A network inspection method, network device and network management device

CN116319398BActive Publication Date: 2026-08-07HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2022-05-07
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

当网络设备的数量很大时,一方面,网络管理设备采集网络数据的效率慢,需要采集的数据量大,对于网络管理设备有很大的性能压力

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319398B_ABST
    Figure CN116319398B_ABST
Patent Text Reader

Abstract

Disclosed are a network inspection method, a network device and a network management device, which are used to improve the efficiency of the network management device in inspecting the network device, reduce the amount of collected data, and improve the effectiveness of the collected network data. The method comprises the following steps: the network device acquires target inspection policy information, the target inspection policy information instructs the network device to collect inspection result information, and the inspection result information comprises first network data and second network data state information. In response to the network device meeting an inspection trigger condition, the network device acquires the inspection result information. The network device sends an inspection report to the network management device, so that the network management device determines a network inspection result according to the inspection report, and the inspection report comprises the inspection result information.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202111573878.0, filed on December 21, 2021, entitled "A Method, System and Apparatus for Network Monitoring", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of signal processing, and more particularly to a network inspection method, network device, and network management device. Background Technology

[0003] In order to monitor the health status of the network system, detect faults in the network system in a timely manner, and perceive changes in the status of network devices in the network system in real time, network management equipment needs to perform real-time monitoring and routine inspections of network devices to ensure that the network system can operate safely, stably, and reliably in the long term.

[0004] Current methods for obtaining network device status typically involve users remotely logging into the network device and entering command lines. These commands instruct the network device to collect specified raw network data, such as device logs and alarm information. The network management device then analyzes the collected raw data to determine the health status of the network device.

[0005] Existing network system inspection methods require users to input command lines one by one to obtain network data from multiple network devices. When the number of network devices is large, on the one hand, the network management device is slow in collecting network data and requires a large amount of data, placing a significant performance burden on the network management device. On the other hand, the network management device collects data from the network devices at that particular moment, resulting in low validity of the collected network data. Summary of the Invention

[0006] This application provides a network inspection method, network device, and network management device to improve the efficiency of network management device in inspecting network devices, reduce the amount of data collected, and enhance the effectiveness of the collected network data.

[0007] A first aspect of this application provides a network inspection method, comprising: a network device acquiring target inspection policy information, the target inspection policy information instructing the network device to collect inspection result information. The inspection result information includes first network data and second network data status information. The first network data is network data reported as instructed by the target inspection policy. The second network data status information indicates whether the second network data is abnormal, and the second network data is network data inspected as instructed by the target inspection policy information. In response to the network device meeting an inspection trigger condition, the network device acquires the inspection result information. The network device sends the inspection report to a network management device, so that the network management device determines the network inspection result based on the inspection report, the inspection report including the inspection result information.

[0008] In this possible implementation, the inspection report sent by the network device to the network management device includes inspection information, which includes first network data and second network data status information. The network device does not need to send the second network data, i.e., the raw network data, to the network management device, thus improving the efficiency of the network management device in obtaining information about the network device. On the other hand, the network management device does not need to analyze and process large amounts of raw data, reducing its workload and lowering its cost.

[0009] In one possible implementation of the first aspect, the network device obtains the target inspection policy information by: the network device receiving the target inspection policy information sent by the network management device; or the network device obtaining the target inspection policy information from a built-in inspection policy information database.

[0010] In this possible implementation, the network device can not only receive inspection policy information sent by the network management device, but also obtain inspection policy information from the built-in inspection policy information database, which increases the feasibility of this solution. At the same time, the built-in inspection policy information database of the network device enables the network device to perform network inspections without interacting with the network management device, reducing information interaction between the network management device and the network device and saving network resources.

[0011] In one possible implementation of the first aspect, the network device satisfies the inspection triggering conditions, including: the network device determines that an event indicating the target inspection policy information has occurred; or the network device determines that the parameters indicating the target inspection policy information meet a threshold condition; or the network device satisfies the time condition indicating the target inspection policy information.

[0012] In this possible implementation, the triggering condition for the inspection strategy information can be event triggering, parameter threshold triggering, or time condition triggering. The diversity of the triggering conditions for the inspection strategy information increases the diversity of the solutions in this application embodiment and increases the feasibility of this solution.

[0013] In one possible implementation of the first aspect, before the network device obtains the inspection result information, the method further includes: the network device converting the target inspection strategy information into executable information of the network device; correspondingly, the network device obtaining the inspection result information includes: the network device obtaining the inspection result information by executing the executable information.

[0014] In one possible implementation of the first aspect, the executable information mentioned above includes one or more of the following: scripts, commands, internal objects, or interfaces.

[0015] In one possible implementation of the first aspect, the network device acquires the inspection result information by: the network device acquiring the first network data and the second network data; and the network device determining the status information of the second network data based on the second network data.

[0016] In this possible implementation, after acquiring the second network data, the network device does not send the raw second network data to the network management device. Instead, it determines the status information of the second network data through logical judgment and other processing, and then sends this status information to the network management device. On the one hand, this reduces the amount of information in the inspection report sent by the network device to the network management device, reduces the waste of network resources, and improves the efficiency of network inspection. On the other hand, by processing the second network data in advance to determine the status information, the network device reduces the workload of the network management device, improves the efficiency of network inspection, and can also reduce the cost of the network management device.

[0017] In one possible implementation of the first aspect, the aforementioned inspection result information further includes the health information of the network device and / or fault snapshot information of abnormal second network data. The abnormal second network data is second network data with abnormal data status. The fault snapshot information includes the second network data with abnormal inspection results, as well as the corresponding context information, related configuration and status data of the abnormal second network data.

[0018] In one possible implementation of the first aspect, the network device acquiring the inspection result information further includes: the network device determining the number of entries of the abnormal second network data; and the network device determining the health information of the network device based on the number of entries of the abnormal second network data, the number of entries of the second network data, and the weight of the abnormal second network data.

[0019] In one possible implementation of the first aspect, the aforementioned inspection result information also includes the identifier of the target inspection strategy information.

[0020] In one possible implementation of the first aspect, the method further includes: the network device sending an inspection policy information acquisition request to the network management device, wherein the inspection policy information acquisition request instructs the network management device to send target inspection policy information to the network device.

[0021] A second aspect of this application provides a network inspection method, the method comprising: a network management device receiving a first inspection report sent by a first network device, the first inspection report including first inspection result information collected by the first network device according to the instruction of first inspection strategy information, the first inspection strategy information instructing the first network device to collect the first inspection result information. The first inspection result information includes first network data and second network data status information, the first network data being network data reported according to the target inspection strategy, the second network data status information indicating whether the second network data is abnormal, and the second network data being network data inspected according to the target inspection strategy information. The network management device determines the network inspection result based on the first inspection report.

[0022] In this possible implementation, the inspection report received by the network management device does not include the original second network data. Instead, it contains status information of the second network data determined through logical judgments and other processing. This reduces the amount of information sent by the network devices to the network management device in the inspection report, minimizing network resource waste and improving network inspection efficiency. Furthermore, by processing the second network data in advance to determine its status, the network management device's workload is reduced, further improving network inspection efficiency and lowering its costs.

[0023] In one possible implementation of the second aspect, the method further includes: the network management device generating the first inspection policy information according to the inspection policy set by the user; and the network management device sending the first inspection policy information to the first network device.

[0024] In this possible implementation, users can avoid manually issuing command lines to retrieve network data from network devices one by one. Instead, they can select inspection items that match their intent from the inspection item management library, generate inspection policy information, and send it to the network devices. This improves the efficiency of network inspection and reduces the time spent issuing network inspection tasks.

[0025] In one possible implementation of the second aspect, the network management device sends the first inspection policy information to the first network device, including: the network management device sends the first inspection policy information to the first network device through a network protocol, wherein the network protocol is one of File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Network Configuration Protocol (NETCONF), and Representational State Transition Configuration Protocol (RESTCONF).

[0026] In one possible implementation of the second aspect, the network management device determines the network inspection result based on the first inspection report, including: the network management device determines the network inspection result based on the first inspection result information.

[0027] In one possible implementation of the second aspect, the network inspection result includes the health information of the entire network system. The network management device determines the network inspection result based on the first inspection result information, including: the network management device acquiring the health information of the first network device; and the network management device determining the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device.

[0028] In one possible implementation of the second aspect, the network management device obtains the health information of the first network device by: the network management device determining the health information of the corresponding network device based on the number of abnormal second network data entries and the number of second network data entries in the first inspection report, wherein the abnormal second network data is second network data with abnormal data status.

[0029] In one possible implementation of the second aspect, the first inspection report includes the health information of the first network device, and the network management device obtains the health information of the first network device by: the network management device determining the health information of the first network device based on the first inspection report.

[0030] In one possible implementation of the second aspect, the network management device determines the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device, including: the network management device receiving a second inspection report sent by a second network device, the second inspection report including the second inspection result information of the corresponding second network device; the network management device acquiring the health information of the first network device and the health information of the second network device; and the network management device determining the health information of the entire network system based on the health information of the first network device, the health information of the second network device, the weight information corresponding to the first network device, and the weight information corresponding to the second network device.

[0031] In one possible implementation of the second aspect, the aforementioned first inspection result information also includes the health information of the first network device and / or fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

[0032] In one possible implementation of the second aspect, the first inspection strategy information includes a first inspection strategy identifier, the first inspection report includes a corresponding inspection strategy identifier, and the method further includes: if the first inspection strategy identifier is consistent with the first inspection report including a corresponding inspection strategy identifier, then the network management device determines the inspection strategy information corresponding to the first inspection report as the first inspection strategy information.

[0033] A third aspect of this application provides a network device comprising: a first acquisition module, configured to acquire target inspection policy information, the target inspection policy information instructing the network device to collect inspection result information, the inspection result information including first network data and second network data status information, the first network data being network data reported as instructed by the target inspection policy, and the second network data status information indicating whether the second network data is abnormal, the second network data being network data inspected as instructed by the target inspection policy. A second acquisition module, configured to acquire the inspection result information in response to the network device meeting an inspection trigger condition. A sending module, configured to send the inspection report to a network management device, so that the network management device determines the network inspection result based on the inspection report, the inspection report including the inspection result information.

[0034] In one possible implementation of the third aspect, the first acquisition module is specifically used to: receive target inspection policy information sent by the network management device; or acquire target inspection policy information from the built-in inspection policy information database.

[0035] In one possible implementation of the third aspect, the network device satisfies the inspection triggering conditions, including: the network device determines that an event indicating the target inspection policy information has occurred; or the network device determines that the parameters indicating the target inspection policy information meet a threshold condition; or the network device satisfies the time condition indicating the target inspection policy information.

[0036] In one possible implementation of the third aspect, the network device further includes a conversion module for converting the target inspection strategy information into executable information of the network device. Correspondingly, the second acquisition module is specifically used to acquire the inspection result information by executing the executable information.

[0037] In one possible implementation of the third aspect, the executable information mentioned above includes one or more of the following: scripts, commands, internal objects, or interfaces.

[0038] In one possible implementation of the third aspect, the second acquisition module includes: an acquisition unit for acquiring the first network data and the second network data; and a first determination unit for determining the status information of the second network data based on the second network data.

[0039] In one possible implementation of the third aspect, the aforementioned inspection result information also includes the health information of the network device and / or fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

[0040] In one possible implementation of the third aspect, the second acquisition module further includes: a second determining unit, configured to determine the number of entries of the abnormal second network data; and a third determining unit, configured to determine the health information of the network device based on the number of entries of the abnormal second network data, the number of entries of the second network data, and the weight of the abnormal second network data.

[0041] In one possible implementation of the third aspect, the aforementioned inspection result information also includes the identifier of the target inspection strategy information.

[0042] A fourth aspect of this application provides a network management device, comprising: a first receiving module, configured to receive a first inspection report sent by a first network device, the first inspection report including first inspection result information collected by the first network device according to the instruction of first inspection strategy information, the first inspection strategy information instructing the first network device to collect the first inspection result information, the first inspection result information including first network data and second network data status information, the first network data being network data reported according to the target inspection strategy, and the second network data status information indicating whether the second network data is abnormal, the second network data being network data inspected according to the target inspection strategy information; and a first determining module, configured to determine the network inspection result based on the first inspection report.

[0043] In one possible implementation of the third aspect, the network management device further includes: a generation module, configured to generate the first inspection policy information according to a user-defined inspection policy; and a sending module, configured to send the first inspection policy information to the first network device.

[0044] In one possible implementation of the third aspect, the aforementioned sending module is specifically used to: send the first inspection strategy information to the first network device via a network protocol, wherein the network protocol is one of the following: File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Network Configuration Protocol (NETCONF), Representative State Transition Configuration Protocol (RESTCONF), and Simple Network Management Protocol (SNMP).

[0045] In one possible implementation of the third aspect, the first determining module is specifically used to: determine the network inspection result based on the first inspection result information.

[0046] In one possible implementation of the third aspect, the network inspection results include health information of the entire network system, and the first determining module includes: an acquisition unit for acquiring the health information of the first network device; and a determining unit for determining the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device.

[0047] In one possible implementation of the third aspect, the aforementioned acquisition unit is specifically used to: determine the health information of the corresponding network device based on the number of abnormal second network data entries in the first inspection report and the number of second network data entries, wherein the abnormal second network data is second network data with abnormal data status.

[0048] In one possible implementation of the third aspect, the first inspection report includes the health information of the first network device, and the acquisition unit is specifically used to: determine the health information of the first network device based on the first inspection report.

[0049] In one possible implementation of the third aspect, the network management device further includes: a second receiving module, configured to receive a second inspection report sent by the second network device, the second inspection report including the second inspection result information of the corresponding second network device; and an acquisition module, configured to acquire the health information of the first network device and the health information of the second network device. Accordingly, the acquisition unit is specifically configured to: determine the health information of the entire network system based on the health information of the first network device, the health information of the second network device, the weight information corresponding to the first network device, and the weight information corresponding to the second network device.

[0050] In one possible implementation of the third aspect, the aforementioned first inspection result information also includes the health information of the first network device and / or fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

[0051] In one possible implementation of the third aspect, the first inspection strategy information includes a first inspection strategy identifier, the first inspection report includes a corresponding inspection strategy identifier, and the network management device further includes: a second determining module, used to determine the inspection strategy information corresponding to the first inspection report as the first inspection strategy information if the first inspection strategy identifier is consistent with the first inspection report including a corresponding inspection strategy identifier.

[0052] A fifth aspect of this application provides a network device that has the function of implementing the method of the first aspect or any possible implementation of the first aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function, such as an acquisition module.

[0053] A sixth aspect of this application provides a network management device that has the function of implementing the method of the second aspect or any possible implementation of the second aspect. This function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above-described function, such as a transmission module.

[0054] A seventh aspect of this application provides a network device including at least one processor, a memory, an input / output (I / O) interface, and computer-executable instructions stored in the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the processor executes a method as described in the first aspect or any possible implementation thereof.

[0055] The eighth aspect of this application provides a network management device, which includes at least one processor, a memory, an input / output (I / O) interface, and computer-executable instructions stored in the memory and executable on the processor. When the computer-executable instructions are executed by the processor, the processor executes a method as described in the second aspect above or any possible implementation of the second aspect.

[0056] The ninth aspect of this application provides a computer-readable storage medium storing one or more computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor performs a method as described in the first aspect or any possible implementation thereof.

[0057] The tenth aspect of this application provides a computer-readable storage medium storing one or more computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor performs a method as described in the second aspect above or any possible implementation thereof.

[0058] The eleventh aspect of this application provides a computer program product that stores one or more computer execution instructions, wherein when the computer execution instructions are executed by a processor, the processor executes a method as described in the first aspect or any possible implementation thereof.

[0059] The twelfth aspect of this application provides a computer program product storing one or more computer-executable instructions, wherein when the computer-executable instructions are executed by a processor, the processor executes a method as described in the second aspect above or any possible implementation thereof.

[0060] The thirteenth aspect of this application provides a chip system including at least one processor for implementing the functions described in the first aspect or any possible implementation thereof. In one possible design, the chip system may further include a memory for storing program instructions and data necessary for processing artificial intelligence models. This chip system may be composed of chips or may include chips and other discrete devices.

[0061] The fourteenth aspect of this application provides a chip system including at least one processor for implementing the functions involved in the second aspect or any possible implementation thereof. In one possible design, the chip system may further include a memory for storing program instructions and data necessary for data processing based on an artificial intelligence model. This chip system may be composed of chips or may include chips and other discrete devices.

[0062] The fifteenth aspect of this application provides a communication apparatus for use as a network device, the communication apparatus comprising: a memory including instructions; and a processor, which, when executing the instructions, causes the communication apparatus to implement the method of the first aspect or any possible implementation thereof.

[0063] The sixteenth aspect of this application provides a communication device for use as a network device, the communication device comprising: a memory including instructions; and a processor, which, when executing the instructions, causes the communication device to implement the method of the second aspect or any possible implementation thereof.

[0064] The seventeenth aspect of this application provides a network inspection system, which includes a network device and a network management device. The network device implements the method of the first aspect or any possible implementation of the first aspect, and the network management device implements the method of the second aspect or any possible implementation of the second aspect.

[0065] The eighteenth aspect of this application provides a computer program product, including a computer program that, when executed by a processor, implements the method in the first aspect, any possible implementation of the first aspect, the second aspect, or any possible implementation of the second aspect.

[0066] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:

[0067] In this embodiment, the network management device no longer interacts with the network devices using raw data, but rather with processed and analyzed status data. This reduces the amount of data collected and increases the speed and efficiency of network inspection. Furthermore, the network management device sends inspection strategy information to the network devices, allowing them to perform self-inspections, thus improving inspection efficiency. On the other hand, the data reported by the network management device through inspection reports can be data related to status anomalies, resulting in highly effective collected network data. Attached Figure Description

[0068] Figure 1 This is a schematic diagram of a network system scenario;

[0069] Figure 2 This is a network architecture diagram of the network inspection method in the embodiments of this application;

[0070] Figure 3 This is a flowchart illustrating a network inspection method in an embodiment of this application.

[0071] Figure 4 This is a signaling interaction diagram of the network inspection method in the embodiments of this application;

[0072] Figure 5 This is a schematic diagram of a scenario for generating inspection strategy information in an embodiment of this application;

[0073] Figure 6 This is a schematic diagram of the structure of a network device in an embodiment of this application;

[0074] Figure 7 This is another structural diagram of the network device in this application embodiment;

[0075] Figure 8 This is a schematic diagram of the network management device in an embodiment of this application;

[0076] Figure 9 This is another structural schematic diagram of the network management device in the embodiments of this application;

[0077] Figure 10 This is another structural diagram of the network device in this application embodiment;

[0078] Figure 11 This is another structural schematic diagram of the network management device in the embodiments of this application;

[0079] Figure 12 This is a schematic diagram of the network system in an embodiment of this application. Detailed Implementation

[0080] This application provides a network inspection method, network device, and network management device to improve the efficiency of network management device in inspecting network devices, reduce the amount of data collected, and enhance the effectiveness of the collected network data.

[0081] The embodiments of this application are described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. As those skilled in the art will understand, with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0082] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0083] like Figure 1 As shown, in order to monitor the health status of the network system, promptly detect faults, and perceive changes in the status of network devices in real time, network management equipment needs to perform real-time monitoring and routine inspections of network devices to ensure the long-term safe, stable, and reliable operation of the network system. In this method of obtaining network device status, users typically remotely log in to the network device and input command lines to instruct the network device to collect specified raw network data, such as device logs and alarm information. After collecting the raw data, the network management equipment analyzes it to determine the health status of the network devices.

[0084] like Figure 2 As shown in the illustration, this application provides a network inspection method applied to a network system. The network system includes a network management device and multiple network devices. The network management device can exchange information with any one of the network devices, and the multiple network devices can also exchange data with an external server. The network inspection method includes: a network device acquiring inspection policy information, which instructs the network device to collect inspection result information. The inspection result information includes first network data and second network data status information. The first network data is the network data reported according to the inspection policy, and the second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected according to the inspection policy information. If the network device determines that the inspection triggering condition corresponding to the inspection policy information is met, the network device acquires the inspection result information. The network device then generates an inspection report based on the inspection result information. The inspection report includes the identifiers of the inspection result information and the inspection policy information. The network device then sends the generated inspection report to the network management device, enabling the network management device to determine network health information based on the inspection report.

[0085] Based on the above network system, the network terminal identification method in the embodiments of this application is described below.

[0086] Figure 3 This is a flowchart illustrating a network inspection method provided in an embodiment of this application. Figure 3 As shown, the method flow includes the following multiple steps.

[0087] 301. Network management devices generate inspection strategy information.

[0088] The network management device generates inspection policy information based on the policy content set by the user. The inspection policy information includes the corresponding inspection policy identifier and instructs the corresponding network device to collect the inspection result information indicated by the inspection policy information.

[0089] Specifically, such as Figure 4 As shown, the network management device has a built-in inspection item management library, which stores multiple inspection items. Each inspection item corresponds to an inspection policy, and each item can instruct the network device to inspect the status of multiple secondary network data. Individual inspection policy content needs to be edited and verified in advance before being added to the inspection item management library. The network management device can generate inspection policy information based on user settings, i.e., the user's inspection intent.

[0090] like Figure 5 As shown, users can select different inspection templates on the network management device, and any inspection template can include multiple inspection items. For example... Figure 5 The first module includes inspection items, namely: pre-inspection equipment status check, basic configuration check, IP routing check, network access check, security configuration specification check, system management status check, system management check, version, IPv6 transformation assessment, and early warning rectification. When the user selects the basic configuration check, network access check, security configuration specification check, system management status check, and system management check in this module, the network management device generates inspection policy information based on these inspection items selected by the user.

[0091] In this embodiment, users can set different inspection strategy information according to their different inspection intentions. In addition, users can also set corresponding inspection strategy information based on the importance, type, and network area hierarchy of network devices. The network management device can also preset different inspection templates based on the importance, type, and network area hierarchy of different network devices. For example, in this embodiment, for inspection items with preset weight information, users can modify the weight information of different inspection items when setting inspection information. Users can modify and adjust the weight information of different inspection items in the inspection strategy information according to their own inspection intentions, increasing the weight of inspection items with high importance and decreasing the weight of inspection items with low importance. Users can also set the weight of some inspection items to zero, that is, only inspect these inspection items, and not calculate these inspection items when calculating network inspection results such as health information; this is not limited here.

[0092] For multiple network devices, users can also generate different inspection policy information to instruct the order in which different network devices perform inspection tasks. For example, users can set different inspection policy information for different network devices, specifying the time for performing inspection tasks. Users can set different times for performing inspection tasks to determine the order in which different network devices perform inspection tasks. For different inspection policy information for the same network device, as well as different inspection items under the same inspection policy information, users can also set different inspection sequences.

[0093] In this embodiment, users can not only set different inspection strategy information according to the inspection templates and inspection items provided by the network management device, but also manage the inspection item management library. For example, users can import inspection templates and inspection items from external sources, write new inspection templates and inspection items on the network management device, and delete or modify the inspection templates and inspection items in the inspection item management library. The specifics are not limited here.

[0094] In this embodiment of the application, the inspection policy information generated by the network management device may include the following information:

[0095] a. Inspection Identifier. The inspection identifier can include the identifier of the inspection strategy information and the identifier of the inspection item in the inspection strategy information. This identifier can be an ID, number, name, etc., and the specifics are not limited here.

[0096] b. The triggering method of the inspection task corresponding to the inspection strategy information.

[0097] The triggering method for the inspection task in this application embodiment may include:

[0098] 1. Event-triggered: When a network device experiences an event indicated by the inspection policy information, the network device is triggered to execute the inspection task. Examples include after each network device upgrade, the appearance of specified information in the network device's logs, network device alarms, or the creation and state changes of objects obtained by the network device through Simple Network Management Protocol (SNMP), Network Configuration Protocol (NETCONF), Representational State Transfer Configuration Protocol (RESTCONF), or command-line interface (CLI). Other events can also trigger the network device to execute the inspection task; specific details are not limited here.

[0099] 2. Threshold triggering: When a certain data indicator of a network device exceeds the threshold indicated by the inspection policy information, the network device is triggered to execute an inspection task. For example, when the utilization rate of the network device's central processing unit (CPU) is greater than 80%, the network device is triggered to execute an inspection task.

[0100] 3. Periodic triggering: At a specific time or period based on the network device's calendar, the network device is triggered to perform inspection tasks, such as every hour or at a fixed time of 2:00 AM every day. The specifics are not limited here.

[0101] 4. One-time trigger: The network device is triggered to perform the inspection task at a specified time based on the network device calendar. For example, the corresponding inspection task is executed at a time specified by a certain inspection policy information, such as 16:00 on May 5, 2022; or the corresponding inspection task is executed immediately when the network device receives the inspection policy information, etc. The specifics are not limited here.

[0102] The triggering method for the inspection task in this application embodiment includes, but is not limited to, the above methods, and may also be other methods, such as a combination of the above triggering methods, AND, OR, NOT logical operations of a single event or multiple events, etc. For example, when the CPU utilization of the network device is greater than 80% or after the network device is upgraded, the network device executes the corresponding inspection task. The specific method is not limited here.

[0103] In this embodiment of the application, the network device will only check whether the triggering conditions of certain inspection policy information are met after receiving the corresponding enable notification from the network management device. That is, the network device will not check whether the triggering conditions of the inspection policy information are met before that, but will only save the inspection policy information.

[0104] c. Execution actions of inspection items.

[0105] The execution actions of the inspection items in this application embodiment can be CLI commands, SNMP or NETCONF, RESTCONF actions, (GNU Bourne-AgainShell, Bash) scripts, Python scripts, Ruby scripts, ToolCommand Language (TCL) scripts, executable files, etc., as well as single or multiple analysis and judgment logic of data.

[0106] After the network management device can arrange the inspection strategy information according to the user's settings, the network management device can generate a health scoring task table based on the inspection strategy information. This health scoring task table is used to determine the health information of the corresponding network device based on the inspection results.

[0107] In this embodiment, users can select inspection items that match their intent from the inspection items provided in the inspection item management library instead of manually issuing command lines to obtain network data from network devices one by one. This generates inspection policy information and sends it to the network devices, improving the efficiency of network inspection and reducing the time spent issuing network inspection tasks.

[0108] 302. Network devices acquire inspection strategy information.

[0109] The network management device sends the inspection policy information to the corresponding network device, which instructs the network device to obtain the corresponding inspection result information. Accordingly, the network device receives the inspection policy sent by the network management device.

[0110] The network management device sends inspection policy information to the network device through a network protocol, which can be any of the following protocols: File Transfer Protocol (FTP), Secure File Transfer Protocol (SSH), NETCONF, RESTCONF, or SNMP.

[0111] Specifically, the inspection strategy information obtained by network devices may be implemented in various ways, such as the Yet Another Next Generation (YANG) model or JavaScript object notation (JSON) files. If the inspection strategy information is modeled using the YANG model, it can be distributed via network management protocols such as NETCONF or RESTCONF. If it is another form of inspection strategy, it can be distributed via file transfer protocols such as FTP or SFTP.

[0112] For inspection policy information in YANG model or JSON file format, the network device will parse and convert the inspection policy information into information that the network device can execute, that is, scripts, internal objects, and / or interfaces that the inspection execution module within the network device can understand. For inspection policy information in the form of executable scripts such as Python or TCL, it will be stored and loaded in a specific space within the network device.

[0113] For example, the inspection strategy information in the form of a JSON file is shown below:

[0114]

[0115] The inspection policy information in JSON format indicates the name of the inspection policy arpCheck, the inspection item xpath of the inspection policy, the trigger condition e1, the execution method of the inspection task: to obtain the value of the node object of xpath through the netconf protocol, the output result arpUsedNum, and the defined condition for inspection failure is that arpUsedNum is greater than 100000.

[0116] For example, an inspection strategy message is sent via the NETCONF protocol, as follows:

[0117]

[0118]

[0119] Similar to the inspection policy information in JSON file format mentioned above, this inspection policy, issued via the NETCONF protocol, specifies the name of the inspection policy (arpCheck), the inspection item (xpath), the trigger condition (e1), the execution method of the inspection task (obtaining the value of the node object of the xpath via the netconf protocol), the output result (arpUsedNum), and defines the condition for inspection failure as arpUsedNum being greater than 100000.

[0120] In this embodiment, for the inspection policy information already sent to the network device and the inspection policy information in the network device's inspection policy information database, the network management device can also send inspection policy management notifications to the network device to manage these inspection policy information. These management operations can include querying, modifying, deleting, enabling, and disabling the inspection policy information, and can also disable periodically triggered inspection policies. For example, if a network management device sends disabled inspection policy information to the network device, the network device will only check whether the triggering conditions of the inspection policy information are met after receiving the corresponding enable notification from the network management device. In addition, the network device can also perform management operations such as querying, modifying, deleting, enabling, and disabling these inspection policy information; the specifics are not limited here.

[0121] One possible implementation is, such as Figure 4 As shown, the network device has a built-in inspection policy information database. Some inspection policies in this database are already enabled, meaning the network device is constantly monitoring whether the trigger conditions corresponding to these inspection policies are met. When the trigger condition for a certain inspection policy is met, the network device can determine the inspection policy based on that condition. For example, the network device can determine the identifier of the corresponding inspection policy based on the trigger condition, and then determine the corresponding inspection policy in the inspection policy information database based on that identifier. The network device can then retrieve the inspection policy information from the built-in database and execute the inspection task corresponding to that policy. Alternatively, step 301 can be omitted; the network device can retrieve inspection policy information from the built-in database, and this information is similar to the inspection policy information sent by the network management device.

[0122] In one possible implementation, the network device receives inspection policy retrieval information sent by the network management device. This inspection policy retrieval information does not include a specific inspection policy, but rather includes an inspection policy information identifier or a network address of the inspection policy information. After receiving the inspection policy retrieval information, the network device can retrieve the corresponding inspection policy information based on this information. For example, if the inspection policy retrieval information sent by the network management device includes an inspection policy information identifier, the network device can retrieve the corresponding inspection policy information from its built-in inspection policy information database based on this identifier. Alternatively, if the inspection policy retrieval information sent by the network management device includes a Universal Resource Locator (URL), this URL can include the network address, identifier, and processing method of one or more inspection policy retrieval information entries. The network device can access an external server based on the network address indicated by the URL and retrieve the inspection policy information indicated by the URL.

[0123] 303. Network devices convert inspection strategy information into executable information.

[0124] The network device converts the acquired inspection policy information into executable information, which includes scripts, commands, internal objects, and / or interfaces.

[0125] In this embodiment of the application, the inspection policy information obtained by the network device may include corresponding execution actions. For details, please refer to the description of the execution actions of the inspection items in step 301. After the network device obtains the inspection policy information, it does not need to perform any conversion and can directly execute the execution actions included in the inspection policy information. That is, step 303 can be omitted. The specifics are not limited here.

[0126] For example, the inspection policy information in JSON file format sent by the network management device in step 302, or the inspection policy issued via the NETCONF protocol, after being converted by the network device, has the following internal interface:

[0127]

[0128] Based on the network device's conversion, the network device can determine the name of the inspection policy, arpCheck, the inspection item xpath of the inspection policy, the trigger condition e1, the execution method of the inspection task, which is to obtain the value of the node object of xpath through the netconf protocol, the output result arpUsedNum, and the condition for inspection failure is defined as arpUsedNum being greater than 100000.

[0129] In one possible implementation, when a network device fails to convert inspection policy information, it sends a conversion failure notification to the network management device. This notification indicates that the network device has failed to convert inspection policy information, allowing the network management device to perform corresponding management operations and avoid unnecessary waiting.

[0130] 304. Network devices obtain inspection results information.

[0131] If the network device meets the inspection triggering conditions corresponding to the inspection strategy information, in response to the network device meeting the inspection triggering conditions, the network device can obtain the inspection result information by executing the inspection task.

[0132] The inspection task in this embodiment can be triggered by event triggering, threshold triggering, periodic triggering, one-time triggering, or a combination of the above triggering methods. For details, please refer to the description of the triggering method of the inspection task in step 301 above, which will not be repeated here.

[0133] In this embodiment, the network device obtains the instructed inspection result information by executing an inspection task based on the inspection strategy information. This inspection result information includes first network data and second network data status information. The first network data is the network data instructed to be reported by the inspection strategy information; that is, the information that the network device customized by the inspection strategy needs to report to the network management device. The network management system can perform performance and status analysis on the network device and the entire network based on the first network data. The second network data is the network data instructed to be inspected by the inspection strategy information; that is, the data that the inspection strategy information specifies for checking whether the network device's status is abnormal, and the second network data status information indicates whether the second network data is abnormal. The second network data status information can be used by the network device to determine the results of the inspection items in the inspection strategy information.

[0134] Specifically, in this embodiment, the network device executes inspection tasks according to the inspection strategy information and collects inspection result information. The network device executes the executable information converted by the network device and collects the first network data that the network device needs to report to the network management device. It also collects the second network data or the status information of the second network data. For the second network data without direct status information, the network device will determine whether the status of the second network data is abnormal, thereby determining the status information of the second network data.

[0135] In this embodiment of the application, the network device executes inspection tasks according to the inspection strategy information in the following ways: SNMP, NETCONF, CLI, telemetry, and internal device interfaces.

[0136] In one possible implementation, when the inspection strategy information indicates that the executable information for the inspection task includes a script from an external server, and specifies the script name and the server address where it is stored, the network device can obtain and execute this script from the remote FTP / SFTP server to obtain the corresponding inspection result information. This executable information may also include internal objects, commands, and / or interfaces of the external server; the network device can also execute the corresponding inspection task to obtain this part of the inspection result information.

[0137] In one possible implementation, when the second network data status information is abnormal, i.e., when the inspection item corresponding to the second network data status information is abnormal, the network device can collect and save the abnormal second network data, including related data of the second network data. Specifically, when the network device determines that the inspection result of a certain inspection item is abnormal, the network device can collect and save the fault snapshot information related to that inspection item. This fault snapshot information includes the second network data corresponding to the inspection item with the abnormal inspection result, as well as the corresponding context information, related configuration, and status data.

[0138] In one possible implementation, if the network device fails to obtain inspection result information or times out, or if the inspection task fails to execute, the network device will send an inspection failure notification to the network management device. This notification instructs the network device to perform the corresponding management operation, thus preventing the network management device from waiting in vain.

[0139] 305. Network equipment generates inspection reports.

[0140] The network device generates an inspection report based on the obtained inspection results information. The inspection results report includes the network device's inspection results information, namely the obtained first network data and second network data status information.

[0141] In one possible implementation, the inspection report also includes network device health information. This health information is an indicator of the normal operating status of the network device. It is affected by the frequency, timing, and importance of abnormal network data caused by malfunctions. Therefore, the normal operating level of the network device can be evaluated based on its health information. The lower the proportion of abnormal inspection items to all inspection items, the lower the weight of the abnormal inspection item, indicating a higher degree of normal operation and a higher health level for the network device. The weight of each inspection item is determined based on factors such as its importance and the amount of inspection data.

[0142] In this embodiment, the network device determines its health based on the number of abnormal second network data entries, the total number of second network data entries, and the weight of the abnormal second network data. The lower the proportion of abnormal second network data entries to the total number of second network data entries, and the lower the weight of the abnormal second network data, the higher the degree of normal operation of the network device, and the higher its health. For example, if a network device has four inspection items: processor operating status, network bandwidth below a threshold, alarm information, and fault information, with a weight of 2 for processor operating status and fault information, and a weight of 1 for network bandwidth below a threshold and alarm information, and the abnormal inspection items are network bandwidth below a threshold and fault information, then the health of this network device is (1*1+1*2) / 4 = 0.75.

[0143] In one possible implementation, the inspection report also includes an identifier for the network device's inspection policy information and an identifier for each inspection item in the inspection policy information. Receiving the identifier for the inspection policy information and the identifier for each inspection item in the inspection policy information can be used to determine which inspection policy information and which inspection items the inspection report is responding to.

[0144] In one possible implementation, the inspection report also includes fault snapshot information related to the abnormal inspection item. This fault snapshot information includes the corresponding context information, relevant configuration, and status data of the trading venue inspection item. That is, for the status information of the second network data that is abnormal, the inspection report may include the abnormal second network data and its context information, relevant configuration, and status information.

[0145] In this embodiment, the inspection report may include the inspection results of the current inspection. In addition, the network device also stores historical inspection results from previous inspections. For a specific anomaly or object, the inspection report may also include historical inspection results for that anomaly or object. For example, regarding an abnormal processor operating temperature, if the current inspection finds an abnormal processor operating temperature, the inspection report for this inspection may include not only the processor's operating temperature status information ("abnormal") and the processor's specific operating temperature, but also the processor's operating temperature status information and historical operating temperatures from previous historical inspection results.

[0146] In this embodiment, the inspection report does not report the original data of the second network data, but rather the status information of the second network data. This greatly reduces the amount of data that the network device needs to upload to the network management device. Furthermore, some of the analysis and judgment tasks related to the second network data can be distributed to the corresponding network devices, reducing the workload of the network management device, lowering the performance requirements of the network management device, and reducing the cost of the network management device.

[0147] 306. The network device sends the inspection report to the network management device.

[0148] The network device sends the generated inspection report to the network management device. This inspection report includes inspection result information, enabling the network management device to determine the network inspection results. Correspondingly, the network management device receives the inspection report sent by the network device.

[0149] In this embodiment, after generating an inspection report, the network device can immediately or at a specified time proactively send the inspection report to the network management device without receiving an inspection report retrieval request from the network device. Alternatively, upon receiving an inspection report retrieval request from the network device, the network device can send the corresponding inspection report to the network management device according to the instructions in the inspection report retrieval request. For example, the inspection report retrieval request can carry an identifier of a certain inspection policy information. The network device can determine the corresponding inspection report based on the identifier of the inspection policy information and send the inspection report to the network management device.

[0150] 307. The network management equipment determines the network inspection results based on the inspection report.

[0151] The network management device determines the network inspection results based on the received inspection report, which includes inspection result information. The network management information can then determine the overall network inspection results for the entire network system based on this inspection result information.

[0152] Specifically, the network management device can receive multiple network inspection reports from multiple network devices. These multiple network inspection reports include multiple inspection result information from the multiple network devices. The network management device can determine the network inspection results of the multiple network devices and the network inspection results of the entire network system based on the multiple inspection result information.

[0153] In this embodiment, the network inspection result can be health information. After the network management device receives multiple inspection reports from multiple network devices, if the inspection report includes the health information of the network device that sent the inspection report, the network device obtains the corresponding health information from the inspection report, and then determines the overall health information of the network system based on the health information of the multiple network devices and the weight of each network device. The weight of a network device is affected by the importance of the network device in the network system. For example, a network system includes four network devices. The network management device obtains the corresponding health information from the inspection reports sent by the four network devices. It receives the health information of the four network devices. Network device A has a health score of 0.6 and a weight of 2; network device B has a health score of 0.8 and a weight of 3; network device C has a health score of 0.7 and a weight of 1; and network device D has a health score of 0.9 and a weight of 2. Then the overall health score of the network system is (0.6*2+0.8*3+0.7*1+0.9*2) / 4=1.525. In addition, the health information of the entire network system can also be determined based on other algorithms. For example, the health information of the entire network system can be determined based on factors such as the business, role, type, and network type level of each network device in the network system. The specifics are not limited here.

[0154] In one possible implementation, the inspection reports sent by the multiple network devices do not include the health information of the corresponding network devices. The network management device can calculate the health information of each network device based on the inspection results in the inspection reports. For example, if a network device's inspection report has four inspection items: processor operating status, network bandwidth below threshold, alarm information, and fault information, with the processor operating status and fault information having a weight of 2, and the network bandwidth below threshold and alarm information having a weight of 1, and the abnormal inspection items being network bandwidth below threshold and fault information, then the health of this network device is (1*1+1*2) / 4=0.75.

[0155] In this embodiment, the network management device can determine the health information of the entire network device. In addition, the network management device can also determine other network inspection results of the entire network system, such as the network throughput, media utilization, latency, bandwidth information, delay information, packet loss information, jitter information and system stability information of the entire network system, etc., which can all be determined based on the inspection report of the network device. Specific details are not limited here.

[0156] In one possible implementation, the inspection report also includes the identifier of the network device's inspection policy information and the identifier of each inspection item in the inspection policy information. After receiving the report, the network management device can determine which inspection policy information and which inspection items the inspection report is responding to based on the identifier of the inspection policy information and the identifier of each inspection item in the inspection policy information.

[0157] In this embodiment, the network inspection information issued has corresponding triggering conditions, so the corresponding inspection task can be executed when needed to obtain more timely network data, improve the timeliness of the network device inspection results information obtained by the network management device, and improve the accuracy of the network inspection results.

[0158] The network devices described in the embodiments of this application are described below. Please refer to [link / reference]. Figure 6 This application provides a network device 600, which can be used for... Figure 3 The network equipment 600 includes:

[0159] The first acquisition module 601 is used to acquire target inspection strategy information. The target inspection strategy information instructs the network device to collect inspection result information. The inspection result information includes first network data and second network data status information. The first network data is the network data reported as instructed by the target inspection strategy. The second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected as instructed by the target inspection strategy information. For specific implementation details, please refer to [reference needed]. Figure 3In the embodiment shown, step 302: the network device obtains inspection strategy information, which will not be described in detail here.

[0160] The second acquisition module 602 is used to acquire inspection result information in response to the network device meeting the inspection trigger condition. For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0161] The sending module 603 is used to send the inspection report to the network management device, so that the network management device can determine the network inspection results based on the inspection report. The inspection report includes inspection result information. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 306: the network device sends the inspection report to the network management device, which will not be described in detail here.

[0162] In this embodiment, the network device can perform the aforementioned... Figure 3 The specific operations performed by the network device in any of the embodiments shown are not described here.

[0163] The network devices described in the embodiments of this application are described below. Please refer to [link / reference]. Figure 7 This application provides a network device 700, which can be used for... Figure 3 The network equipment 700 includes:

[0164] The first acquisition module 701 is used to acquire target inspection strategy information. The target inspection strategy information instructs the network device to collect inspection result information. The inspection result information includes first network data and second network data status information. The first network data is the network data reported as instructed by the target inspection strategy. The second network data status information indicates whether the second network data is abnormal; the second network data is the network data inspected as instructed by the target inspection strategy information. For specific implementation details, please refer to [link / reference needed]. Figure 3 In the embodiment shown, step 302: the network device obtains inspection strategy information, which will not be described in detail here.

[0165] In one possible implementation, the first acquisition module 701 is specifically used to: receive target inspection policy information sent by the network management device; or acquire target inspection policy information from a built-in inspection policy information database. For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 302: the network device obtains inspection strategy information, which will not be described in detail here.

[0166] The conversion module 702 is used to convert target inspection policy information into executable information for network devices. This executable information may include one or more of the following: scripts, commands, internal objects, or interfaces. For specific implementation details, please refer to [reference needed]. Figure 3In the embodiment shown, step 303: The network device converts the inspection strategy information into executable information, which will not be described in detail here.

[0167] The second acquisition module 703 is used to acquire inspection result information in response to the network device meeting the inspection trigger conditions. For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0168] In one possible implementation, the second acquisition module 703 is specifically used to: acquire inspection result information by executing executable information. For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0169] In one possible implementation, the second acquisition module 703 includes:

[0170] Acquisition unit 704 is used to acquire first network data and second network data; for specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0171] The first determining unit 705 is used to determine the status information of the second network data based on the second network data. For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0172] The second determining unit 706 is used to determine the number of entries of abnormal second network data; for specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 304: the network device obtains the inspection result information, which will not be described in detail here.

[0173] The third determining unit 707 is used to determine the health information of the network device based on the number of abnormal second network data entries, the number of second network data entries, and the weight of the abnormal second network data. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 305: the network device generates an inspection report, which will not be described in detail here.

[0174] In one possible implementation, the network device satisfies the inspection triggering conditions, including: the network device determines that an event indicating the target inspection policy information has occurred; or the network device determines that the parameters indicating the target inspection policy information meet a threshold condition; or the network device satisfies the time condition indicating the target inspection policy information.

[0175] The sending module 708 is used to send the inspection report to the network management device, so that the network management device can determine the network inspection results based on the inspection report. The inspection report includes inspection result information. For specific implementation details, please refer to [link to implementation details]. Figure 3 In the illustrated embodiment, step 306: the network device sends the inspection report to the network management device, which will not be described in detail here.

[0176] In one possible implementation, the inspection result information also includes the health information of the network device and / or fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

[0177] In one possible implementation, the inspection result information also includes an identifier for the target inspection strategy information.

[0178] In this embodiment, the network device can perform the aforementioned... Figure 3 The specific operations performed by the network device in any of the embodiments shown are not described here.

[0179] The network management device in the embodiments of this application is described below. Please refer to [link / reference]. Figure 8 This application provides a network management device 800, which can be used for... Figure 3 The network management device 800 includes:

[0180] The receiving module 801 is used to receive a first inspection report sent by a first network device. The first inspection report includes first inspection result information collected by the first network device according to the instruction of first inspection strategy information. The first inspection strategy information instructs the first network device to collect the first inspection result information. The first inspection result information includes first network data and second network data status information. The first network data is the network data reported according to the target inspection strategy, and the second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected according to the target inspection strategy information. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 306: the network device sends the inspection report to the network management device, which will not be described in detail here.

[0181] The determination module 802 is used to determine the network inspection result based on the first inspection report. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0182] In this embodiment, the network management device can perform the aforementioned... Figure 3The specific operations performed by the network management device in any of the embodiments shown are not detailed here.

[0183] The network management device in the embodiments of this application is described below. Please refer to [link / reference]. Figure 9 This application provides a network management device 900, which can be used for... Figure 3 The network management device 900 includes:

[0184] The generation module 901 is used to generate the first inspection strategy information according to the user-defined inspection strategy. For details on its implementation, please refer to [reference needed]. Figure 3 In the embodiment shown, step 301: the network management device generates inspection policy information, which will not be described in detail here.

[0185] The sending module 902 is used to send the first inspection strategy information to the first network device. For details on the implementation, please refer to [reference needed]. Figure 3 In the embodiment shown, step 302: the network device obtains inspection strategy information, which will not be described in detail here.

[0186] In one possible implementation, the sending module 902 is specifically used to: send the first inspection strategy information to the first network device via a network protocol, wherein the network protocol is one of the following: File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Simple Network Management Protocol (SNMP), Network Configuration Protocol (NETCONF), and Representative State Transition Configuration Protocol (RESTCONF). For specific implementation details, please refer to [reference needed]. Figure 3 In the embodiment shown, step 302: the network device obtains inspection strategy information, which will not be described in detail here.

[0187] The first receiving module 903 is used to receive a first inspection report sent by a first network device. The first inspection report includes first inspection result information collected by the first network device according to the instruction of first inspection strategy information. The first inspection strategy information instructs the first network device to collect the first inspection result information. The first inspection result information includes first network data and second network data status information. The first network data is the network data reported according to the target inspection strategy, and the second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected according to the target inspection strategy information. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 306: the network device sends the inspection report to the network management device, which will not be described in detail here.

[0188] The first determining module 904 is used to determine the network inspection result based on the first inspection report. For specific implementation details, please refer to [link / reference needed]. Figure 3In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0189] The first determining module 904 is specifically used to: determine the network inspection result based on the first inspection result information. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0190] In one possible implementation, the network inspection result includes health information of the entire network system, and the first determining module 904 includes:

[0191] The acquisition unit 905 is used to acquire the health information of the first network device. For details on its implementation, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0192] The acquisition unit 905 is specifically used to: determine the health information of the corresponding network device based on the number of abnormal second network data entries and the number of second network data entries in the first inspection report, wherein the abnormal second network data refers to second network data with abnormal data status. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0193] In one possible implementation, the first inspection report includes the health information of the first network device, and the acquisition unit 905 is specifically used to: determine the health information of the first network device based on the first inspection report. For specific implementation details, please refer to [link / reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0194] The determining unit 906 is used to determine the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0195] The determining unit 906 is specifically used to: determine the health information of the entire network system based on the health information of the first network device, the health information of the second network device, the weight information corresponding to the first network device, and the weight information corresponding to the second network device. For specific implementation details, please refer to [reference needed]. Figure 3In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0196] The second receiving module 907 is used to receive the second inspection report sent by the second network device. The second inspection report includes the second inspection result information of the corresponding second network device. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0197] The acquisition module 908 is used to acquire the health information of the first network device and the health information of the second network device. For specific implementation details, please refer to [reference needed]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0198] In one possible implementation, the first inspection result information also includes the health information of the first network device and / or fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

[0199] In one possible implementation, the first inspection strategy information includes a first inspection strategy identifier, and the first inspection report includes the corresponding inspection strategy identifier.

[0200] The second determining module 909 is configured to, if the first inspection policy identifier matches the corresponding inspection policy identifier in the first inspection report, then the network management device determines the inspection policy information corresponding to the first inspection report as the first inspection policy information. For specific implementation details, please refer to [link to implementation details]. Figure 3 In the illustrated embodiment, step 307: The network management device determines the network inspection result based on the inspection report, which will not be elaborated here.

[0201] In this embodiment, the network management device can perform the aforementioned... Figure 3 The specific operations performed by the network management device in any of the embodiments shown are not detailed here.

[0202] Figure 10 This is a schematic diagram of a network device structure provided in an embodiment of this application. The network device 1000 may include one or more central processing units (CPUs) 1001 and a memory 1005, in which one or more applications or data are stored.

[0203] The memory 1005 can be volatile or persistent storage. The program stored in the memory 1005 can include one or more modules, each module including a series of instruction operations on the network device. Furthermore, the central processing unit 1001 can be configured to communicate with the memory 1005 and execute the series of instruction operations in the memory 1005 on the network device 1000.

[0204] The central processing unit 1001 executes a computer program stored in the memory 1005, enabling the network device 1000 to perform the following: the network device acquires target inspection policy information, which instructs the network device to collect inspection result information. The inspection result information includes first network data and second network data status information. The first network data is the network data reported as instructed by the target inspection policy. The second network data status information indicates whether the second network data is abnormal; the second network data is the network data inspected as instructed by the target inspection policy. In response to the network device meeting the inspection trigger condition, the network device acquires the inspection result information. The network device sends the inspection report to the network management device, enabling the network management device to determine the network inspection result based on the inspection report, which includes the inspection result information. For specific implementation details, please refer to [link to implementation details]. Figure 3 Steps 301-307 in the illustrated embodiment will not be repeated here.

[0205] The network device 1000 may also include one or more power supplies 1002, one or more wired or wireless network interfaces 1003, one or more input / output interfaces 1004, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0206] The network device 1000 can perform the aforementioned... Figure 3 The specific operations performed by the network device in the illustrated embodiment will not be described in detail here.

[0207] Figure 11 This is a schematic diagram of a network management device structure provided in an embodiment of this application. The network management device 1100 may include one or more central processing units (CPUs) 1101 and a memory 1105, in which one or more applications or data are stored.

[0208] The memory 1105 can be volatile or persistent storage. The program stored in the memory 1105 can include one or more modules, each module including a series of instruction operations on the network management device. Furthermore, the central processing unit 1101 can be configured to communicate with the memory 1105 and execute the series of instruction operations in the memory 1105 on the network management device 1100.

[0209] The central processing unit 1101 executes the computer program stored in the memory 1105, enabling the network management device 1100 to perform the following: the network management device receives a first inspection report sent by a first network device. The first inspection report includes first inspection result information collected by the first network device according to the instruction of first inspection strategy information. The first inspection strategy information instructs the first network device to collect the first inspection result information. The first inspection result information includes first network data and second network data status information. The first network data is the network data reported according to the target inspection strategy, and the second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected according to the target inspection strategy information. The network management device determines the network inspection result based on the first inspection report. For specific implementation details, please refer to [reference needed]. Figure 3 Steps 301-307 in the illustrated embodiment will not be repeated here.

[0210] The network management device 1100 may also include one or more power supplies 1102, one or more wired or wireless network interfaces 1103, one or more input / output interfaces 1104, and / or one or more operating systems, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0211] The network management device 1100 can perform the aforementioned... Figure 3 The operations performed by the network management device in the illustrated embodiment will not be described in detail here.

[0212] Figure 12 This is a schematic diagram of a network system provided in an embodiment of this application. The network system 1200 may include a network management device 1201 and a network device 1202. The network management device 1201 and the network device 1202 can achieve the following: Figure 3 For details on the network inspection method shown, please refer to [link / reference]. Figure 3 Steps 301-307 in the illustrated embodiment will not be repeated here.

[0213] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0214] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0215] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0216] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0217] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A network inspection method, characterized in that, The method includes: The network device acquires target inspection strategy information, which includes the inspection triggering conditions of the inspection task corresponding to the target inspection strategy information. The target inspection strategy information instructs the network device to collect inspection result information, which includes first network data, second network data status information, and the health information of the network device. The first network data is the network data that the target inspection strategy information instructs to be reported. The second network data status information indicates whether the second network data is abnormal. The second network data is the network data that the target inspection strategy information instructs to be inspected. In response to the network device meeting the inspection triggering condition, the network device acquires the inspection result information. The network device meeting the inspection triggering condition includes the network device determining that the event indicated by the target inspection strategy information has occurred, or the network device determining that the parameter indicated by the target inspection strategy information meets the threshold condition. The network device sends the inspection report to the network management device, so that the network management device can determine the network inspection result based on the inspection report, and the inspection report includes the inspection result information.

2. The method according to claim 1, characterized in that, The network device acquires target inspection strategy information, including: The network device receives the target inspection strategy information sent by the network management device; or The network device obtains target inspection strategy information from its built-in inspection strategy information database.

3. The method according to claim 2, characterized in that, Before the network device obtains the inspection result information, the method further includes: The network device converts the target inspection strategy information into executable information for the network device. Accordingly, the network device acquires the inspection result information including: The network device obtains the inspection result information by executing the executable information.

4. The method according to claim 3, characterized in that, The executable information includes one or more of the following: scripts, commands, internal objects, or interfaces.

5. The method according to any one of claims 1 to 4, characterized in that, The network device acquires the inspection result information, including: The network device acquires the first network data and the second network data; The network device determines the status information of the second network data based on the second network data.

6. The method according to claim 5, characterized in that, The inspection result information also includes fault snapshot information of abnormal second network data, which refers to second network data with abnormal data status.

7. The method according to claim 6, characterized in that, The network device acquires the inspection result information, including: The network device determines the number of entries for the abnormal second network data. The network device determines its health information based on the number of entries of the abnormal second network data, the number of entries of the second network data, and the weight of the abnormal second network data.

8. The method according to claim 7, characterized in that, The inspection result information also includes the identifier of the target inspection strategy information.

9. A network inspection method, characterized in that, The method includes: The network management device receives a first inspection report sent by a first network device. The first inspection report includes first inspection result information collected by the first network device according to the instruction of the first inspection strategy information when the first network device meets the inspection triggering conditions. The first inspection strategy information includes the inspection triggering conditions of the inspection task corresponding to the first inspection strategy information. The first inspection strategy information instructs the first network device to collect the first inspection result information. The first inspection result information includes first network data, second network data status information, and health information of the first network device. The first network data is the network data reported as instructed by the first inspection strategy information. The second network data status information indicates whether the second network data is abnormal. The second network data is the network data inspected as instructed by the first inspection strategy information. The first network device meeting the inspection triggering conditions includes the first network device determining that the event indicated by the first inspection strategy information has occurred, or the first network device determining that the parameter indicated by the first inspection strategy information meets the threshold condition. The network management device determines the network inspection result based on the first inspection report.

10. The method according to claim 9, characterized in that, The method further includes: The network management device generates the first inspection strategy information according to the inspection strategy set by the user; The network management device sends the first inspection strategy information to the first network device.

11. The method according to claim 10, characterized in that, The network management device sends the first inspection policy information to the first network device, including: The network management device sends the first inspection strategy information to the first network device through a network protocol, wherein the network protocol is one of the following: File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), Network Configuration Protocol (NETCONF), Representative State Transition Configuration Protocol (RESTCONF), and Simple Network Management Protocol (SNMP).

12. The method according to claim 11, characterized in that, The network management device determines the network inspection results based on the first inspection report, including: The network management device determines the network inspection result based on the first inspection result information.

13. The method according to claim 12, characterized in that, The network inspection results include health information of the entire network system. The network management device determines the network inspection results based on the first inspection result information, including: The network management device acquires the health information of the first network device; The network management device determines the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device.

14. The method according to claim 13, characterized in that, The network management device obtains the health information of the first network device, including: The network management device determines the health information of the corresponding network device based on the number of abnormal second network data entries and the number of second network data entries in the first inspection report. The abnormal second network data refers to second network data with abnormal data status.

15. The method according to claim 14, characterized in that, The network management device determines the health information of the entire network system based on the health information of the first network device and the weight information corresponding to the first network device, including: The network management device receives a second inspection report sent by the second network device, the second inspection report including the second inspection result information of the corresponding second network device; The network management device acquires the health information of the second network device; The network management device determines the health information of the entire network system based on the health information of the first network device, the health information of the second network device, the weight information corresponding to the first network device, and the weight information corresponding to the second network device.

16. The method according to claim 15, characterized in that, The first inspection result information also includes fault snapshot information of abnormal second network data, wherein the abnormal second network data is second network data with abnormal data status.

17. The method according to claim 16, characterized in that, The first inspection strategy information includes a first inspection strategy identifier, the first inspection report includes the corresponding inspection strategy identifier, and the method further includes: If the first inspection policy identifier is consistent with the corresponding inspection policy identifier in the first inspection report, then the network management device determines the inspection policy information corresponding to the first inspection report as the first inspection policy information.

18. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-17.

19. A communication device, used as a network equipment, characterized in that, The communication device includes: Memory, including instructions; A processor, when executing the instructions, causes the communication device to implement the method described in any one of claims 1-8.

20. A communication device used as a network management device, characterized in that, The communication device includes: Memory, including instructions; A processor, when executing the instructions, causes the communication device to implement the method of any one of claims 9-17.

21. A network inspection system, characterized in that, The network inspection system includes network devices and network management devices. The network devices implement the method described in any one of claims 1-8, and the network management devices implement the method described in any one of claims 9-17.

22. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the method as described in any one of claims 1-17.

Citation Information

Patent Citations

  • Host inspection method and host inspection system

    CN102347965A

  • Network health judgment method and device

    CN111126631A