Method and device for detecting transmission link, equipment and storage medium

By acquiring transmission protocol message log data and sniffing message response information of the transmission link, and combining traffic data to determine the type of transmission link anomaly, the problem of identifying transmission node or link failures in virtualized environments is solved, enabling timely maintenance and improved communication speed.

CN116708246BActive Publication Date: 2026-07-31CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-07-13
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In a network functions virtualization environment, the switch cannot accurately distinguish between a transmission node failure and a transmission link failure, which makes it impossible for maintenance personnel to repair in a timely manner and affects the communication rate.

Method used

By acquiring transmission protocol message log data of the transmission link, sending sniffing messages to monitor the response, and combining traffic data to determine the anomaly type, including transmission node anomaly or link anomaly, address resolution and bidirectional forwarding are used to detect messages to accurately determine the fault type, and the link status is predicted through a traffic anomaly detection model.

Benefits of technology

Accurately identify transmission link or node failures to ensure timely repairs by maintenance personnel, thereby improving network communication speed and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116708246B_ABST
    Figure CN116708246B_ABST
Patent Text Reader

Abstract

This application discloses a method for detecting a transmission link. The transmission link includes a transmission node, and the method includes: acquiring log data of the transmission link for transmission protocol messages; wherein the log data is used to characterize the transmission status of the transmission protocol messages in the transmission link; if an anomaly of the transmission protocol messages is detected based on the log data, a sniffing message is sent to the transmission node, and the response of the transmission node to the sniffing message is monitored; based on the response and the traffic data of the transmission link, the anomaly type of the transmission link is determined; wherein the anomaly type includes either an anomaly of the transmission node or an anomaly of the transmission link. This application's embodiments can accurately identify whether a transmission node or the transmission link itself is faulty, facilitating timely maintenance by operations and maintenance personnel, ensuring network traffic communication rates, and improving user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security detection technology, specifically to a method and apparatus for detecting transmission links, electronic equipment, and computer-readable storage medium. Background Technology

[0002] With the continuous breakthroughs and widespread adoption of modern information technologies such as the Internet, big data, and artificial intelligence, the digital economy is booming. While the deep global internetization brings convenience to social life and economic development, cybersecurity risks are also ever-present. Network Functions Virtualization (NFV), as a network architecture originating from industry, provides a new network design approach for future networks using virtualization technology. Its main idea is to decouple the software implementation of network functions from the underlying hardware and migrate it to a virtual platform. This allows software to run on general-purpose hardware devices such as servers, storage devices, and switches that conform to industry standards, achieving the functions of traditional dedicated network hardware devices and forming corresponding network data transmission links. This provides flexible network function deployment and enables network flow transmission.

[0003] However, when a network data transmission link fails, the switch can detect that the current transmission link is down, but it cannot confirm whether the failure is due to a faulty transmission node or a faulty transmission link. This prevents maintenance personnel from repairing the problem in a timely manner and ensures communication speed. Summary of the Invention

[0004] To address the aforementioned technical problems, embodiments of this application provide a method and apparatus for detecting transmission links, an electronic device, and a computer-readable storage medium.

[0005] According to one aspect of the embodiments of this application, a method for detecting a transmission link is provided, the transmission link including a transmission node, the method comprising: acquiring log data of the transmission link for transmission protocol messages; wherein the log data is used to characterize the transmission status of the transmission protocol messages in the transmission link; if an anomaly of the transmission protocol messages is detected based on the log data, sending a sniffing message to the transmission node and monitoring the response of the transmission node to the sniffing message; determining the anomaly type of the transmission link based on the response and the traffic data of the transmission link; wherein the anomaly type includes an anomaly of the transmission node or an anomaly of the transmission link. According to one aspect of the embodiments of this application, the sniffing message includes an address resolution message and a bidirectional forwarding detection message; determining the anomaly type of the transmission link based on the response status and the traffic data includes: if the response status indicates that the transmission node does not return a response message for the address resolution message, then the transmission link is determined to be an anomaly of the transmission node; if the response status indicates that the transmission node returns a response message for the address resolution message but does not return a response message for the bidirectional forwarding detection message, then the transmission link is determined to be an anomaly of the transmission node; if the response status indicates that the transmission node returns a response message for both the address resolution message and the bidirectional forwarding detection message, then the traffic data of the transmission link is obtained, and a subtype of the transmission link anomaly is determined based on the traffic data of the transmission link; wherein, the subtype includes transmission link overload or transmission link failure.

[0006] According to one aspect of the embodiments of this application, the traffic data includes the actual traffic values ​​of the transmission link at multiple times; the detection of a subtype of transmission link anomaly based on the traffic data of the transmission link includes: if the actual traffic values ​​at the multiple times are detected to reach a preset traffic limit, then the transmission link is determined to be overloaded; if the actual traffic values ​​at the multiple times are detected to be less than or equal to the preset traffic limit, and the actual traffic forwarding quantity of the transmission link is less than the actual traffic should be forwarded quantity, then the transmission link is determined to be faulty.

[0007] According to one aspect of the embodiments of this application, the method further includes: inputting the actual traffic values ​​at the plurality of times into a trained traffic anomaly detection model; wherein the traffic anomaly detection model is trained based on the traffic throughput collected by the switch of the transmission link per unit time and combined with the time sequence structure; and detecting the magnitude relationship between the actual traffic values ​​at the plurality of times and a preset traffic limit through the traffic anomaly detection model.

[0008] According to one aspect of the embodiments of this application, after detecting the relationship between the actual traffic values ​​at the plurality of times and the preset traffic limit through the traffic anomaly detection model, the method further includes: if it is detected that the actual traffic values ​​at the plurality of times are less than or equal to the preset traffic limit, then obtaining the uplink and downlink traffic information of the transmission link; detecting the relationship between the actual traffic forwarding count and the actual required traffic forwarding count of the transmission link based on the uplink and downlink traffic information; if it is detected that the actual traffic forwarding count is less than the actual required traffic forwarding count, then determining that the transmission link belongs to the transmission link fault.

[0009] According to one aspect of the embodiments of this application, the transport protocol message includes at least one of Internet Control Protocol (ICP) message and Transmission Control Protocol (TCP) message, and the log data includes at least one of network quality parameters and lifetime of the transport protocol message; after obtaining the log data of the transport link for the transport protocol message, the method further includes: if the network quality parameter is detected to reach a preset network quality parameter limit, a detection result for characterizing the transport protocol message as abnormal is obtained; if the lifetime is detected to be less than a preset lifetime threshold, a detection result for characterizing the transport protocol message as abnormal is obtained.

[0010] According to one aspect of the embodiments of this application, after determining the anomaly type of the transmission link based on the response situation and the traffic data of the transmission link, the method further includes: if the anomaly type of the transmission link is a transmission node anomaly, then bypassing the abnormal transmission node during message data transmission; if the anomaly type of the transmission link is a transmission link overload, then adjusting the load of the transmission nodes in the transmission link during message data transmission to balance the load of the transmission nodes in the transmission link; if the anomaly type of the transmission link is a transmission link anomaly, then switching to another transmission link during message data transmission, wherein the other transmission link is a transmission link capable of normal network traffic transmission.

[0011] According to one aspect of the embodiments of this application, a transmission link detection device is provided, comprising: an acquisition module, configured to acquire log data of the transmission link for transmission protocol messages; wherein the log data is used to characterize the transmission status of the transmission protocol messages in the transmission link; a sniffing message sending module, configured to send a sniffing message to the transmission node if an anomaly of the transmission protocol message is detected based on the log data, and monitor the response of the transmission node to the sniffing message; and an anomaly determination module, configured to determine the anomaly type of the transmission link based on the response status and the traffic data of the transmission link; wherein the anomaly type includes an anomaly of the transmission node or an anomaly of the transmission link.

[0012] According to one aspect of the embodiments of this application, an electronic device is provided, including: one or more processors; and a storage device for storing one or more programs, which, when executed by the one or more processors, cause the electronic device to implement the transmission link detection method as described above.

[0013] According to one aspect of the embodiments of this application, a computer-readable storage medium is provided, on which computer-readable instructions are stored, which, when executed by a computer's processor, cause the computer to perform the transmission link detection method as described above.

[0014] In the technical solution provided by the embodiments of this application, log data of transmission protocol messages in the transmission link is obtained. The log data is used to characterize the transmission status of transmission protocol messages in the transmission link. If an anomaly of the transmission protocol message is detected based on the log data, a sniffing message is sent to the transmission node in the transmission link, and the response of the transmission node to the sniffing message is monitored. Then, the anomaly type of the transmission link is determined based on the response of the sniffing message and the traffic data of the transmission link. The anomaly type includes transmission node anomaly or transmission link anomaly. In this way, it is possible to accurately confirm whether the transmission node in the transmission link is faulty or the transmission link is faulty, so as to facilitate timely maintenance by operation and maintenance personnel, ensure the communication rate of network traffic on the transmission link, and improve the user experience.

[0015] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description

[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort. In the drawings:

[0017] Figure 1 This is a schematic diagram illustrating data transmission based on a service-oriented function chain, as shown in an exemplary embodiment of this application.

[0018] Figure 2 This is a schematic diagram illustrating an implementation environment for detecting a transmission link in a virtual environment, as shown in an exemplary embodiment of this application.

[0019] Figure 3 This is a schematic diagram illustrating a failure in the service-oriented function chain, as shown in an exemplary embodiment of this application.

[0020] Figure 4 This is a flowchart illustrating a transmission link detection method in an exemplary embodiment of this application;

[0021] Figure 5 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0022] Figure 6 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0023] Figure 7 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0024] Figure 8 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0025] Figure 9 This is a diagram showing the distribution of traffic information on a transmission link in an exemplary application scenario.

[0026] Figure 10 This is a schematic diagram illustrating the training of a traffic anomaly detection model according to an exemplary embodiment of this application;

[0027] Figure 11 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0028] Figure 12 This is a schematic diagram illustrating a traffic forwarding anomaly on a transmission link, as shown in another exemplary embodiment of this application.

[0029] Figure 13 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0030] Figure 14 This is a flowchart illustrating a method for detecting a transmission link, as shown in another exemplary embodiment of this application;

[0031] Figure 15 This is a schematic diagram illustrating the bypassing of transmission nodes in an exemplary application scenario of this application;

[0032] Figure 16 This is a schematic diagram illustrating excessive load on the transmission link in an exemplary application scenario of this application;

[0033] Figure 17 This is a schematic diagram illustrating the primary / backup transmission link switching in an exemplary application scenario of this application;

[0034] Figure 18This is a schematic diagram illustrating direct access from the source node to the target node in an exemplary application scenario of this application;

[0035] Figure 19 This is a simplified flowchart illustrating the detection of the transmission link in a navigation interface in an exemplary application scenario.

[0036] Figure 20 This is a block diagram illustrating a transmission link detection device in an exemplary embodiment of this application;

[0037] Figure 21 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation

[0038] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0039] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0040] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0041] In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0042] First, it should be noted that with the continuous breakthroughs and popularization of modern information technologies such as the Internet, big data, and artificial intelligence, the digital economy is booming and the strategy of cloud-network convergence is constantly being promoted. Cloud-network convergence refers to the combination of cloud computing and communication networks, introducing cloud computing technology into communication networks, or introducing cloud computing technology into communication networks. Therefore, cloud-network convergence is the networking of the cloud and the cloudification of the network.

[0043] The resulting security issues are also one of the obstacles to the in-depth development of cloud-network convergence. Security is the foundation of cloud-network convergence and its basic characteristic. Traditional protection capabilities can no longer meet the security needs under the new circumstances.

[0044] Service function chain (SFC) is essentially a policy-based routing version of SDN (Software Defined Networking). After computing resources within a resource pool are virtualized, traditional hardware devices such as egress firewalls, firewalls, and IPS are deployed in a virtualized manner. End-to-end traffic must pass through different security network elements before reaching its destination address. Guiding traffic through these network elements in an orderly manner is the basic function of SFC. Traditional physical devices are connected via hardware, resulting in a rigid and inflexible traffic flow order. SFC, however, can define network function units and customize traffic paths, thus providing better network support for the controller. Figure 1 As shown, within the resource pool, network traffic transmission service chains utilize SFC (Service Function Chain) traffic orchestration technology. Traffic passes sequentially through security devices such as firewalls (FW), intrusion prevention systems (IPS), and web application firewalls (WAF), traversing the service chain without altering the source and destination addresses, thus achieving traffic auditing. SFC is essentially a policy-based routing version of SDN (software-defined networking). After computing resources within the resource pool are virtualized, traditional hardware devices such as egress firewalls, firewalls, and IPS are deployed in a virtualized manner. End-to-end traffic must pass through different security network elements before reaching its destination address. Guiding traffic through these network elements in an orderly manner is the fundamental function of SFC. Traditional physical devices are connected via hardware, resulting in a rigid and inflexible traffic flow order. SFC, however, can define network functional units and customize traffic paths, thereby achieving better network support.

[0045] in, Figure 2 This is a schematic diagram illustrating the implementation environment of a transmission link detection method according to an exemplary embodiment of this application. Figure 2As shown, in the virtual environment, the control server 220 sends corresponding probe messages to the test terminal 210 based on the link information included in the virtual environment, configures the test link corresponding to each transmission link in the virtual environment, and obtains the log data of the transmission protocol messages in the probe messages. This log data is used to characterize the transmission status of the transmission protocol messages in the probe messages in the transmission links. If the control server 220 detects an anomaly in the transmission protocol messages in the probe messages based on the log data, it sends sniffing messages to the transmission nodes in the transmission links and monitors the response of the transmission nodes in the transmission links to the sniffing messages. Based on the response of the transmission nodes to the sniffing messages, it further detects the abnormal content of the transmission link and specifically distinguishes whether the transmission link is abnormal due to a transmission node or a transmission link.

[0046] In virtualized scenarios, SFC link orchestration schemes have inherent risks. Traditional hardware devices typically use link state detection protocols such as BFD (Bidirectional Forwarding Detection) to detect link failures. During the detection period, if a link interruption is detected, neighboring routers are notified to perform link switching or bypass the faulty node to ensure normal communication. However, in virtualized scenarios, link orchestration relies on software-level implementation and lacks a mechanism for macroscopically understanding link and node states, as follows: Figure 3 As shown, VM1-VM3 are virtual machines, and traffic orchestration is performed via SFC, passing through VM1, VM2, and VM3 respectively. When a link failure occurs, such as a break at the asterisk position, the switch can detect the link failure but cannot determine whether it is a virtual machine failure or a link orchestration problem. Similarly, when a link failure occurs, the upper-layer controller cannot detect the fault point or the faulty link, and cannot perform emergency response measures such as primary / backup switching or fault node bypass. The problems mentioned above are universally applicable in common network data transmission scenarios. It can be seen that when transmitting network streams in a transmission link, it is impossible to determine whether it is a virtual machine failure or a link orchestration problem. Similarly, when a link failure occurs, the upper-layer controller cannot detect the fault point or the faulty link, and cannot perform emergency response measures such as primary / backup switching or fault node bypass. To solve these problems, embodiments of this application propose a transmission link detection method, a transmission link detection device, an electronic device, and a computer-readable storage medium.

[0047] Please see Figure 4 , Figure 4 This is a flowchart illustrating a transmission link detection method as an exemplary embodiment of the invention. This method can be applied to... Figure 2The implementation environment shown is specifically executed by the control server 220 within that implementation environment. It should be understood that this method can also be applied to other exemplary implementation environments and executed by devices in other implementation environments; this embodiment does not limit the implementation environment to which the method is applicable.

[0048] like Figure 4 As shown, in an exemplary embodiment, the transmission link detection method includes at least steps S410 to S430, which are described in detail below:

[0049] Step S410: Obtain log data of the transmission protocol message for the transmission link; wherein, the log data is used to characterize the transmission status of the transmission protocol message in the transmission link.

[0050] Specifically, the connectivity of the transmission link can be tested end-to-end. This can be done using various protocols such as Internet Control Message Protocol (ICMP), User Datagram Protocol (UDP), Transmission Control Protocol (TCP), and Hypertext Transfer Protocol (HTTP). Then, log data generated on the transmission link based on these protocol messages can be obtained, and the specific transmission status of these protocol messages can be determined based on the log data.

[0051] For example, in some feasible embodiments, corresponding transmission protocol messages can be sent to the transmission link in the virtual environment via ICMP (Internet Control Message Protocol), UDP (User Datagram Protocol), or TCP (Transmission Control Protocol), while simultaneously collecting log data such as latency, packet loss rate, and number of packet forwards on the transmission link, so as to further analyze the transmission status of the transmission link based on the collected log data.

[0052] Step S420: If an abnormality in the transmission protocol message is detected based on the log data, a sniffing message is sent to the transmission node, and the response of the transmission node to the sniffing message is monitored.

[0053] Specifically, following step S410 above, if the log data generated by the transmission link in response to the transmission protocol message indicates that the transmission protocol message in the transmission link is abnormal, then it can be determined that the transmission link is abnormal. In order to further determine whether the abnormality is in the transmission link or the transmission node, sniffing messages are sent to the transmission nodes in the transmission link, and the response of the transmission nodes on the transmission link to the sniffing messages is monitored in real time.

[0054] For example, ping (Packet Internet Groper) is an Internet packet explorer used to test network connectivity. Ping is a service command operating at the application layer of the TCP / IP network architecture. It primarily sends ICMP (Internet Control Message Protocol) Echo request messages to a specific destination host to test the reachability of the destination and to understand its relevant status.

[0055] For example, if an anomaly is detected in the transmission protocol messages on the transmission link, a sniffing message is sent to the transmission node on the transmission link, and the response of the transmission node to the sniffing message is monitored, so as to determine the operation status of the transmission node based on the response of the transmission node to the sniffing message.

[0056] Step S430: Based on the response status and the traffic data of the transmission link, detect the anomaly type of the transmission link; wherein, the anomaly type is determined to include transmission node anomaly or transmission link anomaly.

[0057] Specifically, based on the flow tables collected by the transmission nodes in the entire transmission link for sniffed packets and the switches in the transmission link to record traffic forwarding rules, traffic transmission size, and other traffic information, traffic data can be obtained from the flow tables to detect the anomaly type of the transmission link, including determining whether it is a transmission link failure or a transmission node failure.

[0058] For example, when an anomaly in the transmission protocol messages is detected on the transmission link based on the log data of the transmission protocol messages on the transmission link, it can be determined that the transmission link has failed. In order to further determine the specific type of failure in the transmission link, sniffing messages are sent to the transmission nodes in the transmission link, and the response of the transmission nodes in the transmission link to the sniffing messages is monitored. In order to further determine the anomaly type of the transmission link that has failed, that is, to determine whether the transmission link itself is abnormal or the transmission nodes on the transmission link are abnormal, based on the response of the transmission nodes in the transmission link to the sniffing messages and the traffic data on the transmission link. In this embodiment, log data of transmission protocol messages in the transmission link is acquired. The log data is used to characterize the transmission status of transmission protocol messages in the transmission link. If an anomaly in the transmission protocol message is detected based on the log data, a sniffing message is sent to the transmission node in the transmission link, and the response of the transmission node to the sniffing message is monitored. Then, the anomaly type of the transmission link is determined based on the response of the sniffing message and the traffic data of the transmission link. The anomaly type includes transmission node anomaly or transmission link anomaly. In this way, it is possible to accurately identify whether the failure is due to a transmission node failure or a transmission link failure, so as to facilitate timely maintenance by operation and maintenance personnel, ensure the communication rate of network traffic, and improve the user experience.

[0059] Furthermore, based on the above embodiments, please refer to... Figure 5 In one exemplary embodiment provided in this application, the sniffing messages include address resolution messages and bidirectional forwarding detection messages; therefore, the specific implementation process of determining the anomaly type of the transmission link based on the response situation and traffic data may further include steps S510 and S530, which are described in detail below:

[0060] Step S510: If the response status indicates that the transmission node has not returned a response message for the address resolution message, then it is determined that the transmission link is abnormal.

[0061] Specifically, following the above embodiments, log data of transmission protocol messages on the transmission link is obtained. Based on this log data, anomalies in transmission messages are detected on the transmission link. These anomalies can include excessively high packet loss rate, excessive transmission delay, or inability to access the destination address. If such anomalies occur, it can be determined that the transmission link is faulty. To further determine the type of fault, Address Resolution Protocol (ARP) messages are broadcast on the transmission link. If, based on the response behavior of the transmission nodes to ARP messages, no response data is returned, it can be determined that the fault type of the transmission link is a transmission node anomaly.

[0062] It's important to note that Address Resolution Protocol (ARP) is a TCP / IP protocol that retrieves the physical address from the IP address. When a host sends information, it broadcasts an ARP request containing the target IP address to all hosts on the local network and receives a response message to determine the target's physical address. After receiving the response message, the host stores the IP address and physical address in its local ARP cache for a certain period. Subsequent requests directly query the ARP cache to save resources. ARP relies on mutual trust among hosts on the network. Hosts on the local network can independently send ARP reply messages. Other hosts receiving these reply messages do not verify their authenticity but simply record them in their local ARP cache. This allows attackers to send fake ARP reply messages to a host, causing its messages to fail to reach the intended host or reach the wrong host—this constitutes ARP spoofing. ARP commands can be used to query the mapping between IP addresses and MAC addresses in the local ARP cache, add or delete static mappings, etc. Related protocols include RARP and Proxy ARP. NDP is used in IPv6 to replace ARP.

[0063] Step S520: If the response status indicates that the transmission node returns a response message for the address resolution message, but does not return a response message for the bidirectional forwarding detection message, then it is determined that the transmission link is abnormal.

[0064] Specifically, following the above embodiments, after determining that an anomaly exists in the transmission link based on the transmission protocol messages on the transmission link, sniffing messages are sent to the transmission nodes in the transmission link to determine the type of anomaly by monitoring the responses of the transmission nodes to the sniffing messages. For example, an ARP request is broadcast to all transmission nodes on the transmission link, and the response messages returned by the transmission nodes are received to determine the physical address of the transmission nodes. When the response status of the ARP request indicates that all transmission nodes on the transmission link have returned corresponding response information to the ARP request, but the above detection results still determine that the transmission link is abnormal, a bidirectional forwarding detection request (BFD) is then sent in the transmission link to monitor whether the transmission nodes in the transmission link return corresponding response data to the BFD. If no response data is received from the transmission nodes in the transmission link based on the BFD, it can be determined that an anomaly has occurred in the transmission node of the transmission link.

[0065] It's important to note that BFD stands for Bidirectional Forwarding Detection. It's a network protocol used to detect faults between two forwarding points. BFD is a bidirectional forwarding detection mechanism that provides millisecond-level detection, enabling rapid link detection. By working in conjunction with upper-layer routing protocols, BFD can achieve rapid route convergence, ensuring service continuity. BFD only detects the connection status of the next-hop device, featuring light load, high sensitivity, and wide adaptability. BFD can perform fault detection on any type of channel between systems, including direct physical links, virtual circuits, tunnels, multi-hop routing channels, and indirect channels (such as those bridging Layer 2 Ethernet). Furthermore, the simplicity and singularity of BFD's fault detection implementation allows it to focus on rapid detection of forwarding faults, helping the network achieve high-quality transmission of various services.

[0066] Because BFD can establish peering relationships with neighboring systems, each system then monitors the BFD rate from other systems at a negotiated rate. The monitoring rate can be set in millisecond increments. When a peer system fails to receive a pre-defined number of packets, it infers a failure in the software or hardware infrastructure protected by BFD, regardless of whether the infrastructure is a tagged switching path, other types of tunnels, or a switched Ethernet network. BFD is deployed on the control plane of routers and other systems. Network failures detected by BFD can be recovered either from the forwarding plane or from the control plane.

[0067] Step S530: If the response status indicates that the transmission node returns a response message for the address resolution message and a response message for the bidirectional forwarding detection message, then the traffic data of the transmission link is obtained, and the subtype of the transmission link anomaly is determined based on the traffic data of the transmission link; wherein, the subtype includes transmission link overload or transmission link failure.

[0068] Specifically, following the above, after determining that the transmission link is abnormal based on the log data of the transmission packets on the transmission link, sniffing packets are sent in the transmission link, and the response of the transmission nodes in the transmission link to the sniffing packets is monitored. If it is determined that there is no abnormality in the transmission nodes in the transmission link based on the response of the transmission nodes in the transmission link to the sniffing packets, then the traffic information on the corresponding switch of the transmission link is obtained, so as to determine the type of transmission link failure through the traffic information.

[0069] For example, if an APR request is broadcast in a transmission link, and a response data for the APR request is received from a transmission node in the transmission link, along with a Bidirectional Forwarding Detection (BFD) message sent in the transmission link, and a response data based on the BFD message is received from a transmission node in the transmission link, then it is determined that the transmission node in the transmission link is normal. However, if log data on transmission protocol messages collected on the transmission link indicates that the transmission link is abnormal, then it is necessary to further determine the specific subtype of the abnormality in the transmission link.

[0070] In some feasible embodiments, the anomaly subtype of the transmission link can be determined by acquiring traffic data on the transmission link. The anomaly subtypes include transmission link anomaly and excessive transmission link load. Specifically, the traffic data on the transmission link can be determined by acquiring the flow table data in the switch corresponding to the transmission link; therefore, the anomaly subtype of the transmission link can be determined based on the flow table data.

[0071] The flow table serves as the basis for data forwarding. Similar to the MAC address forwarding table and IP address routing table of a switch, the flow table stores network configuration information at various layers of the network, thus enabling richer forwarding rules. When a switch receives a data packet from a host, it queries the local machine for the corresponding action and output port. The flow table contains many entries, each representing a forwarding rule. Generally, the structure of a flow table entry is as follows: a header field for packet matching; a counter to count the number of matching packets; and an action to indicate how to process the matching packet. The flow table is distributed to the switch by the controller.

[0072] For further details, please refer to Figure 6 , Figure 6 This application provides an exemplary schematic diagram illustrating a process for performing security checks on a transmission link within a virtual environment. Figure 6As shown, by acquiring log data of transport protocol messages on the transport link and sensing the log data through operations such as ping, if transport protocol message anomalies are detected, sniffing messages are further sent to the transport link. This includes broadcasting ARP requests on the transport link and monitoring the response of transport nodes to the ARP requests. If no response data is received from the transport nodes in the transport link for the ARP message, the transport node in the transport link is determined to be faulty. If a response data is received from the transport nodes in the transport link for the ARP message, a bidirectional forwarding detection (BDF) message is sent to the transport link, and the response of transport nodes in the transport link to the ARP requests is monitored. If no response data is received from the transport nodes in the transport link for the BDF message, the transport node in the transport link is determined to be abnormal. If a response data is received from the transport nodes in the transport link for the BDF message, traffic information on the transport link is acquired to determine the abnormal subtype of the transport link based on the traffic information. The abnormal subtype of the transport link includes transport link anomaly and excessive transport link load.

[0073] In this embodiment, by detecting the transmission nodes in the transmission link through the address resolution protocol or the bidirectional forwarding detection protocol, the status of the transmission nodes on the transmission link can be grasped from the transmission node level, and the abnormal transmission nodes can be accurately identified, which facilitates timely detection and repair by operation and maintenance personnel and ensures communication transmission efficiency.

[0074] Furthermore, based on the above embodiments, please refer to... Figure 7 In one exemplary embodiment provided in this application, the traffic data includes the actual traffic values ​​of the transmission link at multiple times. The specific implementation process of detecting transmission link anomalies based on the traffic data of the transmission link may further include steps S710 and S720, which are described in detail below:

[0075] Step S710: If the actual traffic value at multiple times is detected to reach the preset traffic limit, it is determined that the transmission link is overloaded.

[0076] Specifically, following the above embodiments, the traffic information on the transmission link can be determined by obtaining the flow table information on the switch corresponding to the transmission link. The flow table information on the switch includes the CPU and memory status of the physical switch; physical interface status information, such as the optical module status and interface bandwidth utilization; interface packet / queue statistics, such as interface packet loss and error statistics, queue packet loss statistics, and queue buffer resource occupancy status; and table / resource data, such as the usage of forwarding table resources, ACL (Access Control List) flow table resources, and virtual interface resources. This information is used to detect whether the physical switching equipment is working properly, whether the PBR (Policy-Based Routing) policies issued by the relevant interfaces are effective, whether the traffic correctly matches the ACL policies (access control list policies are used to control the operations that users can perform on resources and the users who can perform these operations), and whether there is packet loss on the interface.

[0077] For example, since the number of users in a transmission link is not fixed, and there are times when the number of users increases or decreases, the overall traffic distribution is different. Therefore, in this embodiment, a preset traffic limit is used to determine whether there is an overload phenomenon in the actual traffic limit at multiple moments on the transmission link. This preset traffic limit can be predicted using machine learning based on the traffic distribution over historical periods on the transmission link and the traffic throughput of the ports within the transmission link per unit time. In other words, if the actual traffic value at multiple moments on the transmission link is detected to reach the preset traffic limit, it can be determined that the transmission link is overloaded.

[0078] Step S720: If the actual traffic value at multiple times is detected to be less than or equal to the preset traffic limit, and the actual number of traffic forwardings on the transmission link is less than the actual number of traffic forwardings that should be forwarded, then the transmission link is determined to be a transmission link fault.

[0079] Furthermore, if the actual traffic value detected at multiple times is less than or equal to the preset traffic limit, it can be determined that the load of the transmission link is normal and there is no overload. However, considering that there may be an abnormality in the transmission link, the uplink and downlink traffic information of the transmission link in the flow table information of the corresponding switch can be used to determine the relationship between the actual forwarding volume and the actual forwarding volume that should be forwarded in the transmission link. If the actual forwarding volume of the transmission link is less than the actual forwarding volume that should be forwarded, it is determined that the abnormality of the transmission link is a transmission link failure.

[0080] It's important to note that uplink and downlink traffic are two metrics used to calculate network communication data transmission volume. Uplink traffic refers to data traffic uploaded from a local device to the cloud or other remote servers, such as uploading files or sending emails. For example, uploading a video to a video sharing platform uses uplink traffic. Downlink traffic refers to data traffic downloaded from the cloud or other remote servers to a local device, such as browsing web pages, watching online videos, or downloading files. For example, browsing web pages or watching online videos uses downlink traffic.

[0081] In this embodiment, the actual traffic values ​​at multiple times recorded on the transmission link in the flow table information corresponding to the transmission link are used to determine whether the transmission link is overloaded. The uplink and downlink traffic information of the transmission link recorded in the flow table information is used to determine whether the transmission link is faulty. This can accurately determine whether the transmission link is overloaded or faulty, so that maintenance personnel can repair the fault in a timely manner and improve the communication rate.

[0082] Furthermore, based on the above embodiments, in one exemplary embodiment provided in this application, the specific implementation process of the above transmission link detection method may further include the following steps S810 and S820, which are described in detail below:

[0083] Step S810: Input the actual traffic values ​​at multiple times into the trained traffic anomaly detection model; wherein, the traffic anomaly detection model is trained based on the traffic throughput collected by the switch of the transmission link per unit time and the time sequence structure.

[0084] Step S820: Detect the relationship between the actual flow rate at multiple times and the preset flow rate limit using a flow anomaly detection model.

[0085] It's important to note that traffic anomaly detection differs from rule-based models. It cannot rely on hard metrics to determine traffic anomalies. When user usage increases or decreases, the overall traffic distribution differs, making it impossible to determine anomalies in the current link using thresholds. Therefore, a model is needed to determine anomalies based on traffic distribution over a period of time. Traffic logs collect throughput data from a specific interface within a unit of time on the switch, thus conforming to a time-series model structure. Based on these data characteristics, this example proposes a traffic anomaly detection model based on Transformer (feature processor). In other words, Transformer is a model that utilizes an attention mechanism to improve training speed. It can be considered a deep learning model entirely based on self-attention, as its suitability for parallel computation and its inherent model complexity result in higher accuracy and performance than previously popular RNN recurrent neural networks. Its core lies in modeling through a self-attention mechanism, as shown in the following formula:

[0086]

[0087] Reference Figure 9 Here, Q represents the traffic flow during time period T1, K represents the traffic flow during time period T2, and V represents the peak traffic flow at time T. Unlike previous Transformers that used a single time point as data input, using data from time periods T1 and T2 allows the model to capture contextual information, better reducing the impact of outliers on detection results and improving prediction accuracy. Since Q and K represent the traffic flow information per unit time, a recurrent neural network is used to model the characteristics at each time point.

[0088] A flow sequence encoder, composed of recurrent neural networks, including but not limited to RNNs and LSTMs, encodes all labels using a label encoder, as shown in the following formula:

[0089] Where n = 5

[0090] Where n = 3

[0091] Where n = 1

[0092] LSTM is a tag encoder. Let Q and K be the flow rate values ​​at each time point t, where Q and K are the characteristic representations of the flow rate within the time interval T. These characteristic values, along with the current flow rate characteristic value V, are input into the Transformer neural network, as follows: Figure 10 As shown, the preset flow limit is obtained after encoding by the Transformer neural network, and the formula is as follows:

[0093] f(x) = softmax(W l *Att transformer )

[0094] Where W and b are parameters, softmax is the prediction function, and f(x) is the preset flow limit. Furthermore, it can also predict whether the flow is abnormal at the current moment, as shown in the following formula:

[0095] predict label =softmax(W l *Att transformer +b l )

[0096] Where predict∈[0,1] indicates whether the current time is abnormal, where 0 is normal and 1 is abnormal.

[0097] In some exemplary embodiments, in order to further improve the accuracy of the traffic anomaly judgment results obtained by simulation, more comprehensive factors need to be considered in the process of simulating the traffic throughput on the transmission link, such as the number of users on the transmission link, the time period, the running applications, and the users' usage habits. Therefore, machine learning can be used to simulate the real-time traffic throughput on the transmission link.

[0098] Machine learning (ML) is a multidisciplinary field involving probability theory, statistics, approximation theory, convex analysis, and algorithm complexity theory. It specifically studies how computers can simulate or implement human learning behavior to acquire new knowledge or skills and reorganize existing knowledge structures to continuously improve their performance. Machine learning is the core of artificial intelligence and the fundamental way to endow computers with intelligence; its applications span all areas of artificial intelligence. Machine learning and deep learning typically include techniques such as artificial neural networks, belief networks, reinforcement learning, transfer learning, inductive learning, and instruction-based learning.

[0099] Leveraging the powerful learning capabilities of machine learning, a machine learning process based on a large amount of historical data can enable machine learning models to more accurately and reliably predict the traffic throughput of a transmission link, considering factors such as the number of users, user habits, time periods, allowed applications, and included transmission nodes. For example, the machine learning model can include a supervised model based on neural networks, such as a binary classification machine learning model. By training the machine learning model with a large amount of historical data, the model parameters can be adjusted during training, resulting in a more comprehensive predictive performance for various characteristics of the transmission link, including traffic throughput.

[0100] In this embodiment, a pre-trained traffic anomaly detection model is used to detect whether the traffic on the transmission link is abnormal at multiple times. This not only simplifies the detection process of the traffic load on the transmission link, but also ensures the accuracy of the obtained traffic anomaly detection results.

[0101] Furthermore, based on the above embodiments, please refer to... Figure 11 In one exemplary embodiment provided in this application, after detecting the relationship between the actual traffic values ​​at multiple times and the preset traffic limit using the traffic anomaly detection model, the specific implementation process of the above-mentioned transmission link detection method may further include:

[0102] Step S1110: If the actual traffic value at multiple times is detected to be less than or equal to the preset traffic limit, then the uplink and downlink traffic information of the transmission link is obtained.

[0103] Specifically, following the above embodiments, the traffic information on the transmission link can be determined by obtaining the flow table information on the switch corresponding to the transmission link. In a virtualized environment, SFC (Service-Oriented Link) is implemented through an OpenVSwitch (Open Virtual Switching Standard) virtual switch. The flow table is a flow forwarding rule under the virtual switch; traffic is forwarded according to the user-defined flow table. When a link fails, the flow table needs to be checked to detect whether the link failure is caused by an abnormal OpenVSwitch flow table. Therefore, the flow table module analyzes flow table data for a specific environment to check whether the controller link configuration is normal, whether traffic forwarding is normal, and whether there are packet loss issues. The link detection module completes two tasks: one is to check whether the link is end-to-end normal and whether the flow table is normal; the other is to collect various link latency and packet loss data.

[0104] For example, in some feasible embodiments, the relationship between the actual traffic at multiple times and the predicted preset traffic limit of the transmission link is determined by obtaining the OpenVSwitch flow table of the transmission link and comparing the actual traffic at multiple times in the flow table with the predicted preset traffic limit. If the actual traffic value at multiple times on the transmission link is detected to be less than or equal to the predicted preset traffic limit, the uplink and downlink traffic information of the transmission link is obtained from the flow table.

[0105] Step S1120: Detect the relationship between the actual number of traffic forwardings and the actual number of traffic forwardings on the transmission link based on uplink and downlink traffic information.

[0106] Specifically, following the above embodiments, based on the uplink and downlink traffic information of the transmission link obtained from the OpenVSwitch flow table, the relationship between the actual number of traffic forwards on the transmission link and the actual number of times traffic should be forwarded on the transmission link is determined from this uplink and downlink traffic information. Here, traffic forwarding refers to forwarding the corresponding network traffic from the local port to the corresponding target port. In this embodiment, traffic forwarding can refer to forwarding the corresponding network traffic to the corresponding transmission node on the transmission link. In other words, by determining the relationship between the actual number of traffic forwards on the transmission link and the actual number of times traffic should be forwarded through the flow table information on the transmission link, the forwarding capability of the transmission link can be determined.

[0107] Step S1130: If the actual number of traffic forwardings is less than the actual number of traffic forwardings, then the transmission link is determined to be a transmission link failure.

[0108] Specifically, if the flow table information corresponding to the transmission link indicates that the actual number of traffic forwards in the transmission link is less than the actual number of traffic that should be forwarded, then it can be determined that there is a transmission fault in the transmission link, such as a transmission link disconnection.

[0109] like Figure 12 As shown, when a fault occurs between transmission node-virtual machine 1 and transmission node-virtual machine 2, the access request from host (10.2.12.123) to the target address (10.0.13.104) on the target server cannot be successfully forwarded to transmission node-virtual machine 2 in the transmission link. In other words, by obtaining the flow table information of this transmission link, it can be determined that there is no traffic forwarding from transmission node-virtual machine 1 to transmission node-virtual machine 2 in this transmission link, thus confirming a fault in the transmission link. Since the switch can detect that the current transmission link is down, it cannot confirm whether the fault is due to a transmission node failure or a transmission link interruption. However, if by obtaining the uplink and downlink traffic in this transmission link, it is determined that the actual number of traffic forwards in this transmission link is less than the actual number of traffic forwards that should be forwarded, then it can be determined that the transmission link has failed, causing traffic to fail to be forwarded to the corresponding transmission node.

[0110] In this embodiment, the uplink and downlink traffic information on the transmission link is detected to determine whether the traffic forwarding on the transmission link is normal. If the actual number of traffic forwardings on the transmission link is less than the actual number of traffic forwardings that should be forwarded, it can be determined that a fault has occurred on the transmission link, causing the traffic to fail to be forwarded. This accurately identifies the abnormal situation of the transmission link and makes it convenient for maintenance personnel to repair the faulty transmission link in a timely manner.

[0111] Furthermore, based on the above embodiments, please refer to... Figure 13 In one exemplary embodiment provided in this application, the aforementioned transport protocol message includes at least one of Internet Control Protocol (ICP) message and Transmission Control Protocol (TCP) message, and the aforementioned log data includes at least one of network quality parameters and lifetime of the transport protocol message. Therefore, after obtaining the log data of the transport link for the transport protocol message, the specific implementation process of the aforementioned transport link detection method may further include the following steps S1310 and S1320, which are described in detail below:

[0112] Step S1310: If the network quality parameters are detected to reach the preset network quality parameter limit, a detection result is obtained to characterize the abnormality of the transmission protocol message.

[0113] Step S1320: If the detected survival time is less than the preset survival time threshold, a detection result is obtained to characterize the abnormality of the transmission protocol message.

[0114] Specifically, to detect end-to-end connectivity in the transmission link, corresponding ICMP messages can be sent in the transmission link based on ICMP (Internet Control Protocol), and the latency and packet loss rate of the ICMP messages in the transmission link can be obtained. If the transmission latency of the ICMP messages in the transmission link is greater than a preset latency and / or the packet loss rate of the ICMP messages in the transmission link is greater than a preset packet loss rate, then it can be confirmed that there is an ICMP message anomaly in the transmission link. If the packet loss rate and latency of the ICMP messages in the transmission link are within the normal range, then it can be further confirmed that there is a TCP transmission anomaly in the transmission link based on TCP (Transmission Control Protocol), and the latency when the client sends the response data packet to the corresponding target access address in the transmission link can be obtained, that is, the latency of the TCP third handshake can be obtained. If the latency of the TCP third handshake is greater than a preset latency threshold, it can be determined that there is a TCP transmission anomaly in the transmission link.

[0115] Furthermore, in some feasible embodiments, if the IMCP and TCP packets are normal in the transmission link, UDP packets can be sent to the transmission link based on the User Datagram Protocol (UDP) to obtain network quality parameters such as latency and packet loss rate of the UDP packets in the transmission link. If the network quality parameters such as latency and packet loss rate of the detected UDP packets reach the preset latency threshold and preset packet loss rate, a detection result is obtained to characterize the presence of abnormal transmission protocol packets in the transmission link.

[0116] In this implementation, by detecting the real-time log data generated by the transmission link in response to transmitted packets, and by analyzing the preset network quality parameters of the transmitted packets within the transmission link, it is determined whether any anomalies have occurred in the transmission protocol packets. Furthermore, by using network quality parameters such as the duration of time the transmitted packets remain alive, the response of the transmission link to the transmitted packets is determined, thereby identifying whether any anomalies exist in the transmission link. This achieves the detection of transmission link anomalies.

[0117] Furthermore, based on the above embodiments, please refer to... Figure 14 In one exemplary embodiment provided in this application, after determining the anomaly type of the transmission link based on the response status and the traffic data of the transmission link as described above, the specific implementation process of the transmission link detection method may further include the following steps S1410 to S1430, which are described in detail below:

[0118] Step S1410: If the transmission link's anomaly type is transmission node anomaly, then the transmission node with the anomaly is bypassed during message data transmission.

[0119] If the detected anomaly type of the transmission link is an anomaly of one or more transmission nodes within the link, the transmission link can be regenerated during switch configuration, and a single-node primary / backup switchover can be implemented to bypass the faulty node. Figure 15 As shown, in some feasible embodiments, the bypassing of nodes is reported to the server so that the administrator can be aware of the status information of the transmission link and repair the link problem through relevant personnel.

[0120] Step S1420: If the abnormality type of the transmission link is transmission link overload, then the load of the transmission nodes in the transmission link is adjusted during the message data transmission process to balance the load of the transmission nodes in the transmission link.

[0121] Specifically, if the detected anomaly type of the transmission link is link overload, the load of each transmission node in the transmission link can be adjusted during packet data transmission, or the number of transmission nodes can be appropriately increased to balance the load of the transmission link. This can typically be achieved using PBR (Policy Routing), which changes the next-hop address of the traffic on the service switch to balance the load in the transmission link, and then further reports the issue to the platform. Figure 16 As shown, the load of virtual machine 1 is greater than that of other virtual machines in the transmission link. Therefore, the load of the transmission link can be improved by adjusting the load on virtual machine 1.

[0122] Step S1430: If the transmission link is an anomaly, then during the message data transmission process, switch to another transmission link, which is a transmission link that can normally transmit network traffic.

[0123] For example, when a failure is detected in the primary transmission link, the system can switch to a backup transmission link that is capable of transmitting network traffic normally. Specifically, if the detected anomaly type in the transmission link is a transmission link anomaly, which includes transmission link interruption, such as... Figure 17 As shown, uninterrupted service can be achieved by switching to an alternative transmission link. Furthermore, if the alternative transmission link also fails, a bypass approach can be used, directly forwarding traffic to the destination address without going through the security pool, and restoring the link once the fault is repaired. Figure 18 As shown, when a physical machine failure is detected, or when both the primary and backup links are interrupted, the host 10.0.12.123 will no longer access the host 10.0.13.104 through the transmission link (resource pool), but will directly access the destination address.

[0124] Furthermore, in some feasible embodiments, probe messages are generated for multiple transmission links in the same virtual environment, and the anomaly types of each transmission link are determined based on the real-time log data reported by the multiple transmission links in response to the probe messages. By cross-matching the anomaly types of each transmission link, the abnormal transmission nodes in the virtual environment can be identified.

[0125] In this embodiment, when a transmission node failure is detected in the transmission link, the faulty transmission node is bypassed directly to ensure communication efficiency. The node failure is also reported to the platform to facilitate timely repair by maintenance personnel. Furthermore, when the transmission link experiences excessive load, the load of each transmission node in the transmission link is balanced by adding transmission nodes or adjusting the load of each transmission node in the transmission link to further ensure communication efficiency. Moreover, when a transmission link fails, the system switches to a backup transmission link or directly transmits from the source node to the target node without passing through the transmission link, ensuring the timeliness of network transmission.

[0126] Figure 19 This is a simplified flowchart illustrating the detection of a transmission link in an exemplary application environment. Figure 19In the application scenario shown, an IMCP (Internet Control Protocol) message is sent to the transmission link to be tested to detect any anomalies in the responses to ICMP messages on the transmission link, i.e., to check whether the ICMP latency and packet loss rate are normal. If the detection result indicates that there are ICMP message anomalies on the transmission link, an ARP message is broadcast on the transmission link, and the responses of the transmission nodes on the transmission link to the ARP message are monitored. If no response to the ARP message is received from the transmission nodes on the transmission link, it is determined that there is an anomaly in the transmission node on the transmission link. If a response to the ARP message is received from the transmission nodes on the transmission link, a BFD (Bidirectional Forwarding Detection) message is sent on the transmission link, and the responses of the transmission nodes on the transmission link to the BFD message are monitored. If no response data is received from the transmission nodes on the transmission link to the BFD message, it is determined that the transmission node on the transmission link is faulty. Considering the ICMP packet anomalies on the transmission link, it can be determined that the transmission link is faulty. Therefore, the flow table information corresponding to the switch on the transmission link is further obtained. Based on the traffic data of the transmission link recorded in the flow table information at multiple times, the traffic data at multiple times is input into a pre-trained traffic anomaly detection model. The traffic anomaly detection model detects whether the traffic data on the transmission link is abnormal. If the output result of the traffic anomaly detection model indicates that the traffic data at multiple times on the transmission link is greater than the predicted preset traffic limit, it can be determined that the fault of the transmission link is excessive load. Furthermore, if the output result of the traffic anomaly detection model indicates that the traffic data at multiple times on the transmission link is not greater than the predicted preset traffic limit, the uplink and downlink traffic information of the transmission link is further determined by the flow table information of the switch on the transmission link. The relationship between the actual number of traffic forwardings and the actual number of traffic forwardings that should be forwarded on the transmission link is determined by the uplink and downlink traffic information. If the actual number of traffic forwardings on the transmission link is less than the actual number of traffic forwardings that should be forwarded, the fault type of the transmission link can be determined as a transmission link fault (interruption).

[0127] Furthermore, in some feasible embodiments, if no abnormality is detected in the response to ICMP messages on the transmission link, a TCP (Transmission Protocol) message is further sent on the transmission link, and it is detected whether the packet loss rate of the transmission link during the TCP third handshake exceeds a preset packet loss rate. If the packet loss rate of the transmission link during the TCP third handshake exceeds the preset packet loss rate, the step of broadcasting ARP messages on the transmission link described above is executed. If the impact of ICMP messages on the transmission link is normal, and the response to TCP messages is also normal, a UDP (User Transport Protocol) message is sent on the transmission link, and the response of the transmission nodes in the transmission link to the UDP message is monitored. If the latency and packet loss rate of the transmission nodes in the transmission link for TCP messages are greater than a preset network quality parameter threshold, the step of obtaining the flow table information of the switch corresponding to the transmission link described above is executed to determine the specific abnormal subtype of the transmission link through the flow table information.

[0128] Furthermore, in some feasible embodiments, when a fault is detected in a transmission node in the transmission link, the faulty transmission node can be bypassed during network data transmission; if it is determined that the transmission link is faulty, the system can directly switch to a backup transmission link without faults, or control the source node to directly access the target node without going through the transmission link.

[0129] Figure 20 This is a block diagram illustrating a transmission link detection device according to an exemplary embodiment of this application. The device can be applied to... Figure 2 The device is shown in the implementation environment and is specifically configured in the control server 220. This device can also be applied to other exemplary implementation environments and specifically configured in other devices; this embodiment does not limit the implementation environment to which the device is applicable.

[0130] like Figure 20 As shown, the exemplary transmission link detection device includes: an acquisition module 2010, used to acquire log data of the transmission link for transmission protocol messages; wherein the log data is used to characterize the transmission status of transmission protocol messages in the transmission link; a sniffing message sending module 2020, used to send a sniffing message to the transmission node if an anomaly of the transmission protocol message is detected based on the log data, and to monitor the response of the transmission node to the sniffing message; and an anomaly determination module 2030, used to determine the anomaly type of the transmission link based on the response status and the traffic data of the transmission link; wherein the anomaly type includes transmission node anomaly or transmission link anomaly.

[0131] According to one aspect of the embodiments of this application, the sniffing message includes an address resolution message and a bidirectional forwarding detection message. The anomaly determination module 2030 further includes: a first node anomaly detection unit, configured to determine that the transmission link is anomaly if the response status indicates that the transmission node does not return a response message for the address resolution message; a second node anomaly detection unit, configured to determine that the transmission link is anomaly if the response status indicates that the transmission node returns a response message for the address resolution message but does not return a response message for the bidirectional forwarding detection message; and a transmission link anomaly subtype detection unit, configured to obtain the traffic data of the transmission link and determine the subtype of the transmission link anomaly based on the traffic data of the transmission link if the response status indicates that the transmission node returns a response message for both the address resolution message and the bidirectional forwarding detection message; wherein the subtype includes transmission link overload or transmission link failure.

[0132] According to one aspect of the embodiments of this application, the traffic data includes the actual traffic values ​​of the transmission link at multiple times, and the anomaly determination module 2030 further includes: an overload detection unit, used to determine that the transmission link is overloaded if the actual traffic values ​​at multiple times are detected to reach a preset traffic limit; and a link fault detection unit, used to determine that the transmission link is faulty if the actual traffic values ​​at multiple times are detected to be less than or equal to the preset traffic limit, and the actual traffic forwarding quantity of the transmission link is less than the actual traffic forwarding quantity that should be forwarded.

[0133] According to one aspect of the embodiments of this application, the above-mentioned transmission link detection device further includes: an input module, used to input the actual traffic values ​​at multiple times into a trained traffic anomaly detection model; wherein, the traffic anomaly detection model is trained based on the traffic throughput collected by the switch of the transmission link per unit time and combined with the time sequence structure; and a first detection module, used to detect the magnitude relationship between the actual traffic values ​​at multiple times and the preset traffic limit through the traffic anomaly detection model.

[0134] According to one aspect of the embodiments of this application, the above-mentioned transmission link detection device further includes: an uplink and downlink traffic acquisition module, used to acquire uplink and downlink traffic information of the transmission link if the actual traffic value at multiple times is detected to be less than or equal to a preset traffic limit; a second detection module, used to detect the relationship between the actual traffic forwarding count and the actual required traffic forwarding count of the transmission link based on the uplink and downlink traffic information; and a transmission link fault determination module, used to determine that the transmission link is a transmission link fault if the actual traffic forwarding count is detected to be less than the actual required traffic forwarding count.

[0135] According to one aspect of the embodiments of this application, the above-mentioned transmission link detection device further includes: a first detection result determination module, configured to obtain a detection result characterizing the transmission protocol message abnormality if the network quality parameter is detected to reach a preset network quality parameter limit; and a second detection result determination module, configured to obtain a detection result characterizing the transmission protocol message abnormality if the liveness duration is detected to be less than a preset liveness duration threshold.

[0136] According to one aspect of the embodiments of this application, the above-mentioned transmission link detection device further includes: a node bypass module, used to bypass the abnormal transmission node during message data transmission if the transmission link anomaly type is transmission node anomaly; a balancing module, used to adjust the load of the transmission nodes in the transmission link during message data transmission to balance the load of the transmission nodes in the transmission link if the transmission link anomaly type is transmission link overload; and a link switching module, used to switch to other transmission links during message data transmission if the transmission link anomaly type is transmission link anomaly, wherein the other transmission links are transmission links capable of normal network traffic transmission. It should be noted that the transmission link detection device provided in the above embodiments and the transmission link detection method provided in the above embodiments belong to the same concept, and the specific manner in which each module and unit performs its operation has been described in detail in the method embodiments, and will not be repeated here. In practical applications, the transmission link detection device provided in the above embodiments can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the device into different functional modules to complete all or part of the functions described above, and this is not a limitation.

[0137] Embodiments of this application also provide an electronic device, including: one or more processors; and a storage device for storing one or more programs, which, when executed by one or more processors, cause the electronic device to implement the transmission link detection method provided in the above embodiments.

[0138] Figure 21 A schematic diagram of a computer system suitable for implementing the embodiments of this application is shown. It should be noted that... Figure 21 The computer system 2100 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0139] like Figure 21As shown, the computer system 2100 includes a Central Processing Unit (CPU) 211101, which can perform various appropriate actions and processes, such as executing the methods described in the above embodiments, based on programs stored in Read-Only Memory (ROM) 2102 or programs loaded from Storage Section 2108 into Random Access Memory (RAM) 2103. Various programs and data required for system operation are also stored in RAM 2103. The CPU 211101, ROM 2102, and RAM 2103 are interconnected via bus 2104. An Input / Output (I / O) interface 2105 is also connected to bus 2104.

[0140] The following components are connected to I / O interface 2105: an input section 2106 including a keyboard, mouse, etc.; an output section 2107 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 2108 including a hard disk, etc.; and a communication section 2109 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 2109 performs communication processing via a network such as the Internet. A drive 2110 is also connected to I / O interface 2105 as needed. Removable media 2111, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 2110 as needed so that computer programs read from them can be installed into storage section 2108 as needed.

[0141] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 2109, and / or installed from removable medium 2111. When the computer program is executed by central processing unit (CPU) 2101, it performs various functions defined in the system of this application.

[0142] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.

[0143] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0144] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.

[0145] Another aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned method for detecting a transmission link. This computer-readable storage medium may be included in the electronic device described in the above embodiments, or it may exist independently and not incorporated into the electronic device.

[0146] Another aspect of this application provides a computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the transmission link detection method provided in the various embodiments described above.

[0147] The above description is merely a preferred exemplary embodiment of this application and is not intended to limit the implementation of this application. Those skilled in the art can easily make corresponding modifications or alterations based on the main concept and spirit of this application. Therefore, the scope of protection of this application should be determined by the scope of protection claimed in the claims.

Claims

1. A method for detecting a transmission link, characterized in that, The transmission link includes a transmission node, and the method is used in a virtualization scenario. The method includes: Obtain log data for the transmission protocol messages on the transmission link; wherein the log data is used to characterize the transmission status of the transmission protocol messages in the transmission link; If an anomaly is detected in the transmission protocol message based on the log data, a sniffing message is sent to the transmission node, and the response of the transmission node to the sniffing message is monitored. Based on the response status and the traffic data of the transmission link, the anomaly type of the transmission link is determined; wherein, the anomaly type includes an anomaly of the transmission node or an anomaly of the transmission link; The sniffing messages include address resolution messages and bidirectional forwarding detection messages; determining the anomaly type of the transmission link based on the response status and the traffic data includes: If the response indicates that the transmission node does not return a response message for the address resolution message, then it is determined that the transmission link is abnormal due to the transmission node. If the response indicates that the transmission node returns a response message for the address resolution message, but does not return a response message for the bidirectional forwarding detection message, then it is determined that the transmission link belongs to the transmission node anomaly. If the response status indicates that the transmission node returns a response message for the address resolution message and a response message for the bidirectional forwarding detection message, then the traffic data of the transmission link is obtained, and the subtype of the transmission link anomaly is determined based on the traffic data of the transmission link; wherein, the subtype includes the transmission link overload or the transmission link failure.

2. The method as described in claim 1, characterized in that, The traffic data includes the actual traffic values ​​of the transmission link at multiple times; The subtypes for detecting transmission link anomalies based on traffic data of the transmission link include: If the actual traffic value at the multiple times is detected to reach the preset traffic limit, then the transmission link is determined to be overloaded. If the actual traffic value at the multiple times is detected to be less than or equal to the preset traffic limit, and the actual traffic forwarding quantity of the transmission link is less than the actual traffic should be forwarded, then the transmission link is determined to be a transmission link fault.

3. The method as described in claim 2, characterized in that, The method further includes: The actual traffic values ​​at the multiple time points are input into the trained traffic anomaly detection model; wherein, the traffic anomaly detection model is trained based on the traffic throughput collected by the switch of the transmission link per unit time and the time sequence structure. The traffic anomaly detection model is used to detect the relationship between the actual traffic values ​​at multiple times and the preset traffic limit.

4. The method as described in claim 3, characterized in that, After detecting the relationship between the actual traffic values ​​at the multiple time points and the preset traffic limit using the traffic anomaly detection model, the method further includes: If the actual traffic value at the multiple times is detected to be less than or equal to the preset traffic limit, then the uplink and downlink traffic information of the transmission link is obtained; Based on the uplink and downlink traffic information, detect the relationship between the actual number of traffic forwardings and the actual number of traffic forwardings on the transmission link; If the actual number of traffic forwardings is less than the actual number of traffic forwardings that should be forwarded, then the transmission link is determined to be faulty.

5. The method as described in claim 1, characterized in that, The transport protocol message includes at least one of Internet Control Protocol (ICP) message and Transmission Control Protocol (TCP) message, and the log data includes at least one of network quality parameters and lifetime of the transport protocol message; after obtaining the log data of the transport link for the transport protocol message, the method further includes: If the network quality parameter is detected to reach the preset network quality parameter limit, a detection result is obtained to characterize the abnormality of the transmission protocol message. If the survival time is detected to be less than a preset survival time threshold, a detection result is obtained to characterize the abnormality of the transmission protocol message.

6. The method according to any one of claims 1 to 5, characterized in that, After determining the anomaly type of the transmission link based on the response status and the traffic data of the transmission link, the method further includes: If the anomaly type of the transmission link is a transmission node anomaly, then the transmission node with the anomaly is bypassed during message data transmission. If the anomaly type of the transmission link is transmission link overload, the load of the transmission nodes in the transmission link is adjusted during the message data transmission process to balance the load of the transmission nodes in the transmission link. If the transmission link is classified as an anomaly, the system will switch to another transmission link during message data transmission. This other transmission link is one that can transmit network traffic normally.

7. A detection device for a transmission link, characterized in that, The transmission link includes a transmission node, and the device is used for virtualizing the scene. The device includes: The acquisition module is used to acquire log data of the transmission protocol message in the transmission link; wherein the log data is used to characterize the transmission status of the transmission protocol message in the transmission link. The sniffing message sending module is used to send a sniffing message to the transmission node if an anomaly is detected in the transmission protocol message based on the log data, and to monitor the response of the transmission node to the sniffing message; the sniffing message includes an address resolution message and a bidirectional forwarding detection message; An anomaly determination module is used to determine the anomaly type of the transmission link based on the response status and the traffic data of the transmission link; wherein, the anomaly type includes an anomaly of the transmission node or an anomaly of the transmission link; The sniffing message sending module is further configured to determine that the transmission link is abnormal if the response status indicates that the transmission node has not returned a response message for the address resolution message; If the response indicates that the transmission node returns a response message for the address resolution message, but does not return a response message for the bidirectional forwarding detection message, then it is determined that the transmission link belongs to the transmission node anomaly. If the response status indicates that the transmission node returns a response message for the address resolution message and a response message for the bidirectional forwarding detection message, then the traffic data of the transmission link is obtained, and the subtype of the transmission link anomaly is determined based on the traffic data of the transmission link; wherein, the subtype includes the transmission link overload or the transmission link failure.

8. An electronic device, characterized in that, include: One or more processors; A storage device for storing one or more programs, which, when executed by one or more processors, cause the electronic device to implement the method for detecting a transmission link as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, It stores computer-readable instructions, which, when executed by the computer's processor, cause the computer to perform the transmission link detection method according to any one of claims 1 to 6.