Network environment anomaly early warning method and device, and electronic device

By monitoring routing changes in real time on data communication equipment and comparing them to generate predicted paths, the problem of insufficient maintenance of the 5G VoNR voice service bearer network was solved, and timely early warning and efficient maintenance of the network environment were achieved.

CN116708128BActive Publication Date: 2025-10-24CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310580009.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-22
Publication Date
2025-10-24
Estimated Expiration
2043-05-22

AI Technical Summary

Technical Problem

In existing technologies, the bearer network maintenance for 5G VoNR voice services is insufficient, resulting in serious impact on user experience when the network environment is abnormal and a lack of timely early warning mechanism.

Method used

By deploying a real-time routing monitoring module on data communication equipment, routing changes are collected in real time and compared with the pre-collected reference routing table to generate a predicted path. Path indicator comparison is used to identify anomalies and output warning information.

Benefits of technology

It achieves timely early warning of the network environment, reduces the adverse impact of routing changes on users' use of the network, and improves maintenance efficiency and processing speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116708128B_ABST
    Figure CN116708128B_ABST
Patent Text Reader

Abstract

The application discloses a network environment abnormality early warning method and device, belongs to the communication technical field, and is used for solving the problem that communication line abnormality discovery delay affects user network use. The method comprises the following steps: deploying a routing real-time monitoring module on a data communication device, and collecting routing changes of the data communication device in real time; when the real-time routing change of the data communication device is monitored, acquiring a real-time routing table of the data communication device; comparing and analyzing the real-time routing table with a reference routing table collected in advance, acquiring changed routing information and an associated scene; according to the real-time routing table, acquiring a predicted path corresponding to the data communication device under the associated scene by using a routing tree technology; comparing path indexes of the predicted path and a reference path under the associated scene, discovering path abnormalities in a timely manner, and outputting early warning information. The method can discover network routing abnormalities in real time, and effectively reduces the adverse effects of user network use caused by routing changes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a network environment abnormality early warning method and device, an electronic device and a computer readable storage medium. BACKGROUND

[0002] With the development of network technology, network technology is widely used, and network provides many traverses for public life, and the maintenance of network environment is particularly important. Taking 5G (5th Generation Mobile Communication Technology) technology as an example, the development of 5G technology provides a better pipeline for high-definition voice calls, and VoNR (Voice over New Radio) based on 5G has been widely used. 5G VoNR requires high latency, and puts forward higher requirements for network capability and network environment maintenance. At present, the most influential factor on VoNR call quality is the bearer network. In the prior art, the maintenance of the bearer network for voice services mainly includes daily maintenance inspection, response dispatch alarm and user complaint handling, and the problems are not found in time. Once the alarm is dispatched or there is a user complaint, it will seriously affect the use of related services by users.

[0003] Therefore, an abnormality early warning method for a network environment used by a user is needed to pre-identify the abnormality of a network device or a network path and timely notify the corresponding personnel to handle the abnormality. SUMMARY

[0004] The embodiments of the present application provide a network environment abnormality early warning method and device, and an electronic device, which can early warn the running abnormality of a network environment, so that maintenance personnel can handle the network abnormality in advance to avoid serious impact on the use of the network by users when the routing path is abnormal.

[0005] In a first aspect, the embodiments of the present application disclose a network environment abnormality early warning method, comprising:

[0006] In response to monitoring the real-time routing change of a data communication device, acquiring a real-time routing table of the data communication device;

[0007] Comparing and analyzing the real-time routing table with a reference routing table of the data communication device collected in advance to acquire the changed routing information of the data communication device and the associated scene of the routing information;

[0008] According to the pre-generated routing query tree of each data communication device in the target network, acquiring a reference path corresponding to the associated scene;

[0009] According to the real-time routing table, the routing query tree, a predicted path corresponding to the associated scene is acquired;

[0010] The predicted path is compared with the reference path in terms of a path index, and a comparison result is acquired, where the path index is positively correlated with a probability that the path is selected by the data communication device;

[0011] In response to the comparison result indicating that the predicted path is abnormal, early warning information indicating that the network environment is abnormal is output.

[0012] In a second aspect, an early warning device for a network environment anomaly is disclosed, comprising:

[0013] A real-time routing table acquisition module is configured to acquire a real-time routing table of a data communication device in response to monitoring a real-time routing change of the data communication device;

[0014] A routing change analysis module is configured to compare and analyze the real-time routing table with a reference routing table of the data communication device acquired in advance, to acquire changed routing information of the data communication device and an associated scene of the routing information;

[0015] A reference path acquisition module is configured to acquire a reference path corresponding to the associated scene according to a routing query tree of each data communication device in a target network and generated in advance;

[0016] A predicted path acquisition module is configured to acquire a predicted path corresponding to the associated scene according to the real-time routing table and the routing query tree;

[0017] A path comparison module is configured to compare the predicted path with the reference path in terms of a path index, and acquire a comparison result, where the path index is positively correlated with a probability that the path is selected by the data communication device;

[0018] An early warning module is configured to output early warning information indicating that the network environment is abnormal in response to the comparison result indicating that the predicted path is abnormal.

[0019] In a third aspect, an electronic device is disclosed, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to implement the early warning method for a network environment anomaly.

[0020] In a fourth aspect, a computer readable storage medium is disclosed, and a computer program is stored in the computer readable storage medium, and the computer program is executable on a processor to implement the steps of the early warning method for a network environment anomaly.

[0021] The network environment abnormality early warning method disclosed by the embodiments of the present application comprises the following steps: deploying a routing real-time monitoring module on a data communication device, collecting routing changes of the data communication device in real time, and when the real-time routing changes of the data communication device are monitored, acquiring a real-time routing table of the data communication device, comparing and analyzing the real-time routing table with a reference routing table of the data communication device collected in advance, and acquiring routing information changed by the data communication device and an associated scenario of the routing information. Then, according to a routing query tree of each data communication device in a target network generated in advance, a reference path corresponding to the associated scenario is acquired; according to the real-time routing table and the routing query tree, a predicted path corresponding to the associated scenario is acquired, path indexes of the predicted path and the reference path are compared, path abnormalities caused by routing changes are discovered in time, and early warning information is output, so that hidden dangers are eliminated in time, and the probability of adverse effects on user network use caused by routing changes is effectively reduced.

[0022] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the embodiments of the present application can be implemented according to the content of the description, and in order to make the above and other purposes, characteristics and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application are described below. BRIEF DESCRIPTION OF DRAWINGS

[0023] In order to make the purposes, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0024] Figure 1 is a flowchart of the network environment abnormality early warning method disclosed by the embodiments of the present application;

[0025] Figure 2 is a schematic diagram of the application system architecture of the network environment abnormality early warning method disclosed by the embodiments of the present application;

[0026] Figure 3 is another flowchart of the network environment abnormality early warning method disclosed by the embodiments of the present application;

[0027] Figure 4 is a schematic diagram of the application scenario of the network environment abnormality early warning method disclosed by the embodiments of the present application;

[0028] Figure 5 is one of the structure schematic diagrams of the network environment abnormality early warning device disclosed by the embodiments of the present application;

[0029] Figure 6 Fig. 2 is a schematic diagram of a structure of a network environment abnormality early warning device according to an embodiment of the present application;

[0030] Figure 7 Fig. 3 is a block diagram of an electronic device for executing a method according to the present application;

[0031] Figure 8 Fig. 4 is a schematic diagram of a storage unit for storing or carrying program code for implementing a method according to the present application. DETAILED DESCRIPTION

[0032] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0033] The specific embodiments of the network environment abnormality early warning method disclosed in the embodiments of the present application will be described below by way of example.

[0034] As shown in Fig. 1, the network environment abnormality early warning method disclosed in the embodiments of the present application includes steps 110 to 160. Figure 1

[0035] In step 110, in response to monitoring a real-time routing change of a data communication device, a real-time routing table of the data communication device is acquired.

[0036] Optionally, the data communication device includes but is not limited to a switch, a router, a core network, and the like.

[0037] The network environment abnormality early warning method disclosed in the embodiments of the present application includes the following three technical solutions: a front-end routing information collection part, a back-end information processing part, and an early warning part. The network environment abnormality early warning method is applied to a network environment abnormality early warning system as shown in Fig. 2. Figure 2 As shown in Fig. 2, the network environment abnormality early warning system includes a real-time routing monitoring module 210 and a message processing module 220.

[0038] Optionally, the real-time routing monitoring module 210 is deployed in a data communication device, and the message processing module 220 can be deployed in one server or multiple servers. As shown in Fig. 3, the message processing module 220 can be deployed in a first preset server and a second preset server. Figure 2 Optionally, the first preset server can be located in a log host, and the second preset server can be located in a monitoring host. As shown in Fig. 2, the network environment abnormality early warning system includes a real-time routing monitoring module 210 and a message processing module 220.

[0039] In some embodiments of the present application, a route real-time monitoring module needs to be deployed in the data communication device in advance. By running the route real-time monitoring module 210, the route change of the corresponding data communication device is collected in real time.

[0040] The route real-time monitoring module 210 can be in the form of a monitoring program or the like executable by the data communication device.

[0041] As shown in Figure 3 Before obtaining the real-time routing table of the data communication device in response to monitoring the real-time route change of the data communication device, the method further comprises steps 100 and 101.

[0042] Step 100: receiving a real-time route change message sent by the route real-time monitoring module deployed in the data communication device when the route change of the data communication device is collected.

[0043] Step 101: generating a route change data stream corresponding to the data communication device according to the real-time route change message.

[0044] Optionally, the route real-time monitoring module deployed in the data communication device collects the route change of the data communication device in real time; and sends a real-time route change message to the first preset server when monitoring that the route of the data communication device has changed.

[0045] Then, the first preset server generates a route change data stream corresponding to the data communication device according to the real-time route change message.

[0046] Optionally, the route real-time monitoring module comprises a python monitoring script.

[0047] Optionally, the route change of the data communication device includes but is not limited to adding a route, modifying a route, deleting a route, and introducing a route.

[0048] Taking a python script for realizing real-time monitoring of routing as an example, first, an OPS (Open Programmability System) function can be deployed on the data communication device, so that the data communication device opens the system by providing a uniform application programming interface, so that the system has programmable capability. OPS allows users or third-party developers to use the API exposed by the system to develop and deploy their own network management strategies to achieve user-defined functions. Then, a Python monitoring script is made and uploaded to the data communication device. In the Python monitoring script, the monitoring function of the key routing change can be enabled to monitor the key routing change of the data communication device. At the same time, the Python monitoring script can also monitor the addition of routes, the modification of routes, the deletion of routes, the introduction of routes and other routing changes.

[0049] Further, in the Python monitoring script, configuration can be made to send a real-time routing change message to a preset log host, i.e. a first preset server, when the key routing change of the data communication device occurs.

[0050] The first preset server receives and manages the real-time routing change message sent by the data communication device based on real-time stream processing technology. Optionally, the first preset server can receive and manage the first preset server sent by the data communication device based on real-time message processing technology.

[0051] The first preset server sequentially processes the received real-time routing change message, and converts the key information related to the routing change into a real-time data stream, so as to facilitate reading by the second preset server.

[0052] Optionally, the first preset server generates the routing change data stream corresponding to the data communication device according to the real-time routing change message, including: the first preset server receives the real-time routing change message by using real-time message processing technology, and cleans the real-time routing change message to obtain at least a communication device management identifier carried in the real-time routing change message; and the first preset server generates the routing change data stream corresponding to the data communication device according to at least the obtained communication device management identifier.

[0053] Optionally, the communication device management identifier includes a data communication device management IP.

[0054] Optionally, the real-time message processing technology can be a kafka message system.

[0055] For example, the first preset server receives a real-time routing change message through a streaming message queue (such as a Kafka message queue). The real-time routing change message can include time, scene, device, account, routing change information, reason, and the like. For example, the real-time routing change message can have the following format: xx year xx month xx day xx hour xx minute xx second, 5G VoNR xx scene xx device to xx device path change, the original path is xx->xx->...->xxx, the current path is xx->xx->...->xxx, the reason is that the path of the xxx device xxx routing change, the original route is xxx, and the current route is yyy.

[0056] Subsequently, the routing change data stream in the Kafka message queue is cleaned through a kafkaStream (Kafka real-time streaming technology) program to obtain key information related to routing changes. The first preset server cleans up information unrelated to obtaining routing information, such as data communication device configuration responsible person, routing change reason, and the like, and only retains key information related to routing changes, so as to reduce the space occupied by the routing change data stream and improve processing efficiency. Optionally, the key information includes but is not limited to one or more of the following information: time, communication device management identifier, routing change information. Subsequently, the first preset server can generate a routing change data stream corresponding to the data communication device according to the scene and the communication device management identifier, and store it in another streaming message queue (such as a Kafka message queue).

[0057] Next, the second preset server can monitor the routing changes of each data communication device by reading the routing change data stream in the streaming message queue in real time.

[0058] Optionally, in response to monitoring the real-time routing change of the data communication device, the real-time routing table of the data communication device is obtained, including: using a real-time data stream processing technology to listen to the routing change data stream, and obtaining the communication device management identifier of the data communication device that has routing change; collecting the real-time routing table of the data communication device corresponding to the communication device management identifier through an IP gateway.

[0059] Optionally, the real-time data stream processing technology can be a sparkstreaming (spark-based streaming batch processing engine) technology.

[0060] The second preset server, as a consumer of the route change data stream, can monitor the Kafka queue through the spark streaming, read the route change data stream, and obtain the route change information in real time. According to the obtained route change data stream, the second preset server obtains the communication device management identifier of the data communication device that has the route change. Then, the second preset server immediately collects the latest route table of the data communication device corresponding to the communication device management identifier through the predicted route information collection program, and records the latest route table as a "real-time route table".

[0061] According to the method, the second preset server can obtain the real-time route table of each data communication device that has the route change in real time.

[0062] Optionally, as shown in FIG. 1, in response to monitoring the real-time route change of the data communication device, before obtaining the real-time route table of the data communication device, the method further includes steps 102 and 103. Figure 3

[0063] Step 102: Collect the reference route table of each data communication device in the target network.

[0064] Optionally, the network environment abnormality early warning system can collect the real-time route table of each data communication device in the target network according to a detection period or according to a trigger, and store the collected reference route table in the database.

[0065] The specific implementation of collecting the route information of each data communication device in the target network and storing the route information as the reference route table is prior art, and will not be described here.

[0066] Step 103: According to the reference route table, the route query tree of the corresponding data communication device is generated by simulating the route strategy of the data communication device to select the optimal path, and the route query tree is updated and stored.

[0067] Optionally, the route query tree can be constructed in the manner of constructing the LC_Tr ie tree.

[0068] ​Trie tree is a kind of multi-way tree, which is often used in spelling correction, word auto-completion, longest prefix matching of IP routing, etc. The principle of longest prefix matching is as follows: suppose a local router is adjacent to several routers, and these adjacent routers form their own subnets. At this time, the routing table in the local router should contain the paths of these subnets. However, if each subnet is planned a specific path in the local routing table, the routing table will be very large. Therefore, the routing table will explore whether the prefixes of these subnet IP addresses have the same part, and the longest length of the same part of the subnet prefix, and then group the IP addresses with the same "next hop" and the same length (as long as possible) of the network prefix. Therefore, as long as the IP address prefix is consistent with the length of the network prefix in a certain group, the router knows that this type of address goes to the next hop corresponding to the group.

[0069] In specific implementation, the Trie tree is constructed by the binary bits of the IP address, which forms a binary search tree, but in order to balance the time complexity and space complexity, the Trie tree is optimized. Path compression is used to remove empty nodes, and a variable skip is added to each node to save the number of removed empty nodes. Then the level is optimized by increasing the compression level of the child node, and finally it becomes an LC_Trie tree (query tree).

[0070] Generally, the routing table of each data communication device is configured with several routing entries, therefore, the routing query tree constructed according to the routing entries in the routing table will be very large. In the embodiments of the present application, in order to reduce the size of the routing query tree and improve the query efficiency of the routing query tree, the optimal path is selected to construct the routing query tree.

[0071] Optionally, according to the routing information in all routing entries in the real-time routing table, such as the routing priority, IP address, virtual private network and other information of each data communication device, the routing strategy preset by the data communication device is used to simulate the routing process of the data communication device, and the optimal path of the data communication device corresponding to each routing entry is obtained. For example, for each routing entry, the data communication devices on the shortest path between the starting IP address and the next hop are screened to form the optimal path. For another example, according to the associated scene of the routing entry, the virtual private network is screened, and the virtual private network matching the associated scene is selected as the next hop virtual private network. For another example, the next hop can be screened according to the routing priority to obtain the optimal path.

[0072] Then, according to the determined several optimal paths, the LC_Trie tree is constructed, and the LC_Trie tree is taken as the routing query tree of the data communication device.

[0073] Step 120, comparing and analyzing the real-time routing table with the pre-acquired reference routing table of the data communication device, obtaining the changed routing information of the data communication device and the associated scene of the routing information.

[0074] Optionally, the changed routing information at least includes the starting IP (Internet Protocol Address) address, the destination IP address, and the IP address of the data communication device involved of the digital link.

[0075] In the foregoing steps, the acquired routing change of the data communication device includes routing information change, and also includes scene change, port state change, etc. Next, the second preset server needs to judge whether the data communication device has changed the routing information change that causes the network path change, such as deleting routing, adding routing, and modifying routing.

[0076] In the implementation process of the present application, the normal routing information of each data communication device in the communication network needs to be collected regularly and stored as a reference routing table. For example, the normal routing table and port state of the data communication device in the bearer network involved in all 5G VoNR services are collected regularly and updated and saved in the database of the network environment abnormality early warning system. At the same time, according to various scenes, the reference routing table is used to generate a routing tree. Further, according to the generated routing tree, one or more reference paths corresponding to each data communication device can be obtained. For example, the routing, IP address, and port normally passed through each scene are made into a reference path list and saved in the database for subsequent query and comparison.

[0077] Generally, the reference routing table and the real-time routing table of the data communication device include one or more routing entries, each routing entry corresponds to a business scene, and each routing entry describes the routing information of the data communication device involved in the business scene. For example, a routing entry can include scene information, data communication device information of both ends of a digital link, routing device information involved in the scene, etc. For the data communication device in the routing entry, the IP address and other device management information of each data communication device can be obtained by using the existing technology.

[0078] By comparing the routing entries in the real-time routing table with the routing entries in the reference routing table, the changed routing entries can be obtained, and the IP addresses of the data communication devices at both ends of the digital link and the IP addresses of the data communication devices involved in the changed routing entries are taken as the changed routing information of the data communication device. The scene recorded in the routing entry is taken as the associated scene of the corresponding routing information.

[0079] At step 130, the reference path corresponding to the associated scenario is obtained according to the pre-generated routing query tree of each data communication device in the target network.

[0080] Optionally, each node in the routing query tree can store the IP address, associated scenario, port state and other information of the corresponding data communication device. For a data communication device, the next hop data communication device of the data communication device can be obtained by querying the routing query tree of the data communication device based on the IP address of the data communication device. By progressively querying the routing query tree of the data communication device, one or more paths from the start IP address to the destination IP address of the data communication devices corresponding to the associated scenario can be obtained in sequence as the reference path corresponding to the associated scenario.

[0081] Optionally, when querying the routing query tree, the virtual private network irrelevant to the associated scenario can be filtered out, and only the virtual private network relevant to the associated scenario is retained to form the reference path. For example, for a voice service scenario, only the virtual private network providing the voice service scenario in the routing entry needs to be retained to form the reference path.

[0082] At step 140, the predicted path corresponding to the associated scenario is obtained according to the real-time routing table and the routing query tree.

[0083] For the data communication device for which it is determined that the routing information change occurs, next, the predicted path of the associated scenario corresponding to the changed routing information is calculated according to the real-time routing table of the data communication device and the routing query tree of other data communication devices in the target network pre-built according to the reference routing table.

[0084] In the embodiment of the application, the calculated predicted path is the actual path of the data communication device in the associated scenario and under the routing information configured in the routing entry.

[0085] Optionally, obtaining the predicted path corresponding to the associated scenario according to the real-time routing table and the routing query tree includes: selecting an optimal path by simulating the routing strategy of the data communication device according to the real-time routing table to generate a current routing query tree of the data communication device; and querying the current routing query tree and the routing query tree of other data communication devices in the target network except the data communication device to obtain the predicted path corresponding to the associated scenario.

[0086] The specific implementation of generating the current routing query tree of the data communication device by simulating the routing strategy of the data communication device to select an optimal path according to the real-time routing table can be referred to the related description of generating the routing query tree in the foregoing, which will not be described here again.

[0087] The specific implementation of querying the current routing query tree and the routing query tree of the data communication device other than the data communication device in the target network to obtain the predicted path corresponding to the association scenario can refer to the related description of generating the reference path in the foregoing, and details are not described herein again.

[0088] At step 150, the predicted path is compared with the reference path in terms of a path index to obtain a comparison result.

[0089] As can be known from the method of generating a path based on a routing table, when the real-time routing table is the same as the reference routing table, the query routing tree constructed based on the routing table is the same, and the path obtained by searching the routing query tree is also the same for the same routing entry. If one or more routing entries in the real-time routing table changes, the generated routing query tree changes, and thus different routing query trees are searched based on the same routing entry or different routing entries, and different paths can be searched.

[0090] In an actual scenario, different paths can bring different experiences to the communication application of a user. For example, for a route from the data communication device A to the data communication device B and then to the data communication device C, the data transmission time is longer than that from the data communication device A to the data communication device C. For another example, for a route from the data communication device A to the data communication device D and then to the data communication device C, the data transmission time can be equal to that from the data communication device A to the data communication device B and then to the data communication device C. When the communication time of two different paths from the start IP address to the destination IP address is the same or less than a preset smaller time threshold, it can be considered that the communication quality provided by the two different paths to the user is the same. Therefore, directly comparing the number of paths or IP addresses cannot accurately determine whether the communication quality of two paths is the same.

[0091] In the embodiment of the present application, the difference between the path indexes of the paths is used to measure the deviation between the paths. The path index is positively correlated with the probability that the path is selected by the data communication device.

[0092] In the case where the reference path represents a normal path from the start IP address to the destination IP address, if the path index of the predicted path is greater than that of the reference path, it can be considered that the probability of selecting the predicted path is greater when selecting a communication path from the start IP address to the destination IP address, that is, an abnormal communication path will be selected, and communication abnormality can occur. If the path index of the predicted path is less than that of the reference path, it can be considered that the probability of selecting the reference path is greater when selecting a communication path from the start IP address to the destination IP address, and no communication abnormality occurs.

[0093] Based on the above analysis, in the embodiments of the present application, the predicted path and the reference path are compared in terms of path indicators to obtain a comparison result, which is used to determine whether the predicted path is abnormal.

[0094] Optionally, the predicted path and the reference path are compared in terms of path indicators to obtain a comparison result, including: according to the preset path selection influencing factors of each data communication device in the path, the path indicators of the predicted path and the reference path are respectively calculated; the path indicators of the predicted path are subtracted by the path indicators of the reference path to obtain a path indicator difference value; in response to the path indicator difference value being greater than or equal to a specified adaptive deviation range of the path indicators of the reference path, a comparison result indicating that the predicted path is abnormal is obtained, wherein the specified adaptive deviation range is obtained according to the product of a path adaptive deviation threshold value obtained by pre-training and the path indicators of the reference path.

[0095] First, according to the currently determined associated scene, the routing query tree of each data communication device in the specified communication network updated periodically is queried to obtain all paths from the start IP address to the destination IP address corresponding to the associated scene according to the routing query tree of each data communication device updated recently as the reference path. The reference path obtained is obtained according to the routing configuration of the data communication device in the network under the condition that the network communication is normal, which is a normal path.

[0096] Next, the path indicators of the predicted path and the reference path are respectively calculated for subsequent comparison.

[0097] Optionally, the path indicators of the predicted path and the reference path are calculated by the following method: taking the data communication devices in the current type path as vertices, a graph is constructed according to the current type path; the weight of the edge in the graph is calculated according to one or more of the following preset path selection influencing factors: the physical bandwidth between the data communication devices corresponding to a pair of vertices connected by the edge, the quality of service bandwidth, the routing priority; the relaxation operation is performed on the edges in the graph by using the relaxation technique of the shortest path to obtain the shortest path between each pair of vertices in the graph; the shortest path of the current type path is determined according to the shortest path between each pair of vertices, as the target path; the path indicators of the current type path are calculated according to the weight of the edge in the graph corresponding to the adjacent path nodes in the target path.

[0098] The relaxation technique refers to setting an attribute dist[v] for each vertex v in the graph G=(V, E), which is used to describe the upper bound of the weight on the shortest path from the source point S to v. When starting a shortest path algorithm, the weights of the edges in the graph need to be initialized, and the information of the shortest path between each pair of vertices is gradually obtained as the algorithm proceeds. The algorithm gradually updates this information, and each step checks whether a shorter path can be found than the currently given path.

[0099] In the embodiments of the present application, when calculating the path indicators of the predicted paths, a graph, for example, denoted as "first graph", is constructed according to all the predicted paths, and then the edges in the first graph are subjected to the relaxation operation to obtain the shortest paths between each pair of vertices in the graph; when calculating the path indicators of the reference paths, a graph, for example, denoted as "second graph", is constructed according to all the reference paths, and then the edges in the second graph are subjected to the relaxation operation to obtain the shortest paths between each pair of vertices in the graph.

[0100] In the calculation of the path indicators of the predicted paths, the current type path is the predicted path, and in the calculation of the path indicators of the reference paths, the current type path is the reference path. The specific implementation of calculating the path indicators of the current type path is described below by taking the calculation of the path indicators of the predicted paths as an example.

[0101] First, the first graph is constructed according to all the predicted paths. For example, the path nodes in the predicted paths are taken as the vertices of the first graph, and the adjacent path nodes are connected by edges to construct a graph structure, i.e., the "first graph" is obtained.

[0102] Then, the weights of the edges in the first graph are set.

[0103] Optionally, the weight of an edge in the graph can be calculated according to one or more factors that affect path selection between the data communication devices corresponding to the two vertices of the edge, such as physical bandwidth, quality of service bandwidth, and routing priority. For example, the weight calculation formula of the edge between vertices U and V can be expressed as follows:

[0104] Weight[u][v]=f weight (u,v)=f bandwidth (u,v)*f QoS (u,v)+f preference (u,v);

[0105] wherein f bandwidth (u,v) is the physical bandwidth between the data communication devices corresponding to the two vertices, which can be calculated by the number of ports, the bandwidth of a single link, and the bundling algorithm; f QoS(u, v) is the QoS (Quality of Service) bandwidth between the data communication devices corresponding to the two vertices, which can be calculated by the QoS algorithm, service priority in the prior art; f preference (u, v) is the routing weight of the data communication devices corresponding to the two vertices, which can be calculated according to the routing table, routing priority and artificial adjustment value of the data communication devices.

[0106] Optionally, other calculation methods can also be used to calculate the weight of the corresponding edge according to one or more factors affecting path selection between the data communication devices corresponding to the two vertices, such as physical bandwidth, quality of service bandwidth, routing priority, which will not be listed one by one in the embodiments of the application.

[0107] Next, the edges in the graph are relaxed.

[0108] Let u, v represent a pair of vertices, <u, v> represent the edge between vertices u, v, and S represent the source point. The relaxation operation on the edge <u, v>, that is, trying to pass through <u, v>, improves the shortest path found so far for v. Taking dist[i] representing the shortest path from point i to the source point S as an example, initialize all dist[i], dist[s] of the source point = 0, and other dist[i] = INF. Traverse all edges between vertices v and u, and if dist[v] > dist[u] + weight[u][v], set dist[v] = dist[u] + weight[u][v] and update dist[v]. That is, through the relaxation operation, the weight of the shortest path between two vertices is found. The source point can be the vertex corresponding to the starting IP address.

[0109] After obtaining the path indicators of the predicted path and the reference path, the path indicator W now of the predicted path is subtracted from the path indicator W normal of the reference path, to obtain a path indicator difference. Then, it is further determined whether the path indicator difference deviates from the path indicator of the reference path. If W now -W normal ≥ P x W normal , that is, the path indicator difference is greater than or equal to the specified adaptive deviation range of the path indicator of the reference path, a comparison result indicating that the predicted path is abnormal can be obtained, wherein P represents a path adaptive deviation threshold value, which is obtained by pre-training.

[0110] For example, an AI model for adaptive IP routing is trained using a training set consisting of sample paths from communication failure cases and manually set sample paths from normal communication. This yields an AI model for detecting abnormal IP routing deviations with adaptive parameters. P, as a model parameter, participates in model training.

[0111] Optionally, in response to the path indicator difference being smaller than a specified adaptive deviation range of the path indicator of the reference path, a comparison result indicating that the predicted path is normal is obtained.

[0112] Step 160: In response to the comparison result indicating that the predicted path is abnormal, outputting warning information indicating that the network environment is abnormal.

[0113] The network environment warning information is used to indicate that a routing anomaly occurs in the data communication device under the preset scenario.

[0114] Optionally, if the comparison in the aforementioned steps reveals a change in the scenario path, an early warning message is immediately output. For example, this can be sent via SMS to the maintenance personnel and / or supervisor of the data communication equipment, enabling emergency response to be initiated before users even notice network fluctuations, thereby avoiding public outcry and improving network maintenance efficiency.

[0115] Optionally, upon discovering a network problem, notifications can be sent through multiple channels. For example, using Python to call SMS modules and send email notifications to equipment administrators, maintenance supervisors, and other relevant maintenance personnel can shorten the time it takes to report and investigate multiple levels of problems. Responsible personnel can receive first-hand information on the issue at the earliest opportunity, improving the timeliness and efficiency of network operations and maintenance.

[0116] The following combination Figure 4 The network diagram in the figure illustrates the application and beneficial effects of the network environment abnormality warning method disclosed in the embodiment of the present application.

[0117] like Figure 4As shown, the A city node is online in the figure, and needs to access the CDMA-NGN VPN of the CN2 network, so the route of the VPN is introduced on the B21 / 22 device in the A city, causing the 5G VoNR device in the B city close to the A city to also learn the route of the VPN, and the route is more optimal, so that the traffic from the B city CT cloud to the VoNR network passes through the B21 / 22 device in the A city to enter the CN2. Due to the above route change, the VoNR to VoNR core network route detours to the A city PE (Provider Edge, service provider edge router) and then to the B city PE, causing the VoNR user connection time to be too long. By deploying the route real-time monitoring module 210 in the data communication device in the network, when the CDMA-NGN VPN of the CN2 network is introduced on the B21 / 22 device in the A city, the route real-time monitoring module 210 will quickly monitor the change when the route configuration of the B21 / 22 device changes, and send the change in the form of a real-time route change message to the message processing module 220.

[0118] Further, the message processing module 220 obtains the real-time routing table of the B21 / 22 device in the A city, and compares and analyzes the real-time routing table with the reference routing table previously collected for the device, finds that the routes of multiple intermediate routers have changed, and then obtains the changed route information of the data communication device and the associated scenario of the route information, for example, calculates the affected scenario mode as: VoNR to AS (Auto Scaling, elastic scaling) platform. Then, the message processing module 220 obtains the corresponding predicted path of the data communication device in the associated scenario according to the real-time routing table using the route tree technology, and compares the predicted path with the reference path of the data communication device in the associated scenario to obtain a comparison result. After comparison, the message processing module 220 will find that the intermediate path has changed greatly, and will output early warning information indicating that the network environment is abnormal in time, so that the problem can be handled in time to avoid affecting the users of the subscribed AS service.

[0119] The network environment abnormality early warning method disclosed by the embodiments of the present application can realize real-time collection of route changes of a data communication device by deploying a routing real-time monitoring module on the data communication device, so that when a real-time route change of the data communication device is monitored, a real-time routing table of the data communication device is acquired, the real-time routing table is compared and analyzed with a reference routing table of the data communication device collected in advance, route information of the data communication device that has changed and an associated scene of the route information are acquired. Then, a reference path corresponding to the associated scene is acquired according to a routing query tree of each data communication device in a target network generated in advance, a predicted path corresponding to the associated scene is acquired according to the real-time routing table and the routing query tree, path indicators of the predicted path and the reference path are compared, path abnormalities caused by route changes are discovered in time, and early warning information is output, so that hidden dangers are eliminated in time, and the probability of adverse effects on user network use caused by route changes is effectively reduced.

[0120] The present application can discover in a few seconds which scene has a route change and rapidly judge an influence range by real-time monitoring of route changes of a data communication device and using real-time data flow processing technology to notify a message processing module of the route changes, and the processing efficiency can be improved by 95% compared with traditional device abnormality troubleshooting based on user complaints.

[0121] Further, in the embodiments of the present application, a python monitoring script is deployed on the data communication device, route changes and port state changes can be transmitted to the message processing module in the first time, and the vacancy of missing monitoring of key route changes in the prior art that only focuses on port hardware maintenance is made up.

[0122] In the embodiments of the present application, a query routing tree can be generated in advance according to a routing table, a port state, QOS, occupied bandwidth and various factors, actual problem processing needs a large number of ping, tracert and other execution instructions are avoided, the message processing speed can be improved, and the burden of the data communication device can be reduced. Moreover, the scene of a changed route is acquired by a query routing table, the present application can rapidly locate a scene key route change, the dynamic perception time of device and route abnormalities is accurate to seconds, the influence range can be given at the same time when the abnormalities are discovered. Compared with a traditional processing mode in which experts often need to query logs and instructions from multiple aspects, and make judgments according to the query results and expert experience after user calls appear abnormalities, or a situation in which professional personnel do not dispose in time, the present application can greatly save maintenance time and maintenance personnel cost. According to test data, the original problem processing time of 50 minutes per person can be shortened to only 3 minutes by using the method disclosed in the embodiments of the present application, and the labor cost is saved by 94%.

[0123] Correspondingly, the application further discloses a network environment abnormality early warning device, as shown in the accompanying drawings. Figure 5 The device comprises:

[0124] The real-time routing table acquisition module 510 is configured to acquire a real-time routing table of the data communication device in response to monitoring a real-time routing change of the data communication device.

[0125] The routing change analysis module 520 is configured to compare and analyze the real-time routing table with a reference routing table of the data communication device acquired in advance, to acquire changed routing information of the data communication device and an associated scenario of the routing information.

[0126] The reference path acquisition module 530 is configured to acquire a reference path corresponding to the associated scenario according to a routing query tree of each data communication device in a target network.

[0127] The predicted path acquisition module 540 is configured to acquire a predicted path corresponding to the associated scenario according to the real-time routing table and the routing query tree.

[0128] The path comparison module 550 is configured to compare a path index of the predicted path with a path index of the reference path, to acquire a comparison result, wherein the path index is positively correlated with a probability of being selected by the data communication device.

[0129] The early warning module 560 is configured to output early warning information indicating a network environment abnormality in response to the comparison result indicating that the predicted path is abnormal.

[0130] Optionally, the predicted path acquisition module 540 is further configured to:

[0131] select an optimal path by simulating a routing strategy of the data communication device according to the real-time routing table, to generate a current routing query tree of the data communication device;

[0132] query the current routing query tree and the routing query tree of other data communication devices in the target network except the data communication device, to acquire the predicted path corresponding to the associated scenario.

[0133] Optionally, the path comparison module 550 is further configured to:

[0134] respectively calculate a path index of the predicted path and a path index of the reference path according to preset path selection influencing factors of each data communication device in the path;

[0135] subtract the path index of the reference path from the path index of the predicted path, to obtain a path index difference value.

[0136] in response to the path indicator difference being greater than or equal to a specified adaptive deviation range of the path indicator of the reference path, obtaining a comparison result indicating that the predicted path is abnormal, wherein the specified adaptive deviation range is obtained according to a product of a path adaptive deviation threshold value obtained through pre-training and the path indicator of the reference path.

[0137] Optionally, the path indicator of the predicted path and the path indicator of the reference path are obtained through the following method:

[0138] taking a data communication device in the current type path as a vertex, and constructing a graph according to the current type path;

[0139] calculating a weight of an edge in the graph according to one or more of the following preset path selection influencing factors: a physical bandwidth between data communication devices corresponding to a pair of vertices connected by the edge, a quality of service bandwidth, a routing priority;

[0140] performing a relaxation operation on the edges in the graph by using a relaxation technique of a shortest path, to obtain a shortest path between each pair of vertices in the graph;

[0141] determining a shortest path of the current type path as a target path according to the shortest path between each pair of vertices;

[0142] calculating a path indicator of the current type path according to a weight of an edge in the graph corresponding to adjacent path nodes in the target path.

[0143] Optionally, as shown in Figure 6 the device further comprises:

[0144] a route change collection module 500, configured to receive a real-time route change message sent by a route real-time monitoring module deployed in a data communication device when the route real-time monitoring module collects a route change of the data communication device;

[0145] a route change real-time transmission module 501, configured to generate a route change data stream corresponding to the data communication device according to the real-time route change message.

[0146] Optionally, as shown in Figure 6 the device further comprises:

[0147] a reference route table collection module 502, configured to collect reference route tables of data communication devices in the target network;

[0148] a route query tree update storage module 503, configured to select an optimal path by simulating a routing strategy of the data communication device according to the reference route tables, to generate a route query tree of the corresponding data communication device, and to update and store the route query tree.

[0149] Optionally, the real-time routing table of the data communication device is acquired in response to monitoring the real-time routing change of the data communication device, comprising:

[0150] The real-time data stream processing technology is adopted to listen to the routing change data stream, and the communication device management identifier of the data communication device with the routing change is acquired;

[0151] The real-time routing table of the data communication device corresponding to the communication device management identifier is acquired through the IP gateway.

[0152] The network environment abnormality early warning device disclosed in the embodiments of the present application is used to implement the network environment abnormality early warning method disclosed in the embodiments of the present application, and the specific implementation manners of the modules of the device will not be described again, and can be referred to the specific implementation manners of the corresponding steps of the method embodiments.

[0153] The network environment abnormality early warning device disclosed in the embodiments of the present application acquires the routing change of the data communication device in real time by deploying a routing real-time monitoring module on the data communication device, so that when the real-time routing change of the data communication device is monitored, the real-time routing table of the data communication device is acquired, the real-time routing table is compared and analyzed with a reference routing table of the data communication device collected in advance, the changed routing information of the data communication device and the associated scene of the routing information are acquired. Then, the reference path corresponding to the associated scene is acquired according to the routing query tree of each data communication device in the target network generated in advance, the prediction path corresponding to the associated scene is acquired according to the real-time routing table and the routing query tree, the path index of the prediction path is compared with the reference path, the path abnormality caused by the routing change is discovered in time, and the early warning information is output, so that the hidden danger is eliminated in time, and the occurrence probability of the adverse effects on the user using the network caused by the routing change is effectively reduced.

[0154] The present application can discover the scene in which the routing change occurs within a few seconds by monitoring the routing change of the data communication device in real time and adopting the real-time data stream processing technology to notify the routing change to the message processing module, and the influence range can be rapidly judged. Compared with the traditional device abnormality troubleshooting and disposal based on user complaints, the processing efficiency can be improved by 95%.

[0155] Further, in the embodiments of the present application, the python monitoring script is deployed on the data communication device, and the routing change and the port state change can be transmitted to the message processing module in the first time, which makes up for the vacancy of the prior art which only focuses on the port hardware maintenance and lacks the monitoring of the key routing change.

[0156] Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between the various embodiments can be referred to in conjunction with each other. For the device embodiments, since they are generally similar to the method embodiments, their description is relatively simple, and for relevant parts, reference can be made to the description of the method embodiments.

[0157] The above is a detailed introduction to a network environment anomaly warning method and device provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, based on the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

[0158] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0159] The various component embodiments of the present application can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. It will be appreciated by those skilled in the art that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components in the electronic device according to the embodiment of the present application. The application can also be implemented as a device or apparatus program (for example, a computer program and a computer program product) for performing a part or all of the methods described herein. Such a program implementing the present application can be stored on a computer-readable medium, or can have the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.

[0160] For example, Figure 7An electronic device is shown, which can implement the method according to the present application. The electronic device can be a PC, a mobile terminal, a personal digital assistant, a tablet computer, etc. The electronic device traditionally comprises a processor 710 and a memory 720 and a program code 730 stored on the memory 720 and executable on the processor 710, which, when executed by the processor 710, implements the method described in the above embodiments. The memory 720 can be a computer program product or a computer readable medium. The memory 720 can be an electronic memory such as a flash memory, an EEPROM (electrically erasable programmable read-only memory), an EPROM, a hard disk or a ROM. The memory 720 has a storage space 7201 for the program code 730 of the computer program for executing any of the method steps described above. For example, the storage space 7201 for the program code 730 can comprise individual computer programs for implementing the various steps in the above methods, respectively. The program code 730 is computer readable code. The computer programs can be read out of or written into one or more computer program products. The computer program products comprise program code carriers such as hard disks, compact discs (CDs), memory cards or floppy disks. The computer programs comprise computer readable code which, when executed on the electronic device, causes the electronic device to perform the method according to the above embodiments.

[0161] The embodiments of the present application further disclose a computer readable storage medium, having stored thereon a computer program, which, when executed by a processor, implements the steps of the network environment anomaly early warning method according to the embodiments of the present application.

[0162] Such a computer program product can be a computer readable storage medium, which can have stored thereon the computer readable code 730' for implementing the above described method. The computer readable storage medium can be similar to the memory 720 in the electronic device shown above. The program code can be stored in the computer readable storage medium, for example, in a compressed form. The computer readable storage medium is typically a portable or stationary storage unit as described above with reference to the memory 720. Typically, the storage unit comprises computer readable code 730', which is code readable by a processor, which, when executed by the processor, implements the various steps in the above described method. Figure 7 The computer readable storage medium can be similar to the memory 720 in the electronic device shown above. The program code can be stored in the computer readable storage medium, for example, in a compressed form. The computer readable storage medium is typically a portable or stationary storage unit as described above with reference to the memory 720. Typically, the storage unit comprises computer readable code 730', which is code readable by a processor, which, when executed by the processor, implements the various steps in the above described method. Figure 8 The computer readable storage medium can be similar to the memory 720 in the electronic device shown above. The program code can be stored in the computer readable storage medium, for example, in a compressed form. The computer readable storage medium is typically a portable or stationary storage unit as described above with reference to the memory 720. Typically, the storage unit comprises computer readable code 730', which is code readable by a processor, which, when executed by the processor, implements the various steps in the above described method.

[0163] The terms "one embodiment", "an embodiment” or "one or more embodiments” as used herein mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment.

[0164] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been shown in detail in order not to obscure an understanding of this description.

[0165] In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unitary claim, several devices or sub-claims can be joined by means of the word 'or'. The word 'first','second', 'third', etc. do not imply any order. The terms 'first','second', 'third', etc. are to be interpreted according to their meaning in the context and are not to be interpreted as a ranking.

[0166] It has to be noted that, while the above describes example embodiments of the application, these are merely given by way of non-limiting examples. Many variations and modifications of the embodiments described herein can become apparent to those skilled in the art once they are made aware of the general nature of the application, as described in the preceding detailed description. The references cited herein are hereby incorporated by reference in their entirety. Any resulting integration of the various "elements" disclosed herein, and natural variations and / or modifications of the application are deemed to be within the scope of the application as defined by the appended claims.

Claims

1. A method for early warning of network environment anomaly, characterized in that, The method comprises the following steps: in response to monitoring the real-time routing change of the data communication device, acquiring the real-time routing table of the data communication device; comparing and analyzing the real-time routing table with the pre-acquired reference routing table of the data communication device to acquire the changed routing information of the data communication device and the associated scene of the routing information; acquiring the reference path corresponding to the associated scene according to the pre-generated routing query tree of each data communication device in the target network; acquiring the predicted path corresponding to the associated scene according to the real-time routing table and the routing query tree; comparing the path indicators of the predicted path and the reference path to obtain a comparison result, wherein the path indicator is positively correlated with the probability of being selected by the data communication device; in response to the comparison result indicating that the predicted path is abnormal, outputting early warning information indicating that the network environment is abnormal; wherein the acquiring the predicted path corresponding to the associated scene according to the real-time routing table and the routing query tree comprises: selecting the optimal path by simulating the routing strategy of the data communication device according to the real-time routing table to generate the current routing query tree of the data communication device; querying the current routing query tree and the routing query tree of other data communication devices in the target network except the data communication device to acquire the predicted path corresponding to the associated scene.

2. The method of claim 1, wherein, The comparison result is obtained by comparing the path indicators of the predicted path and the reference path, comprising: calculating the path indicators of the predicted path and the reference path according to the preset path selection influencing factors of each data communication device in the path; subtracting the path indicators of the reference path from the path indicators of the predicted path to obtain the path indicator difference value; in response to the path indicator difference value being greater than or equal to a specified adaptive deviation range of the path indicator of the reference path, obtaining a comparison result indicating that the predicted path is abnormal, wherein the specified adaptive deviation range is obtained according to the product of the path adaptive deviation threshold value obtained by pre-training and the path indicator of the reference path.

3. The method of claim 2, wherein, The path indicators of the predicted path and the reference path are calculated by the following method: taking the data communication devices in the current type path as vertices, and constructing a graph according to the current type path; calculating the weight of the edge in the graph according to one or more of the following preset path selection influencing factors: the physical bandwidth between the data communication devices corresponding to a pair of vertices connected by the edge, the quality of service bandwidth, and the routing priority; performing relaxation operation on the edges in the graph by using the relaxation technique of the shortest path to obtain the shortest path of each pair of vertices in the graph; determining the shortest path of the current type path as the target path according to the shortest path of each pair of vertices; calculating the path indicator of the current type path according to the weight of the edge in the graph corresponding to the adjacent path nodes in the target path.

4. The method of claim 1, wherein, Before the step of acquiring the real-time routing table of the data communication device in response to monitoring the real-time routing change of the data communication device, the method comprises the following steps: The receiving part is arranged in a data communication device, and a real-time route monitoring module is arranged in the data communication device to send a real-time route change message when the route of the data communication device is changed; According to the real-time route change message, a route change data stream corresponding to the data communication device is generated.

5. The method of claim 4, wherein, The real-time route table of the data communication device is obtained in response to the monitoring of the real-time route change of the data communication device, and the method comprises the following steps: The real-time route table of the data communication device is obtained in response to the monitoring of the real-time route change of the data communication device, and the method comprises the following steps: The real-time route table of the data communication device is obtained in response to the monitoring of the real-time route change of the data communication device, and the method comprises the following steps:

6. The method of claim 1, wherein, The reference route table of each data communication device in the target network is collected; According to the reference route table, a route query tree of the corresponding data communication device is generated by simulating the route strategy of the data communication device to select the optimal path, and the route query tree is updated. The device comprises:

7. A network environment anomaly early warning device, characterized by, A real-time route table acquisition module is arranged to obtain the real-time route table of the data communication device in response to the monitoring of the real-time route change of the data communication device; A route change analysis module is arranged to compare and analyze the real-time route table with a reference route table of the data communication device collected in advance to obtain the changed route information of the data communication device and an associated scenario of the route information; A reference path acquisition module is arranged to obtain a reference path corresponding to the associated scenario according to a route query tree of each data communication device in the target network generated in advance; A predicted path acquisition module is arranged to obtain a predicted path corresponding to the associated scenario according to the real-time route table and the route query tree; A path comparison module is arranged to compare the predicted path with the reference path according to a path index to obtain a comparison result, wherein the path index is positively correlated with the probability of the path being selected by the data communication device; An early warning module is arranged to output early warning information indicating an abnormal network environment in response to the comparison result indicating that the predicted path is abnormal. The predicted path acquisition module is further arranged to: According to the real-time route table, a current route query tree of the data communication device is generated by simulating the route strategy of the data communication device to select the optimal path; The current route query tree and the route query tree of other data communication devices in the target network except the data communication device are queried to obtain the predicted path corresponding to the associated scenario. The processor executes the program code to implement the network environment abnormality early warning method of any one of claims 1 to 6.

8. An electronic device comprising a memory, a processor, and program code stored on the memory and executable on the processor, wherein, The program code is executed by the processor to implement the steps of the network environment abnormality early warning method of any one of claims 1 to 6. 9.A computer readable storage medium having stored thereon a program code, characterized in that, ​

Citation Information

Patent Citations

  • System for routing functionality packets based on monitoring real-time indicators

    US11070454B1

  • Network management method

    US20020116487A1