Network anomaly positioning and anomaly positioning method, device, system and storage medium

By managing multiple probes in a unified manner through a probe management node, network quality distribution characteristics can be obtained, solving the problem of network anomaly location in large-scale architecture systems and enabling rapid and automatic anomaly location and maintenance.

CN116155705BActive Publication Date: 2026-01-23ALIBABA (CHINA) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310159983.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-15
Publication Date
2026-01-23
Estimated Expiration
2043-02-15

AI Technical Summary

Technical Problem

Network anomaly localization in large-scale architecture systems is difficult to achieve quickly. Existing technologies lack a full-link network anomaly localization method, and relying on manual judgment is inefficient.

Method used

By managing multiple probes in a unified manner through the probe management node, target detection data can be obtained, network quality distribution characteristics can be determined, and network anomaly localization can be performed based on this.

Benefits of technology

It enables network anomaly localization based on network quality distribution characteristics, shortens anomaly localization time, provides a foundation for system maintenance, and reduces manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116155705B_ABST
    Figure CN116155705B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a network anomaly positioning method and device, a system and a storage medium. In the embodiments of the present application, a plurality of probes of a to-be-tested system are uniformly managed by a probe management node, and the network quality distribution characteristics of the to-be-tested system can be determined according to target detection data of the plurality of probes of the to-be-tested system. The network anomaly positioning of the to-be-tested system is performed according to the network quality distribution characteristics of the to-be-tested system, the network anomaly positioning of the to-be-tested system is realized based on the network quality distribution characteristics of the to-be-tested system, and a basis is provided for subsequent maintenance of the to-be-tested system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a network anomaly location and anomaly location method, device, system and storage medium. Background Technology

[0002] Large-scale architecture systems, due to their complex architecture and large coverage, are difficult to quickly locate anomalies in engineering practice. The Internet is a typical large-scale architecture system. Taking the Internet's network communication system as an example, the network communication system includes the user's mobile network, the operator's network, and the service provider's data center network. In this entire chain, each link has the potential to have problems. Therefore, anomalies in the Internet's network communication system are characterized by being difficult to locate. Summary of the Invention

[0003] This application provides an anomaly location and network anomaly location method, device, system and storage medium for realizing network anomaly location of the system under test.

[0004] This application also provides a method for locating network anomalies, including:

[0005] Acquire target detection data from multiple probes of the system under test within a set time period; the multiple probes are used to detect the network quality of the network communication system.

[0006] Based on the target detection data, determine the network quality distribution characteristics of the system under test;

[0007] Based on the network quality distribution characteristics of the system under test, network anomaly localization is performed on the system under test.

[0008] This application also provides an anomaly localization method for locating anomalies in a system under test. The system under test includes a user terminal, a server terminal, and a gateway located between the user terminal and the server terminal. The server terminal includes an application programming interface (API) and provides services through the API. Probes are deployed on the user terminal and the gateway. The probes detect the service quality of the system under test by calling the API to obtain detection data.

[0009] The method includes:

[0010] Acquire target detection data from multiple probes of the system under test within a set time period;

[0011] Based on the target detection data, the service quality distribution characteristics of the system under test are determined;

[0012] Based on the service quality distribution characteristics of the system under test, anomalies are located in the system under test.

[0013] This application embodiment also provides a management system, including: a system under test and a probe management node; the system under test includes: a user terminal, a server terminal, and a gateway disposed between the user terminal and the server terminal; the server terminal includes: an application programming interface (API), and provides services through the API; probes are deployed on the user terminal and the gateway.

[0014] The probe detects the service quality of the system under test by calling the API to obtain detection data;

[0015] The multiple probes are used to detect the quality of service of the system under test in order to obtain detection data;

[0016] The probe management node is used to execute the steps in the above-described anomaly localization method.

[0017] This application also provides a network management system, including: a system under test and a probe management node; the system under test is equipped with multiple probes;

[0018] The multiple probes are used to perform network quality detection on the system under test in order to obtain detection data;

[0019] The probe management node is used to execute the steps in the above-described network anomaly localization method.

[0020] This application embodiment also provides a computing device, including: a memory and a processor; wherein, the memory is used to store computer programs;

[0021] The processor is coupled to the memory and is used to execute the computer program for performing the steps in the above-described anomaly localization method and / or the network anomaly localization method.

[0022] This application also provides a computer-readable storage medium storing computer instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps in the above-described anomaly location method and / or the network anomaly location method.

[0023] In this embodiment, by managing multiple probes of the system under test in a unified manner, the network quality distribution characteristics of the system under test can be determined based on the target detection data of the multiple probes. Based on the network quality distribution characteristics of the system under test, network anomaly localization is performed on the system under test, realizing network anomaly localization of the system under test based on the network quality distribution characteristics of the system under test, and providing a foundation for the subsequent maintenance of the system under test. Attached Figure Description

[0024] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0025] Figures 1-3 This is a schematic diagram of the structure of the network management system provided in an embodiment of this application;

[0026] Figure 4a This is a schematic diagram of the structure of the management system provided in the embodiments of this application;

[0027] Figure 4b A flowchart illustrating the network anomaly localization method provided in this application embodiment;

[0028] Figure 5a A flowchart illustrating another network anomaly location method provided in this application embodiment;

[0029] Figure 5b A flowchart illustrating the anomaly localization method provided in this application embodiment;

[0030] Figure 6 A schematic diagram of the structure of a computing device provided in an embodiment of this application. Detailed Implementation

[0031] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0032] Traditional network monitoring and anomaly localization methods are generally only applicable to certain application scenarios. For example, network monitoring within a data center can only detect network anomalies within the data center and the connection between the data center and the carrier; internet dial-up testing technology can only monitor the network status between the test initiator and the target, failing to reflect real user scenarios. Therefore, in actual network operations and maintenance, there is still no comprehensive method for locating network anomalies across the entire internet link. Operations and maintenance personnel still need to manually judge various network monitoring signals based on their experience, a cumbersome and inefficient approach.

[0033] In this embodiment, by managing multiple probes of the system under test through a probe management node, the quality distribution characteristics of the system under test can be determined based on the target detection data of the multiple probes. Based on the quality distribution characteristics of the system under test, network anomaly localization can be performed, thus realizing anomaly localization of the system under test based on its quality distribution characteristics, providing a foundation for the subsequent maintenance of the system under test.

[0034] The technical solutions provided by the various embodiments of this application are described in detail below with reference to the accompanying drawings.

[0035] It should be noted that the same reference numerals denote the same object in the following figures and embodiments. Therefore, once an object is defined in one figure or embodiment, it does not need to be discussed further in subsequent figures and embodiments.

[0036] Figure 1 This is a schematic diagram of the network management system provided in an embodiment of this application. Figure 1 As shown, the network management system includes: System under Test S10. System under Test S10 refers to the system that needs to undergo network quality testing.

[0037] In this embodiment, the system under test S10 can be implemented as a centralized system or a distributed system. A distributed system refers to an entity architecture consisting of multiple nodes deployed in a distributed manner to provide services externally. For example, ... Figure 2 As shown, the network communication system provides network services through a variety of network participants. These participants include: user terminals 21, Internet Service Providers (ISPs) 22, and data centers 23 that provide cloud services, etc.

[0038] Among them, the user terminal 21 refers to the computer device used by the user that has the computing, communication and other functions required by the user, such as mobile phones, tablets, personal computers, wearable devices, etc.

[0039] ISP 22 primarily refers to the equipment used by telecommunications operators to provide internet access services to users, including but not limited to base stations and routers. Telecommunications operators can provide internet access services to users.

[0040] Data center 23 may be a data center of a cloud service provider that provides services to users. The cloud services provided by data center 23 to users include, but are not limited to: live streaming services, data processing services, artificial intelligence (AI) and data storage services, etc.

[0041] In this embodiment, to achieve network quality detection of the system under test (S10), multiple probes 20 can be deployed in S10. Multiple probes 20 are used to detect the network quality of S10. "Multiple" refers to two or more probes. To perform the most comprehensive quality detection possible, multiple probes 20 can be deployed in different modules of S10, and the detection range of multiple probes 20 can cover S10. It should be noted that all probes 20 deployed in S10 are authorized by the respective owners of the objects within S10.

[0042] In this embodiment, the probe used for network quality detection, also known as a network probe, can be used to listen to network data packets. The probe can be implemented as a software functional module, such as a software development kit (SDK). Of course, the probe can also be a physical device with network data packet listening capabilities.

[0043] For any probe, the probe can monitor the network quality of the system under test (S10) by sending probe packets. Specifically, the probe can send probe packets to the probe link. These probe packets include a source address and a destination address. The source and destination addresses can be Internet Protocol (IP) addresses. The source address is the IP address of the device where the probe is located; the destination address is the IP address of the probe link. For example, Figure 1 In this example, assuming the probe is deployed on module 1 and the probe link is the network link between module 1 and module n, then the source address is the IP address of module 1 and the destination IP address is the IP address of module n.

[0044] Probes can acquire probe data by probing data packets. Probe data may include: the source and destination IP addresses of the probe packets, and network quality parameters of the probe link. Network quality parameters are used to measure network performance. These parameters include, but are not limited to, packet loss rate and network latency of the probe link. Network latency refers to the delay between the probe sending a probe packet and receiving a response packet.

[0045] The packet loss rate of the probe link can be represented by the ratio between the number of response packets received by the probe and the number of probe packets sent by the probe.

[0046] Based on the probe's detection data, it can be seen that the probe's detection data reflects the network quality of the probe's detection link. Therefore, in this embodiment, to achieve network anomaly localization in the system under test (S10), a probe management node 30 can be added to the management node of the system under test. The probe management node 30 refers to a server-side device that manages and processes the probe data. The server-side device can be a single server device, a cloud-based server array, or a virtual machine (VM) running in a cloud-based server array. Alternatively, the server-side device can also refer to other computing devices with corresponding service capabilities, such as computers or other terminal devices (running service programs).

[0047] In this embodiment, to achieve anomaly localization, the probe management node 30 can uniformly manage multiple probes 20 of the system under test S10. The probes 20 can send the acquired detection data to the probe management node 30. In this embodiment, the triggering timing for multiple probes 20 to perform network quality detection is not limited. Specifically, the probes 20 can respond to a quality detection event by sending detection data packets to perform network quality detection.

[0048] In some embodiments, the probe may periodically perform network quality probing. For any probe 20, a probe data packet may be sent to perform network quality probing when the probing period arrives. The arrival of the probing period indicates that a network quality probing event has occurred.

[0049] In other embodiments, the management system of the system under test (S10) may provide a human-machine interface (HMI) through which users can trigger network quality detection. The probe can respond to a network quality detection request by sending probe data packets to perform network quality detection on S10.

[0050] Probe 20 can send the collected detection data to probe management node 30. When locating network anomalies, probe management node 30 can acquire target detection data from multiple probes 20 within a set time period. In this embodiment, probe management node 30 can perform real-time online network anomaly location. Accordingly, the set time period can be the time period during which the detection data is received in real time, such as the last 5 minutes or 1 hour.

[0051] Of course, the probe management node 30 can also be used for offline network anomaly localization and periodic review of the network quality of the system under test. Accordingly, the set time period can be a historical time period to be processed. For example, 8:00 to 9:00 on November 2, 2022. The probe management node 30 can obtain target detection data from multiple probes 20 on the same access path within the set time period from the stored detection data.

[0052] The inventors of this application have discovered that the network quality distribution characteristics of a system under test (SUT) differ depending on the location of the anomaly. In the embodiments of this application, the network quality distribution characteristics of the SUT specifically refer to the distribution information of the network quality characteristics detected by the probes of the SUT, and may include a combination of the network quality characteristics of the detection links of multiple probes of the SUT. The network quality characteristics of the detection links can reflect the degree of anomaly of those detection links.

[0053] Based on the target detection data, the probe management node 30 can determine the network quality distribution characteristics of the system under test. Specifically, the probe management node 30 can determine the network quality of the detection links of multiple probes 20 of the system under test based on the target detection data.

[0054] Optionally, for any probe A, the probe management node 30 can determine the source IP address and destination IP address of the probe link of probe A from the target probe data of probe A, and determine the network link between the source IP address and the destination IP address as the probe link of probe A. The probe management node 30 can also obtain the network quality parameters of probe A from the target probe data of probe A; and determine the network quality of the probe link of probe A based on the network quality parameters of the probe link of probe A.

[0055] Optionally, the probe management node 30 can determine whether the network quality parameters of the probe A's probe link meet the set parameter conditions. If the network quality parameters of the probe A's probe link meet the set parameter conditions, then the probe A's probe link is determined to be normal.

[0056] The following example illustrates this using specific network quality parameters. The probe management node 30 can determine the network quality of the probe link of probe A through the following judgment operations. These judgment operations may include:

[0057] Judgment Operation 1: Determine whether the packet loss rate of the probe link of probe A is greater than or equal to the set packet loss rate threshold;

[0058] Judgment Operation 2: Determine whether the delay time of the probe link of probe A is greater than or equal to the set duration.

[0059] If the result of the above judgment operation 1 and / or judgment operation 2 is yes, it is determined that the network of probe A's probe link is abnormal. If the result of judgment operation 1 and 2 is no, it is determined that the network of probe A's probe link is normal.

[0060] Using the same or similar methods, the network quality of the probe links detected by multiple probes 20 of the system under test can be determined. Furthermore, the probe management node 30 can determine the network quality distribution characteristics of the system under test S10 based on the network quality of the probe links.

[0061] The following is an exemplary description of a specific implementation method for determining the network quality distribution characteristics of the system under test S10.

[0062] In some embodiments, the system under test S10 can be divided into multiple modules 10. Specifically, the system under test S10 can be divided into multiple modules 10 according to the functions of each object in the system under test S10.

[0063] Accordingly, such as Figure 1 As shown, the system under test S10 may include: multiple modules 10, such as Figure 1 The system under test (S10) consists of modules 1, 2, 3, ..., n, where n ≥ 2 and is an integer. Multiple modules 10 are interconnected. Correspondingly, the multiple modules 10 of the system under test S10 correspond to multiple probes 20. For example... Figure 1 The probes are numbered 1, 2, 3, ..., n. Each module 10 is equipped with at least one probe 20. Each module 10, corresponding to at least one probe 20, is used to probe the network quality of a portion of the links in the system under test. Preferably, each module 10 is equipped with multiple probes. For example, Figure 1 Each probe represents multiple probes deployed in the corresponding module. In various embodiments of this application, the multiple probes are two or more. It should be noted that the probes 20 deployed in each module 10 are all authorized by the owner of module 10.

[0064] In this embodiment, the multiple modules 10 can be wirelessly or wiredly connected. Optionally, the multiple modules 10 can be connected via a mobile network. Accordingly, the network standard of the mobile network can be any one of 2G (such as Global System for Mobile Communications (GSM), 2.5G (such as General Packet Radio Service (GPRS), 3G (such as Wideband Code Division Multiple Access (WCDMA), Time Division-Synchronous Code Division Multiple Access (TD-SCDMA), Code Division Multiple Access 2000 (CDMA2000), Universal Mobile Telecommunications System (UTMS), 4G (such as Long Term Evolution (LTE), 4G+ (such as LTE-Advanced (LTE-A)), 5G, World Interoperability for Microwave Access (WiMax), etc. Alternatively, multiple modules 10 can also communicate and connect with each other via Bluetooth, Wireless Fidelity (WiFi), infrared, or other means.

[0065] In this application embodiment, the implementation form of the system under test is not limited. Different implementation forms of the system under test result in different dimensions of module division. In some embodiments, such as... Figure 2 As shown, the system under test S10 can be implemented as a network communication system S20. Accordingly, the multiple modules 10 can be implemented as: user terminal 21, Internet Service Provider (ISP) 22, and data center 23 of application service provider. Among them, user terminal 21, ISP 22, and data center 23 are each implemented as one module.

[0066] like Figure 2As shown, in the network communication system, user terminal 21 and ISP 22 are connected via a first network link. This first network link can be a mobile network link. ISP 22 and data center 23 are connected via a second network link. Service equipment in data center 23 is connected via a third network link. This third network link can be the data center's internal network.

[0067] In the network communication system, user terminal 21 can deploy multiple user terminal probes 20a to detect the network quality of the first and second network links. ISP 22 can also deploy multiple ISP probes 20b to detect the network quality of the second network link. Data center 23 can deploy multiple cloud probes 20c to detect the network quality of the second and third network links. In this embodiment, because the public IP addresses of ISP 22 and data center 23 are public, while the IP address of user terminal 21 is not public to ISP 22 and data center 23, user terminal probes 20a can detect the network quality of the first and second network links, while cloud probes 20c cannot detect the first and second network links, and ISP probes 20b cannot detect the first network link. Similarly, because the public IP address of data center 23 is public, and the public IP address of ISP 22 is also public, cloud probes 20b can probe the second and third network links, and ISP probes 20b can probe the second network link.

[0068] In other embodiments, the system under test can also be implemented as a distributed computing system or a distributed storage system. A distributed computing system can be divided into multiple modules, such as a user terminal, a management node, and a data center composed of computing nodes.

[0069] A control node refers to a device, module, or virtual instance (such as a virtual machine or container) that responds to computing requests from users and schedules resources for the computing node based on those requests. A computing node refers to a server-side device that provides computing resources.

[0070] Communication connections exist between the user terminal and the control node; between the control node and the data center; and between computing devices within the data center. Multiple probes can be deployed on the user terminal to probe the network quality of the link between the user terminal and the control node, and between the control node and the data center. Similarly, multiple probes can be deployed on the control node to probe the network quality of the link between the control node and the data center. Finally, multiple probes can be deployed within the data center to probe the network quality of links within the data center.

[0071] Of course, distributed computing systems can also be divided into: user terminals, schedulers, controllers, and data centers. The user terminals communicate with the scheduler; the scheduler communicates with both the controller and the data center; the controller communicates with the data center; and the computing nodes within the data center communicate with each other.

[0072] The controller is primarily used to monitor resources in the data center and return the monitoring results to the scheduler. The scheduler then performs resource scheduling within the data center based on the monitoring results.

[0073] The user terminal can deploy at least one probe to detect the network quality of the link between the user terminal and the scheduler, and the network quality of the link between the scheduler and the data center.

[0074] At least one probe is deployed on the scheduler side to detect the network quality of the link between the scheduler and the controller, and the network quality of the link between the scheduler and the data center.

[0075] At least one probe is deployed on the controller side to detect the network quality of the link between the controller and the data center.

[0076] Data centers can deploy multiple probes to detect the network quality of links and devices within the data center.

[0077] Distributed storage systems can be divided into multiple modules such as user terminals, management nodes, and storage nodes. Their probe deployment methods can be found in the relevant content of the above-mentioned distributed computing systems, which will not be repeated here.

[0078] The above embodiments only illustrate the deployment locations of the system under test and the probe by taking the system under test as a network communication system, a distributed computing system, and a distributed storage system as examples, but do not constitute a limitation.

[0079] In the embodiments of this application, such as Figure 1 As shown, at least one probe of each module 10 can be used to probe a portion of the link in the system under test. The detection range of probes corresponding to multiple modules 10 can cover the system under test.

[0080] In some embodiments, for any module 10, the probe management node 30 can determine the proportion P of abnormal probe links corresponding to module 10 based on the network quality of the probe links corresponding to module 10. Here, the probe links corresponding to module 10 refer to the network links detected by the multiple probes 20 deployed in that module. For two probes with the same probe link, the number of probe links detected is 2. For example, the ratio of the number N of abnormal probe links corresponding to module 10 to the total number M of probe links corresponding to module 10 can be calculated as P = N / M. Here, 0 ≤ N ≤ M. N and M are both integers, and M equals the number of multiple probes corresponding to that module. Here, the probe link of a probe refers to the link detected by that probe. An abnormal probe link refers to a probe link with network anomalies among the links detected by multiple probes.

[0081] Furthermore, the probe management node 30 can determine the network quality characteristics of the probe links corresponding to module A based on the proportion of abnormal probe links corresponding to module 10. The network quality characteristics of the probe links reflect the degree of abnormality of the links, while the detection results of multiple probes detecting the link represent the number of network anomalies on that link, which can reflect the degree of abnormality to some extent. For example, the detection results of multiple probes may indicate that the number of anomalies on the link is a small number, a large number, all anomalies, or all normal.

[0082] For example, if the proportion of the anomaly detection link corresponding to module 10 is greater than 0 and less than or equal to the set first proportion, the network quality characteristics of the detection links of the multiple probes corresponding to module 10 are determined to be the first type of quality characteristics.

[0083] If the proportion of abnormal detection links of multiple probes corresponding to module 10 is greater than or equal to a set second proportion, and less than 1, the network quality characteristic of the detection link corresponding to module 10 is determined to be a second type of quality characteristic; the second proportion is greater than the first proportion. Accordingly, the first type of quality characteristic can characterize a small number of anomalies in the detection links corresponding to multiple probes; the second type of quality characteristic can characterize a large number of anomalies in the detection links corresponding to multiple probes.

[0084] If the proportion of abnormal detection links corresponding to any module 10 is equal to 1, the network quality characteristic of the detection link corresponding to that module 10 is determined to be a third type of quality characteristic. The third type of quality characteristic can characterize that all detection links corresponding to multiple probes are abnormal.

[0085] If the percentage of abnormal detection links corresponding to any module 10 is equal to 0, the network quality characteristic of the detection link corresponding to that module 10 is determined to be the fourth type of quality characteristic. The fourth type of quality characteristic can characterize that all detection links detected by multiple probes are normal.

[0086] After determining the network quality characteristics of the probe links corresponding to each module, the probe management node 30 can determine the network quality characteristics of the system under test S10 based on the network quality characteristics of the probe links corresponding to the multiple modules 10. For example, the combination of the network quality characteristics of the probe links of the multiple probes 20 corresponding to the multiple modules 10 can be used as the network quality distribution characteristics of the system under test S10. For example, the system under test S10 includes three modules: module 1, module 2, and module 3. The network quality characteristics of the probe links corresponding to the three modules are as follows: the network quality characteristics of the probe links corresponding to module 1 are the first type of quality characteristics (such as a few anomalies), the network quality characteristics of the probe links corresponding to module 2 are the second type of quality characteristics (such as a large number of anomalies), and the network quality characteristics of the probe links corresponding to module 3 are the third type of anomaly characteristics (such as all anomalies). Then the network quality distribution characteristics of the system under test S10 are (module 1: first type of quality characteristics, module 2: second type of quality characteristics, module 3: third type of anomaly characteristics).

[0087] After determining the network quality distribution characteristics of the system under test S10, the probe management node 30 can locate network anomalies in the system under test S10 based on the network quality distribution characteristics of the system under test S10.

[0088] Specifically, the probe management node 30 can obtain the pre-stored correspondence between network anomaly locations and network quality distribution features; and use the network quality distribution features of the system under test S10 to match the correspondence between network anomaly locations and network quality distribution features to obtain the network anomaly location corresponding to the network quality distribution features of the system under test S10; and take the network anomaly location corresponding to the network quality distribution features of the system under test S10 as the network anomaly location of the system under test S10.

[0089] The pre-stored correspondence between network anomaly locations and network quality distribution characteristics was obtained by the inventors of this application through analysis of the probe detection data of the system under test.

[0090] The network quality distribution characteristics, which correspond to network anomaly locations and network quality distribution characteristics, can be represented by combinations of network quality characteristics. These combinations can include multiple combinations of various network quality characteristics. The number of network quality characteristics in each combination is equal to the number of modules in the system under test (S10). The number of network quality characteristic combinations is less than or equal to m raised to the power of n, where m represents the total number of network quality characteristics and n represents the total number of modules in the system under test.

[0091] For example, multiple network quality characteristics may include the four quality characteristics mentioned above, from the first to the fourth. For instance, if the system under test S10 has three modules, the total number of combinations of network quality characteristics can be 4 to the power of 3. The network quality characteristic of the probe link corresponding to each module can be any one of the four network quality characteristics.

[0092] The correspondence between the aforementioned network anomaly locations and network quality distribution characteristics can be expressed as a correspondence between network anomaly locations and combinations of network quality characteristics. Accordingly, the network quality distribution characteristics of the system under test S10 determined above may include: combinations of network quality characteristics of the probe links corresponding to multiple modules (defined as target combinations). Accordingly, this target combination can be matched within the correspondence between network anomaly locations and combinations of network quality characteristics to obtain the network anomaly location corresponding to the target combination. Furthermore, the network anomaly location corresponding to the target combination can be used as the network anomaly location of the system under test S10.

[0093] In this embodiment, by unifying the management of multiple probes of the system under test (SUT), the network quality distribution characteristics of SUT can be determined based on the target detection data of the multiple probes. Furthermore, based on these network quality distribution characteristics, network anomaly localization can be performed on SUT, achieving anomaly localization based on the network quality distribution characteristics of SUT, thus providing a foundation for subsequent maintenance of SUT. Compared to the separate probe quality monitoring schemes in traditional approaches, this also shortens the time required for anomaly localization in SUT.

[0094] To facilitate understanding of the network anomaly localization method provided in the embodiments of this application, the system under test is taken as a network communication system as an example below, and combined with... Figure 2 and Figure 3 The provided network management system provides an exemplary description of the anomaly location method provided in the embodiments of this application for network anomaly location in a network communication system.

[0095] about Figure 2 The description of the network communication system S20 can be found in the relevant content of the management system embodiment of the system under test described above, and will not be repeated here. It is worth noting that... Figure 2 and Figure 3 The probes deployed on the user end, ISP side, and data center are all authorized by the user end owner, ISP, and data center owner.

[0096] For network communication system S20, such as Figure 2As shown, the probe management node 30 can acquire target detection data from multiple probes 20 of the network communication system S20 within a set time period. The multiple probes 20 are used to detect the network quality of the network communication system S20. To perform full-link detection of the network communication system S20, the detection range of the multiple probes 20 can be set to cover the entire network link of the network communication system S20, i.e., covering the entire network link of the network communication system S20. For a description of the set time period, please refer to the relevant content of the above-described embodiment of the system under test, which will not be repeated here.

[0097] Based on the acquired target detection data, the probe management node 30 can determine the network quality distribution characteristics of the network communication system S20 according to the target detection data of multiple probes of the network communication system; and perform network anomaly localization on the network communication system S20 according to the network quality distribution characteristics of the network communication system S20.

[0098] like Figure 2 As shown, the network communication system S20 may include multiple probes 20a deployed at the user terminal 21, multiple ISP probes 20b deployed at the ISP, and multiple cloud probes 20c deployed at the data center 23.

[0099] Among them, multiple user-end probes 20a can detect the network quality of the first network link and the second network link; multiple ISP probes 20b can detect the network quality of the second network link. Multiple cloud probes 20c can detect the network quality of the second network link and the third network link within the data center 23. For details on the implementation methods of probe network quality detection, please refer to the relevant content of the above-described embodiment of the system under test, which will not be repeated here.

[0100] Accordingly, when performing network anomaly location on the network communication system S20, the probe management node 30 can obtain target detection data of the user-end probe 20a within a set time period, target detection data of the ISP probe 20b within a set time period, and target detection data of the cloud probe 20c within a set time period.

[0101] Furthermore, the probe management node 30 can determine the network quality distribution characteristics of the network communication system S20 based on the target detection data of the user-end probe 20a within a set time period, the target detection data of the ISP probe 20b within a set time period, and the target detection data of the cloud probe 20c within a set time period.

[0102] Specifically, the probe management node 30 can determine the network quality of the probe link of the user-end probe 20a based on the target detection data of the user-end probe 20a within a set time period; and determine the network quality characteristics of the user-end probe 20a based on the network quality of the probe link of the user-end probe 20a.

[0103] Using the same method, the probe management node 30 can determine the network quality characteristics of the ISP probe 20b based on the target detection data of the ISP probe 20b within a set time period; and determine the network quality characteristics of the cloud probe 20c based on the target detection data of the cloud probe 20c within a set time period.

[0104] For a detailed implementation of determining the network quality of the probe's detection link based on the probe's target detection data, please refer to the judgment operations 1 and 2 above.

[0105] Furthermore, the probe management node 30 can determine the network quality distribution characteristics of the network communication system S20 based on the network quality characteristics of the user-end probe 20a, the ISP probe 20b, and the cloud probe 20c. Specifically, a combination of the network quality characteristics of the user-end probe 20a, the ISP probe 20b, and the cloud probe 20c can be used as the network quality distribution characteristics of the network communication system S20.

[0106] After determining the network quality distribution characteristics of the network communication system S20, the probe management node 30 can locate network anomalies in the network communication system based on the network quality distribution characteristics of the network communication system S20.

[0107] Specifically, the probe management node 30 can utilize the network quality distribution characteristics of the network communication system S20 to match the pre-set correspondence between network anomaly locations and network quality distribution characteristics, so as to obtain the network anomaly location corresponding to the network quality distribution characteristics of the network communication system S20, and use the network anomaly location as the network anomaly location of the network communication system.

[0108] The quality distribution characteristics in the correspondence between network anomaly locations and network quality distribution characteristics can be represented by combinations of network quality characteristics. These combinations can include multiple combinations of various network quality characteristics. The number of quality characteristics in each combination is equal to the number of modules in the network communication system S20. The number of network quality characteristic combinations is less than or equal to m raised to the power of n, where m represents the total number of network quality characteristic combinations and n represents the total number of modules in the network communication system.

[0109] The correspondence between the aforementioned network anomaly locations and network quality distribution characteristics can be expressed as a correspondence between network anomaly locations and combinations of network quality characteristics. Accordingly, the quality distribution characteristics of the network communication system S20 determined above may include: a combination of network quality characteristics of the user-end probe 20a, the ISP probe 20b, and the cloud probe 20c (defined as a target combination). Accordingly, this target combination can be matched within the correspondence between network anomaly locations and combinations of network quality characteristics to obtain the network anomaly location corresponding to the target combination. Furthermore, the network anomaly location corresponding to the target combination can be used as the network anomaly location of the network communication system S20.

[0110] The inventors of this application have discovered the correspondence between network anomaly locations and network quality distribution characteristics for non-inter-ISP network communication systems, as shown in Table 1 below. Here, "non-inter-ISP network communication system" refers to a network communication system whose ISP is the same operator.

[0111] Table 1. Correspondence between network anomaly locations and network quality distribution characteristics for access paths not spanning ISPs.

[0112]

[0113] Based on Table 1 above, the probe management node 30 can use the network quality distribution characteristics of the network communication system S20 to perform a match in Table 1. If no network quality distribution characteristics of the network communication system S20 are found in Table 1, then the network of the network communication system S20 is determined to be normal. If network quality distribution characteristics of the network communication system S20 are found in Table 1, then the network anomaly location corresponding to the network quality distribution characteristics of the network communication system S20 is determined as the network anomaly location of the network communication system S20. For example, if the network quality distribution characteristics of the network communication system S20 match the network quality distribution characteristics corresponding to the last set distance of the user terminal, then the network anomaly at the last set distance of the user terminal (such as the last 1 meter of the user terminal) is determined, and the network anomaly location is the last set distance of the user terminal.

[0114] In some embodiments of this application, the network communication system S20 is a cross-ISP network communication system, that is, the ISPs of the network communication system S20 are multiple telecommunications operators. For example, Figure 3As shown, the ISPs in the network communication system S20 include: a first ISP 22a and a second ISP 22b. The first ISP and the second ISP are different telecommunications operators. The second ISP 22b is connected to the first ISP 22a via a fourth network link. For example, the first ISP can be a domestic ISP, and the second ISP can be a foreign ISP. Accordingly, the fourth network link can be an international network. The first ISP 22a is connected to the data center 23 providing cloud services via a third network link (the first network). Figure 3 The illustration uses only the user terminal 21, which is the user terminal of the second ISP 22b, as an example, but it does not constitute a limitation. Figure 3 The diagram illustrates data center 23, which is the data center on the side of the first ISP 22a (such as a domestic data center).

[0115] The inventors discovered that, when both the first ISP 22a and the second ISP 22b are authorized to deploy probes, the ISP probe 20b includes: a probe deployed on the first ISP 22a, i.e., the first ISP probe, and a probe deployed on the second ISP 22b, i.e., the second ISP probe. The first ISP probe is used to probe a second network link. The second ISP probe is used to probe a fourth network link. The user-side probe can be used to probe the network link between the user end and the data center entry point, i.e., the first network link, the fourth network link, and the second network link. For cloud probes deployed in the data center on the first ISP side, they can be used to probe network links within the data center (the third network link) and network links between the data center and the first ISP (such as the second network link). For cloud probes deployed in the data center on the second ISP side, they can be used to probe network links within the data center and network links between the second ISP and the data center.

[0116] In this embodiment, Table 1 indicates that the user's access path does not cross ISPs. For example, for a first user (e.g., a domestic user) accessing data center 23 (defined as the first data center, e.g., a domestic data center), the first user's access path is: first user's client -> first ISP -> first data center 23. Or, for a second user (e.g., a foreign user) accessing a data center on the second ISP's side (defined as the second data center, e.g., a foreign data center), the user's access path is: second user's client -> second ISP -> second data center. This situation assumes that probes are authorized for deployment on the first foreign user's client, the first and second ISPs, and the cloud application service provider. The correspondence between network anomaly locations and network quality distribution characteristics in these application scenarios is shown in Table 1 above. Figure 3 Data center 23 is the first data center.

[0117] In this context, the first user refers to a user within the service area of ​​the first ISP (e.g., a domestic ISP), and the first data center refers to a data center within the service area of ​​the first ISP (e.g., a domestic ISP). The second user refers to a user within the service area of ​​the second ISP (e.g., a foreign ISP), and the second data center refers to a data center within the service area of ​​the second ISP (e.g., a foreign ISP).

[0118] In Table 1, for the scenario where the first user accesses the first data center, the client in Table 1 refers to the client of the first user; the data center in Table 1 refers to the first data center. For the scenario where the second user accesses the second data center, the client in Table 1 refers to the client of the second user; the data center in Table 1 refers to the second data center.

[0119] Table 2 shows the user's access path across ISPs. For example, for a first user (e.g., a domestic user) accessing a second data center (e.g., a foreign data center) providing cloud services, the access path is: First user's client -> First ISP -> Second ISP -> Second data center. As another example, for a second user accessing a first data center (e.g., a domestic data center) providing cloud services, the access path is: Second user's client -> Second ISP -> First ISP -> First data center. This scenario involves probes being deployed authorized at the client's client, the first and second ISPs, and the cloud service provider. The correspondence between network anomaly locations and network quality distribution characteristics in these application scenarios is shown in Table 2 below.

[0120] Table 2. Correspondence between network anomaly locations and network quality distribution characteristics in cross-ISP access paths.

[0121]

[0122] Based on Tables 1 and 2 above, the probe management node 30 can use the network quality distribution characteristics of the network communication system S20 to match them in Tables 1 and 2. If no network quality distribution characteristics of the network communication system S20 are found in Tables 1 and 2, then the network of the network communication system S20 is determined to be normal. If network quality distribution characteristics of the network communication system S20 are found in Tables 1 and 2, then the network anomaly location corresponding to the network quality distribution characteristics of the network communication system S20 is determined as the network anomaly location of the network communication system S20. For example, if the network quality distribution characteristics of the network communication system S20 match the network quality distribution characteristics corresponding to the last set distance of the user terminal, then the network anomaly at the last set distance of the user terminal (e.g., the last 1 meter of the user terminal) is determined, and the network anomaly location is the last set distance of the user terminal. In the scenario where the first user accesses the second data center, the user terminal in Table 2 is the user terminal of the first user; the data center in Table 2 is the second data center. In the scenario where the second user accesses the first data center, the user terminal in Table 2 is the user terminal of the second user; the data center in Table 2 is the first data center.

[0123] In some embodiments, for cross-ISP network communication systems, some ISPs in the network communication system may not be authorized to deploy probes. For example, the first ISP may be authorized to deploy probes, while the second ISP may not be authorized. In this application scenario, Figure 3 ISP probe 20b is a probe deployed at the first ISP, i.e., the first ISP probe, used to probe the network link between the first ISP and the network entry point of the data center. Figure 3 The second network link in the network. In this case, the inventors discovered the correspondence between network anomaly locations and network quality distribution characteristics, as shown in Tables 3-5 below.

[0124] The inventors of this application have discovered that, in an application scenario where the first ISP is authorized to deploy probes and the second ISP is not authorized to deploy probes, the correspondence between network anomaly locations and network quality distribution characteristics for a second user (such as a foreign user) accessing a first data center (such as a domestic data center) is shown in Table 3 below.

[0125] Table 3. Correspondence between Second User Accessing First Data Center—Network Anomaly Locations and Network Quality Distribution Characteristics

[0126]

[0127] In an application scenario where the first ISP is authorized to deploy probes and the second ISP is not authorized to deploy probes, the correspondence between network anomaly locations and network quality distribution characteristics for a first user (e.g., a domestic user) accessing a second data center (e.g., a foreign data center) is shown in Table 4 below.

[0128] Table 4. Correspondence between the location of network anomalies and network quality distribution characteristics when the first user accesses the second data center.

[0129]

[0130] In the application scenario where the first ISP is authorized to deploy probes and the second ISP is not authorized to deploy probes, the correspondence between the network anomaly location and the network quality distribution characteristics for the first user (e.g., a domestic user) accessing the first data center (domestic data center) is shown in Table 5 below.

[0131] Table 5. Correspondence between the first user accessing the first data center—network anomaly locations and network quality distribution characteristics.

[0132]

[0133]

[0134] Based on Table 3-5 above, the probe management node 30 can use the network quality distribution characteristics of the network communication system S20 to perform a match within Table 3-5. If no network quality distribution characteristics of the network communication system S20 are found in Table 3-5, then the network of the network communication system S20 is determined to be normal. If network quality distribution characteristics of the network communication system S20 are found in Table 3-5, then the network anomaly location corresponding to the network quality distribution characteristics of the network communication system S20 is determined as the network anomaly location of the network communication system S20. For example, if the network quality distribution characteristics of the network communication system S20 match the network quality distribution characteristics corresponding to the network anomaly location of the first ISP, then the network anomaly of the first ISP is determined, and the network anomaly location is the first ISP. As another example, if the network quality distribution characteristics of the network communication system S20 match the network quality distribution characteristics corresponding to the network anomaly location of the second ISP, then the network anomaly of the second ISP is determined, and the network anomaly location is the second ISP.

[0135] This embodiment can determine the network quality distribution characteristics of a network communication system based on probe data deployed by probes from other modules of the network communication system (such as the first ISP, the user terminal, and the cloud application provider) when some ISPs (such as the second ISP) in the network communication system are not authorized to deploy probes. Then, using these network quality distribution characteristics, a pre-built correspondence between network anomaly locations and network quality distribution characteristics (as shown in Tables 3-5) is queried to locate network anomalies in the network communication system. This enables network anomaly location even when probes from some ISPs (such as the second ISP) are missing. Even when network anomalies occur in ISPs lacking probes, the network anomaly location method provided in this application embodiment can still locate the anomaly.

[0136] It is worth noting that the minor anomalies, major anomalies, all anomalies, or all normal conditions corresponding to each detection link in Tables 1-5 above represent the quality characteristics of that detection link. Among them, minor anomalies are the first type of quality characteristic, major anomalies are the second type of quality characteristic, all anomalies are the third type of quality characteristic, and all normal conditions are the fourth type of quality characteristic.

[0137] The anomaly location method provided in this application can be applied not only to network anomaly location but also to anomaly location in other aspects. The process of applying it to anomaly location in other aspects is described below by way of example.

[0138] Figure 4a This is a schematic diagram of the structure of the management system provided in an embodiment of this application. Figure 4a As shown, the management system may include: System under Test S40. System under Test S40 refers to the system that needs to undergo service quality detection.

[0139] In this embodiment, the system under test (S40) may deploy multiple probes 40c to probe the service quality of the system under test (S40). The system under test (S40) may include a user terminal 40a and a server terminal 40d. The server terminal 40d may provide services through an application programming interface (API). Figure 4a The illustrations only use APIs from API-1 to API-n, but this does not constitute a limitation.

[0140] In this embodiment, the system under test S40 may further include a gateway 40b deployed between the user terminal 40a and the server terminal 40d. There may be one or more gateways 40b, where "multiple" refers to two or more. In this embodiment, probes 40c are deployed on both the user terminal 40a and the gateways 40b. The user terminal 40a may deploy at least one probe (e.g., probe 1). Each gateway 40b may deploy at least one probe (e.g., probe 2 or probe 3). Probes 40c can probe the service quality of the system under test by calling an API to obtain probe data.

[0141] Specifically, probe 40c is used to initiate an API call request to server 40d; if the API call is successful, it is determined that the access path of the API call request is normal.

[0142] In this embodiment, to achieve anomaly localization, the probe management node S50 can uniformly manage multiple probes 40c of the system under test S10. The anomaly localization performed in this embodiment does not identify the specific dimension of the anomaly. Network anomalies, system crashes, or program errors are all considered anomalies in this embodiment.

[0143] In this embodiment, probe 40c can initiate an API call request to server 40d; server 40d can respond to the API call request and return a response data packet. Probe 40c can send the response data packet as probe data to probe management node S50. Of course, the probe data of probe 40c may also include network quality parameters. For a description of the network quality parameters, please refer to the relevant content of the above embodiment, which will not be repeated here.

[0144] Probe 40c can initiate API call requests to multiple APIs of server 40d. Correspondingly, probe management node S50 can determine whether the access path of the API call requests is normal based on the success status of multiple API calls. Probe management node S50 can also determine whether the access path of the API scheduling request corresponding to the response data packets of each API call request is normal by analyzing the response data packets.

[0145] Specifically, for any response data packet Y received by any probe A, the probe management node S50 can parse the response data packet Y to obtain the parsing result; and based on the parsing result, determine whether the API call request corresponding to the response data packet Y was successful. If the API call request is successful, it is determined that the access path of the API call request is normal.

[0146] Specifically, the probe management node S50 can determine whether the API call to the API call request corresponding to the response data packet Y was successful through the following judgment operations:

[0147] Judgment Operation 3: The probe management node S50 can parse the response data packet Y to determine the protocol type of the response data packet. It determines whether the protocol type of the response data packet is the set protocol type;

[0148] Judgment Operation 4: The probe management node S50 can parse the response data packet Y to determine the payload content of the response data packet. It then determines whether the payload content matches the content requested by the API call request corresponding to response data packet Y.

[0149] If both judgments 3 and 4 above result in "yes," it is determined that the API call request corresponding to the response data packet was successful, and therefore the access path of the API call request is normal. If either judgment 3 or 4 results in "no," it is determined that the API call request corresponding to the response data packet failed, and therefore the access path of the API call request is normal.

[0150] Of course, the probe management node S50 can also determine whether the API call request was successful based on network quality parameters. Accordingly, the probe management node S50 can use the above-mentioned judgment operations 1 and 2 to determine whether the API call request was successful.

[0151] Specifically, the probe management node S50 can combine judgment operations 1-4 to determine whether the API call request was successful. The determination of success or failure based on the results of judgment operations 1-4 can be flexibly configured according to actual needs. For example, it can be configured that if all judgment operations 1-4 result in "yes," the API call request is considered successful; if any of the judgment operations 1-4 result in "no," the API call request is considered to have failed.

[0152] The inventors of this application have discovered that the quality of service (QoS) distribution characteristics of the system under test differ depending on the location of the anomaly. In the embodiments of this application, the QoS distribution characteristics of the system under test specifically refer to the distribution information of the QoS characteristics of the access paths of API call requests initiated by multiple probes of the system under test. This can include a combination of the QoS characteristics of the access paths corresponding to the API call requests initiated by the multiple probes of the system under test. The QoS characteristics of the access paths can reflect the success rate of the probes used to probe that path calling multiple API services provided by server 40d.

[0153] Based on the above analysis, when performing anomaly localization on the system under test, the probe management node S50 can acquire target detection data from multiple probes 40c within a set time period. Specifically, the probe management node S50 can acquire response data packets received by multiple probes 40c within the set time period as target detection data. In this embodiment, the probe management node S50 can perform real-time online network anomaly localization on the system under test. Of course, the probe management node S50 can also be used for offline network anomaly localization, periodic review of the service quality of the system under test, etc. Accordingly, the set time period can be a historical time period to be processed.

[0154] Based on the target detection data, the probe management node S50 can determine the service quality distribution characteristics of the system under test. Specifically, the probe management node S50 can determine the service quality of the access paths of API call requests initiated by multiple probes 40c based on the target detection data.

[0155] Optionally, for any probe A, the target probe data of probe A includes: multiple response data packets received by probe A when it calls multiple APIs. For any response data packet Y, the probe management node S50 can parse the response data packet to obtain the parsing result; and based on the parsing result, determine whether the API call corresponding to the API call request of the response data packet Y was successful.

[0156] By using the same or similar methods, it can be determined whether the API call corresponding to each response data packet received by probe A was successful. Based on the success status of the API call corresponding to each response data packet, the success status of probe A's API call is determined.

[0157] The success rate of an API call to probe A can be represented by the percentage of API call failures. Accordingly, the service quality characteristics of the access path of the API call request of probe A can be determined based on the percentage of API call failures of probe A.

[0158] Furthermore, the service quality distribution characteristics of the system under test (S40) can be determined based on the service quality characteristics of the access paths of the API call requests of each probe in S40. The service quality distribution characteristics of the system under test S40 include the service quality characteristics of the access paths of multiple probes.

[0159] After determining the quality of service distribution characteristics of the system under test S40, the probe management node S50 can locate anomalies in the system under test S40 based on the quality of service distribution characteristics of the system under test S40.

[0160] Specifically, the probe management node S50 can obtain the pre-stored correspondence between abnormal locations and service quality distribution features; and use the service quality distribution features of the system under test S40 to match the correspondence between abnormal locations and service quality distribution features to obtain the abnormal location corresponding to the service quality distribution features of the system under test S40; and take the abnormal location corresponding to the service quality distribution features of the system under test S40 as the abnormal location of the system under test S40.

[0161] The pre-stored correspondence between abnormal locations and service quality distribution characteristics was obtained by the inventors of this application through analysis of the probe detection data of the system under test.

[0162] In this embodiment, by unifying the management of multiple probes of the system under test, the service quality distribution characteristics of the system under test can be determined based on the target detection data of the multiple probes. Furthermore, based on these service quality distribution characteristics, anomaly localization of the system under test is achieved, realizing anomaly localization based on the service quality distribution characteristics of the system under test, thus providing a foundation for subsequent maintenance of the system under test. Compared to the separate probe quality monitoring schemes in traditional approaches, this also shortens the time required for anomaly localization in the system under test.

[0163] In addition to the above system embodiments, this application also provides a network anomaly location method, which will be described below as an example.

[0164] Figure 4b This is a flowchart illustrating the network anomaly localization method provided in an embodiment of this application. Figure 4b As shown, the method mainly includes:

[0165] 401. Acquire target detection data of multiple probes of the system under test within a set time period; multiple probes are used to detect the network quality of the system under test.

[0166] 402. Based on the target detection data, determine the network quality distribution characteristics of the system under test.

[0167] 403. Based on the network quality distribution characteristics of the system under test, locate network anomalies in the system under test.

[0168] In this embodiment, the description of the system under test can be found in the relevant content of the above system embodiment, and will not be repeated here. The system under test includes: multiple modules; multiple probes corresponding to the multiple modules; each module is equipped with at least one probe; the at least one probe corresponding to each module is used to detect the network quality of a portion of the links of the system under test; the detection range of the probes corresponding to the multiple modules (the multiple probes of the system under test) covers the entire network link of the system under test. Preferably, each module is equipped with multiple probes.

[0169] Based on the probe's detection data, it can be seen that the probe's access path and the network quality of the probe's detection link. Therefore, in this embodiment, to achieve network anomaly localization of the system under test, in step 401, target detection data of multiple probes of the system under test within a set time period can be obtained.

[0170] In this embodiment, network anomaly location can be performed online in real time. Accordingly, the set time period can be the time period during which the detection data is received in real time. For example, the last 5 minutes, 1 hour, etc.

[0171] Of course, it can also be used for offline network anomaly localization and periodic review of the network quality of the system under test. Accordingly, the set time period can be a historical time period to be processed. Correspondingly, target detection data of multiple probes on the system under test within the set time period can be obtained from the stored detection data, showing the target along the same access path.

[0172] The inventors of this application have discovered that the mass distribution characteristics of the system under test differ depending on the location of the anomaly. For a description of the mass distribution characteristics, please refer to the relevant content in the above system embodiments, which will not be repeated here.

[0173] Based on the target detection data, in step 402, the network quality distribution characteristics of the system under test can be determined according to the target detection data.

[0174] Specifically, the network quality of the probe links of multiple probes in the system under test can be determined based on the target detection data. Optionally, for any probe A, the source IP address and destination IP address of the probe link of probe A can be determined from the target detection data of probe A, and the network link between the source IP address and the destination IP address can be identified as the probe link of probe A. Furthermore, the network quality parameters of the probe link of probe A can be obtained from the target detection data of probe A; and the network quality of the probe link of probe A can be determined based on the network quality parameters of the probe link. For details on the quality parameters and the specific implementation of determining the network quality of the probe link based on the network quality parameters of the detection path, please refer to the relevant content of the above system embodiment, which will not be repeated here.

[0175] Using the same or similar methods, the network quality of the probe links of multiple probes in the system under test can be determined. Furthermore, based on the network quality of the probe links of the multiple probes in the system under test, the network quality distribution characteristics of the system under test can be determined.

[0176] In some embodiments, for any module, the proportion P of abnormal detection links corresponding to that module can be determined based on the network quality of the detection links corresponding to that module. For example, the ratio of the number N of abnormal detection links corresponding to the module to the total number M of detection links corresponding to module 10 is calculated, P = N / M. Where 0 ≤ N ≤ M. N and M are both integers, and M equals the number of probes corresponding to the module.

[0177] Furthermore, the quality characteristics of the detection link corresponding to module A can be determined based on the proportion of the anomaly detection link corresponding to module A.

[0178] For example, if the proportion of the anomaly detection link corresponding to the module is greater than 0 and less than or equal to the set first proportion, the network quality characteristics of the detection link corresponding to the module are determined to be the first type of quality characteristics.

[0179] If the proportion of abnormal detection links corresponding to a module is greater than or equal to a set second proportion, and less than 1, the network quality characteristic of the detection link corresponding to any module is determined to be a second type of quality characteristic; the second proportion is greater than the first proportion. Accordingly, the first type of quality characteristic can characterize a small number of anomalies in the detection links of multiple probes; the second type of quality characteristic can characterize a large number of anomalies in the detection links of multiple probes.

[0180] If the proportion of abnormal detection links corresponding to any module is equal to 1, the network quality characteristic of the detection link corresponding to any module is determined to be the third type of quality characteristic. The third type of quality characteristic can characterize that all detection links of multiple probes are abnormal.

[0181] If the percentage of abnormal detection links corresponding to any module is equal to 0, the network quality characteristic of the detection link corresponding to any module is determined to be the fourth type of quality characteristic. The fourth type of quality characteristic can characterize that all detection links of multiple probes are normal.

[0182] After determining the network quality characteristics of the probe links for each module, the network quality distribution characteristics of the system under test can be determined based on the network quality characteristics of the probe links corresponding to multiple modules. For example, the combination of the network quality characteristics of the probe links of multiple probes corresponding to multiple modules can be used as the network quality distribution characteristics of the system under test.

[0183] After determining the network quality distribution characteristics of the system under test, network anomalies can be located based on these characteristics.

[0184] Specifically, the correspondence between pre-stored network anomaly locations and network quality distribution features can be obtained; and the network quality distribution features of the system under test can be used to match the correspondence between network anomaly locations and network quality distribution features to obtain the network anomaly locations corresponding to the network quality distribution features of the system under test; and the network anomaly locations corresponding to the network quality distribution features of the system under test can be used as the network anomaly locations of the system under test.

[0185] The pre-stored correspondence between network anomaly locations and network quality distribution characteristics was obtained by the inventors of this application through analysis of the probe detection data of the system under test.

[0186] The quality distribution characteristics in the correspondence between network anomaly locations and network quality distribution characteristics can be represented by combinations of quality characteristics. These combinations can include multiple combinations of various quality characteristics. The correspondence between network anomaly locations and network quality distribution characteristics can be expressed as a correspondence between network anomaly locations and combinations of network quality characteristics. Accordingly, the network quality distribution characteristics of the system under test determined above can include combinations of network quality characteristics of probe links corresponding to multiple modules (defined as a target combination). This target combination can be matched against the correspondence between network anomaly locations and combinations of network quality characteristics to obtain the network anomaly location corresponding to the target combination. Furthermore, the network anomaly location corresponding to the target combination can be used as the network anomaly location of the system under test.

[0187] In this embodiment, by unifying the management of multiple probes of the system under test, the network quality distribution characteristics of the system under test can be determined based on the target detection data of the multiple probes. Furthermore, based on these network quality distribution characteristics, network anomaly localization can be performed on the system under test. This achieves network anomaly localization based on the network quality distribution characteristics of the system under test, providing a foundation for subsequent maintenance of the system under test. Compared to the separate probe quality monitoring schemes in traditional approaches, this also shortens the time required for network anomaly localization.

[0188] To facilitate understanding of the anomaly localization method provided in the embodiments of this application, the following uses a network communication system as an example to illustrate the process of network anomaly localization in a network communication system provided in the embodiments of this application.

[0189] Figure 5a This is a flowchart illustrating the network anomaly localization method provided in an embodiment of this application. Figure 5a As shown, the method includes:

[0190] 501. Acquire target detection data from multiple probes of the network communication system within a set time period; multiple probes are used to detect the network quality of the network communication system.

[0191] 502. Based on the target detection data, determine the network quality distribution characteristics of the network communication system.

[0192] 503. Based on the network quality distribution characteristics of the network communication system, locate network anomalies in the network communication system.

[0193] In this embodiment, all probes deployed in the network communication system have been authorized by their respective owners.

[0194] For a network communication system, in step 501, target detection data of multiple probes of the network communication system within a set time period can be acquired. In some embodiments, the detection range of the multiple probes can cover the network link of the network communication system, that is, cover the entire network link of the network communication system. For a description of the set time period, please refer to the relevant content of the above-described embodiment of the system under test, and it will not be repeated here.

[0195] Based on the acquired target detection data, in step 502, the network quality distribution characteristics of the network communication system can be determined according to the target detection data of multiple probes of the network communication system; and in step 503, the network anomaly location of the network communication system is performed according to the network quality distribution characteristics of the network communication system.

[0196] The aforementioned network communication system may include: a user terminal, an ISP, and a data center of the application service provider. For a description of the user terminal, ISP, and data center of the application service provider, please refer to the relevant content in the above system embodiments, which will not be repeated here. The network communication system may include: multiple user terminal probes deployed at the user terminal, multiple ISP probes deployed at the ISP, and multiple cloud probes deployed at the data center.

[0197] Among them, multiple user-end probes can detect the network quality of the first and second network links; multiple ISP probes can detect the network quality of the second network link; and multiple cloud probes can detect the network quality of the second network link and the third network link within the data center. For details on the implementation methods of probe network quality detection, please refer to the relevant content of the above-described embodiment of the system under test, which will not be repeated here.

[0198] Accordingly, when performing network anomaly localization on the network communication system, step 501 can be implemented as follows: acquiring target detection data of the user-end probe within a set time period, target detection data of the ISP probe within a set time period, and target detection data of the cloud probe within a set time period.

[0199] Furthermore, step 502 can be implemented as follows: determining the network quality distribution characteristics of the network communication system based on the target detection data of the user-end probe within a set time period, the target detection data of the ISP probe within a set time period, and the target detection data of the cloud probe within a set time period.

[0200] Specifically, the network quality of the probe's detection link can be determined based on the target detection data of the probe within a set time period; and the network quality characteristics of the probe can be determined based on the network quality of the probe's detection link.

[0201] Using the same method, the network quality characteristics of ISP probes can be determined based on the target detection data of ISP probes within a set time period; and the network quality characteristics of cloud probes can be determined based on the target detection data of cloud probes within a set time period.

[0202] Furthermore, the network quality distribution characteristics of the network communication system can be determined based on the network quality characteristics of the user-end probe, the ISP probe, and the cloud probe. Specifically, a combination of the network quality characteristics of the user-end probe, the ISP probe, and the cloud probe can be used as the network quality distribution characteristics of the network communication system.

[0203] After determining the network quality distribution characteristics of the network communication system, in step 503, network anomaly localization can be performed on the network communication system based on the network quality distribution characteristics.

[0204] Specifically, the network quality distribution characteristics of the network communication system can be used to match the pre-set correspondence between network anomaly locations and network quality distribution characteristics to obtain the network anomaly location corresponding to the network quality distribution characteristics of the network communication system, and this network anomaly location can be used as the network anomaly location of the network communication system.

[0205] The correspondence between network anomaly locations and network quality distribution characteristics can be found in Tables 1-5 above, and will not be repeated here.

[0206] The anomaly location method provided in this application can be applied not only to network anomaly location but also to anomaly location in other aspects. The process of applying it to anomaly location in other aspects is described below by way of example.

[0207] Figure 5b This is a flowchart illustrating the anomaly localization method provided in an embodiment of this application. Figure 5b As shown, the method mainly includes:

[0208] 51. Acquire target detection data of multiple probes of the system under test within a set time period; multiple probes are used to detect the service quality of the system under test.

[0209] 52. Based on the target detection data, determine the service quality distribution characteristics of the system under test.

[0210] 53. Based on the service quality distribution characteristics of the system under test, locate network anomalies in the system under test.

[0211] In this embodiment, the system under test (SUT) may deploy multiple probes to probe the service quality of the SUT. The SUT may include a client and a server. The server can provide services via an API. In this embodiment, the SUT may also include a gateway deployed between the client and the server. There may be one or more gateways, where "multiple" means two or more. In this embodiment, the client may deploy at least one probe. At least one probe may be deployed on each gateway. The probes can probe the service quality of the SUT by calling the API to obtain probe data.

[0212] Specifically, the probe is used to initiate API call requests to the server; if the API call is successful, it is determined that the access path of the API call request is normal. For specific implementation methods for determining whether an API call is successful, please refer to the relevant content of the above system embodiment, which will not be repeated here.

[0213] In this embodiment, to achieve anomaly localization, a probe management node can uniformly manage multiple probes of the system under test. The anomaly localization performed in this embodiment does not identify the specific dimension of the anomaly. Network anomalies, system crashes, or program errors are all considered anomalies in this embodiment.

[0214] In this embodiment, the probe can initiate an API call request to the server; the server can respond to the API call request and return a response data packet. The probe can then send the response data packet as probe data to the probe management node. Of course, the probe's probe data may also include network quality parameters. For a description of the network quality parameters, please refer to the relevant content in the above embodiments, which will not be repeated here.

[0215] The probe can initiate API call requests to multiple APIs on the server. Correspondingly, the probe management node can determine whether the access path of the API call requests is normal based on the success status of multiple API calls. The probe management node S50 can determine whether the access path of the API scheduling request corresponding to the response data packets of each API call request is normal by analyzing the response data packets.

[0216] The inventors of this application have discovered that the quality of service (QoS) distribution characteristics of a system under test differ depending on the location of the anomaly. Based on this analysis, when locating anomalies in the system under test, target detection data from multiple probes within a set time period can be acquired. Specifically, response data packets and network quality data received by multiple probes within the set time period can be acquired as target detection data.

[0217] Based on target probing data, the service quality distribution characteristics of the system under test can be determined. Specifically, the service quality of access paths for API call requests initiated by multiple probes can be determined based on the target probing data.

[0218] Optionally, for any probe A, the target probe data of probe A includes: multiple response data packets received by probe A when it calls multiple APIs. For any response data packet Y, the response data packet can be parsed to obtain the parsing result; and based on the parsing result, it can be determined whether the API call corresponding to the API call request of the response data packet Y was successful.

[0219] By using the same or similar methods, it can be determined whether the API call corresponding to each response data packet received by probe A was successful. Based on the success status of the API call corresponding to each response data packet, the success status of probe A's API call is determined.

[0220] The success rate of an API call to probe A can be represented by the percentage of API call failures. Accordingly, the service quality characteristics of the access path of the API call request of probe A can be determined based on the percentage of API call failures of probe A.

[0221] Furthermore, the service quality distribution characteristics of the system under test can be determined based on the service quality characteristics of the access paths of the API call requests of each probe in the system under test. These service quality distribution characteristics include the service quality characteristics of the access paths of multiple probes.

[0222] After determining the service quality distribution characteristics of the system under test, anomaly localization can be performed based on these characteristics.

[0223] Specifically, the probe management node can obtain the pre-stored correspondence between anomaly locations and service quality distribution features; and use the service quality distribution features of the system under test to match the correspondence between anomaly locations and service quality distribution features to obtain the anomaly location corresponding to the service quality distribution features of the system under test; and take the anomaly location corresponding to the service quality distribution features of the system under test as the anomaly location of the system under test.

[0224] The pre-stored correspondence between abnormal locations and service quality distribution characteristics was obtained by the inventors of this application through analysis of the probe detection data of the system under test.

[0225] In this embodiment, by unifying the management of multiple probes of the system under test, the service quality distribution characteristics of the system under test can be determined based on the target detection data of the multiple probes. Furthermore, based on these service quality distribution characteristics, anomaly localization of the system under test is achieved, realizing anomaly localization based on the service quality distribution characteristics of the system under test, thus providing a foundation for subsequent maintenance of the system under test. Compared to the separate probe quality monitoring schemes in traditional approaches, this also shortens the time required for anomaly localization in the system under test.

[0226] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 401 and 402 can be device A; or the execution subject of step 401 can be device A, and the execution subject of step 402 can be device B; and so on.

[0227] Furthermore, some processes described in the above embodiments and accompanying drawings include multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or they may be executed in parallel. The operation numbers, such as 401, 402, etc., are merely used to distinguish different operations and do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel.

[0228] It should also be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0229] Accordingly, embodiments of this application also provide a computer-readable storage medium storing computer instructions, which, when executed by one or more processors, cause one or more processors to perform the above-described network anomaly location method, and / or the steps in the anomaly location method.

[0230] Figure 6 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application. Figure 6 As shown, the computing device includes a memory 60a and a processor 60b. The memory 60a is used to store computer programs.

[0231] The processor 60b is coupled to the memory 60a and is used to execute a computer program for: acquiring target detection data of multiple probes of the system under test within a set time period; using the multiple probes to detect the network quality of the system under test; determining the network quality distribution characteristics of the system under test based on the target detection data; and locating network anomalies in the system under test based on the network quality distribution characteristics of the system under test.

[0232] Optionally, when determining the network quality distribution characteristics of the system under test based on the target detection data, the processor 60b is specifically used to: determine the network quality of the detection links of the system under test based on the target detection data; and determine the network quality distribution characteristics of the system under test based on the network quality of the detection links of the system under test.

[0233] In some embodiments, the system under test includes: multiple modules; each module is equipped with multiple probes for detecting the network quality of certain network links of the system under test.

[0234] Accordingly, when determining the network quality distribution characteristics of the system under test based on the network quality of the probe links of the system under test, the processor 60b is specifically used to: for any module among multiple modules, determine the proportion of abnormal probe links corresponding to any module based on the network quality of the probe links corresponding to any module; determine the network quality characteristics of the probe links corresponding to any module based on the proportion of abnormal probe links corresponding to any module; and determine the network quality distribution characteristics of the system under test based on the network quality characteristics of the probe links corresponding to the multiple modules respectively.

[0235] Furthermore, when determining the network quality characteristics of the detection links corresponding to any module based on the proportion of anomaly detection links corresponding to any module, the processor 60b specifically performs the following: if the proportion of anomaly detection links corresponding to any module is greater than 0 and less than or equal to a set first proportion, the network quality characteristics of the detection links corresponding to any module are determined to be a first type of quality characteristic; if the proportion of anomaly detection links corresponding to any module is greater than or equal to a set second proportion and less than 1, the network quality characteristics of the detection links corresponding to any module are determined to be a second type of quality characteristic; the second proportion is greater than the first proportion; if the proportion of anomaly detection links corresponding to any module is equal to 1, the network quality characteristics of the detection links corresponding to any module are determined to be a third type of quality characteristic; if the proportion of anomaly detection links corresponding to any module is equal to 0, the network quality characteristics of the detection links corresponding to any module are determined to be a fourth type of quality characteristic.

[0236] Optionally, when determining the network quality of the detection link of the system under test based on the target detection data, the processor 60b is specifically used to: for any probe, obtain the network quality parameters of the detection link detected by any probe from the target detection data of any probe; and determine the network quality of the detection link detected by any probe based on the network quality parameters of the detection link detected by any probe.

[0237] Optionally, when processor 60b performs anomaly localization on the system under test based on the network quality distribution characteristics of the system under test, it specifically performs the following: obtaining a pre-stored correspondence between network anomaly locations and network quality distribution characteristics; using the network quality distribution characteristics of the system under test, matching the correspondence between network anomaly locations and network quality distribution characteristics to obtain the network anomaly location corresponding to the network quality distribution characteristics of the system under test; and using the network anomaly location corresponding to the network quality distribution characteristics of the system under test as the network anomaly location of the system under test.

[0238] In some embodiments, the network quality distribution characteristics of the system under test include: target combinations of network quality characteristics of probe links corresponding to multiple modules respectively. Accordingly, when the processor 60b performs network anomaly localization on the system under test based on the network quality distribution characteristics, it is specifically used to: obtain a pre-stored correspondence between network anomaly locations and network quality feature combinations; the network quality feature combinations in the correspondence include: multiple combinations of multiple network quality features; using the target combination, match in the correspondence between network anomaly locations and network quality feature combinations to obtain the network anomaly location corresponding to the target combination; and use the network anomaly location corresponding to the target combination as the network anomaly location of the system under test.

[0239] In some embodiments of this application, the system under test can be implemented as a network communication system. The processor 60b is further configured to: acquire target detection data from multiple probes of the network communication system within a set time period; use the multiple probes to detect the network quality of the network communication system; determine the network quality distribution characteristics of the network communication system based on the target detection data; and locate network anomalies in the network communication system based on the network quality distribution characteristics.

[0240] The network communication system includes: user terminals, network service providers (ISPs), and application service providers' data centers; user terminals and ISPs communicate via a first network link; ISPs and application service providers communicate via a second network link; and service equipment in the data centers communicate with each other via a third network link.

[0241] The probes include: multiple user-end probes, multiple network service provider (ISP) probes, and multiple cloud probes; the multiple user-end probes are used to detect the network quality of the first and second network links; the multiple ISP probes are used to detect the network quality of the second network link; and the multiple cloud probes are used to detect the network quality of the third network link.

[0242] Accordingly, the target detection data includes: detection data from multiple user-end probes within a set time period, detection data from multiple ISP probes within a set time period, and detection data from multiple cloud probes within a set time period.

[0243] Accordingly, when determining the network quality distribution characteristics of the system under test based on the target detection data, the processor 60b is specifically used to: determine the network quality distribution characteristics of the network communication system based on the detection data of multiple user terminal probes within a set time period, the detection data of multiple ISP probes within a set time period, and the detection data of multiple cloud probes within a set time period.

[0244] In other embodiments of this application, the processor 60b is further configured to: acquire target detection data of multiple probes of the system under test within a set time period; use the multiple probes to detect the service quality of the system under test; determine the service quality distribution characteristics of the system under test based on the target detection data; and locate service anomalies in the system under test based on the service quality distribution characteristics of the system under test.

[0245] In some alternative implementations, such as Figure 6 As shown, the computing device may also include optional components such as a communication component 60c and a power supply component 60d. In some embodiments, the computing device may be implemented as a terminal device such as a mobile phone or a computer, and may also include components such as a display component 60e and an audio component 60f. Figure 6 The diagram only shows some components and does not mean that the computing device must contain them. Figure 6 The inclusion of all components does not imply that a computing device can only include... Figure 6 The components shown.

[0246] The computing device provided in this embodiment, through unified management of multiple probes of the system under test, can determine the network quality distribution characteristics of the system under test based on the target detection data of the multiple probes of the system under test; and based on the network quality distribution characteristics of the system under test, it can perform network anomaly localization of the system under test, realizing network anomaly localization of the system under test based on the quality distribution characteristics of the system under test, and providing a foundation for the subsequent maintenance of the system under test.

[0247] In this embodiment, the memory is used to store computer programs and can be configured to store various other data to support operation on its host device. The processor can execute the computer programs stored in the memory to implement corresponding control logic. The memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Electrically Programmable Read Only Memory (EPROM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0248] In the embodiments of this application, the processor can be any hardware processing device capable of executing the above-described method logic. Optionally, the processor can be a central processing unit (CPU), a graphics processing unit (GPU), or a microcontroller unit (MCU); it can also be a field-programmable gate array (FPGA), a programmable array logic (PAL), a general array logic (GAL), a complex programmable logic device (CPLD), or other programmable devices; or it can be an advanced RISC machine (ARM) or a system on chip (SoC), etc., but is not limited thereto.

[0249] In this embodiment, the communication component is configured to facilitate wired or wireless communication between its host device and other devices. The device housing the communication component can access wireless networks based on communication standards, such as WiFi, 2G or 3G, 4G, 5G, or combinations thereof. In one exemplary embodiment, the communication component receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In another exemplary embodiment, the communication component may also be implemented based on Near Field Communication (NFC), Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wideband (UWB), Bluetooth (BT), or other technologies.

[0250] In embodiments of this application, the display component may include a liquid crystal display (LCD) and a touch panel (TP). If the display component includes a touch panel, the display component can be implemented as a touchscreen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation.

[0251] In this embodiment, a power supply component is configured to provide power to various components of the device in which it resides. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which the power supply component resides.

[0252] In embodiments of this application, the audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC), which is configured to receive external audio signals when the device containing the audio component is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals can be further stored in memory or transmitted via a communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals. For example, in devices with voice interaction capabilities, voice interaction with the user can be achieved through the audio component.

[0253] It should be noted that the terms "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a chronological order, nor do they limit "first" and "second" to different types.

[0254] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, compact disc read-only memory (CD-ROM), optical storage, etc.) containing computer-usable program code.

[0255] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0256] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0257] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0258] In a typical configuration, a computing device includes one or more processors (CPU, etc.), input / output interfaces, network interfaces, and memory.

[0259] Memory may include non-persistent storage in computer-readable media, such as random-access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0260] Computer storage media are readable storage media, also known as removable media. Removable and non-removable media can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, Digital Video Disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient media, such as modulated data signals and carrier waves.

[0261] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the aforementioned element.

[0262] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for locating network anomalies, characterized in that, include: Acquire target detection data from multiple probes of the system under test within a set time period; The multiple probes are used to detect the network quality of the system under test; The system under test includes: multiple modules; each module is equipped with multiple probes to detect the network quality of some links in the system under test; Based on the target detection data, the network quality distribution characteristics of the system under test are determined; the network quality distribution characteristics include: target combinations of network quality characteristics of the detection links corresponding to the multiple modules respectively; Using the target combination, a match is made in a pre-stored correspondence between network anomaly locations and network quality feature combinations to obtain the network anomaly location corresponding to the target combination; the network quality feature combinations in the correspondence include multiple combinations of various network quality features; The network anomaly location corresponding to the target combination is taken as the network anomaly location of the system under test.

2. The method according to claim 1, characterized in that, Based on the target detection data, the network quality distribution characteristics of the system under test are determined, including: Based on the target detection data, determine the network quality of the detection link of the system under test; Based on the network quality of the probe link of the system under test, determine the network quality distribution characteristics of the system under test.

3. The method according to claim 2, characterized in that, The step of determining the network quality distribution characteristics of the system under test based on the network quality of the probe links of the system under test includes: For any one of the multiple modules, the proportion of abnormal detection links corresponding to any one module is determined based on the network quality of the detection link corresponding to that module. Based on the proportion of anomaly detection links corresponding to any module, determine the network quality characteristics of the detection links corresponding to any module; The network quality characteristics of the probe links corresponding to the multiple modules are combined to determine the network quality distribution characteristics of the system under test.

4. The method according to claim 3, characterized in that, The step of determining the network quality characteristics of the detection links corresponding to any module based on the proportion of abnormal detection links corresponding to any module includes: If the proportion of the abnormal detection link corresponding to any module is greater than 0 and less than or equal to the set first proportion, the network quality feature of the detection link corresponding to any module is determined to be the first type of quality feature. If the proportion of the anomaly detection link corresponding to any module is greater than or equal to the set second proportion, and less than 1, the network quality characteristic of the detection link corresponding to any module is determined to be the second type of quality characteristic; the second proportion is greater than the first proportion; If the proportion of the abnormal detection link corresponding to any module is equal to 1, the network quality characteristic of the detection link corresponding to any module is determined to be the third type of quality characteristic. If the proportion of the abnormal detection link corresponding to any module is equal to 0, the network quality characteristic of the detection link corresponding to any module is determined to be the fourth type of quality characteristic.

5. The method according to claim 2, characterized in that, Determining the network quality of the detection link of the system under test based on the target detection data includes: For any probe, obtain the network quality parameters of the probe link detected by the probe from the target detection data of the probe. The network quality of the probe link detected by any probe is determined based on the network quality parameters of the probe link detected by any probe.

6. The method according to any one of claims 1-5, characterized in that, The system under test is a network communication system; the multiple modules include: a user terminal, a network service provider (ISP), and a data center for providing cloud services; the user terminal and the ISP are connected via a first network link; the ISP and the data center are connected via a second network link; and the service devices within the data center are connected via a third network link. The probes of the system under test include: multiple user terminal probes, multiple ISP probes, and multiple cloud probes; The plurality of user-end probes are used to detect the network quality of the first network link and the second network link; The plurality of ISP probes are used to detect the network quality of the second network link; The plurality of cloud probes are used to detect the network quality of the second network link and the third network link; The step of determining the network quality distribution characteristics of the system under test based on the target detection data includes: Based on the detection data of the multiple user-end probes within a set time period, the detection data of the multiple ISP probes within a set time period, and the detection data of the multiple cloud probes within a set time period, the network quality distribution characteristics of the network communication system are determined.

7. An anomaly localization method, characterized in that, The anomaly localization method locates anomalies in the system under test. The system under test includes a user terminal, a server terminal, and a gateway located between the user terminal and the server terminal. The server terminal includes an application programming interface (API) and provides services through the API. The user terminal and the gateway are equipped with probes. The probes detect the service quality of the system under test by calling the API to obtain detection data. The method includes: Acquire target detection data from multiple probes of the system under test within a set time period; Based on the target detection data, the service quality distribution characteristics of the system under test are determined; the service quality distribution characteristics include: a combination of service quality characteristics of the access paths corresponding to API call requests initiated by multiple probes; By utilizing the service quality distribution characteristics of the system under test, a match is made between the pre-stored correspondence between abnormal locations and service quality distribution characteristics to obtain the abnormal locations corresponding to the service quality distribution characteristics of the system under test. The abnormal locations corresponding to the service quality distribution characteristics of the system under test are taken as the abnormal locations of the system under test.

8. A network management system, characterized in that, include: System under test and probe management node; The system under test is equipped with multiple probes; The multiple probes are used to perform network quality detection on the system under test in order to obtain detection data; The probe management node is used to perform the steps in the method according to any one of claims 1-6.

9. A management system, characterized in that, include: System under test and probe management node; The system under test includes: a user terminal, a server terminal, and a gateway located between the user terminal and the server terminal; the server terminal includes: an application programming interface (API) and provides services through the API; probes are deployed on the user terminal and the gateway. The probe detects the service quality of the system under test by calling the API to obtain detection data; The probe management node is used to perform the steps in the method of claim 7.

10. A computing device, characterized in that, include: A memory and a processor; wherein the memory is used to store computer programs; The processor is coupled to the memory for executing the computer program to perform the steps of the method according to any one of claims 1-7.

11. A computer-readable storage medium storing computer instructions, characterized in that, When the computer instructions are executed by one or more processors, the one or more processors cause the processors to perform the steps of the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Network fault detection method and system

    CN107835098A