Routing risk analysis method, device, equipment and storage medium
By acquiring and reconstructing the risk link group of the 5G-SPN network topology, performing collapse processing and co-routing analysis, the problem of the inability to identify the 5G-SPN transmission service and the same routing potential hazards in the prior art are solved, and effective potential hazard analysis of 5G-SPN transmission service is realized.
Patent Information
- Application Number
- CN202111298746.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-03
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2041-11-03
AI Technical Summary
The existing routing security analysis method cannot identify security risks such as the same routing of SDN transmission services in 5G-SPN scenarios, especially transmission services with multiple alternate paths.
By obtaining the first network topology and its corresponding risk link group, collapse processing is performed to obtain the collapsed nodes, and reconstruct the network topology based on these nodes, performing synchronous routing analysis to identify hidden danger circuits.
The routing hazard analysis of 5G-SPN transmission services is realized, and the same routing hazard circuits and low-robust circuits with insufficient protection capabilities are automatically identified, so as to eliminate hidden dangers in a timely manner.
Smart Images

Figure CN116074842B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network transmission technology, and in particular to a routing hidden danger analysis method, device, equipment and storage medium. Background Art
[0002] SPN (Slicing Packet Network) is a key technology in 5G network slicing. With the continuous development of 5G technology, routing security analysis for SPN transmission services is extremely important. Currently, existing routing security analysis methods for transmission services can identify security risks in transmission services. However, in the 5G-SPN scenario, transmission services that support SDN (Software Defined Network) have rerouting protection features and multiple backup paths. In this case, existing routing security analysis methods will fail, resulting in the inability to identify security risks such as duplicate routing. Summary of the Invention
[0003] The main purpose of the present invention is to provide a routing risk analysis method, device, equipment and storage medium, aiming to solve the technical problem that the routing risk analysis method in the prior art does not support 5G-SPN transmission services.
[0004] To achieve the above object, the present invention adopts the following technical solutions:
[0005] In a first aspect, the present invention provides a method for analyzing routing vulnerabilities, the method comprising:
[0006] Acquire a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links having the same risk segment;
[0007] Performing collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group;
[0008] Reconstructing the first network topology according to at least one collapsed node to obtain a second network topology;
[0009] According to the transmission path of the second network topology, a same-route analysis is performed to obtain a same-route potential risk circuit to obtain a potential risk analysis result.
[0010] Optionally, in the above-mentioned routing risk analysis method, the step of obtaining the first network topology specifically includes:
[0011] Obtain the transmission network topology and optical path of the slice packet network;
[0012] A topology segment in the transmission network topology is associated with the optical path to obtain a first network topology, where the first network topology includes at least two topology links.
[0013] Optionally, in the above-mentioned routing risk analysis method, the step of obtaining at least one risk link group corresponding to the first network topology specifically includes:
[0014] Performing drill-down analysis based on the topological links of the first network topology and their corresponding optical paths to obtain dumb resource information of the topological links;
[0015] According to the dumb resource information, it is determined whether the topological link has a same-route hidden danger, wherein the same-route hidden danger includes the same optical cable, the same pole line, the same pipeline, the same direct burial, and the same board with different ports;
[0016] If the topological link has a same-route hidden danger, determining that the topological link has a hidden danger section;
[0017] All topology links with the same risk segment in the first network topology are divided into a risk link group, and at least one risk link group corresponding to the first network topology is obtained.
[0018] Optionally, in the above-mentioned routing risk analysis method, the step of performing collapse processing on each risk link group to obtain a collapsed node corresponding to the risk link group specifically includes:
[0019] For each of the risk link groups, add a virtual node;
[0020] All topological links in the risk link group are disconnected, all topological links are connected to the virtual node, and a collapsed node corresponding to the risk link group is obtained.
[0021] Optionally, in the above-mentioned routing vulnerability analysis method, the step of reconstructing the first network topology according to at least one collapsed node to obtain the second network topology specifically includes:
[0022] According to the at least one risk link group, obtaining at least one corresponding collapsed node;
[0023] reconstructing the first network topology according to at least one collapsed node to obtain a second network topology; or
[0024] The first network topology is reconstructed multiple times according to a preset number of collapsed nodes to obtain multiple second network topologies.
[0025] Optionally, in the above-mentioned routing vulnerability analysis method, the step of performing same-route analysis based on the transmission path of the second network topology to obtain same-route vulnerability circuits to obtain vulnerability analysis results specifically includes:
[0026] Determining, based on the transmission path of the second network topology, whether the transmission path has a same-route risk;
[0027] If there is a same-route hidden danger in the transmission path, determining that the transmission path is a same-route hidden danger circuit;
[0028] If the transmission path does not have a common routing risk, determining that the transmission path passing through the collapsed node is a low-robustness circuit;
[0029] A hidden danger analysis result is obtained according to the same-route hidden danger circuit or the low-robustness circuit.
[0030] Optionally, in the above-mentioned routing vulnerability analysis method, the step of determining whether the transmission path has a routing vulnerability specifically includes:
[0031] Determining whether all transmission paths of the second network topology need to pass through the collapsed node;
[0032] If there is a transmission path that does not pass through the collapsed node, the collapsed node is determined to be a non-essential node, and the transmission path does not have the risk of same-route collision.
[0033] If all transmission paths must pass through the collapsed node, the collapsed node is determined to be a necessary node, and the transmission path has the risk of the same route.
[0034] In a second aspect, the present invention provides a routing vulnerability analysis device, the device comprising:
[0035] A data acquisition module, configured to acquire a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links having the same risk segment;
[0036] A collapse processing module, configured to perform collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group;
[0037] a topology reconstruction module, configured to reconstruct the first network topology according to at least one collapsed node to obtain a second network topology;
[0038] The hidden danger analysis module is used to perform a same-route analysis based on the transmission path of the second network topology, obtain the same-route hidden danger circuit, and obtain a hidden danger analysis result.
[0039] In a third aspect, the present invention provides a routing vulnerability analysis device, comprising a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the routing vulnerability analysis method as described above is implemented.
[0040] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program can be executed by one or more processors to implement the routing vulnerability analysis method as described above.
[0041] The above one or more technical solutions provided by the present invention may have the following advantages or at least achieve the following technical effects:
[0042] The present invention proposes a routing risk analysis method, device, equipment and storage medium. By obtaining a first network topology and a risk link group corresponding to the first network topology, each risk link group is collapsed and a corresponding collapsed node is established, thereby reconstructing the first network topology according to the collapsed node to generate a second network topology; and then performing a same-route analysis on multiple transmission paths in the second network topology to obtain same-route risk circuits, thereby obtaining risk analysis results. The present invention fully considers the characteristics of 5G-SPN transmission services with rerouting protection, and achieves the purpose of routing risk analysis of 5G-SPN transmission services. It does not need to rely entirely on the topological structure of the transmission service, nor does it need to rely entirely on the routing of the transmission service. It automatically identifies same-route risk circuits and low-route circuits with insufficient protection capabilities, making it convenient to take timely measures to eliminate risks as soon as possible. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these provided drawings without paying any creative work.
[0044] Figure 1 This is a flow chart of a first embodiment of a method for analyzing routing vulnerabilities according to the present invention;
[0045] Figure 2 This is a schematic diagram of the hardware structure of the routing risk analysis device involved in the present invention;
[0046] Figure 3 This is a flow chart of a second embodiment of the routing vulnerability analysis method of the present invention;
[0047] Figure 4 A first network topology diagram of the second embodiment of the routing vulnerability analysis method of the present invention;
[0048] Figure 5 for Figure 4 Schematic diagram of topological links;
[0049] Figure 6 A second network topology diagram of the second embodiment of the routing vulnerability analysis method of the present invention;
[0050] Figure 7 for Figure 6 Schematic diagram of the transmission path;
[0051] Figure 8 This is a functional module diagram of the first embodiment of the routing risk analysis device of the present invention.
[0052] The realization of the objectives, functional features and advantages of the present invention will be further explained with reference to the embodiments and drawings. DETAILED DESCRIPTION
[0053] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative work shall fall within the scope of protection of the present invention.
[0054] It should be noted that, in the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "include..." does not exclude the existence of other identical elements in the process, method, article or system including the element. In addition, in the present invention, unless otherwise clearly specified and defined, the terms "connect", "fixed" and the like should be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be the internal communication of two elements or the interaction relationship between two elements.
[0055] In the present invention, if there are descriptions involving "first," "second," etc., such descriptions are for descriptive purposes only and should not be understood as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature specified as "first" or "second" may explicitly or implicitly include at least one of such features. In the present invention, the use of suffixes such as "module," "component," or "unit" to indicate elements is merely to facilitate the description of the present invention and does not have any specific meaning in itself. Therefore, "module," "component," or "unit" may be used interchangeably.
[0056] Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances. Furthermore, the technical solutions of the various embodiments may be combined with each other, but this must be based on the fact that they can be implemented by those skilled in the art. If the combination of technical solutions is mutually inconsistent or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection claimed by the present invention.
[0057] An analysis of existing technologies reveals that there are two main methods for analyzing routing security for transmission services: one is the traditional analysis method based on the topology of transmission network elements. This method uses a graph theory algorithm to analyze routing vulnerabilities. The analysis results are dependent on the network element topology, resulting in the inability to support cross-vendor, cross-plane, and cross-ring transmission services, nor can it support 5G transmission services with MPLS (Multi-Protocol Label Switching) protection.
[0058] The other is a co-routing risk analysis method based on the primary and backup paths of transmission services, which can identify security risks of transmission services. However, in the 5G-SPN scenario, transmission services that support SDN, such as SR-TP (Segment Routing-Transport Profile) transmission services, have the characteristics of APS (Automatic Protection Switched) protection and rerouting protection. Before the transmission interruption occurs, the actual transmission path after the switching cannot be predicted, that is, this type of transmission service has multiple backup paths, and these backup paths are all generated by independently deployed network management systems. In this case, the method cannot obtain the transmission path in advance for risk analysis, cannot identify co-routing risks, and the method fails.
[0059] Therefore, for the transmission services of 5G-SPN, it is currently impossible to identify security risks such as the same route through the existing routing security analysis methods, that is, the routing security analysis methods of the existing technology do not support the transmission services of 5G-SPN.
[0060] In view of the technical problem that the routing risk analysis method in the prior art does not support 5G-SPN transmission services, the present invention provides a routing risk analysis method, the overall idea of which is as follows:
[0061] A first network topology and at least one corresponding risk link group are obtained, wherein the risk link group includes topological links with the same potential risk segment; a collapse process is performed on each risk link group to obtain a collapsed node corresponding to the risk link group; the first network topology is reconstructed based on at least one collapsed node to obtain a second network topology; a same-route analysis is performed based on the transmission path of the second network topology to obtain a same-route potential risk circuit to obtain a potential risk analysis result.
[0062] Through the above technical solution, the first network topology and the risk link group corresponding to the first network topology are obtained, each risk link group is collapsed, and a corresponding collapsed node is established, so that the first network topology is reconstructed according to the collapsed node to generate a second network topology; then, by performing co-routing analysis on multiple transmission paths in the second network topology, the co-routing hidden danger circuit is obtained, and thus the hidden danger analysis result is obtained; the present invention fully considers the characteristics of 5G-SPN transmission services with rerouting protection, and realizes the purpose of routing hidden danger analysis of 5G-SPN transmission services. It does not need to rely entirely on the topological structure of the transmission service, nor does it need to rely entirely on the routing of the transmission service. It automatically identifies co-routing hidden danger circuits and low-robustness circuits with insufficient protection capabilities, so as to facilitate timely measures and eliminate hidden dangers as soon as possible.
[0063] Example 1
[0064] Reference Figure 1 A flow chart of the present invention is provided, which proposes a first embodiment of the routing risk analysis method of the present invention, and the routing risk analysis method is applied to a routing risk analysis device.
[0065] The routing vulnerability analysis device refers to a terminal device or network device that can achieve network connection, which can be a terminal device such as a mobile phone, computer, tablet computer, portable computer, embedded industrial computer, or a network device such as a server or cloud platform.
[0066] like Figure 2 FIG2 is a schematic diagram of the hardware structure of a routing vulnerability analysis device, which may include: a processor 1001 , such as a CPU (Central Processing Unit), a communication bus 1002 , a user interface 1003 , a network interface 1004 and a memory 1005 .
[0067] Those skilled in the art will understand that Figure 2The hardware structure shown in the figure does not constitute a limitation on the routing vulnerability analysis device of the present invention, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0068] Specifically, the communication bus 1002 is used to implement connection and communication between these components;
[0069] The user interface 1003 is used to connect to the client and perform data communication with the client. The user interface 1003 may include an output unit, such as a display screen, an input unit, such as a keyboard, and optionally, the user interface 1003 may also include other input / output interfaces, such as a standard wired interface or a wireless interface.
[0070] The network interface 1004 is used to connect to the backend server and perform data communication with the backend server. The network interface 1004 may include an input / output interface, such as a standard wired interface or a wireless interface, such as a Wi-Fi interface.
[0071] The memory 1005 is used to store various types of data, which may include, for example, instructions for any application or method in the routing risk analysis device, as well as application-related data. The memory 1005 may be a high-speed RAM memory or a stable memory such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the processor 1001.
[0072] For details, please refer to Figure 2 , the memory 1005 may include an operating system, a network communication module, a user interface module and a computer program, wherein the network communication module is mainly used to connect to the server and perform data communication with the server;
[0073] The processor 1001 is configured to call the computer program stored in the memory 1005 and perform the following operations:
[0074] Acquire a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links having the same risk segment;
[0075] Performing collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group;
[0076] Reconstructing the first network topology according to at least one collapsed node to obtain a second network topology;
[0077] According to the transmission path of the second network topology, a same-route analysis is performed to obtain a same-route potential risk circuit to obtain a potential risk analysis result.
[0078] Based on the above routing vulnerability analysis equipment, the following Figure 1 The flowchart shown in FIG. 1 describes in detail the routing vulnerability analysis method of this embodiment. The method may include the following steps:
[0079] Step S10: obtaining a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links with the same risk segment.
[0080] Specifically, for 5G-SPN transmission services, the transmission network topology of the full transmission service can be directly obtained, or when a new transmission service is added, the transmission network topology for the transmission service can be obtained; after obtaining the transmission network topology, the topological segment of the transmission network topology is associated with the optical path according to its corresponding optical path to obtain the associated network topology, that is, the first network topology.
[0081] For all topological links in the first network topology, determine whether any two topological links have common routing vulnerabilities. These topological links with common routing vulnerabilities are marked, and then the topological links with the same vulnerability segments are grouped into a risk link group, thereby obtaining at least one risk link group corresponding to the first network topology. Common routing vulnerabilities include the same optical cable, the same pole line, the same pipeline, the same direct burial, and different ports on the same board.
[0082] Step S20: performing collapse processing on each of the risk link groups to obtain the collapsed node corresponding to the risk link group.
[0083] Specifically, for each risk link group, the logical topology is collapsed, a virtual node is added for the risk link group, and the original topological edge of the risk link group is broken and connected to the virtual node to obtain the collapsed node corresponding to the risk link group.
[0084] Step S30: reconstructing the first network topology according to at least one collapsed node to obtain a second network topology.
[0085] Specifically, after corresponding collapsed nodes are obtained for all risk link groups, a collapsed network topology, ie, a second network topology, is regenerated based on the first network topology.
[0086] Step S40: performing a same-route analysis based on the transmission path of the second network topology to obtain a same-route potential risk circuit to obtain a potential risk analysis result.
[0087] Specifically, a same-route analysis is performed on all transmission paths in the second network topology to determine whether there are same-route hidden dangers in the transmission paths, that is, to determine whether the collapsed node is a necessary node for all transmission paths. If so, it means that the transmission path passing through the collapsed node in the second network topology has a same-route hidden danger, which is a same-route hidden danger circuit. Conversely, if there is a transmission path that does not need to pass through the collapsed node, it means that the transmission path passing through the collapsed node in the second network topology does not have a same-route hidden danger, but it passes through the collapsed node, lacks protection capability, and is a low-route circuit. The transmission path that does not pass through the collapsed node will not have security risks, let alone same-route hidden dangers, and has better protection capability, which is a high-robustness circuit. Finally, the hidden danger analysis results are summarized based on the obtained same-route hidden danger circuits or low-robustness circuits.
[0088] The routing risk analysis method provided in this embodiment obtains a first network topology and a risk link group corresponding to the first network topology, collapses each risk link group, establishes a corresponding collapsed node, and reconstructs the first network topology according to the collapsed node to generate a second network topology; then, same-route analysis is performed on multiple transmission paths in the second network topology to obtain same-route risk circuits, thereby obtaining risk analysis results; the present invention fully considers the characteristics of 5G-SPN transmission services with rerouting protection, and achieves the purpose of routing risk analysis of 5G-SPN transmission services. It does not need to rely entirely on the topological structure of the transmission service, nor does it need to rely entirely on the routing of the transmission service. It automatically identifies same-route risk circuits and low-route circuits with insufficient protection capabilities, and facilitates timely measures to eliminate risks as soon as possible.
[0089] Example 2
[0090] Based on the same invention concept, Figure 3 , a second embodiment of the routing risk analysis method of the present invention is proposed, and the routing risk analysis method is applied to a routing risk analysis device.
[0091] The following combination Figure 3 The flowchart shown in FIG. 1 describes in detail the routing vulnerability analysis method of this embodiment. The method may include the following steps:
[0092] Step S10: obtaining a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links with the same risk segment.
[0093] The method can be applied to the routing risk analysis of newly added 5G-SPN transmission services, and can also be applied to the routing risk analysis of existing 5G-SPN transmission services. The main difference lies in the difference in computational complexity. This embodiment takes a newly added transmission service from A to M and N in the 5G-SPN scenario, in the transmission service from 5G station to NGC (Next Generation Core), as an example for explanation.
[0094] Furthermore, step S10 may include:
[0095] Step S11: Obtain the transmission network topology and optical path of the slice packet network;
[0096] Step S12: Associating the topology segments in the transmission network topology with the optical path to obtain a first network topology, where the first network topology includes at least two topology links.
[0097] During implementation, 5G-SPN transmission services can deploy rerouting protection in addition to SR-TP's APS protection. However, the transmission path generated by the rerouting protection function is not predictable or collectible in advance. Therefore, existing methods cannot perform risk analysis.
[0098] Specifically, 5G-SPN generally has an independently deployed resource management system, which can collect the transmission network topology of SPN transmission services through the automatic collection function of the resource management system, and then combine the corresponding optical path information in the resource management system to automatically match the topology segments in the transmission network topology with the optical path, and associate the topology segments with the optical path to obtain the first network topology of SPN.
[0099] In this embodiment, for the transmission service from the 5G station to the NGC, after obtaining the transmission network topology and optical path, the topology segment in the transmission network topology is associated with the optical path to obtain the following: Figure 4 The first network topology diagram is shown.
[0100] Furthermore, the step S10 may further include:
[0101] Step S13: performing a drill-down analysis based on the topological links of the first network topology and the corresponding optical paths to obtain dummy resource information of the topological links.
[0102] Specifically, dumb resources include transmission equipment, optical cables, and other resources that cannot automatically report their own information. Drill down to dumb resources based on all topological links and corresponding optical paths in the first network topology. The specific order is: service circuit → transmission circuit → topology → optical path → board ports → optical path routing → optical cable segment → pole line / pipeline / direct burial. This obtains dumb resource information for all topological links.
[0103] In this embodiment, according to Figure 4 The first network topology is obtained as Figure 5 In the topology link diagram shown, taking the path from A to M as an example, the corresponding topology links include: ABFEM, ABCDEM, ABFEDNM, ABCDNM, AHIJKM, AHLKM, AHIJNM, AHLKJNM, AHIJNDEM, etc., and the corresponding dummy resource information is obtained.
[0104] Step S14: judging whether the topological link has a same-route hidden danger based on the dumb resource information, wherein the same-route hidden danger includes the same optical cable, the same pole line, the same pipeline, the same direct burial, and the same board with different ports;
[0105] Step S15: If the topology link has a same-route risk, then determining that the topology link has a risky section;
[0106] Step S16: Divide all topology links with the same risk section in the first network topology into a risk link group, and obtain at least one risk link group corresponding to the first network topology.
[0107] Specifically, based on the dummy resource information, a determination is made as to whether a topological link contains the aforementioned same-route risk. If so, the segment containing the same-route risk is considered a risk segment. If not, the topological link is skipped, meaning that risk analysis for that topological link is not required. After identifying same-route risks for all topological links in the first network topology, topological links with risk segments are marked in the first network topology map. All topological links with the same risk segments are then grouped into a risk link group, and the risk link group is marked in the first network topology.
[0108] During the specific implementation process, when analyzing the hidden dangers of the original stock transmission business, you can set up a timed acquisition of the first network topology and its risk link group, and store the acquired data in the database. When storing, the specific storage information may include: risk link group name, risk point type, risk point name, risk link generation time, etc. At the same time, the risk link group is pushed to the background server for automatic configuration of the routing constraint strategy.
[0109] In this embodiment, it is assumed that there are two risky links with the same routing. The topological links corresponding to the first risky link are FE, BC, HL, and IJ, and the topological links corresponding to the second risky link are CD and LK. The topological links FE, BC, HL, and IJ are divided into a risky link group, denoted as risk group 1, and the topological links CD and LK are divided into a risky link group, denoted as risk group 2. Figure 4 shown.
[0110] Step S20: performing collapse processing on each of the risk link groups to obtain the collapsed node corresponding to the risk link group.
[0111] Furthermore, the step S20 may include:
[0112] Step S21: adding a virtual node for each risk link group;
[0113] Step S22: disconnecting all topological links in the risk link group, connecting all topological links to the virtual node, and obtaining a collapsed node corresponding to the risk link group.
[0114] In the specific implementation process, a virtual node is added to each risk link group, and then the original topological segment in the risk link group is interrupted and connected to the virtual node, thereby obtaining the collapsed node of the risk link group.
[0115] In this embodiment, a virtual node is added to the risk group 1, and then the original topology links FE, BC, HL, and IJ are disconnected and connected to the virtual node, thereby obtaining the collapsed node O.
[0116] Step S30: reconstructing the first network topology according to at least one collapsed node to obtain a second network topology.
[0117] Furthermore, the step S30 may include:
[0118] Step S31: obtaining at least one corresponding collapsed node according to the at least one risk link group;
[0119] Specifically, for all risk link groups in the first network topology, the collapsed nodes corresponding to all risk link groups are obtained according to step S20.
[0120] Step S32: reconstructing the first network topology according to at least one collapsed node to obtain a second network topology; or
[0121] Step S33: reconstructing the first network topology multiple times according to a preset number of collapsed nodes to obtain multiple second network topologies.
[0122] Specifically, when it is necessary to perform routing risk analysis on new transmission services, the amount of data is small, and all collapsed nodes in the first network topology can be calculated to regenerate the collapsed network topology, that is, the second network topology; when it is necessary to perform routing risk analysis on existing transmission services, the amount of data is large, and it is difficult to obtain all collapsed nodes in one calculation, thereby obtaining a complete second network topology. Therefore, it is possible to first obtain a preset number of collapsed nodes, perform the first reconstruction, and then continue to obtain other collapsed nodes to obtain the final second network topology.
[0123] In this embodiment, after obtaining the collapsed node P according to step S20, Figure 4 The first network topology shown and the collapsed nodes O and P are obtained as Figure 6 The second network topology diagram is shown.
[0124] Step S40: performing a same-route analysis based on the transmission path of the second network topology to obtain a same-route potential risk circuit to obtain a potential risk analysis result.
[0125] Furthermore, the step S40 may include:
[0126] Step S41: judging whether there is a same-route risk in the transmission path of the second network topology;
[0127] Specifically, step S41 may include:
[0128] Step S41.1: Determine whether all transmission paths of the second network topology need to pass through the collapsed node;
[0129] Step S41.2: If there is a transmission path that does not pass through the collapsed node, the collapsed node is determined to be a non-essential node, and the transmission path does not have the risk of same-route collision.
[0130] Step S41.3: If all transmission paths must pass through the collapsed node, the collapsed node is determined to be a necessary node, and the transmission path has a common routing risk.
[0131] During the specific implementation process, when analyzing routing risks of existing transmission services, the specific collapse process is: obtaining topology link data, risk link group data, collapsed node data and collapsed node routing data, and then linking the SR tunnel segment through the collapsed node routing data, and generating a second network topology through each group of risk link groups and collapsed nodes in a loop, thereby obtaining the final second network topology.
[0132] In this embodiment, Figure 7 Shown Figure 6The transmission path diagram of the second network topology is calculated according to graph theory, without the need to calculate according to the SR-TP path. All transmission paths of the second network topology are analyzed for the same routing risks.
[0133] Step S42: If the transmission path has a common routing vulnerability, determining that the transmission path is a common routing vulnerability circuit;
[0134] Specifically, all transmission paths of the second network topology pass through the collapsed node, and these transmission paths are all circuits with common routing vulnerabilities.
[0135] Step S43: If the transmission path does not have a common routing risk, then the transmission path passing through the collapsed node is determined to be a low-robustness circuit;
[0136] Specifically, among all the transmission paths of the second network topology, the transmission path passing through the collapsed node is a low-robustness circuit, which lacks protection capability and can be adjusted accordingly. The transmission path that does not pass through the collapsed node is a high-robustness circuit and does not require any routing adjustment. The security of the path without the same routing hidden danger is at least greater than or equal to the security of the MPLS ring protection deployed by the PTN (Packet Transport Network), and the calculated route supports fiber breaking on the opposite side.
[0137] In this embodiment, according to Figure 7 From the transmission path diagram of the second network topology shown, it can be seen that the transmission service of node A must pass through the collapsed node O to reach NGC, that is, the collapsed node O is a necessary node. For this necessary node, there is a serious hidden danger that a single optical cable failure will cause all rerouting functions of certain services to fail. Correspondingly, the transmission service of the 5G station must have the same routing hidden danger, which needs to be eliminated, so as to obtain the same routing hidden danger circuit based on the transmission path. However, only part of the transmission path passes through the collapsed node P. The collapsed node P is a non-necessary node and will not cause the service route to be completely blocked. Therefore, it can be ignored. However, it has only two optional routes and its robustness is relatively weak. It can be modified and optimized. Therefore, based on the collapsed node P, a low-robustness circuit can be obtained.
[0138] Step S44: Obtain a hidden danger analysis result according to the same-route hidden danger circuit or the low-robustness circuit.
[0139] During implementation, the obtained risk analysis results can be tabulated and output. The second network topology can also be output, listing all transmission paths that failed the same-route analysis, i.e., those with same-route risk, as determined in step S42. This allows maintenance personnel to rectify the situation by optimizing the transmission topology. Relevant information about the risky link group can also be pushed to a backend server for automatic configuration of routing constraint policies.
[0140] In this embodiment, the co-routing status of the incremental transmission service from A to M and N is summarized and displayed in a report. If there are co-routing vulnerability circuits in this incremental service, subsequent rectification of the transmission network structure vulnerability is required. For example, by modifying the transmission network topology or rectifying the situation where the same optical cable, pole line, pipeline, direct burial, or different boards are used for the same equipment, the size of the vulnerable link group can be reduced and security improved. During subsequent normal transmission, routing vulnerability analysis will continue for this transmission service to ensure the normal operation of the entire network service.
[0141] The routing risk analysis method provided in this embodiment supports routing risk analysis of 5G-SPN transmission services with SR-TP rerouting function. It specifically provides a method for performing same-route risk analysis on new transmission services and existing transmission services, automatically discovering same-route risks that must be rectified and non-same-route but very weak robustness paths, effectively discovering same-route nodes and network weaknesses for early optimization. According to this embodiment, all SR-TP services can also be traversed and analyzed to eliminate blind spots of risks. At the same time, according to the risk analysis results, this embodiment can timely modify new transmission services, or formulate corresponding same-route transformation plans for the existing network topology of existing transmission services to ensure the normal operation of services across the entire network.
[0142] Example 3
[0143] Based on the same invention concept, Figure 8 , a first embodiment of a routing vulnerability analysis device of the present invention is proposed. The routing vulnerability analysis device can be a virtual device applied to a routing vulnerability analysis device.
[0144] The following combination Figure 8 The functional module diagram shown in FIG. 1 is a detailed description of the routing vulnerability analysis device provided by this embodiment. The device may include:
[0145] A data acquisition module, configured to acquire a first network topology and at least one corresponding risk link group, wherein the risk link group includes topology links having the same risk segment;
[0146] A collapse processing module, configured to perform collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group;
[0147] a topology reconstruction module, configured to reconstruct the first network topology according to at least one collapsed node to obtain a second network topology;
[0148] The hidden danger analysis module is used to perform a same-route analysis based on the transmission path of the second network topology, obtain the same-route hidden danger circuit, and obtain a hidden danger analysis result.
[0149] Furthermore, the data acquisition module may include:
[0150] An initial topology unit, used to obtain the transmission network topology and optical path of the slice packet network;
[0151] The optical path associating unit is used to associate the topology segment in the transmission network topology with the optical path to obtain a first network topology, wherein the first network topology includes at least two topology links.
[0152] Furthermore, the data acquisition module may further include:
[0153] a drill-down unit, configured to perform a drill-down analysis based on a topological link of the first network topology and a corresponding optical path thereof, to obtain dumb resource information of the topological link;
[0154] a judgment unit, configured to judge whether the topological link has a same-route hidden danger based on the dumb resource information, wherein the same-route hidden danger includes the same optical cable, the same pole line, the same pipeline, the same direct burial, and the same board with different ports;
[0155] a hidden danger unit, configured to determine that the topology link has a hidden danger section if the topology link has a same-route hidden danger;
[0156] The grouping unit is configured to divide all topology links having the same risk segment in the first network topology into a risk link group, and obtain at least one risk link group corresponding to the first network topology.
[0157] Furthermore, the collapse processing module may include:
[0158] A node adding unit, configured to add a virtual node for each risk link group;
[0159] The collapse processing unit is used to disconnect all topological links in the risk link group, connect all topological links to the virtual node, and obtain a collapsed node corresponding to the risk link group.
[0160] Furthermore, the topology reconstruction module may include:
[0161] A collapse node acquisition unit, configured to obtain at least one corresponding collapse node according to the at least one risk link group;
[0162] A first reconstruction unit is configured to reconstruct the first network topology according to at least one collapsed node to obtain a second network topology; or
[0163] The second reconstruction unit is used to reconstruct the first network topology multiple times according to a preset number of collapsed nodes to obtain multiple second network topologies.
[0164] Furthermore, the hidden danger analysis module may include:
[0165] a same-route risk analysis unit, configured to determine, based on the transmission path of the second network topology, whether the transmission path has a same-route risk;
[0166] a same-route potential circuit determination unit, configured to determine that the transmission path is a same-route potential circuit if there is a same-route potential circuit in the transmission path;
[0167] a low-robustness circuit determination unit, configured to determine that the transmission path passing through the collapsed node is a low-robustness circuit if there is no co-routing risk in the transmission path;
[0168] The analysis result summarizing unit is used to obtain a hidden danger analysis result according to the same-route hidden danger circuit or the low-robustness circuit.
[0169] Furthermore, the same-route hidden danger analysis unit is specifically used to:
[0170] Determining whether all transmission paths of the second network topology need to pass through the collapsed node;
[0171] If there is a transmission path that does not pass through the collapsed node, the collapsed node is determined to be a non-essential node, and the transmission path does not have the risk of same-route collision.
[0172] If all transmission paths must pass through the collapsed node, the collapsed node is determined to be a necessary node, and the transmission path has the risk of the same route.
[0173] It should be noted that the functions and corresponding technical effects that can be achieved by each module in the routing vulnerability analysis device provided in this embodiment can be referred to the description of the specific implementation methods in each embodiment of the routing vulnerability analysis method of the present invention. For the sake of brevity of the description, they will not be repeated here.
[0174] Example 4
[0175] Based on the same inventive concept, this embodiment provides a routing vulnerability analysis device. The device may include a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, it implements all or part of the steps of each embodiment of the routing vulnerability analysis method of the present invention.
[0176] Specifically, the routing vulnerability analysis device refers to a terminal device or network device that can achieve network connection, which can be a terminal device such as a mobile phone, computer, tablet computer, portable computer, embedded industrial computer, or a network device such as a server or cloud platform.
[0177] It can be understood that the device may further include a communication bus, a user interface and a network interface.
[0178] The communication bus is used to realize the connection and communication between these components.
[0179] The user interface is used to connect to the client and communicate data with the client. The user interface may include an output unit, such as a display screen, and an input unit, such as a keyboard. Optionally, the user interface may also include other input / output interfaces, such as a standard wired interface and a wireless interface.
[0180] The network interface is used to connect to the backend server and perform data communication with the backend server. The network interface may include an input / output interface, such as a standard wired interface, or a wireless interface, such as a Wi-Fi interface.
[0181] The memory is used to store various types of data, which may include, for example, instructions for any application or method in the routing vulnerability analysis device, as well as data related to the application. The memory can be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. Optionally, the memory can also be a storage device independent of the processor.
[0182] The processor is configured to call a computer program stored in the memory and execute the above-described routing vulnerability analysis method. The processor may be an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a controller, a microcontroller, a microprocessor, or other electronic component, configured to execute all or part of the steps of each embodiment of the above-described routing vulnerability analysis method.
[0183] Example 5
[0184] Based on the same inventive concept, this embodiment provides a computer-readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a disk, an optical disk, a server, an App application store, etc. The storage medium stores a computer program, and the computer program can be executed by one or more processors. When the computer program is executed by the processor, it can implement all or part of the steps of each embodiment of the routing risk analysis method of the present invention.
[0185] It should be noted that the serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0186] The above descriptions are merely optional embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by utilizing the contents of the present invention specification and drawings under the inventive concept of the present invention, or directly or indirectly applied in other related technical fields, are included in the patent protection scope of the present invention.
Claims
1. A routing risk analysis method, characterized in that: The method comprises: Obtaining a first network topology and at least one corresponding risk link group, wherein the first network topology is a transmission network topology of a sliced packet network in which a topology segment is associated with an optical path, the first network topology includes at least two topology links, and the risk link group includes topology links having the same vulnerable segment, where the same vulnerable segment is a segment in a topology link having a same-route vulnerability and the same-route vulnerability is located; Performing collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group; Reconstructing the first network topology according to at least one collapsed node to obtain a second network topology; Performing a same-route analysis based on the transmission path of the second network topology to obtain a same-route potential risk circuit to obtain a potential risk analysis result; The step of performing collapse processing on each risk link group to obtain a collapsed node corresponding to the risk link group specifically includes: For each of the risk link groups, add a virtual node; All topological links in the risk link group are disconnected, all topological links are connected to the virtual node, and a collapsed node corresponding to the risk link group is obtained.
2. The routing risk analysis method according to claim 1, wherein: The step of obtaining the first network topology specifically includes: Obtain the transmission network topology and optical path of the slice packet network; The topology segments in the transmission network topology are associated with the optical paths to obtain a first network topology.
3. The routing vulnerability analysis method according to claim 1, wherein: The step of obtaining at least one risk link group corresponding to the first network topology specifically includes: Performing drill-down analysis based on the topological links of the first network topology and their corresponding optical paths to obtain dumb resource information of the topological links; According to the dumb resource information, it is determined whether the topological link has a same-route hidden danger, wherein the same-route hidden danger includes the same optical cable, the same pole line, the same pipeline, the same direct burial, and the same board with different ports; If the topological link has a same-route hidden danger, determining that the topological link has a hidden danger section; All topology links with the same risk segment in the first network topology are divided into a risk link group, and at least one risk link group corresponding to the first network topology is obtained.
4. The routing risk analysis method according to claim 1, wherein: The step of reconstructing the first network topology according to at least one collapsed node to obtain the second network topology specifically includes: According to the at least one risk link group, obtaining at least one corresponding collapsed node; reconstructing the first network topology according to at least one collapsed node to obtain a second network topology; or The first network topology is reconstructed multiple times according to a preset number of collapsed nodes to obtain multiple second network topologies.
5. The routing vulnerability analysis method according to claim 1, wherein: The step of performing a same-route analysis based on the transmission path of the second network topology to obtain a same-route vulnerable circuit to obtain a vulnerable analysis result specifically includes: Determining, based on the transmission path of the second network topology, whether the transmission path has a same-route risk; If there is a same-route hidden danger in the transmission path, determining that the transmission path is a same-route hidden danger circuit; If the transmission path does not have a common routing risk, determining that the transmission path passing through the collapsed node is a low-robustness circuit; A hidden danger analysis result is obtained according to the same-route hidden danger circuit or the low-robustness circuit.
6. The routing vulnerability analysis method according to claim 5, characterized in that: The step of determining whether the transmission path has a same-route risk specifically includes: Determining whether all transmission paths of the second network topology need to pass through the collapsed node; If there is a transmission path that does not pass through the collapsed node, the collapsed node is determined to be a non-essential node, and the transmission path does not have the risk of same-route collision. If all transmission paths must pass through the collapsed node, the collapsed node is determined to be a necessary node, and the transmission path has the risk of the same route.
7. A routing risk analysis device, characterized in that: The device comprises: A data acquisition module, configured to acquire a first network topology and at least one corresponding risk link group, wherein the first network topology is a transmission network topology of a sliced packet network in which a topology segment is associated with an optical path, the first network topology includes at least two topology links, and the risk link group includes topology links having a common risk segment, where the common risk segment is a segment in a topology link having a common route risk and the common route risk is located; A collapse processing module, configured to perform collapse processing on each of the risk link groups to obtain a collapsed node corresponding to the risk link group; a topology reconstruction module, configured to reconstruct the first network topology according to at least one collapsed node to obtain a second network topology; a hidden danger analysis module, configured to perform a same-route analysis based on the transmission path of the second network topology, obtain a same-route hidden danger circuit, and obtain a hidden danger analysis result; The collapse processing module includes: A node adding unit, configured to add a virtual node for each risk link group; The collapse processing unit is used to disconnect all topological links in the risk link group, connect all topological links to the virtual node, and obtain a collapsed node corresponding to the risk link group.
8. A routing vulnerability analysis device, characterized in that: The device includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the routing vulnerability analysis method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: The computer program can be executed by one or more processors to implement the routing vulnerability analysis method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Cross layer mapping management method of share risk link group
CN102868563A
Method for standardized data surface dynamic reconstruction for multiple services
CN103731307A