Method and system for locating configuration errors in a computer network
By building an incremental network control plane model and using reverse constraint search method, the problems of large origin tracking overhead and insufficient diagnosis of missing events in the prior art are solved, and efficient and accurate network failure location is achieved.
Patent Information
- Application Number
- CN202310798953.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-30
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2043-06-30
AI Technical Summary
The origin tracking overhead in the existing network control plane error positioning technology is high and does not support the diagnosis of missing events, resulting in inefficient network failure positioning.
By abstracting the complex routing protocol semantics of the network control plane into interactions between data tables, an incremental network control plane model is constructed, and state information is tracked in the form of a log when the model is run. Combined with the reverse constraint search method, the origin tree incremental construction and negative origin tree boot strategy are used to locate the root cause of errors.
It reduces the performance overhead of origin tracking, improves the efficiency and accuracy of network failure location, and can quickly and accurately locate the root causes of abnormal forwarding table changes and missing events.
Smart Images

Figure CN116614351B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and in particular to a method and system for locating configuration errors of a computer network. Background Art
[0002] The rapid development and application of computer networks have made the network more and more complex, and with it comes frequent network failures. Network failures have become the single biggest cause of all IT service downtime events. In recent years, some network configuration verification technologies have been proposed, which prevent network failures by formally verifying network configurations. However, existing network configuration verification technologies can only provide data packets that violate network intent and their forwarding information, but cannot provide configurations related to erroneous forwarding tables in forwarding information. Currently, administrators still need to manually locate the root cause of the error to further repair the erroneous configuration.
[0003] The forwarding table is generated by the network control plane based on the network configuration, statically or dynamically according to the routing protocol, and determines the forwarding path of the data packet from the source host to the destination host in the network. The network control plane has complex protocol semantics. In large-scale complex networks, there is a complex mapping relationship between the error forwarding table output by the control plane and the relevant configuration. Manually locating the network configuration related to the error forwarding table requires a lot of expert knowledge, which is very cumbersome. The inability to automatically locate the errors of the network control plane has seriously affected the availability of network configuration verification tools.
[0004] The Data Provenance analysis technology, which first appeared in the database field, is used to locate the system status and causal dependencies related to abnormal events. The Network Provenance technology developed from this technology tracks the provenance by recording the causal relationships between network events at runtime, and provides input related to abnormal events and their dependencies in a "backtracking" manner during diagnostic queries, thereby locating errors.
[0005] DistTape tracks the complete mapping between output events and related state change events in the input when the distributed system is running, as shown in the attached figure. Figure 1As shown in the figure, during diagnostic queries, an origin tree of abnormal output events can be quickly constructed according to the mapping for explanation. The leaf nodes of the origin tree are the relevant input events. However, this method can only diagnose events that have already occurred. For events missing in the system output, that is, events that are expected to occur but did not, Y! uses counterfactual reasoning to determine the reason for the non-occurrence of the event and constructs a negative origin tree to explain the missing event. Since counterfactual reasoning requires enumerating all possible counterfactual causes, this method will generate multiple possible negative origin trees. SouffleProv records a small amount of tuple derivation information in an annotation manner during runtime and constructs the origin tree from top to bottom through a matching search method during diagnostic queries, avoiding directly recording the complete causal mapping during runtime, with relatively low runtime performance overhead. However, it does not support the diagnosis of events related to state changes and cannot explain abnormal network behavior changes.
[0006] Although the network origin method can give the error cause leading to abnormal events, there is a problem of a large amount of origin information in the complete construction of the origin tree, making it difficult to determine the root cause of the error. Further root cause localization needs to be achieved through origin reference. DDProv uses the reference in the time dimension for root cause localization, maintains the reverse calculation context between changing data streams based on incremental operators during system runtime, records the mapping relationship from the output of the incremental operator to the input, and performs inverse operations on abnormal output events using the reverse calculation context during diagnostic queries to quickly give the direct triggering cause of the abnormal output events, which can effectively reduce the scale of origin information. However, this method has limited modeling expression ability based on incremental operators and cannot obtain the reverse calculation context of missing events for inverse operations. Therefore, it does not support the diagnosis of missing events. DiffProv uses the reference in the space dimension for root cause localization, directly records the complete mapping relationship between the output and the input using the DistTape method during system runtime, and first constructs the origin trees of abnormal events and reference events during diagnostic queries, and reasons the root cause of the deviation of abnormal events from normal execution by analyzing the differences between the origin trees. Existing methods for root cause localization based on origin reference can achieve root cause localization for some error events using reference, but when applied to the error localization of the control plane in a network verification system, there are the following two defects:
[0007] 1. In terms of performance, the complete origin tracking has a large runtime overhead. Error localization under network verification is only executed when it is verified that the network intent is violated. It is a non-essential process in the verification process and has a lower priority than the original verification task. The performance overhead generated by origin tracking during the operation of the verification system should be minimized to ensure the original verification performance of the system. However, existing methods directly record the complete mapping relationship between the output and each input event during system runtime to provide a "backtracking" path during diagnostic queries of abnormal events, resulting in a large runtime overhead. When applied to a network verification system, it will reduce the operating efficiency of the system.
[0008] 2. Functionally, it does not support diagnosing missing events. Network intent violation errors are not only related to the events already existing in the output, but may also be caused by the missing events in the output. For example, network reachability failures caused by routing black holes (missing events in the forwarding table). Therefore, error localization in the network control plane needs to support diagnosing missing events in the output. However, existing methods all rely on the state information of runtime origin tracking for difference analysis, and can only locate the root cause of events that have occurred. They do not support diagnosing missing events and are difficult to give complete control plane error localization results. Summary of the Invention
[0009] In order to overcome the defects of the above-mentioned existing technologies, the purpose of the present invention is to provide a method and system for configuring error localization in a computer network to solve the technical problems of large origin tracking overhead and lack of support for diagnosing the root cause of missing event errors in the existing network control plane error localization technology.
[0010] The present invention is realized through the following technical solutions:
[0011] A method for configuring error localization in a computer network includes the following steps:
[0012] Step 1: Abstract the complex routing protocol semantics of the network control plane into the interaction between data tables, and construct an incremental network control plane model;
[0013] Step 2: When the incremental network control plane model is running, track the runtime state information in the form of logs to support subsequent error localization requirements;
[0014] Step 3: For the abnormal forwarding table changes and forwarding table missing events output by the incremental network control plane model, based on the reverse constraint search method, respectively adopt the strategies of incremental construction of the origin tree and guided construction of the negative origin tree to locate the root cause of the error.
[0015] Preferably, in Step 1, abstract the complex routing protocol semantics of the network control plane, and use the relationship instances in the incremental declarative programming language DDlog to represent; the state changes of the network control plane state information are represented as the addition or deletion events of relationship instances; among them, the vendor-independent configuration is abstracted into the EDB relationship instances in the incremental declarative programming language DDlog as the basic input of the incremental network control plane model; the network state during the network simulation process is abstracted into the IDB relationship instances in DDlog, where the FIB relationship instance represents the forwarding table output by the incremental network control plane model.
[0016] Preferably, in step 1, an incremental network control plane model is constructed. The simulation of the control plane is abstracted as a process of continuously propagating and updating routing messages until all routing tables no longer change and converge, which can be modeled as operations between relational tables and described using the incremental declarative programming language DDlog.
[0017] Furthermore, the process of describing using the incremental declarative programming language DDlog is as follows:
[0018] S1. Generate a local routing table based on information such as the port IP configuration and static routes of devices in the network;
[0019] S2. According to the dynamic routing protocol configuration, publish the local route to neighbor nodes and select the optimal route from the routes announced by neighbor nodes: group the routes by network prefix, use the optimal route selection algorithm to calculate the best route under the same prefix, and add the best route to the local routing information library and the routing table to be propagated;
[0020] S3. Modify or filter the routing message table to be propagated according to the configured routing policy;
[0021] S4. Repeat S2 - S3 until the various routing tables of all devices no longer change.
[0022] Preferably, in step 1, the incremental network control plane model is translated into a Differential Dataflow data stream model, and a set of general differential operators are used to support incremental calculation of recursive data streams.
[0023] Preferably, in step 2, when the incremental network control plane model runs, the runtime state information is tracked in the form of logs, where the runtime state information only records rule - derived events and extended attribute information: The rule - derived event is the change event of the rule - head relationship instance, including the unique identifier rid of the rule corresponding to the derived event, the global logical time ts, the event type type, and the specific relationship instance tuple. The set of attributes corresponding to each element in the tuple is denoted as Field base ; The extended information includes the attribute values that only appear in the rule - body relationship and cannot be simply deduced from the rule - head relationship instance, and there is no associated dependency between these attribute values. The corresponding set of attributes is denoted as Field ext .
[0024] Preferably, in step 3, for a given diagnostic query target, the specific process of constructing an origin tree using reverse constraint search is as follows:
[0025] K1. Use the given query event e as the root node root of the origin tree and add its corresponding log record log(e) to the query queue queue;
[0026] K2. If the queue is not empty, dequeue the event record log(e) from the query queue, obtain the corresponding rule definition according to the recorded rule identifier rid, and output the event e to each input event e in combination with the rule definition context i The mapping relationship to generate the reverse constraints that the events corresponding to each input relationship need to satisfy, which consists of the tuple attributes and incremental status that the log record log(e i ) of each input event needs to satisfy;
[0027] K3. Use the logs recorded at runtime with the reverse constraints to perform a bottom-up matching search. For the satisfiable event record log(e i ), by adding a directed edge from event e i to event e to construct the sub-origination tree of event e; if event e i is an IDB relationship event, add the record log(e i ) to the query queue queue and re-execute step K2.
[0028] Furthermore, in step 3, for the abnormal forwarding table change event, through the reference in the time dimension, use the origination tree incremental construction strategy to locate the relevant configuration change operations: on the basis of the reverse constraint search method, constrain the input event and the output event to be in the same transaction, so as to exclude the input events with unchanged status in the current change during the search process, and output the causal mapping between the changed events in the current change, that is, the incremental origination tree.
[0029] Preferably, in step 3, for the abnormal forwarding table missing event, through the reference in the space dimension, use the negative origination tree-guided construction strategy to locate the relevant configuration missing operations. The specific process is as follows:
[0030] L1. Given the forwarding table addition event e2 with the same forwarding port as the forwarding table missing event e1 as the reference event, and use the original attributes with differences between the two events as the seed attributes;
[0031] L2. Use the reverse constraint search method to construct the sub-origination trees T(e1) and T(e2) of the given missing event e1 and its reference event e2 respectively;
[0032] L3. Consider the input event differences caused by the seed attributes in T(e1) and T(e2) as equivalent. If there are non-equivalent input event differences, then obtain the counterfactual cause that the missing event e1 cannot generate by referring to the input events of the same type in T(e2) and replacing the seed attributes, and then use the missing event corresponding to this cause and its reference as a new query and re-execute step L2.
[0033] A configuration error location system for a computer network, comprising:
[0034] A configuration parsing module, which is used to abstract the complex routing protocol semantics of the network control plane into the interaction between data tables and construct an incremental network control plane model;
[0035] An incremental network simulation module, which is used to support subsequent error location requirements by tracking runtime state information in the form of logs when the incremental network control plane model is running;
[0036] An origin tree construction module, which is used to construct an origin tree based on reverse constraint search for the abnormal forwarding table change and forwarding table missing event output by the incremental network control plane model, and adopt an origin tree construction strategy with reference to locate the root cause of the abnormal error forwarding table output by the network control plane model.
[0037] Compared with the prior art, the present invention has the following beneficial technical effects:
[0038] The present invention provides a method for locating configuration errors in a computer network. First, a declarative network control plane model is modeled based on DDlog, then origin tracking is performed lightly during model runtime, and finally differential location is performed using multi-dimensional origin references during diagnostic queries. The model uses declarative syntax to perform a high-level abstraction of the routing propagation process, can describe various routing characteristics, and improves the scalability of model functions; by translating into the calculation of incremental data streams, incremental simulation of the control plane can be efficiently implemented, improving the calculation efficiency of the model. When the incremental network control plane model is running, runtime state information is tracked in the form of logs to support subsequent error location requirements. By only recording limited incremental event state information, the direct maintenance of the complete mapping between rule outputs and each input is avoided, the performance overhead generated by origin tracking can be reduced, and the running efficiency of model incremental simulation is ensured. For the error forwarding table event output by the model, by generating reverse constraints that the input events corresponding to a given output event need to satisfy under different rule semantics, the only satisfiable matching result can be directly located from the running log, so that the complex causal mapping relationship during model runtime can be quickly and accurately constructed in an offline state, and finally the error cause can be located.
[0039] Furthermore, for the abnormal forwarding table change events output by the model, from the time dimension for reference, an incremental origin tree is directly constructed by defining the relationship of events in the reverse constraint in terms of time sequence to locate the relevant network configuration change operations. Constructing the incremental origin tree reduces the origin information in terms of scale on the one hand, can more clearly show the impact of configuration updates on the network control plane, and improves the accuracy of the location result; on the other hand, it avoids the administrator from adjusting the configuration operations other than the current update, thereby having side effects on the reference system state and causing new faults, and improves the security of the location result.
[0040] Furthermore, for the forwarding table events missing in the model output, with the existing forwarding table with the same port as the reference, by analyzing the differences between the missing events and the reference event origin tree, it guides the generation of the corresponding counterfactual causes of the missing events, locates the relevant network configuration missing operations, avoids enumerating in the parameter space to explore a large number of counterfactual causes, and improves the accuracy of error location. Description of the Drawings
[0041] Figure 1 Schematic diagram of full - scale origin tracking of DistTape;
[0042] Figure 2 Flow chart of the method for locating configuration errors in a computer network in the present invention;
[0043] Figure 3 Schematic diagram of the derivation of DDlog relationships for modeling the BGP protocol in the present invention;
[0044] Figure 4 Partial DDlog rule definitions for describing the BGP protocol in the present invention;
[0045] Figure 5 Schematic diagram of using log records to determine reverse attribute constraints in the present invention;
[0046] Figure 6 Pseudocode of the general algorithm for constructing an origin tree using reverse constraints in the present invention;
[0047] Figure 7 Schematic diagram of the incremental origin tree in the present invention;
[0048] Figure 8 Schematic diagram of guiding the construction of a negative origin tree in the present invention;
[0049] Figure 9 Configuration error location system for a computer network designed in the present invention. Detailed Embodiments
[0050] To enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solution in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0051] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0052] The following further describes the present invention in detail with reference to the accompanying drawings:
[0053] The object of the present invention is to provide a method and system for locating configuration errors in a computer network to solve the technical problems of large origin tracking overhead and lack of support for diagnosing the root cause of missing event errors in the existing network control plane error location technology.
[0054] Specifically, according to the attached Figure 2 As shown, the method for locating configuration errors in the computer network includes the following steps:
[0055] Step 1, abstract the complex routing protocol semantics of the network control plane into the interaction between data tables, and construct an incremental network control plane model;
[0056] Specifically, abstract the complex routing protocol semantics of the network control plane, and represent it using relationship instances in the incremental declarative programming language DDlog; the state change of the network control plane state information is represented as an addition or deletion event of relationship instances; among them, the vendor-independent configuration is abstracted into EDB relationship instances in the incremental declarative programming language DDlog as the basic input of the incremental network control plane model; the network state during the network simulation is abstracted into IDB relationship instances in DDlog, where the FIB relationship instance represents the forwarding table output by the incremental network control plane model.
[0057] Specifically, an incremental network control plane model is constructed. The simulation of the control plane is abstracted as a process of continuously propagating and updating routing messages until all routing tables no longer change and reach convergence. This process can be modeled as operations between relational tables and is described using the incremental declarative programming language DDlog.
[0058] Among them, the process of describing with the incremental declarative programming language DDlog is as follows:
[0059] S1. Generate a local routing table based on information such as the port IP configuration and static routes of devices in the network;
[0060] S2. According to the dynamic routing protocol configuration, publish the local route to neighbor nodes and optimize the routes announced by neighbor nodes: Group the routes by network prefix, use the optimal routing selection algorithm to calculate the best route under the same prefix, and add the best route to the local routing information library and the routing table to be propagated;
[0061] S3. Modify or filter the routing message table to be propagated according to the configured routing policy;
[0062] S4. Repeat steps S2 - S3 until the various routing tables of all devices no longer change.
[0063] Then, translate the incremental network control plane model into a Differential Dataflow data stream model, and use a set of general differential operators to support incremental calculation of recursive data streams. On the one hand, using declarative syntax to perform high - level abstraction on the routing propagation process can describe various routing characteristics and improve the scalability of the model function; on the other hand, through translation into incremental data stream calculation, incremental simulation of the control plane can be efficiently implemented.
[0064] Step 2, when the incremental network control plane model is running, track the runtime state information in the form of logs to support subsequent error - location requirements;
[0065] Specifically, when the incremental network control plane model is running, track the runtime state information in the form of logs, where the runtime state information only records rule - derived events and extended attribute information;
[0066] Among them, the rule - derived event is the change event of the rule - head relationship instance, including the unique identifier rid of the rule corresponding to the derived event, the global logical time ts, the event type type, and the specific relationship instance tuple. The set of attributes corresponding to each element in the tuple is denoted as Field base ;
[0067] The extended information includes attribute values that only appear in the rule body relationships and cannot be simply deduced from the rule head relationship instances, and there is no associated dependency among these attribute values. The corresponding set of attributes is denoted as Field ext 。
[0068] By recording this extended attribute information, the attribute mapping from the rule head relationship instance to each relationship instance in the rule body is made injective or surjective, enabling the direct determination of the input instance attributes participating in the rule derivation through simple reverse deduction, such as field projection or monotonic inverse operations, given a rule head relationship instance. Subsequently, the subsequent reverse constraint search is used to further determine each rule body relationship instance participating in the rule derivation.
[0069] In the present invention, the DDlog rule is rewritten to perform provenance tracking on the incremental event status in the form of a log. The present invention records the incremental event status generated by rule derivation based on a log, which can very flexibly record the status information to be tracked and persistently store it on the disk. This recording form does not require modifying the original rule logic and does not increase the memory overhead during model runtime, enabling a "non-intrusive" expansion of the original incremental control plane model.
[0070] Step 3, for the abnormal forwarding table changes and forwarding table missing events output by the incremental network control plane model, based on the reverse constraint search method, the origin tree incremental construction and negative origin tree guided construction strategies are respectively adopted to locate the root cause of the error.
[0071] Specifically, for a given diagnostic query target, the specific process of constructing an origin tree using reverse constraint search is as follows:
[0072] K1, Use the given query event e as the root node root of the origin tree, and add its corresponding log record log(e) to the query queue queue;
[0073] K2, If queue is not empty, dequeue the event record log(e) from the query queue, obtain the corresponding rule definition according to the recorded rule identifier rid, and combine the mapping relationship from the output event e to each input event e in the rule definition context i to generate the reverse constraints that each input relationship corresponding event needs to satisfy, which consists of the tuple attributes and incremental status that the log record log(e i ) of each input event needs to satisfy;
[0074] K3, Use the reverse constraints to perform a bottom-up matching search on the log recorded at runtime. For the satisfiable event record log(e i ), construct the sub-origin tree of event e by adding a directed edge from event e i to event e; If event e iIf it is an IDB relationship event, then record log(e i ) and add it to the query queue queue, and re - execute step K2.
[0075] Specifically, for the abnormal forwarding table change event, through the reference of the time dimension, use the incremental construction strategy of the origin tree to locate the relevant configuration change operations. The present invention observes that the network verification technology can ensure that the network state during online operation is correct. Therefore, in the network change scenario, the correct network state before the change can be used as a reference, only focusing on the input events corresponding to the state changes in the current incremental simulation, rather than those input events from the correct network state that have not changed. By constructing an incremental origin tree between state change events, the direct trigger cause of the abnormal forwarding table change, that is, the abnormal configuration change input, can be located.
[0076] The specific process can exclude the input events with unchanged states in the current change during the search process by restricting the input events and output events to be in the same transaction based on the reverse constraint search method, and output the causal mapping between the change events in the current change, that is, the incremental origin tree.
[0077] Specifically, for the abnormal forwarding table missing event, through the reference of the space dimension, use the negative origin tree guided construction strategy to locate the relevant configuration missing operations. The present invention observes that based on counterfactual reasoning, it is necessary to consider all counterfactual reasons that make the missing event not be deduced, thus constructing a large number of negative origin trees, which is difficult to locate the root cause. Therefore, the present invention uses the origin information of the reference event to guide the generation of specific counterfactual reasons and construct a definite negative origin tree from top to bottom, avoiding exploring a large number of counterfactual reasons. The specific process is as follows:
[0078] L1. Given the forwarding table addition event e2 with the same forwarding port as the forwarding table missing event e1 as the reference event, and use the original attributes with differences between the two events as the seed attributes;
[0079] L2. Use the above - mentioned reverse constraint search method to construct the sub - origin trees T(e1) and T(e2) of the given missing event e1 and its reference event e2 respectively. Since the event e1 cannot be deduced, T(e1) is unsatisfiable;
[0080] L3. Consider the input event differences caused by the seed attributes in T(e1) and T(e2) as equivalent, and do not further construct the sub - origin trees of these input events; if there are non - equivalent input event differences, then obtain the counterfactual reasons that the missing event e1 cannot generate by referring to the input events of the same type relationship in T(e2) and replacing the seed attributes, and then use the missing event corresponding to this reason and its reference as a new query, and re - execute step L2.
[0081] Embodiment
[0082] In this embodiment, a method for locating configuration errors in a computer network is provided. First, a method for modeling the complex protocol semantics of the network control plane based on DDlog is given; then, during the model operation, a lightweight incremental event state origin tracking method is combined; finally, during the diagnostic query, a general method for constructing an origin tree based on reverse constraint search is combined, and further, an origin tree incremental construction and negative origin tree guided construction strategy are used to locate the root causes of errors that lead to abnormal forwarding table change events and missing events.
[0083] First, in the method for modeling the complex protocol semantics of the network control plane based on DDlog, an incremental network control plane model based on DDlog is provided, which can declaratively encode various routing protocols simply and efficiently and perform simulation calculations incrementally. The following is an introduction to this model:
[0084] DDlog is an incremental Datalog language built on top of Differential Dataflow. A Datalog program usually consists of a series of rules, and the rules have the form of "R0(X0): -R1(X1),..., R n (X n ).", where R i represents a relational predicate or an arithmetic predicate, and the derivation logic is: when R1(X1),..., R n (X n ) in the rule body are all true at the same time, R0(X0) in the rule head is true, and a new relational instance is derived. The relational instance is also called a fact and is represented by a data tuple. While maintaining the Datalog language specification, DDlog automatically compiles the computational logic defined by the rules into differential data flow operations and uses a set of general differential operators to support incremental calculations of recursive data flows.
[0085] The present invention abstracts vendor - independent configurations into EDB relational facts as the basic input. For example, the configuration fact that router node sets routing policies policies for BGP neighbor router to_node is represented by the input relational instance RouteMapOut(node, to_node, policies). The model has multiple intermediate relations representing network states and an output relation FIB, which represents the forwarding information base fib calculated by the control plane. The fib forwarding information base is defined by the triple (node, pfx, intf), where node represents the node with the forwarding information base, pfx represents the network prefix that can be matched, and intf represents the forwarding port. When a data packet can match multiple forwarding information bases, the Longest Prefix Match (LPM) principle is followed. In the case of network change scenarios, the model takes the addition or deletion of relational facts corresponding to configuration changes as input, and through incremental simulation, outputs the changes in the FIB relational instance, that is, the addition or deletion of the forwarding information base.
[0086] The present invention uses DDlog rules to describe the interaction of relational tables to model complex routing protocols in the control plane. Taking the simulation of the BGP routing protocol as an example, according to Figure 3 As shown, a schematic diagram of the derivation of the main relationships related to the BGP routing protocol in the network control plane model is given. The relationships are connected by arrows, indicating the direction of the derivation of relational instances in the rules. First, the BGP protocol publishes the routing prefixes existing in the global routing table (GlobalRIB), such as the prefixes of static routes (StaticRoute), to the local BGP routing information base BGPRIB through the network configuration command (BGPNetwork) or route redistribution (BGPRedis); then, according to the type of neighbor, the routing message to be propagated NeedRIBOut is determined, and after filtering and modification using the outbound routing policy (RouteMapOut), the routing message table AdjRIBOut announced to the neighbor is obtained; finally, the neighbor router filters and modifies the received routing message (AdjRIBOut) using the inbound routing policy to obtain the acceptable routing message (MatchedRIBIn), updates the best route locally using the BGP selection principle, and installs it into BGPRIB and GlobalRIB. The above process is continuously repeated until all relational tables no longer change, and the incremental simulation of the control plane is completed. Attached Figure 3 The specific DDlog coding implementations corresponding to the marked parts of rules R1, R2, and R3 are as shown in Attached Figure 4 As shown.
[0087] Then, based on the incremental event state origin tracking method of the declarative network control plane model, it is possible to avoid directly recording the complete causal mapping during runtime and reduce the performance overhead of origin tracking. The following introduces this method:
[0088] The incremental event status origin tracking method records the rule-derived events themselves and a small amount of extended information during the model incremental derivation process for subsequent origin tree construction. Define a triple (ts, type, tuple) to represent a rule-derived event, where ts represents the timestamp of the event occurrence, defined by a binary tuple (epoch, iterSeq), where epoch represents the update transaction number of the incremental execution, and iterSeq represents the execution number of the recursive calculation within the transaction; type represents the type of the event, including three types: addition event (+), deletion event (-), and missing event (!), which are identified by the symbols in parentheses in the following text; tuple represents the relational tuple that has changed. For the DDlog rule "R0(X0) :- R1(X1),..., R n (X n ).", the present invention tracks the relevant status information by adding log record statements to each rule, and the specific form is as follows:
[0089] R0(X0) :- R1(X1),..., R n (X n ), Log(ts, rid, type, x base , x ext )#(1)
[0090] In the formula: Log is the API for calling the log interface; ts is the global logical timestamp of the rule derivation, which can be obtained through the DDlog internal variable DDlog_timestamp; type is the event type generated by the rule derivation, which can be obtained through the internal variable DDlog_weight; rid is the unique identifier of the rule Rule i ; x base is the attribute value of the relational instance in the rule head; x ext is the extended attribute value; when the rule derivation generates an incremental event e, the system synchronously outputs a log record, which is represented by log(e) in the following text, and Field all (rid) represents all the attribute sets of the event after expansion, that is, Field all = Field base ∪ Field ext .
[0091] To improve the efficiency of log search and lookup, the present invention establishes an index in the log record with the relation name R i of the relational instance, and can quickly find all the log records logs(R i ) corresponding to the instance-derived events of the relational predicate R i .
[0092] Taking the rule R1 in Figure 4 as an example, the attribute set Field of the rule head relationship header = {node, prefix, next_ip, real_as_path, type}, and the attribute set Field of all relationships in the rule body body = Field header ∪ {to_node, rm_name, policies}. According to the mapping relationship between attributes, the attributes of the rule body instance that cannot be obtained by reverse inference from the rule head relationship instance are {to_node, rm_name, policies}. Therefore, these attributes need to be recorded separately. Since the routing policy name rm_name in the network configuration is required to be globally unique and there is a one-to-one correspondence between rm_name and the specific policy policies, the extended attributes that need to be recorded after eliminating the associated dependencies between attributes should be {to_node, rm_name}. The log record statement that needs to be added at the end of the rule is: Log(DDlog_timestamp, DDlog_weight, R1, {node, prefix, next_ip, real_as_path, type}, {to_n. Given a specific log record (T, +, R1, {D, 1011 / 4, 1111, [], incomplete}, {S, rm2}), according to the Figure 5 attribute projection shown, the attribute constraints that each input instance in the rule body needs to satisfy can be directly inferred from the rule head relationship instance.
[0093] Finally, the general method of constructing the origin tree using reverse constraint search can locate the relevant input events from the unstructured origin trace log records for a given diagnostic query event and construct a complete origin tree from top to bottom. The following is an introduction to this method:
[0094] The method of constructing the origin tree using reverse constraint search generates the reverse constraints that the corresponding input events need to satisfy based on the given diagnostic query event, and obtains the corresponding input events by searching for the matching results that satisfy the reverse constraints in the log recorded at runtime, thereby constructing the origin tree. For the abnormal event e that needs to be diagnosed and queried in the control plane output, the present invention uses the reverse constraint search method to recursively construct the origin tree from top to bottom, and gives the input event e related to the derived event e i , as well as the sub-origin trees of each input event. Since the input event e i derived from the rule strictly follows the "happens-before" principle with the query target e, so the search target e iIt already strictly exists in the events derived from the model bottom-up. Based on the event information recorded in the log at runtime, the present invention transforms the task of constructing the origin tree of diagnostic events into a process of searching for satisfiable log records in the log. To ensure that the search result is a valid rule derivation instance, according to the log record log(e) of the diagnostic event, the present invention realizes it by restricting the tuple attributes and incremental states that the search object log(e i ) needs to satisfy. Since this kind of constraint is from the output event to the input event, which is opposite to the bottom-up derivation process, the present invention calls this kind of constraint reverse constraint, and the corresponding search process is called reverse constraint search.
[0095] The incremental control plane model constructed by the present invention includes three types of DDlog rules: rules with general semantics, rules with negative semantics, and rules with aggregation semantics. The following respectively introduces the generation methods of reverse constraints in these three types of rules, and it is agreed that ρ k is the unique identifier for each subsequent rule.
[0096] 1) Let the rule with general semantics have the form of "R0(X0): -R1(X1),..., R n (X n ).", for example, rule R1 in the appendix Figure 4 , where R i (X i ) represents a relational predicate, R i represents a relation name, and X i is an attribute vector composed of variables or constants. Formally, the rule body is composed of the conjunction of predicates, and each clause is connected by "AND" equivalently. The logical proposition equivalent to the rule is: check all the facts of each relational predicate in the rule body. If there is a fact for each relational predicate such that each clause in the rule body is true, then the rule head is true, and a new relation instance is derived. The output event e generated by the incremental derivation of the rule corresponds to an instance change of the rule head predicate R0(X0), and the required general input event e i corresponds to an instance change of the relational predicate R i (X i ) in the rule body. According to the log record log(e) of the output event e, the log record log(e i ) of the input event e i ) that needs to be satisfied by the reverse constraint match e (e i ) can be defined as follows:
[0097]
[0098] In the formula, the symbol "<" represents "happens - before", that is, the log generation time of the input event should be earlier than the output event; the symbol "≡" represents "is defined as", that is, the constraints that the attribute vector of the input event log on the left side of the symbol needs to satisfy are defined by the attribute assignment on the right side of the symbol. represents the attribute set Field extended from the relational predicate R0 all (ρ k ) to the predicate R in the relation body i attribute set X i The reverse mapping between them, and then this mapping is applied by the map operator to the attributes corresponding to the log record log(e) to generate specific attribute assignments. For example, in the rule "A(X, Y): -B(X, Z), Y = Z + 1.", the reverse mapping from the attribute set of the relational predicate A to the attribute set of the relational predicate B is {X B = X A , Y B = X z + 1}, for a relational instance A(1, 2) derived from the rule, using the above reverse mapping, the attribute constraints that the corresponding instance of the relational predicate B in the input needs to satisfy can be determined as {X B = 1, Y B = 1}.
[0099] 2) Let the rule with negative semantics have the form of "R0(X0): -R1(X1),..., not R n (X n ).", for example, R2 in Figure 4 . Based on the form of the general rule, there are also relational predicates with negation (not). Similar to the meaning of the general semantic rule, when each clause in the rule body is true, the rule head is true, which means that the relational atom with not modification is false, that is, there is no relational fact that satisfies the variable constraints of the rule body, corresponding to the absence or deletion event of the relational instance. The present invention regards the absence or deletion of the relational instance and the addition of the relational instance as "reciprocal" event types. For the general input events {e i |i = 1, 2,..., n - 1} in the rule body, the reverse constraint from the output event to the input event is still formula (2); for the input event e n corresponding to the relational predicate R n (X n ), when satisfying the attribute constraints of each relation in the rule body, the type of the event is reciprocal to the output event. Therefore, the second term in formula (2) needs to be modified to log(e n).type = ~log(e).type, where the operator "~" represents taking the inverse of the event type. For example, when the type of the event output by the rule is deletion, the corresponding input event type after taking the inverse should be addition.
[0100] 3) Let the rule with aggregation semantics be in the form of "R(X, Z) :- R1(X1, Y), z = A gg re g ate(X1, func(Y)).", such as Figure 4 R3 in the appendix. In the formula, the relation table of the relation predicate R1 is the object to be aggregated, X1 is the key for grouping during aggregation, func() is the reduction function executed on the grouped results, and the parameter Y represents the relation attribute participating in the reduction calculation. The rule first groups the data records in the relation table according to the specified grouping key, then applies the reduction function to the data records within each group, collects the reduced results within each group to obtain the aggregation result, and derives the rule head relation instance. Under rule incremental derivation, only when the change of the input relation predicate instance changes the reduction result within the corresponding group, will the existing reduction result be updated, that is, the original reduction result (if any) is deleted, and the current reduction result is added. The rule containing the aggregation process is only used to select the optimal route in the present invention, so it only involves the reduction function related to extreme value calculation, that is, selecting one extreme value from a data set as the output according to a specific comparison method. For example, the select_best() function is used in R3 to select the MatchedRIBIn record with the shortest as_path length under the same prefix as the optimal BGP route.
[0101] The existing origin method simply associates all the inputs of the rule as the origin of the output. However, this approach will generate redundancy in the aggregation process related to optimal route calculation, because only the input events that affect the original optimal route will cause the aggregation result to change. Therefore, the reverse constraint match e (e1) from the output event log log(e) to the aggregated input event log log(e1) needs to additionally constrain the input events to be the part that affects the original extreme value in the rule input; in addition, since there is no clear relationship between the change type of the relation instance in the input event and the change type of the rule head relation instance, match e (e1) does not contain the constraint on the change type of the input event and can be defined as follows:
[0102]
[0103] Among them, the operator "≥" means that the attribute y participating in the reduction calculation in the input event "is not inferior to" the result z of the reduction calculation. This enables the located input event to always affect the original extreme value during the aggregation process, is a valid input participating in the aggregation process, conforms to the semantics of the actual aggregation process, and avoids introducing irrelevant input events into the provenance information.
[0104] Based on the above reverse constraint generation method, the present invention constructs a provenance tree by searching for satisfiable matching results in the log records of runtime provenance tracking. Since the DDlog program is a data-driven system, that is, newly input incremental events trigger incremental derivation of rules, and the generated incremental output events are temporally close to the input events. To improve the efficiency of provenance information search, the present invention uses reverse constraints to perform reverse search in the log records of the ordered output of rule derivation, so as to quickly obtain the latest input events that satisfy the constraints. Specifically, the present invention uses the Figure 6 algorithm 1 shown below to construct the provenance tree from top to bottom: For the query event e, the algorithm first generates the root node root of the provenance tree using the corresponding log record log(e), and initializes the query queue queue (lines 1-2). Then perform a BFS search: Obtain the record corresponding to the diagnostic event from the queue, and the event corresponding to the record. Determine whether it is a basic input event of the EDB type according to the rule identifier RID (line 5): If so, there is no input event that needs to be further searched; otherwise, it indicates that the event is a derived event. Then, according to the rule identifier of the event, query the definition of the rule to obtain the set of relationship names {R1, R2,..., R n} in the rule body (line 8). Then, in the log records logs(R i ) corresponding to each relationship, check the corresponding record e ij in each log in reverse order to see if it satisfies the reverse constraint condition match e (e ij ). If it is satisfied, generate the corresponding node in the provenance tree for e ij , point to the parent node and add it to the queue (lines 10-13). Since when deriving rules without an aggregation process, each relationship in the rule body requires at most one input event, for such rules, searching for one satisfiable input event is sufficient (lines 15-16), otherwise multiple log records that satisfy the constraints need to be searched. Finally, the algorithm outputs the root node of the provenance tree, and the complete provenance tree can be traversed according to the dependency relationship between the nodes. The leaf nodes of the provenance tree represent all basic input events related to the query event, corresponding to specific network configuration change operations.
[0105] The present invention proposes a method for efficiently locating the root causes of abnormal forwarding table change events and abnormal forwarding table missing events through time and space dimension references. The method is introduced as follows:
[0106] The error forwarding table event output by the incremental network control plane includes two types of events: abnormal forwarding table changes and abnormal forwarding table missing. However, the above method for constructing the origin tree based on reverse constraint search cannot meet the root cause localization of these two types of events. On the one hand, although this method outputs complete origin information, there is still a problem that there is too much origin information to analyze. On the other hand, this method can only explain the existing events in the system output and does not support the construction of negative origin trees for missing events. Therefore, based on the above method, in this section, for abnormal forwarding table changes and missing events, references are made from the time and space dimensions respectively, and the root cause of the error is located using the incremental construction strategy of the origin tree and the guided construction strategy of the negative origin tree.
[0107] 1) For the abnormal forwarding table change events in the output, that is, the forwarding table addition and deletion events, the present invention is based on the time dimension, refers to the system state before the change, and uses the incremental construction strategy of the origin tree to locate the root cause of the error and outputs the configuration operations related to the network change. The present invention observes that the error localization under network verification can always ensure the correctness of the deployed configuration through the verification tool. Therefore, the state before the network configuration change can be used as a reference, paying attention to the system state changes affected by the configuration change, and using the incremental construction strategy of the origin tree to give the dependency relationship between the incremental events in the current update to achieve root cause localization.
[0108] To construct the incremental origin tree, based on the above reverse constraint search, the present invention modifies the constraint that the events in the reverse constraint need to meet in terms of time sequence to: log(e i ).ts < log(e).ts ∧ log(e i ).ts.epoch = log(e).ts.epoch, that is, the timestamp of the input event e i has the same update transaction serial number as the event e of the diagnostic query, so as to exclude the input events generated before the previous change transaction, and then search in the logs tracked during the operation of the algorithm in Appendix Figure 6 to directly obtain the incremental origin tree. The leaf nodes are the triggering root causes leading to abnormal output, which can correspond to specific configuration change operations. The incremental origin tree T′(e) obtained by this method is equivalent to excluding the unchanged parts from the full-scale origin tree T(e) corresponding to the event e, such as T(c1) and T(c2), as shown in Appendix Figure 7 .
[0109] 2) For abnormal missing events in the output, such as the missing forwarding table, the present invention, based on the spatial dimension, refers to the existing forwarding table origin information that is similar to the missing event, and uses the negative origin tree-guided construction strategy to locate the root cause and output the missing configuration operations in the change. The present invention observes that Y! Based on counterfactual reasoning, it is necessary to consider all counterfactual reasons that prevent the missing event from being deduced, generating a large number of negative origin trees, making it difficult to locate the root cause. Since the origin tree can reflect the execution logic of the system to generate specific events, by analyzing the differences between the negative origin tree of the abnormal missing event and the origin tree of the reference event, the root cause of the system "deviating" from the normal execution logic and resulting in abnormalities can be located. Therefore, in the process of constructing the negative origin tree of the missing event, the present invention combines the origin information of the reference event and guides the generation of definite counterfactual reasons from top to bottom, avoiding exploring the huge parameter space, thereby locating the root cause. It is specifically implemented through the following three steps. The negative origin tree-guided construction process under non-negated semantics can be represented as attached Figure 8 as shown.
[0110] Step 3.2.1: Determine the seeds. For the forwarding table missing event e1: (t1,!, FIB(n, pfx1, a)) and the reference event e2: (t2, +, FIB(n, pfx2, a)) with the same forwarding port, the two events only differ in attributes such as the change type, timestamp, and network prefix. The present invention defines these initial differences as the "seed" attributes of the event and keeps them unchanged in the subsequent origin tree construction process.
[0111] Step 3.2.2: Establish equivalence. Based on reverse matching search, construct the full quantum origin trees T(e1) and T(e2) of the missing event e1 and the reference event e2 respectively, that is, search for all satisfiable input events e 1i and e 2i , for the events in e 1i and e 2i that only differ in seed attributes, the present invention regards them as equivalent. In the incremental network control plane model, events are generated by a definite rule derivation logic. It can be proved that the sub-origin trees corresponding to equivalent events should also be equivalent: Assuming that there are non-equivalent differences in the sub-origin trees of equivalent events, then these differences will further deduce non-equivalent output events, violating the premise that the root node events of the sub-origin trees are equivalent. The assumption is not valid. Therefore, the sub-origin trees of equivalent events are equivalent. Since there are no more origin differences in the sub-origin trees of equivalent events, there is no need to further construct sub-origin trees to analyze the differences, which are marked with terminators in the figure.
[0112] Step 3.2.3: Determine the counterfactual reason. For e 1i and e 2iFor the parts that still have differences after establishing equivalence, it is necessary to further determine the counterfactual cause by using the origin difference and seed attributes. If the rule cannot deduce the occurrence of event e1, there are two possibilities: e 1i lacks input events As shown in the appendix Figure 8 , or e 1i contains a negated input event For the former, based on the same type of events in e 2i , the present invention creates a copy, and then replaces the seed attribute values of e into the corresponding attributes of the copy to generate the missing input event in e i . If the relational tuple in this event is an IDB fact, then 1i and its reference event are used as inputs, and steps 3.2.2 and 3.2.3 are recursively executed to generate a determined negative origin tree; if this instance is an EDB fact, then is used as the leaf node of the negative origin tree, indicating the missing operation in the configuration change. For the latter, at this time the corresponding reference event is a missing event . The present invention follows the above method, uses the currently existing event as the reference of to guide the generation of the negative origin tree of . The counterfactual cause corresponding to the leaf node and its reference event ref are the root causes that lead to the absence of and thus the missing event e1. Therefore, canceling the operation corresponding to event ref is the missing operation in the configuration change. is missing while is deduced, and then leads to the missing event e1. Therefore, canceling the operation corresponding to event ref is the missing operation in the configuration change.
[0113] According to the appendix Figure 9 shown, the present invention also provides a configuration error location system for a computer network, including:
[0114] A configuration parsing module for abstracting the complex routing protocol semantics of the network control plane into the interaction between data tables and constructing an incremental network control plane model;
[0115] An incremental network simulation module for, when the incremental network control plane model is running, tracking the runtime state information in the form of logs to support subsequent error location requirements;
[0116] An origin tree construction module for, for the abnormal forwarding table changes and forwarding table missing events output by the incremental network control plane model, constructing an origin tree based on reverse constraint search and using a reference-based origin tree construction strategy to locate the root cause of the abnormal error forwarding table output by the network control plane model.
[0117] Among them, the configuration parsing module parses network configuration files of different manufacturers into a unified representation independent of manufacturers, and then further abstracts the differences before and after network configuration changes into relationship fact change instances required by the incremental network control plane model, and transmits them to the incremental network simulation system. The incremental network simulation module includes a control plane incremental calculation unit and a log collection unit; the control plane incremental calculation unit is used to receive relationship fact changes corresponding to configuration changes from the configuration parsing system, and then incrementally execute relevant rules according to the input relationship fact changes, derive relevant network state change events until the network states in the control plane no longer change, and finally output the relationship instance changes of the forwarding table; the log collection unit is used to record specified incremental event status information during the process of incremental rule execution, and perform log storage and index establishment. The origin tree construction module includes a reverse constraint generation unit, a matching search unit, and a counterfactual generation unit; the reverse constraint generation unit generates tuple attributes and incremental state constraints that the corresponding input events need to satisfy according to the diagnostic query event; the matching search unit is used to search for log records that meet the reverse constraints from the log information maintained by the log collection unit and provide input events related to the diagnostic query event; the counterfactual generation unit uses the sub-origin tree of the reference event to guide the generation of corresponding counterfactual reasons in the sub-origin tree where the missing event is unsatisfied through the feature attribute replacement method. The system first adopts different origin tree construction strategies according to the event type of the diagnostic query: for abnormal forwarding table change events (+ / -fib), it adopts the origin tree incremental construction strategy and is processed by the reverse constraint generation unit and the matching search unit in sequence; for abnormal forwarding table missing events, it adopts the negative origin guidance generation strategy and is processed by the reverse constraint generation unit, the matching search unit, and the counterfactual generation unit in sequence. Then it is judged whether the matching result is the basic input event corresponding to the EDB relationship. If it is a basic event, it indicates that the specific wrong configuration operation has been located, and the result is presented by the visualization system; otherwise, it indicates that the input event is a derived event corresponding to the IDB relationship, and it needs to be further used as a new diagnostic query object and recursively processed by the origin tree construction system.
[0118] The present invention also includes a visualization module for presenting the result of error location to the user and helping the user understand the cause of the error in the form of a structured origin tree, where the leaf nodes of the origin tree are the root causes leading to errors in the network control plane and can correspond to specific network configuration operations.
[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement without departing from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.
Claims
1. A method for locating configuration errors in a computer network, characterized in that It includes the following steps: Step 1: Abstract the complex routing protocol semantics of the network control plane into the interaction between data tables, and construct an incremental network control plane model; Step 2: When the incremental network control plane model is running, track the runtime state information in the form of logs to support subsequent error location requirements; Step 3: For the abnormal forwarding table changes and forwarding table missing events output by the incremental network control plane model, based on the reverse constraint search method, use the origin tree incremental construction and negative origin tree guided construction strategies to locate the root cause of the error.
2. The method for locating configuration errors in a computer network according to claim 1, characterized in that, In Step 1, the abstraction of the complex routing protocol semantics of the network control plane is represented by relationship instances in the incremental declarative programming language DDlog; the state changes of the network control plane state information are represented as the addition or deletion events of relationship instances; among them, the vendor-independent configuration is abstracted into the EDB relationship instance in the incremental declarative programming language DDlog as the basic input of the incremental network control plane model; the network state in the network simulation process is abstracted into the IDB relationship instance in DDlog, where the FIB relationship instance represents the forwarding table output by the incremental network control plane model.
3. The method for locating configuration errors of a computer network according to claim 1, characterized in that, In Step 1, to construct an incremental network control plane model, the simulation of the control plane is abstracted as a process of continuously propagating and updating routing messages until all routing tables no longer change and reach convergence, which can be modeled as operations between relationship tables and described using the incremental declarative programming language DDlog.
4. A method for locating configuration errors in a computer network according to claim 3, characterized in that, The description process of the incremental declarative programming language DDlog is as follows: S1: Generate the local routing table according to the port IP configuration and static routing information of the devices in the network; S2: According to the dynamic routing protocol configuration, publish the local routing to neighbor nodes and select the optimal routes announced by neighbor nodes: group the routes by network prefix, use the optimal route selection algorithm to calculate the best route under the same prefix, and add the best route to the local routing information library and the routing table to be propagated; S3: Modify or filter the routing message table to be propagated according to the configured routing policy; S4: Repeat S2 - S3 until the various routing tables of all devices no longer change.
5. A method for locating configuration errors in a computer network according to claim 1, characterized in that In Step 1, translate the incremental network control plane model into a Differential Dataflow data stream model, and use a set of general differential operators to support the incremental calculation of recursive data streams.
6. A method for locating configuration errors in a computer network according to claim 1, characterized in that, In step 2, when the incremental network control plane model is running, the runtime state information is tracked in the form of logs, where the runtime state information only records rule derivation events and extended attribute information: the rule derivation event is the change event of the rule head relationship instance, including the unique identifier rid corresponding to the rule that derives the event, the global logical time ts, the event type type, and the specific relationship instance tuple, and the attribute set corresponding to each element in the tuple is denoted as Field base ; The extended information includes the attribute values that only appear in the rule body relationship and cannot be simply deduced from the rule head relationship instance, and there is no associated dependency between these attribute values, and the corresponding attribute set is denoted as Field ext .
7. A method for locating configuration errors in a computer network according to claim 1, characterized in that, In Step 3, the specific process of constructing the origin tree using the reverse constraint search for a given diagnostic query target is as follows: K1: Use the given query event e as the root node root of the origin tree, and add its corresponding log record log(e) to the query queue queue; K2, if the queue is not empty, dequeue the event record log(e) from the query queue, obtain the corresponding rule definition according to the recorded rule identifier rid, and combine the mapping relationship between the output event e and each input event e in the rule definition context to generate the reverse constraints that each input relationship corresponding event needs to satisfy, which consists of the tuple attributes and incremental status that the log record log(e i ) of each input event needs to satisfy; i ) K3, perform a matching search from bottom to top using the logs recorded at runtime with reverse constraints. For the satisfiable event record log(e i ), construct the sub-origination tree of event e by adding a directed edge from event e i to event e; if event e i is an IDB relationship event, add the record log(e i ) to the query queue queue and re-execute step K2.
8. A method for locating configuration errors in a computer network according to claim 7, characterized in that, In Step 3, for the abnormal forwarding table change event, through the reference of the time dimension, use the origin tree incremental construction strategy to locate the relevant configuration change operations: based on the reverse constraint search method, constrain the input event and the output event to be in the same transaction, so as to exclude the input events with unchanged states in the current change during the search process, and output the causal mapping between the changed events in the current change, that is, the incremental origin tree.
9. The method for locating configuration errors of a computer network according to claim 1, wherein, In step 3, for the abnormal forwarding table missing event, through the reference in the spatial dimension, the negative origin tree-guided construction strategy is used to locate the relevant configuration missing operations. The specific process is as follows: L1. Given the forwarding table addition event e2 with the same forwarding port as the forwarding table missing event e1 as the reference event, and taking the original attributes with differences between the two events as the seed attributes; L2. Use the reverse constraint search method to construct the sub-origin trees T(e1) and T(e2) of the given missing event e1 and its reference event e2 respectively; L3. Consider the input event differences caused by the seed attributes in T(e1) and T(e2) as equivalent. If there are non-equivalent input event differences, then obtain the counterfactual reason that the missing event e1 cannot generate by referring to the input events of the same type relationship in T(e2) and replacing the seed attributes. Then, take the missing event corresponding to this reason and its reference as a new query, and re-execute step L2.
10. A configuration error location system for a computer network, characterized in that, Including: A configuration parsing module, which is used to abstract the complex routing protocol semantics of the network control plane into the interaction between data tables and construct an incremental network control plane model; An incremental network simulation module, which is used to support the subsequent error location requirements by tracking the runtime state information in the form of logs when the incremental network control plane model is running; An origin tree construction module, which is used for the abnormal forwarding table changes and forwarding table missing events output by the incremental network control plane model, constructs an origin tree based on reverse constraint search, and adopts an origin tree construction strategy with reference to locate the root cause of the abnormal error forwarding table output by the network control plane model.
Citation Information
Patent Citations
A control plane fault diagnosis system based on differential detection and an implementation method thereof
CN109936479A
Control plane debugging method and device, node and storage medium
CN114422336A