Network topology-based verification method and device, electronic equipment and storage medium
By automatically identifying target and extended network devices through acquiring device change information, constructing and verifying a simulated network topology, this technology solves the problem of the difficulty in manually building network topologies in existing technologies and improves the efficiency of large-scale network simulation verification.
Patent Information
- Application Number
- CN202310710403.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-14
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2043-06-14
AI Technical Summary
The lack of automated network topology construction methods in existing technologies makes it difficult to achieve large-scale network simulation and verification.
By obtaining device change information from network verification requests, the system automatically identifies the target network devices that have changed in the real network, obtains extended network devices from the real network, constructs a simulated network topology, and builds a simulation runtime environment for simulation verification.
It enables automated construction of simulated network topologies, improving the efficiency of network verification, especially for the simulation verification of large-scale network topologies.
Smart Images

Figure CN116614387B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of network simulation, specifically to a verification method, apparatus, electronic device, and storage medium based on network topology. Background Technology
[0002] Network emulation is primarily used to verify switch configurations and assess the potential risks of configuration changes to a real network. Its main task is to create a 1:1 replica of the real network using network virtualization technology, based on network change requirements, thereby enabling the verification of network changes within the simulated environment.
[0003] Current network simulation solutions lack automated methods for building network topologies, still requiring manual implementation of the process. Consequently, existing methods face significant challenges in setting up large-scale network simulation environments due to their inability to automatically build network topologies, making network simulation verification difficult. Summary of the Invention
[0004] In view of this, the present disclosure provides a network topology-based verification method, apparatus, electronic device, and storage medium to solve the problem that network simulation verification is difficult to achieve due to the inability to automatically build network topology in the prior art.
[0005] In a first aspect, embodiments of this disclosure provide a verification method based on network topology, the method comprising:
[0006] Obtain a network verification request, wherein the network verification request includes device change information for a real network, the real network includes multiple layers, and each layer includes multiple network devices;
[0007] The device change information is used to identify the target network device that has changed in the real network, and extended network devices are obtained from the network devices at each level of the real network, wherein the extended network devices obtained at each level correspond to different vendors;
[0008] Construct a simulated network topology based on the target network device and the extended network device;
[0009] A simulation environment corresponding to the simulated network topology is built, and the simulated network topology is simulated and verified based on the simulation environment to obtain the simulation verification results.
[0010] Secondly, embodiments of this disclosure provide a network topology-based verification device, the device comprising:
[0011] An acquisition module is configured to include, wherein, the network verification request includes device change information for a real network, the real network comprising multiple layers, and each layer comprising multiple network devices;
[0012] The determination module is used to determine the target network device that has changed in the real network using the device change information, and to obtain extended network devices from the network devices at each level of the real network, wherein the extended network devices obtained at each level correspond to different vendors;
[0013] The construction module is used to construct a simulated network topology based on the target network device and the extended network device;
[0014] The processing module is used to build a simulation runtime environment corresponding to the simulated network topology, and to perform simulation verification on the simulated network topology based on the simulation runtime environment to obtain simulation verification results.
[0015] Thirdly, embodiments of this disclosure provide a computer device, including: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the network topology-based verification method of the first aspect or any corresponding embodiment described above.
[0016] Fourthly, embodiments of this disclosure provide a computer-readable storage medium storing computer instructions for causing a computer to execute the network topology-based verification method described in the first aspect or any corresponding embodiment thereof.
[0017] The technical solution provided in this disclosure has the following advantages: The method provided in this disclosure firstly, based on the device change information carried in the network verification request, can automatically determine the target network device that has undergone a change from the real network. Secondly, it traverses multiple extended network devices corresponding to the target network device from the real network. Furthermore, it constructs a simulated network topology based on the target network device and the extended network devices, and builds a simulation runtime environment for the simulated network topology. Finally, it performs simulation verification on the simulated network topology and obtains the simulation verification results. By automatically traversing relevant extended devices based on the changed device and building the simulated network topology, it achieves automatic construction of the simulated network topology, eliminating the need for manual construction even for large-scale network topologies. In addition, automatic network verification can be performed after the simulated network topology is built, improving the efficiency of network verification. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the specific embodiments of this disclosure or the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0019] Figure 1 This is a schematic flowchart of a network topology-based verification method according to some embodiments of the present disclosure;
[0020] Figure 2 This is a schematic diagram of a real network according to some embodiments of this disclosure;
[0021] Figure 3 This is a schematic diagram of a real network according to some embodiments of this disclosure;
[0022] Figure 4 This is a schematic diagram of a simulated network topology according to some embodiments of this disclosure;
[0023] Figure 5 This is a connection diagram of the target host according to some embodiments of this disclosure;
[0024] Figure 6 This is a structural block diagram of a network topology-based verification device according to an embodiment of the present disclosure;
[0025] Figure 7 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this disclosure. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0027] According to embodiments of this disclosure, a verification method, apparatus, electronic device, and storage medium based on network topology are provided. It should be noted that the steps shown in the flowcharts in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0028] This embodiment provides a network topology-based verification method that can be used on smart terminals such as computers and tablets. Figure 1 This is a flowchart of a network topology-based verification method according to an embodiment of the present disclosure, as shown below. Figure 1 As shown, the process includes the following steps:
[0029] Step S11: Obtain a network verification request, wherein the network verification request includes device change information for the real network, the real network includes multiple layers, and each layer includes multiple network devices.
[0030] In this embodiment of the disclosure, the smart terminal is equipped with a network verification platform. The user triggers a network verification request based on the network verification platform. The network verification request includes device change information for the real network. The real network includes multiple layers, and each layer includes multiple network devices. The network devices can be switches.
[0031] Specifically, the network verification platform can receive a list of device names uploaded by the user. This list includes the device names of at least one changed device in the real network. The platform uses these device names to query the corresponding device change information, which may include: the device name, device information for newly added devices in the real network, device information for replaced devices, or the modified configuration information of a specific device in the real network, etc. Finally, a real network verification request is made based on this device change information.
[0032] Step S12: Use the device change information to determine the target network device that has changed in the real network, and obtain the extended network device from the network devices at each level in the real network. The extended network device obtained at each level corresponds to a different vendor.
[0033] In this embodiment, the target network device undergoing change in the real network is determined using the device name in the device change information, and the hierarchical level of the target network device in the real network is also determined. Then, based on the hierarchical level of the target network device in the real network, the network devices at the next and next levels of the device, as well as network devices at the same level, are traversed to obtain the extended network devices finally used to construct the simulated network topology. The extended network devices at each level correspond to different vendors. For example, if the target network device is currently at the third level, the extended network devices obtained from the previous level (second level) include: device 2 and device 3, where device 2 corresponds to vendor A and device 3 corresponds to vendor B. The extended network devices obtained from the next level (fourth level) include: device 5 and device 7, where device 5 corresponds to vendor A and device 7 corresponds to vendor C.
[0034] Specifically, obtaining extended network devices from network devices at each layer of the real network includes the following steps A1-A3:
[0035] Step A1: Traverse the real network to obtain the set of upstream network devices and the set of downstream network devices associated with the target network device. The set of upstream network devices includes target upstream network devices at multiple levels, and the set of downstream network devices includes target downstream network devices at multiple levels.
[0036] In this embodiment of the disclosure, traversing the real network to obtain the set of upstream network devices and the set of downstream network devices associated with the target network device includes the following steps A101-A104:
[0037] Step A101: Traverse the real network to obtain the first set of devices at the next level of the target network device and the second set of devices at the next level of the target network device. The first set of devices includes multiple upstream network devices, and the second set of devices includes multiple downstream network devices.
[0038] In this embodiment of the disclosure, the real network can be traversed simultaneously to obtain a first set of devices at the next level (i.e., upstream) and a second set of devices at the next level (i.e., downstream) on the target network device. The first set of devices includes all upstream network devices at that level, and the second set of devices includes all downstream network devices at that level.
[0039] Step A102: Determine the first supplier set corresponding to the first equipment set and the second supplier set corresponding to the second equipment set, wherein the first supplier set includes multiple different first suppliers and the second supplier set includes multiple different second suppliers.
[0040] In this embodiment of the disclosure, a first supplier is queried for each upstream network device in the first device set, and a first supplier set is constructed based on the first suppliers. A second supplier is queried for each downstream network device in the second device set, and a second supplier set is constructed based on the second suppliers.
[0041] As an example, the first set of equipment includes equipment 2, equipment 3, and equipment 4, where equipment 2 corresponds to supplier A, equipment 3 corresponds to supplier B, and equipment 4 corresponds to supplier B. In this case, the first supplier set includes supplier A and supplier B. The second set of equipment includes equipment 5, equipment 6, and equipment 8, where equipment 5 corresponds to supplier A, equipment 6 corresponds to supplier A, and equipment 8 corresponds to supplier C. In this case, the first supplier set includes supplier A and supplier C.
[0042] Step A103: Select one upstream network device corresponding to each first supplier from the first device set as the target upstream network device and add it to the upstream network device set.
[0043] In this embodiment of the disclosure, when there are multiple upstream network devices corresponding to the first supplier in the first device set, one upstream network device corresponding to the first supplier can be arbitrarily selected from the first device set as the target upstream network device. The target upstream network device is then added to the upstream network device set.
[0044] In this embodiment of the disclosure, after selecting an upstream network device corresponding to each first supplier from the first device set as a target upstream network device and adding it to the upstream network device set, the method further includes: detecting whether each upstream network device in the first device set belongs to the root node, and obtaining a first detection result; taking the upstream network device whose first detection result is not a vertex as the baseline upstream network device, and traversing the real network to obtain a third device set one level above the baseline upstream network device, wherein the third device set includes multiple upstream network devices; determining the third supplier set corresponding to the third device set, wherein the third supplier set includes multiple different third suppliers; selecting an upstream network device corresponding to each third supplier from the third device set as a target upstream network device and adding it to the upstream network device set, until the upstream network device belonging to the root node is traversed.
[0045] As an example, such as Figure 2 As shown, target network device 1 is at the third layer in the real network. We then iterate through the upstream network devices at the next higher layer to obtain a first set of devices, which includes devices 2, 3, and 4. We then query the suppliers corresponding to each device in the first set: device 2 corresponds to supplier A, device 3 to supplier B, and device 4 to supplier B. This gives us the first supplier set (A, B), and we add devices 2 and 3 (or 4) to the upstream network device set.
[0046] Next, determine if devices 2, 3, and 4 are root nodes. Based on the actual network, devices 2, 3, and 4 are not root nodes. Therefore, traverse the parent level of devices 2, 3, and 4 to obtain the third set of devices, which includes devices 5, 6, and 7. Query the suppliers corresponding to each device in the third set: device 5 corresponds to supplier A, device 6 to supplier B, and device 7 to supplier B. This yields the third supplier set (A, B), and devices 5 and 6 (or 7) are added to the upstream network device set. Check if devices 5, 6, and 7 are root nodes; if so, stop traversing. The final upstream network device set includes devices 2, 3 (or 4), 5, and 6 (or 7).
[0047] It should be noted that, since upstream devices from different vendors behave differently in the network environment, when traversing the upstream network devices at each level, the corresponding vendor is determined, and then any upstream network device from each vendor is added to the upstream network device set. Based on this, by obtaining upstream network devices from different vendors at each level during the traversal process, the behavior of devices from each vendor can be encompassed in subsequent simulations, improving the accuracy of the simulation.
[0048] Step A104: Select one downstream network device corresponding to each second supplier from the second device set as the target downstream network device and add it to the downstream network device set.
[0049] In this embodiment of the disclosure, when there are multiple downstream network devices corresponding to the second supplier in the second device set, one downstream network device corresponding to the second supplier can be arbitrarily selected from the second device set as the target downstream network device. The target downstream network device is then added to the downstream network device set.
[0050] In this embodiment of the disclosure, after selecting a downstream network device corresponding to each second supplier from the second device set as the target downstream network device and adding it to the downstream network device set, the method further includes:
[0051] Detect whether each downstream network device in the second device set belongs to a leaf node to obtain a second detection result; take the downstream network devices that do not belong to a leaf node according to the second detection result as the baseline downstream network devices, and traverse the real network to obtain the fourth device set at the next level of the baseline downstream network devices, wherein the fourth device set includes multiple downstream network devices; determine the fourth supplier set corresponding to the fourth device set, wherein the fourth supplier set includes multiple different fourth suppliers; select one downstream network device corresponding to each fourth supplier from the fourth device set as the target downstream network device, and add it to the downstream network device set, until the downstream network devices belonging to the leaf nodes are traversed.
[0052] As an example, such as Figure 3 As shown, target network device 1 is at the third layer in the real network. We then iterate through the downstream network devices at the next lower layer of target network device 1 to obtain the first set of devices. The second set of devices includes devices 8, 9, and 10. We then query the suppliers corresponding to each device in the second set: device 8 corresponds to supplier A, device 9 to supplier B, and device 10 to supplier B. This gives us the second supplier set (A, B), and we add devices 8 and 9 (or 10) to the downstream network device set.
[0053] Next, it checks whether devices 8, 9, and 10 are root nodes. Based on the actual network, we know that devices 8, 9, and 10 are not root nodes. Therefore, it iterates through the next level of devices 8, 9, and 10 to obtain the fourth device set, which includes devices 11, 12, and 13. It then queries the suppliers corresponding to each device in the fourth device set: device 11 corresponds to supplier A, device 12 to supplier B, and device 13 to supplier B. This yields the third supplier set (A, B), and devices 11 and 12 (or 13) are added to the downstream network device set. It then checks whether devices 11, 12, and 13 are root nodes; if so, the iteration stops. The final downstream network device set includes devices 8, 9 (or 10), 11, and 12 (or 13).
[0054] It should be noted that, since downstream devices from different vendors behave differently in the network environment, when traversing the downstream network devices at each level, the corresponding vendor is identified, and then any downstream network device from each vendor is added to the downstream network device set. Based on this, by acquiring the downstream network devices from different vendors at each level during the traversal process, the behavior of devices from each vendor can be encompassed in subsequent simulations, improving the accuracy of the simulation.
[0055] Step A2: Traverse the real network to obtain target neighbor devices at the same level as the target network device.
[0056] In this embodiment of the disclosure, traversing the real network to obtain target neighbor devices at the same level as the target network device includes the following steps A201-A202:
[0057] Step A201: Traverse the real network to obtain candidate neighbor devices that are at the same level as the target network device.
[0058] Step A202: Identify the candidate neighbor devices that have not undergone device changes as the target neighbor devices.
[0059] In this embodiment, the real network is traversed to obtain candidate neighbor devices at the same level as the target network device. Since the candidate neighbor devices may include devices that have undergone device changes and devices that have not undergone changes, in order to accurately obtain the impact of the target network device changes on the network, candidate neighbor devices at the same level that have not undergone device changes need to be used as target neighbor devices. The number of candidate neighbor devices can be set according to simulation requirements.
[0060] It should be noted that simply obtaining the upstream and downstream network devices of the target network device will not provide the impact of the target network device in the simulated network. Furthermore, since the target network device also affects devices at the same level, obtaining the neighboring devices at the same level can improve the accuracy of the simulation in subsequent simulations.
[0061] Step A3: Designate the target upstream network device, the target downstream network device, and the target neighbor device as extended network devices.
[0062] In this embodiment of the disclosure, each target upstream network device in the upstream network device, each target downstream network device in the downstream network device, and the target neighbor device are used as extended network devices.
[0063] Step S13: Construct a simulated network topology based on the target network device and the extended network devices.
[0064] In this embodiment of the disclosure, constructing a simulated network topology based on the target network device and extended network devices includes the following steps B1-B2:
[0065] Step B1: Determine the first connection relationship between the target network device and the extended network devices, and the second connection relationship between each extended network device.
[0066] In this embodiment of the disclosure, according to the hierarchical relationship in the real network, the extended network devices at the next level and the next level of the target network device are obtained from the extended network devices and used as the first extended network device. The target network device is directly connected to the first extended network device.
[0067] Step B2: Based on the target network device, expand the network device, and construct the simulated network topology using the first connection relationship and the second connection relationship.
[0068] In the embodiments disclosed herein, such as Figure 4 As shown, the target network device in the simulated network topology includes: Extended network devices include: the target network device is device 1, and the extended network devices include: device 2, device 3, device 4, device 5, device 6, device 7, device 8, and device 9. The first connection relationship includes: the connection between device 1 and devices 2, 3, 6, and 7. The second connection relationship includes: the connection between device 2 and devices 4 and 5; the connection between device 3 and devices 4 and 5; the connection between device 6 and devices 8 and 9; and the connection between device 7 and devices 8 and 9.
[0069] In this embodiment of the disclosure, the method further includes the following steps C1-C3:
[0070] Step C1: Obtain the set of links between every two network devices in the simulated network topology, wherein the set of links includes at least one original link used to connect the two network devices.
[0071] In this embodiment of the disclosure, an excessive number of links in the simulated network topology may lead to significant performance overhead, such as reduced overall speed or test startup time. Therefore, to reduce performance overhead, it is necessary to prune the links between network devices in the simulated network topology.
[0072] Specifically, obtain the set of links between every two network devices in the simulated network topology. Each link set includes at least one original link connecting the two network devices. For example, in a simulated network topology including devices 1, 2, and 3, the link set between device 1 and device 2 includes link a, link b, and link c. The link set between device 2 and device 3 includes link d, link e, link f, and link g.
[0073] Step C2 involves pruning the original links in the link set to obtain the pruned target links.
[0074] Step C3: Update the link set based on the target link.
[0075] In this embodiment of the disclosure, the original links in the link set are pruned to obtain the pruned target links, including: removing a first number of original links from the link set to obtain a second number of remaining original links; comparing the second number of links with a preset number of links; and if the second number of links is greater than or equal to the preset number of links, using the remaining original links corresponding to the second number of links as the target links.
[0076] As an example, the simulated network topology includes device 1, device 2, and device 3. The link set between device 1 and device 2 consists of 7 links, and the link set between device 2 and device 3 consists of 9 links. Taking devices 2 and 3 as an example, 3 original links (the first number of links) are removed from the link set, leaving 6 original links (the second number of links). Comparing the second number of links (6) with the preset number of links (5), the second number of links is greater than the preset number. Therefore, the remaining original links corresponding to the second number of links can be directly used as the target links. It should be noted that the preset number of links can be understood as the number of links to ensure the simulation effect. When the second number of links is greater than the preset number of links, not only are the original links pruned, but some are also preserved, which is beneficial to improving the simulation effect.
[0077] In this embodiment of the disclosure, when the number of second links is less than the number of preset links, the difference between the number of second links and the number of preset links is determined; the original links corresponding to the difference are obtained from the original links of the number of first links; and the original links corresponding to the difference and the remaining original links corresponding to the number of second links are used as target links.
[0078] As an example, let's take device 1 and device 2 as examples. The link set between device 1 and device 2 includes 7 links. Three original links (the first number of links) are removed from the link set, leaving 4 (the second number of links) original links. Comparing the second number of links (4) with the preset number of links (5), the second number of links is less than the preset number, indicating that simply retaining the remaining original links corresponding to the second number of links is insufficient for the simulation effect. Therefore, the difference between the second number of links and the preset number of links is determined (1 link). One original link is randomly selected from the previously removed 3 links, and this original link, along with the remaining original links corresponding to the second number of links (5), are used as the target links. It should be noted that when the second number of links is less than the preset number of links, it means that pruning the original links is insufficient for the simulation effect, and a corresponding number of links need to be obtained from the removed original links to ensure the simulation effect.
[0079] Step S14: Build the simulation environment corresponding to the simulated network topology, and perform simulation verification on the simulated network topology based on the simulation environment to obtain the simulation verification results.
[0080] In this embodiment of the disclosure, the simulation runtime environment corresponding to the simulated network topology is built, including the following steps D1-D4:
[0081] Step D1: Obtain the number of layers in the simulated network topology.
[0082] Step D2: Determine the corresponding number of target hosts according to the number of tiers, and determine the number of containers in the target hosts based on the number of network devices in each tier.
[0083] In this embodiment of the disclosure, a corresponding number of target hosts can be set according to the number of tiers. For example, if the number of tiers is 5, then 5 target hosts can be set. Then, the number of network devices in each tier is obtained, and the number of containers in the target hosts is determined based on the number of devices. For example, if the number of network devices in each tier is 2, then the number of containers in each target host can be determined to be 2.
[0084] Step D3: Deploy the container number of containers within the target host.
[0085] In this embodiment of the disclosure, deploying a number of containers on a target host includes: determining the virtual machines to be deployed to each container on the host, and obtaining the virtual machine image and virtual machine startup program of the virtual machine; generating a container image based on the virtual machine image, the virtual machine startup program and a preset software library; and creating a container using the container image.
[0086] Step D4: Establish the connection relationships between various containers within the target host, as well as the connection relationships between containers between different target hosts, to obtain the simulation runtime environment.
[0087] In this embodiment of the disclosure, the connection relationships between various containers within the target host, as well as the connection relationships between containers between different target hosts, are established to obtain the simulation runtime environment, including the following steps E1-E3:
[0088] Step E1: Connect to each container in the target host through the virtual network interface port inside the container.
[0089] Step E2: Connect the Ethernet interfaces of each container in the target host to the first bridge, and use network tunnels to connect the first bridge in each target host.
[0090] Step E3: Connect the management interface of each container in the target host to the second bridge, and connect the second bridge in each target host to obtain the simulation running environment.
[0091] In this embodiment of the disclosure, containers within the same target host can directly connect using a virtual network interface card (veth), such as... Figure 5 As shown, containers (container1) and (container2) in the target host (Host1) are connected through virtual network interface ports. At the same time, the network interface of the virtual machine inside the container is connected to the network interface of the external container through the MacvTap interface, and a one-to-one mapping is achieved.
[0092] In this embodiment of the disclosure, for different target hosts, such as Figure 5As shown, the Ethernet interface (eth) of container (container1) in the target host (Host1) is connected to the first bridge (OVS Bridge) within the target host (Host1), and the container (container3) in the target host (Host2) is also connected to the first bridge (OVS Bridge) within the target host (Host2). Then, the first bridge (OVS Bridge) in the target host (Host1) and the first bridge (OVS Bridge) in the target host (Host2) are connected via a network. This network tunnel can support Virtual Extensible Local Area Network (VXLAN) protocol, as well as Generic Routing Encapsulation (GRE) protocol, and more.
[0093] Simultaneously, containers (container1) and (container2) on the target host (Host1) connect to the second bridge (Linux Bridge) within the target host (Host1) via the management interface (mgmt), while containers (container3) and (container4) on the target host (Host2) also connect to the second bridge (Linux Bridge) within the target host (Host2). Then, the second bridge (Linux Bridge) on the target host (Host1) connects to the second bridge (Linux Bridge) on the target host (Host2) via a network.
[0094] In this embodiment of the disclosure, the simulated network topology is simulated and verified based on the simulation runtime environment to obtain the simulation verification results, including the following steps F1-F4:
[0095] Step F1: Obtain the network verification task from the network verification request.
[0096] Step F2: Use the network verification task to obtain the network verification strategy and verification metrics.
[0097] Step F3: In the simulation environment, perform simulation verification on the simulated network topology according to the network verification strategy to obtain the verification data corresponding to the verification indicators.
[0098] Step F4: Generate simulation verification results based on verification metrics and verification data.
[0099] In this embodiment, network verification tasks can be directly extracted from network verification requests. These tasks can include loop detection tasks and reachability difference tasks, among others. The network verification strategy for the reachability difference task is to calculate the end-to-end reachability differences for all service categories in the simulated network topology. The network verification strategy for the loop detection task is to answer the question "Does a routing loop exist in the network?" based on the routing tables of all simulated network devices.
[0100] In this embodiment of the disclosure, when the network verification task is a reachability difference task, a routing table of the simulated network topology is obtained. The routing table includes: directly connected routing relationships and non-directly connected routing relationships between devices in the simulated network topology. It can be understood that: directly connected routes are the routing methods of the subnets connected to the network device interfaces; non-directly connected routes are routes learned from other network devices through routing protocols. Then, the reachability between network devices in the network topology is verified (i.e., whether the directly connected or non-directly connected routes in the routing table are affected or changed). Specifically, corresponding detection packets are constructed for multiple network devices. A network device can send the detection packet to other network devices with which it has a directly connected routing relationship, or it can send the detection packet to other network devices with which it has a non-directly connected routing relationship. Then, response packets for the detection packets are received. If the packet attributes of the response packet match the packet attributes of the detection packet, it is determined that the directly connected or non-directly connected routing relationships between the network device and other network devices have not changed. Conversely, if the message attributes of the response message do not match the message attributes of the detection message, it is determined that the direct or indirect routing relationship between the network device and other network devices has changed.
[0101] In this embodiment of the disclosure, when the network verification task is a loop detection task, the network device generates a loop detection message. The network device queries the routing table for the route corresponding to the destination IP address of the loop detection message and sends the loop detection message using the route. The network device receives the service data message fed back by the route. When the service data message matches the loop detection message, it can be determined that the route corresponding to the destination IP address of the loop detection message identified by the network device is a loop route.
[0102] The method provided in this disclosure firstly automatically identifies the target network device that has undergone a change from the real network based on the device change information carried in the network verification request. Secondly, it traverses multiple extended network devices corresponding to the target network device from the real network. Furthermore, it constructs a simulated network topology based on the target network device and the extended network devices, and sets up a simulation runtime environment for the simulated network topology. Finally, it performs simulation verification on the simulated network topology to obtain the simulation verification results. This method automatically traverses relevant extended devices based on the changed device and constructs a simulated network topology, achieving automated construction of the simulated network topology, even for large-scale network topologies, eliminating the need for manual construction. In addition, automatic network verification can be performed after the simulated network topology is constructed, improving the efficiency of network verification.
[0103] This embodiment also provides a network topology-based verification device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0104] This embodiment provides a verification device based on network topology, such as... Figure 6 As shown, it includes:
[0105] The acquisition module 61 is used to acquire network verification requests, wherein the network verification requests include device change information for the real network, the real network includes multiple layers, and each layer includes multiple network devices;
[0106] The determination module 62 is used to determine the target network device that has changed in the real network using the device change information, and to obtain the extended network device from the network devices at each level of the real network, wherein the extended network device obtained at each level corresponds to a different vendor;
[0107] Module 63 is used to build a simulated network topology based on the target network device and extended network devices;
[0108] The processing module 64 is used to build a simulation runtime environment corresponding to the simulated network topology, and to perform simulation verification on the simulated network topology based on the simulation runtime environment, and obtain simulation verification results.
[0109] In this embodiment of the disclosure, the determining module 62 is used to traverse the real network to obtain the set of upstream network devices and the set of downstream network devices associated with the target network device, wherein the set of upstream network devices includes target upstream network devices at multiple levels, and the set of downstream network devices includes target downstream network devices at multiple levels; traverse the real network to obtain target neighbor devices at the same level as the target network device; and use the target upstream network devices, target downstream network devices, and target neighbor devices as extended network devices.
[0110] In this embodiment of the disclosure, the determining module 62 is used to traverse the real network to obtain a first set of devices at the next level of the target network device and a second set of devices at the next level of the target network device. The first set of devices includes multiple upstream network devices, and the second set of devices includes multiple downstream network devices. The module determines a first set of suppliers corresponding to the first set of devices and a second set of suppliers corresponding to the second set of devices. The first set of suppliers includes multiple different first suppliers, and the second set of suppliers includes multiple different second suppliers. The module selects one upstream network device corresponding to each first supplier from the first set of devices as the target upstream network device and adds it to the upstream network device set. The module selects one downstream network device corresponding to each second supplier from the second set of devices as the target downstream network device and adds it to the downstream network device set.
[0111] In this embodiment of the disclosure, the determining module 62 is used to detect whether each upstream network device in the first device set belongs to the root node and obtain a first detection result; take the upstream network devices whose first detection result is not belonging to the vertex as the reference upstream network devices, and traverse the real network to obtain a third device set one level above the reference upstream network device, wherein the third device set includes multiple upstream network devices; determine the third supplier set corresponding to the third device set, wherein the third supplier set includes multiple different third suppliers; select one upstream network device corresponding to each third supplier from the third device set as the target upstream network device and add it to the upstream network device set, until the upstream network device belonging to the root node is traversed.
[0112] In this embodiment of the disclosure, the determining module 62 is used to detect whether each downstream network device in the second device set belongs to a leaf node, and obtain a second detection result; the downstream network devices whose second detection result is not to a leaf node are taken as the baseline downstream network devices, and the real network is traversed to obtain the fourth device set at the next level of the baseline downstream network devices, wherein the fourth device set includes multiple downstream network devices; the fourth supplier set corresponding to the fourth device set is determined, wherein the fourth supplier set includes multiple different fourth suppliers; a downstream network device corresponding to each fourth supplier is selected from the fourth device set as the target downstream network device, and added to the downstream network device set, until the downstream network device belonging to a leaf node is traversed.
[0113] In this embodiment of the disclosure, the determining module 62 is used to traverse the real network to obtain candidate neighbor devices at the same level as the target network device; and to determine the candidate neighbor devices that have not undergone device changes as the target neighbor devices.
[0114] In this embodiment of the disclosure, the construction module 63 is used to determine the first connection relationship between the target network device and the extended network devices, and the second connection relationship between each extended network device; and to construct a simulated network topology based on the target network device, the extended network devices, the first connection relationship and the second connection relationship.
[0115] In this embodiment of the disclosure, the apparatus further includes: a pruning module, configured to obtain a set of links between every two network devices in the simulated network topology, wherein the set of links includes at least one original link for connecting the two network devices; prune the original links in the set of links to obtain the pruned target links; and update the set of links based on the target links.
[0116] In this embodiment of the disclosure, the pruning module is used to remove a first number of original links from the link set to obtain a second number of remaining original links; compare the second number of links with a preset number of links; and if the second number of links is greater than or equal to the preset number of links, use the remaining original links corresponding to the second number of links as the target links.
[0117] In this embodiment of the disclosure, the trimming module is used to determine the difference between the second number of links and the preset number of links when the second number of links is less than the preset number of links; obtain the original link corresponding to the difference from the original links of the first number of links; and use the original link corresponding to the difference and the remaining original links corresponding to the second number of links as the target links.
[0118] In this embodiment of the disclosure, the processing module 64 is used to obtain the number of layers in the simulated network topology; determine the corresponding number of target hosts according to the number of layers, and determine the number of containers in the target hosts according to the number of network devices in each layer; deploy the containers of the specified number in the target hosts; establish the connection relationship between each container in the target hosts, as well as the connection relationship between containers in different target hosts, to obtain the simulation running environment.
[0119] In this embodiment of the disclosure, the processing module 64 is used to determine the virtual machines to be deployed to each container in the host, and obtain the virtual machine image and the virtual machine startup program of the virtual machine; generate a container image based on the virtual machine image, the virtual machine startup program and the preset software library; and create a container using the container image.
[0120] In this embodiment of the disclosure, the processing module 64 is used to connect to each container in the target host through the virtual network card port in the container; connect the Ethernet interface of each container in the target host to the first bridge, and connect the first bridge in each target host using a network tunnel; connect the management interface of each container in the target host to the second bridge, and connect the second bridge in each target host to obtain the simulation running environment.
[0121] In this embodiment of the disclosure, the processing module 64 is used to obtain a network verification task from a network verification request; obtain a network verification strategy and verification indicators using the network verification task; perform simulation verification on the simulated network topology according to the network verification strategy in a simulation running environment to obtain verification data corresponding to the verification indicators; and generate simulation verification results based on the verification indicators and verification data.
[0122] This disclosure also provides an electronic device, such as... Figure 7 As shown, the electronic device may include: a processor 1501, a communication interface 1502, a memory 1503, and a communication bus 1504, wherein the processor 1501, the communication interface 1502, and the memory 1503 communicate with each other through the communication bus 1504.
[0123] Memory 1503 is used to store computer programs;
[0124] When the processor 1501 executes the computer program stored in the memory 1503, it implements the steps of the above embodiments.
[0125] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0126] The communication interface is used for communication between the aforementioned terminal and other devices.
[0127] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0128] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0129] In yet another embodiment provided in this disclosure, a computer-readable storage medium is also provided, which stores instructions that, when executed on a computer, cause the computer to perform any of the video stream transmission methods described in the above embodiments.
[0130] In yet another embodiment provided in this disclosure, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform any of the video stream transmission methods described in the above embodiments.
[0131] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk).
[0132] The above description is merely a preferred embodiment of this disclosure and is not intended to limit the scope of protection of this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure are included within the scope of protection of this disclosure.
[0133] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.
[0134] Although embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A verification method based on network topology, characterized in that, The method includes: Obtain a network verification request, wherein the network verification request includes device change information for a real network, the real network includes multiple layers, and each layer includes multiple network devices; The device change information is used to identify the target network device that has changed in the real network, and extended network devices are obtained from the network devices at each level of the real network, wherein the extended network devices obtained at each level correspond to different vendors; Construct a simulated network topology based on the target network device and the extended network device; A simulation environment corresponding to the simulated network topology is built, and the simulated network topology is simulated and verified based on the simulation environment to obtain the simulation verification results; The step of obtaining extended network devices from network devices at each level of the real network includes: traversing the real network to obtain a set of upstream network devices and a set of downstream network devices associated with the target network device, wherein the set of upstream network devices includes target upstream network devices at multiple levels, and the set of downstream network devices includes target downstream network devices at multiple levels; traversing the real network to obtain target neighbor devices at the same level as the target network device; and using the target upstream network device, target downstream network device, and target neighbor device as the extended network device.
2. The method according to claim 1, characterized in that, The process of traversing the real network to obtain the set of upstream network devices and the set of downstream network devices associated with the target network device includes: Traverse the real network to obtain a first set of devices at the next level of the target network device and a second set of devices at the next level of the target network device, wherein the first set of devices includes multiple upstream network devices and the second set of devices includes multiple downstream network devices; Determine a first supplier set corresponding to the first set of equipment and a second supplier set corresponding to the second set of equipment, wherein the first supplier set includes multiple different first suppliers and the second supplier set includes multiple different second suppliers; Select one upstream network device corresponding to each of the first suppliers from the first device set as the target upstream network device, and add it to the upstream network device set; Select one downstream network device from each of the second suppliers in the second device set as the target downstream network device and add it to the downstream network device set.
3. The method according to claim 2, characterized in that, After selecting one upstream network device corresponding to each of the first suppliers from the first device set as the target upstream network device and adding it to the upstream network device set, the method further includes: Detect whether each upstream network device in the first set of devices belongs to the root node, and obtain the first detection result; The upstream network device whose first detection result is not a vertex is taken as the benchmark upstream network device, and the real network is traversed to obtain the third device set at the next level of the benchmark upstream network device, wherein the third device set includes multiple upstream network devices. Determine the third supplier set corresponding to the third equipment set, wherein the third supplier set includes multiple different third suppliers; Select one upstream network device corresponding to each of the third suppliers from the third device set as the target upstream network device and add it to the upstream network device set until the upstream network device belonging to the root node is reached.
4. The method according to claim 3, characterized in that, After selecting one downstream network device corresponding to each of the second suppliers from the second device set as the target downstream network device and adding it to the downstream network device set, the method further includes: The second detection result is obtained by detecting whether each downstream network device in the second set of devices belongs to a leaf node. The downstream network devices whose second detection result is not a leaf node are taken as the baseline downstream network devices, and the real network is traversed to obtain the fourth set of devices at the next level of the baseline downstream network devices, wherein the fourth set of devices includes multiple downstream network devices. Determine the fourth supplier set corresponding to the fourth equipment set, wherein the fourth supplier set includes multiple different fourth suppliers; Select one downstream network device corresponding to each of the fourth suppliers from the fourth device set as the target downstream network device and add it to the downstream network device set until the downstream network device belonging to the leaf node is traversed.
5. The method according to claim 1, characterized in that, The step of traversing the real network to obtain target neighbor devices at the same level as the target network device includes: Traverse the real network to obtain candidate neighbor devices at the same level as the target network device; Candidate neighbor devices that have not undergone device changes are identified as the target neighbor devices.
6. The method according to claim 1, characterized in that, The construction of a simulated network topology based on the target network device and the extended network device includes: Determine the first connection relationship between the target network device and the extended network device, and the second connection relationship between each of the extended network devices; The simulated network topology is constructed based on the target network device, the extended network device, the first connection relationship, and the second connection relationship.
7. The method according to claim 6, characterized in that, The method further includes: Obtain the set of links between every two network devices in the simulated network topology, wherein the set of links includes at least one original link used to connect the two network devices; The original links in the link set are pruned to obtain the pruned target links; Update the link set based on the target link.
8. The method according to claim 7, characterized in that, The step of pruning the original links in the link set to obtain the pruned target links includes: Remove a first number of original links from the link set to obtain a second number of remaining original links; Compare the second number of links with the preset number of links; If the second number of links is greater than or equal to the preset number of links, the remaining original links corresponding to the second number of links shall be used as the target links.
9. The method according to claim 8, characterized in that, After comparing the second number of links with the preset number of links, the method further includes: If the number of the second links is less than the preset number of links, determine the difference between the number of the second links and the preset number of links; Obtain the original link corresponding to the difference from the original links of the first number of links; The original link corresponding to the difference and the remaining original links corresponding to the second number of links are taken as the target link.
10. The method according to claim 1, characterized in that, The process of building the simulation runtime environment corresponding to the simulation network topology includes: Obtain the number of layers in the simulated network topology; The number of target hosts is determined according to the number of tiers, and the number of containers in the target hosts is determined according to the number of network devices in each tier. Deploy the specified number of containers within the target host; The connection relationships between the containers within the target host and the connection relationships between containers between different target hosts are established to obtain the simulation runtime environment.
11. The method according to claim 10, characterized in that, The deployment of the specified number of containers within the target host includes: Identify the virtual machines to be deployed to each container in the host, and obtain the virtual machine images and virtual machine startup programs for the virtual machines; Based on the virtual machine image, the virtual machine startup program and preset software libraries generate a container image; The container is created using the container image.
12. The method according to claim 10, characterized in that, The process of establishing the connection relationships between various containers within the target host, and the connection relationships between containers between different target hosts, to obtain the simulation runtime environment includes: Connect to each container within the target host via a virtual network interface card port within the container; Connect the Ethernet interface of each container in the target host to the first bridge, and use network tunnels to connect the first bridge in each of the target hosts. The management interfaces of each container within the target host are connected to the second bridge, and the second bridge within each target host is connected to obtain the simulation runtime environment.
13. The method according to claim 1, characterized in that, The simulation verification of the network topology based on the simulation environment, and the resulting simulation verification results, include: Obtain the network verification task from the network verification request; The network verification task is used to obtain the network verification strategy and verification indicators; In the simulation environment, the simulated network topology is simulated and verified according to the network verification strategy to obtain the verification data corresponding to the verification indicators. The simulation verification results are generated based on the verification metrics and the verification data.
14. A verification device based on network topology, characterized in that, The device includes: The acquisition module is used to acquire network verification requests, wherein the network verification requests include device change information for a real network, the real network includes multiple layers, and each layer includes multiple network devices; The determination module is used to determine the target network device that has changed in the real network using the device change information, and to obtain extended network devices from the network devices at each level of the real network, wherein the extended network devices obtained at each level correspond to different vendors; The construction module is used to construct a simulated network topology based on the target network device and the extended network device; The processing module is used to build a simulation runtime environment corresponding to the simulation network topology, and to perform simulation verification on the simulation network topology based on the simulation runtime environment to obtain simulation verification results; The determining module is specifically used to traverse the real network to obtain the upstream network device set and the downstream network device set associated with the target network device, wherein the upstream network device set includes target upstream network devices at multiple levels, and the downstream network device set includes target downstream network devices at multiple levels; traverse the real network to obtain target neighbor devices at the same level as the target network device; and use the target upstream network device, target downstream network device, and target neighbor device as the extended network device.
15. A computer device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the verification method of any one of claims 1 to 13 by executing the computer instructions.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a computer to perform the verification method according to any one of claims 1 to 13.
Citation Information
Patent Citations
Three-layer network change scheme verification method and system
CN112953768A