often reassign IP addresses, which leads to further inefficiencies.

[0025] Accordingly, the disclosed techniques provide systems, methods, and computer-readable media for detecting smaller-scale outages that will work in both IPv4 and IPv6 environments. In addition, the disclosed techniques can be used to identify outages in the last mile of a telecommunications network. The last mile is the final leg of a telecommunications network that delivers telecommunications services (e.g., Internet) to end users (e.g., customers). For example, an outage affecting a neighborhood or a specific Internet route may occur due to a particular device being misconfigured, a power outage between networks, or some other local issue. These outages can be classified as last-mile outages and are difficult to detect for existing technologies. The disclosed techniques can detect and characterize outages for last-mile outages in an adaptive manner.

[0026] This technology will be described in the following subsequent disclosures. The discussion begins with a description of an example ISP network having various network nodes (e.g., routers, switches, client endpoints) as shown in Figure 1 . A description of an example method for determining a network structure is provided as shown in Figure 2 . A description of an example method for detecting and identifying smaller scale outages (e.g., last mile outages) is provided as shown in Figures 3 to 4 . The discussion concludes with a description of an example network device as shown in Figure 5 and an example computing device architecture including example hardware components adapted to provide outage detection in a networked environment as shown in Figure 6 . This disclosure now turns to Figure 1 .

[0027] Figure 1 FIG. 14 illustrates an example network environment 100 having an Internet service provider (ISP) core network 110. The ISP core network 110 communicates with various network nodes 120-1 through 120-9 (collectively 120). Communication between and across the ISP core network 110 and the network nodes 120 can utilize the Border Gateway Protocol (BGP) (including both External BGP (EBGP) and Internal BGP (IBGP)), or the Interior Gateway Protocol (IGP). Additionally, the network nodes 120 can communicate between other network nodes by utilizing tunneling techniques.

[0028] The ISP core network 110 can provide Internet access to one or more network nodes 120 by sending, receiving, maintaining, and monitoring data packets to and from the network nodes 120. In some implementations, the ISP core network 110 has network apparatus 112 configured to manage data packets within the network environment 100. Additionally, the network apparatus 112 can analyze data packets to create a network model and determine when a network node 120 is disconnected from the network environment 100. For example, the network apparatus 112 can receive network data packets including routes between network nodes. The network apparatus 112 can then generate a network model based on the connected nodes (e.g., the routes between network nodes).

[0029] It is also contemplated that the network apparatus 112 is not necessarily part of the ISP core network 110. For example, a third-party application or service can similarly send, receive, maintain, and monitor data packets to and from the network nodes 120. Additionally, the third-party application or service can utilize the network data packets to generate a network model.

[0030] Network node 120 can be connected to the ISP core network 110. Network node 120 can be any type of network node, including but not limited to routers, access points, servers, hubs, antennas, network interface cards (NICs), modules, cables, firewalls, repeaters, sensors, client endpoints, private networks, etc. In addition, network node 120 is configured to send and receive data packets to allow the connected users to access the Internet. In addition, network node 120 is configured to utilize wired protocols, wireless protocols, or any other protocols, including but not limited to TCP / IP, OSI (Open System Interconnection) protocols (e.g., L1-L7 protocols), routing protocols (e.g., RIP, IGP, BGP, STP, ARP, OSPF, EIGRP, NAT), or any other protocols (e.g., HTTP, SSH, SSL, RTP, FTP, SMTP, POP, PPP, NNTP, IMAP, Telnet, SSL, SFTP, WIFI, Bluetooth, VTP, ISL, IEEE802 standards, L2TP, IPSec, etc.). It should also be understood that network node 120 can receive and utilize one or more policies, configurations, services, settings, and / or capabilities (e.g., security policies, subnet and routing schemes, forwarding schemes, NAT settings, VPN settings, IP mapping, port numbers, security information, network management services, backup services, disaster recovery services, bandwidth or performance services, intrusion detection services, network monitoring services, content filtering services, application control, WAN optimization, firewall services, gateway services, storage services, protocol configuration services, wireless deployment services, etc.).

[0031] In addition, network node 120 is configured to send, receive, and / or update or modify network data packets. The network data packets can be associated with the routing between the first network node and the second network node. In addition, the network data packets can associate the first network node as the source node and the second network node as the destination node, such that the first network node can send the network data packets to the second network node through the network environment 100. In some cases, the network data packets can traverse through a third network node to finally reach the second network node. In these cases, the third network node can be configured to update and / or modify the routing of the network data packets to associate the third network node as the traversing node. Therefore, when the second network node receives the network data packets, the network data packets identify the source node of the network data packets and any traversing nodes in the routing to the destination node. In addition, the network data packets can include the IP addresses of any and / or all network nodes 120 (e.g., sending nodes, receiving nodes, intermediate nodes) that have interacted with the network data packets. In some implementations, network node 120 can implement a traceroute function, multiple traceroute functions, a multi-traceroute function (e.g., Dublin traceroute), etc.

[0032] As used herein, a traceroute function can include computer network diagnostic commands to generate and display possible routes and to measure the latency of packets on an Internet Protocol (IP) network. Additionally, the history of a route can be recorded as the round-trip time of packets received from each network node 120 in the route.

[0033] The network device 112 can utilize the information (e.g., network data packets) collected by the traceroute function to generate a network topology. In some embodiments, the network device can transform one or more routes identified by the traceroute into a graph (e.g., a directed acyclic graph) of connections between network nodes 120 among a plurality of network nodes 120. Then, the graph can be transformed and / or used to generate a network model (e.g., a tree data structure) based on the nodes in the graph.

[0034] Additionally, the network topology generated by the network device 112 can identify communications between a particular network node 120 and the ISP core network 110. More specifically, the network device can identify that communications from the ISP core network 110 to, towards, and / or through a particular network node 120 are downstream communications, while communications from a network node 120 to, or towards, the core network 110 are upstream communications. However, it should be understood that the communications do not need to traverse through the ISP core network 110. For example, communications from network node 120-8 to network node 120-5 would be upstream communications, while communications from network node 120-5 to network node 120-8 would be downstream communications.

[0035] Figure 2 An example method 200 for generating a network model is shown. Figure 2 The illustrated method 200 is provided as an example because there are multiple ways to perform the method. Additionally, although the example method is shown in a particular order of steps, those of ordinary skill in the art will understand that Figure 2 and the modules shown therein can be performed in any order and can include fewer or more modules than those shown. Additionally, Figure 2 each of the modules shown represents one or more steps, processes, methods, or routines in the method.

[0036] At block 202, the method 200 can, for example, send a network data packet from a first network node to a second network node. The network data packet can include a route associating the first network node as a source node and the second network node as a destination node.

[0037] At block 204, the method 200 can update the route in the network data packet by a third network node as the network data packet traverses through the third network node.

[0038] At block 206, method 200 receives, at a second network node, a network data packet having an updated route that indicates that the network data packet has traversed through a third network node.

[0039] At block 208, method 200 sends, at the second network node, the network data packet having the updated route to a network device.

[0040] At block 210, method 200 generates, at the network device, a network model based on the route of the network data packet. In some cases, multiple network data packets may have been sent and received by various other nodes. In such cases, the network device may generate and / or update the network model. As described above, it is also contemplated that the network device may be a device external to the ISP. In other words, a network device external to the ISP may also generate a network model based on the route of the network data packet.

[0041] In addition, in some cases, multiple routes are available between network nodes. Thus, in such cases, the network model may include multiple routes between these network nodes. For example, a Dublin traceroute function may identify a superset of possible paths between network nodes. Thus, the network device may use multiple routes between network nodes to generate a network model having multiple routes between network nodes. Thus, the network model reflects the current state of the infrastructure and topology of a given network environment and can be used to efficiently answer queries related to a common ancestor (e.g., a network node closer to the ISP core network 110). Those of ordinary skill in the art will also understand that when a new network node is added to the network environment, the new network node may be added to the network model.

[0042] Figure 3 An example tree data structure 300 generated and / or transformed from a network environment (e.g., network environment 100) is shown. More specifically, network device 112 may generate and / or transform tree data structure 300 from network environment 100. A tree data structure is an undirected graph in which any two nodes are connected by exactly one path. As shown, tree data structure 300 contains network nodes 120 of different structures from network environment 100. To generate tree data structure 300, network device 112 may apply an algorithm (e.g., method 400 below) to compute tree data structure 300. Tree data structure 300 provides a structure that accurately reflects the state of network environment 100 while also providing a data structure that is efficient in answering common ancestor-related queries. More specifically, tree data structure 300 identifies the (ambiguous) common ancestor of each network node 120. Then, tree data structure 300 may be used as a network model for answering common ancestor-related queries (e.g., for identifying a single point of failure for an interruption of one or more network nodes 120).

[0043] Figure 4 Illustrates an example method 400 for generating, transforming, or converting a network topology into a tree data structure (e.g., tree data structure 300). Figure 4 The illustrated method 400 is provided as an example because there are multiple ways to perform the method. Additionally, although the example method is illustrated in a specific order of steps, those of ordinary skill in the art will understand that Figure 4 and the modules illustrated therein can be performed in any order and may include fewer or more modules than those illustrated. Additionally, Figure 4 each module illustrated represents one or more steps, processes, methods, or routines in the method.

[0044] At block 402, a network controller receives a network topology (e.g., a data packet reflecting network environment 100 and / or a directed acyclic graph of network environment 100).

[0045] At block 404, a network device may determine a plurality of nodes in the network topology (e.g., network nodes 120).

[0046] At block 406, a network device may determine a lowest single common ancestor for each of the plurality of nodes. The lowest single common ancestor may be a first ancestor node upstream of a particular node among the plurality of nodes in a network model (e.g., tree data structure 300).

[0047] At block 408, a network device may generate a tree data structure based on the plurality of nodes and each lowest single common ancestor. The tree may be configured to remove redundant paths in the graph (e.g., multiple paths or routes between nodes), and the nodes may be directly connected to the lowest single common ancestor. For example, in Figure 1 , network node 120-4 has multiple routes from the ISP core network 110. Thus, network node 120-4 is shown in Figure 3 as having a single common ancestor at the ISP core network 110. As another example, in Figure 1 , network node 120-8 has only one route through network node 120-5. Thus, network node 120-8 is shown in Figure 3 as having a single common ancestor at network node 120-5.

[0048] Figure 5A and Figure 5B Illustrate example network environments 500a, 500b having an ISP core network 110 and network nodes 120-1 to 120-7 (collectively network nodes 120). Network environments 500a, 500b reflect the same network environment (collectively network environment 500). More specifically, Figure 5Aillustrates a network environment 500a in an acyclic graph format, while Figure 5B illustrates a network environment 500b in a tree data structure format. As described above, the tree data structure of environment 500b provides the lowest single common ancestor node for each network node 120. In addition, the network environment 500 has detected that some network nodes are now disconnected network nodes 120-8 to 120-9 (collectively referred to as the disconnected network nodes 120').

[0049] As described above, the ISP core network 110 may include network devices 112. The network devices 112 may be configured to detect when a network node 120 becomes a disconnected network node 120'. For example, the network node 120 may be configured to periodically send data packets to indicate that the network node 120 is still connected to the ISP core network 110, and the network devices 112 may be configured to receive and monitor the data packets. Thus, when the network devices 112 do not receive data packets from the disconnected network nodes 120', the network devices 112 may determine that the disconnected network nodes 120' are disconnected from the ISP core network 110.

[0050] In addition, the network devices 112 may be configured to identify the source of the fault that causes a network node 120 to become a disconnected network node 120'. More specifically, based on the network model generated by the network devices 112, the network devices 112 can generally identify the common links and alternative routes between network nodes 120. Thus, by searching for common network nodes for the disconnected network nodes 120', the network devices 112 can identify the source of the fault. For example, in Figure 5A , the network nodes 120-8', 120-9' have the network node 120-5 of the network node 120 as a common connection. However, if the network node 120-5 is the source of the fault, the disconnected network node 120-9' will not be disconnected due to the possible routes across the network nodes 120-6, 120-7. Therefore, the network node 120-2 may be the source of the fault. In other words, the analysis result of the network devices 112 is the node in the network model that highlights the potential single fault point and defines the area currently experiencing an interruption. Using this method, the network devices 112 can pick up and characterize faults (e.g., interruptions) not only on a smaller scale but also in an adaptive manner. Thus, the network devices 112 can detect, identify, and present interruptions from hyper-local interruptions (e.g., an interruption of a customer's router) to large-scale ISP interruptions (e.g., an interruption affecting an entire city) and medium-scale interruptions in between (e.g., a power outage in a region or neighborhood).

[0051] This can be achieved by using Figure 5Bis further simplified by a tree data structure. Continuing with the above example, network nodes 120-8' and 120-9' are not shown as having network node 120-5 of network node 120 as a common connection. Instead, the tree data structure identifies network node 120-2 as the lowest common ancestor. Thus, by pre-computing the tree data structure and using the tree data structure for queries, queries related to common ancestors can be answered with improved efficiency.

[0052] Figure 6 An example method 600 for identifying a source of a fault (e.g., a last-mile outage) in a network environment is shown. Figure 6 The method 600 shown is provided as an example because there are multiple ways to perform the method. Additionally, although the example method is shown in a specific order of steps, those of ordinary skill in the art will understand that Figure 6 and the modules shown therein can be performed in any order and can include fewer or more modules than those shown. Additionally, Figure 6 each module shown represents one or more steps, processes, methods, or routines in the method.

[0053] At block 602, method 600 can monitor multiple network nodes in real time by a network device of the network. The network nodes can be monitored by applicable techniques for detecting node-level outages, such as real-time monitoring. For example, the network device can be configured to receive data packets from multiple network nodes at a predetermined interval. As described above, the network device can be separate from the ISP. In other words, the network device can be an application, service, and / or device capable of performing the network device.

[0054] At block 604, method 600 can detect that at least one of the multiple network nodes has been disconnected from the network by the network device. When monitoring the network nodes and detecting the disconnection of the network nodes, the IP address of the node that is the subject of the outage can be identified. For example, when the network device fails to receive a data packet from a network node within a predetermined time or within a set amount of time, the network device can detect that the network node has been disconnected from the network.

[0055] When monitoring the network nodes and identifying the disconnected nodes, the flow of device disconnections caused by, for example, the aggregation of M tunnel states can be monitored. Additionally, applicable outage detection schemes can be used to identify potential Internet outages. The applied outage detection scheme can be defined by an outage model, which can be based on a burst model (e.g., the Kleinberg burst model) or a binomial model (e.g., based on a basic binomial test). Additionally, when an outage occurs, a set of potentially outage IP addresses can be identified.

[0056] At block 606, method 600 may cause a network device to overlay at least one network node onto a network model generated by the network device. For example, the network model may be the network model generated by the network device at block 210 in Figure 2 . A model overlay is then generated from the at least one network node overlaid onto the network model. The model overlay may identify and / or illustrate a disconnected node (e.g., at least one network node) in the network model's scheme. For example, Figure 5A and Figure 5B illustrate a model overlay overlaid onto a network model to identify and demonstrate at least one network node (e.g., network nodes 120-8’ and 120-9’) that has become disconnected.

[0057] At block 608, method 600 may cause a network device to determine an interruption source for the at least one network node by identifying a lowest common ancestor node of the at least one network node. More specifically, the lowest common ancestor node may be the closest upstream node in the network that provides a single point of failure for either or both of the upstream communication from the network node and the downstream communication to the network node. In the case where two or more network nodes experience an interruption, the lowest common ancestor node of the two or more network nodes may be the closest shared upstream node in the network that provides a single point of failure for either or both of the upstream communication from the two or more network nodes and the downstream communication to the two or more network nodes.

[0058] The present disclosure now turns to Figure 7 and Figure 8 , which illustrate example network devices and computing devices such as switches, routers, nodes, servers, client devices, coordinators, etc.

[0059] Figure 7FIG. 700 shows an example network device 700 (e.g., network node 120) suitable for performing switching, routing, load balancing, and other networking operations. The network device 700 includes a central processing unit (CPU) 704, an interface 702, and a bus 710 (e.g., PCI bus). When the CPU 704 operates under the control of appropriate software or firmware, it may be responsible for performing packet management, error detection, and / or routing functions. The CPU 704 preferably completes all these functions under the control of software including an operating system and any appropriate application software. The CPU 704 may include one or more processors 708, such as processors from the INTEL X86 family of microprocessors. In some cases, the processor 708 may be specially designed hardware for controlling the operation of the network device 700. In some cases, the memory 706 (e.g., non-volatile RAM, ROM, etc.) also forms part of the CPU 704. However, there are many different ways to couple the memory to the system.

[0060] The interface 702 is typically provided as a modular interface card (sometimes referred to as a "line card"). Generally, the interface 702 controls the sending and receiving of data packets over the network and sometimes supports other peripheral devices used with the network device 700. Interfaces that may be provided include Ethernet interfaces, Frame Relay interfaces, cable interfaces, DSL interfaces, and Token Ring interfaces, among others. In addition, various very high-speed interfaces may be provided, such as Fast Token Ring interfaces, wireless interfaces, Ethernet interfaces, Gigabit Ethernet interfaces, ATM interfaces, HSSI interfaces, POS interfaces, FDDI interfaces, WIFI interfaces, 3G / 4G / 7G cellular interfaces, CAN bus, LoRA, etc. Generally, these interfaces may include ports suitable for communicating with an appropriate medium. In some cases, they may also include independent processors and, in some cases, volatile RAM. The independent processor may control communication-intensive tasks such as packet switching, media control, signal processing, encryption processing, and management. By providing a separate processor for communication-intensive tasks, these interfaces allow the main CPU (e.g., 704) to effectively perform routing calculations, network diagnostics, security functions, etc.

[0061] Although Figure 7 the system shown is a particular network device of the present disclosure, it is by no means the only network device architecture on which the present disclosure may be implemented. For example, an architecture with a single processor for handling communication and routing calculations is often used. In addition, other types of interfaces and media may also be used with the network device 700.

[0062] Regardless of the configuration of the network device, it can use one or more memories or memory modules (including memory 706), which are configured to store program instructions for general network operations described herein and mechanisms for roaming, route optimization, and routing functions. For example, the program instructions can control the operation of the operating system and / or one or more applications. One or more memories can also be configured to store tables such as mobile bindings, registrations, and related tables. Memory 706 can also hold various software containers as well as virtualized execution environments and data.

[0063] Network device 700 can also include an application specific integrated circuit (ASIC), which can be configured to perform routing and / or switching operations. The ASIC can communicate with other components in network device 700 via bus 710 to exchange data and signals and coordinate various types of operations of network device 700, such as routing, switching, and / or data storage operations.

[0064] Figure 8 An example computing system architecture of a system 800 (e.g., network device 112) that can be used to process FaaS operations and requests, deploy execution environments, load code associated with FaaS functions, and perform any other computing operations described herein is shown. In this example, the components of system 800 communicate electrically with each other using a connection 806 such as a bus. System 800 includes a processing unit (CPU or processor) 804 and a connection 806 that couples various system components including a memory 820 (e.g., read only memory (ROM) 818 and random access memory (RAM) 816) to the processor 804.

[0065] The computing system 800 may include a cache of high-speed memory that is directly connected to, in close proximity to, or integrated as part of the processor 804. The system 800 may copy data from the memory 820 and / or the storage device 808 to the cache 802 for quick access by the processor 804. In this way, the cache can provide a performance boost, thereby avoiding latency of the processor 804 while waiting for data. These modules and other modules may control or be configured to control the processor 804 to perform various actions. Other memory 820 is also available. The memory 820 may include a variety of different types of memory with different performance characteristics. The processor 804 may include any general-purpose processor and hardware or software services (e.g., Service 1 810, Service 2 812, and Service 3 814 stored in the storage device 808), the general-purpose processor and hardware or software services being configured to control the processor 804 as well as a dedicated processor, where the software instructions are incorporated into the actual processor design. The processor 804 may be a fully self-contained computing system that includes multiple cores or processors, buses, memory controllers, caches, etc. The multi-core processor may be symmetric or asymmetric.

[0066] To enable a user to interact with the computing system 800, the input device 822 may represent any number of input mechanisms, e.g., a microphone for voice, a touch-sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. The output device 824 may also be one or more of the many output mechanisms known to those of ordinary skill in the art. In some instances, a multimodal system may enable a user to provide multiple types of input to communicate with the computing system 800. The communication interface 826 may generally govern and manage user input and system output. There is no limitation on operation on any particular hardware arrangement, so the basic features herein can be easily replaced by an improved hardware or firmware arrangement when such is developed.

[0067] The storage device 808 is non-volatile memory and may be a hard disk or other type of computer-readable medium that can store data accessible by a computer, e.g., magnetic tape, flash memory cards, solid-state memory devices, digital versatile disks, cassette tapes, random access memory (RAM) 816, read-only memory (ROM) 818, and mixtures of the foregoing.

[0068] The storage device 808 may include services 810, 812, 814 for controlling the processor 804. Other hardware or software modules may be contemplated. The storage device 808 may be connected to the connection 806. On the one hand, a hardware module that performs a specific function may include a software component stored in a computer-readable medium that is connected to the necessary hardware components (e.g., the processor 804, the connection 806, the output device 824, etc.) to perform the function.

[0069] For clarity, in some instances, the present technology may be represented as including various functional blocks, which include functional blocks having the functions of devices, device components, steps or routines of methods embodied in software, or combinations of hardware and software.

[0070] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals that contain bitstreams and the like. However, when mentioned, non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals themselves.

[0071] The methods according to the above examples may be implemented using computer-executable instructions stored on a computer-readable medium or otherwise obtainable from a computer-readable medium. Such instructions may include, for example, instructions and data that cause or otherwise configure a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform a certain function or a set of functions. Some of the computer resources used may be accessed via a network. The computer-executable instructions may be, for example, binary, intermediate format instructions (e.g., assembly language, firmware, or source code). Examples of computer-readable media that may be used to store instructions, information used during and / or created in the methods according to the examples include magnetic or optical disks, flash memory, USB devices equipped with non-volatile memory, network storage devices, and the like.

[0072] Devices that implement the methods according to these disclosures may include hardware, firmware, and / or software, and may take any of a variety of form factors. Typical examples of such form factors include laptops, smartphones, small personal computers, personal digital assistants, rack-mounted devices, stand-alone devices, etc. The functions described herein may also be embodied in peripheral devices or add-on cards. As a further example, such functions may also be implemented on a circuit board between different chips or different processes executed in a single device.

[0073] Instructions, the media for conveying such instructions, the computing resources for executing such instructions, and other structures for supporting such computing resources are devices that provide the functions described in these disclosures.

[0074] While various examples and other information are used to explain aspects within the scope of the appended claims, no limitation to the claims should be implied based on the specific features or arrangements in such examples, as those of ordinary skill in the art will be able to use these examples to obtain a wide variety of implementations. Additionally, while some subject matter may have been described in language specific to examples of structural features and / or method steps, it should be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or acts. For example, such functionality may be distributed differently among components other than those identified herein or performed by components other than those identified herein. Instead, the described features and steps are disclosed as examples of components of a system and methods within the scope of the appended claims.

[0075] Claim language or other language that recites "at least one" of a group and / or "one or more" of a group means that one member of the group or multiple members of the group (in any combination) satisfy the claim. For example, claim language that recites "at least one of A and B" means A, B, or A and B. In another example, claim language that recites "at least one of A, B, and C" means A, B, C, or A and B, or A and C, or B and C, or A and B and C. The language "at least one" of a group and / or "one or more" of a group does not limit the group to the items listed in the group. For example, claim language that recites "at least one of A and B" may mean A, B, or A and B, and may additionally include items not listed in the group of A and B.

Claims

1. A computer-implemented method comprising: monitoring a plurality of network nodes by a network device associated with the network; detecting, by the network device, that a network node of the plurality of network nodes is disconnected from the network in a last mile of the network, wherein the last mile of the network is a last branch of the network for delivering telecommunication services to an end user; overlaying, by the network device, the disconnected network node on a network model for at least a portion of the network including the disconnected network node to generate a model overlay, the network model being for at least a portion of the network including the disconnected network node, wherein the model overlay identifies and / or illustrates the disconnected network node in a scheme of the network model; and A last mile outage source associated with a disconnection of the network node is determined by the network device by identifying a lowest common ancestor node of the network node from the model overlay, wherein the lowest common ancestor node is an upstream node in the network closest to the network node that provides a single point of failure for either or both of upstream communications from the network node and downstream communications to the network node.

2. The computer-implemented method according to claim 1, wherein, The network is at least partially formed by an Internet Service Provider (ISP) network, and the network device is separate from the ISP network.

3. The computer-implemented method of claim 1 or 2, further comprising: receiving, by the network device as part of a traceroute, one or more data packets that traverse at least a portion of the plurality of network nodes; as well as The network model is generated based on one or more routes of the one or more data packets identified by the traceroute and received at the network device.

4. The computer-implemented method according to claim 3, wherein, The traceroute is performed as part of a multi-traceroute that includes identifying a plurality of routes traversed by the one or more data packets.

5. The computer-implemented method of claim 3 , further comprising: converting the one or more routes identified by the traceroute into a directed acyclic graph of connections between nodes in at least a portion of the plurality of network nodes; and The acyclic graph is transformed into a tree to form the model.

6. The computer-implemented method according to claim 5, wherein, The lowest common ancestor node of the network nodes is the first ancestor node of the network nodes in the tree.

7. The computer-implemented method of claim 1 or 2, further comprising: Responsive to the network device failing to receive a packet from the network node within a predetermined time, it is detected that the network node has been disconnected from the network.

8. The computer-implemented method of claim 1 or 2, wherein: The network model is generated based on Internet Protocol version 6 (IPv6) addresses associated with nodes in at least a portion of the network.

9. The computer-implemented method according to claim 1 or 2, wherein, The network model is generated based on Internet Protocol version 4 (IPv4) addresses associated with nodes in at least a portion of the network. 10 . A network system comprising one or more processors, wherein the one or more processors are configured to execute the method according to claim 1 .

11. A computer-readable medium comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Determination of packet loss locations

    US20100157788A1