Link monitoring method, apparatus, device, and storage medium
By injecting a monitoring program into the target host and statistically analyzing packet loss data based on kernel function calls, the problem of insufficient accuracy in link monitoring in existing technologies is solved, achieving higher monitoring accuracy and fault location precision.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
- Filing Date
- 2024-02-06
- Publication Date
- 2026-07-21
AI Technical Summary
In network link quality monitoring, existing technologies struggle to accurately pinpoint fault locations, especially when host-side restrictions or dropped response packets exist. Lost packet data can easily lead to errors, affecting the accuracy of link monitoring.
By injecting a first monitoring program into the target host, it can collect packet loss data based on kernel function calls and report the host-side packet loss data to the control device, so that the control device can eliminate the influence of the host side and ensure the accuracy of network packet loss data.
It improves the accuracy of link monitoring, ensures the accuracy of network packet loss data, and enables more precise location of network faults.
Smart Images

Figure CN117955875B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a link monitoring method, apparatus, device, and storage medium. Background Technology
[0002] During the process of monitoring the quality of network links, it is often difficult to determine the location of the fault on the network link, and it is necessary to locate the fault by checking network devices step by step.
[0003] The relevant technology employs an end-to-end latency statistics scheme for link monitoring, which involves deploying host proxies to enable mutual probing between host IPs (Internet Protocol). In the event of a network failure, IP tags can be used to identify the faulty area.
[0004] However, when there are restrictions or dropped response messages on the host side, packet loss data is prone to errors, making it difficult to guarantee the accuracy of link monitoring. Summary of the Invention
[0005] This application provides a link monitoring method, apparatus, device, and storage medium. The technical solution is as follows:
[0006] On one hand, embodiments of this application provide a link monitoring method, the method comprising:
[0007] Identify the link to be monitored, which is the link between the source host to be monitored and the destination host to be monitored;
[0008] A first program injection instruction is sent to the destination host agent of the destination host to be monitored in the link to be monitored. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the side of the destination host to be monitored based on the kernel function call situation.
[0009] Receive packet loss data from the target host agent on the host side;
[0010] The network packet loss data of the link to be monitored is determined based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0011] On the other hand, embodiments of this application provide a link monitoring method, the method comprising:
[0012] Receive the first program injection command sent by the control device through the destination host agent;
[0013] Based on the first program injection instruction, a first monitoring program is injected into the kernel through the target host agent. The first monitoring program is used to count packet loss data on the target host side to be monitored based on the kernel function call status.
[0014] The destination host agent reports host-side packet loss data to the control device, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0015] On the other hand, embodiments of this application provide a link monitoring device, the device comprising:
[0016] The link determination module is used to determine the link to be monitored, wherein the link to be monitored is the link between the source host to be monitored and the destination host to be monitored.
[0017] The sending module is used to send a first program injection instruction to the destination host agent of the destination host to be monitored in the link to be monitored. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the side of the destination host to be monitored based on the kernel function call situation.
[0018] The receiving module is used to receive packet loss data reported by the destination host agent on the host side;
[0019] The data determination module is used to determine the network packet loss data of the link to be monitored based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0020] On the other hand, embodiments of this application provide a link monitoring device, the device comprising:
[0021] The receiving module is used to receive the first program injection command sent by the control device through the destination host agent;
[0022] An injection module is used to inject a first monitoring program into the kernel through the target host agent based on the first program injection instruction. The first monitoring program is used to count packet loss data on the target host side to be monitored based on the kernel function call status.
[0023] The reporting module is used to report host-side packet loss data to the control device through the destination host proxy, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0024] On the other hand, embodiments of this application provide a computer device, which is a control device or a host. The computer device includes a processor and a memory. The memory stores at least one instruction, which is loaded and executed by the processor to implement the link monitoring method as described above.
[0025] On the other hand, embodiments of this application provide a computer-readable storage medium storing at least one instruction, which is loaded and executed by a processor to implement the link monitoring method as described above.
[0026] On the other hand, embodiments of this application provide a computer program product, the computer program product including computer instructions stored in a computer-readable storage medium; a processor of a terminal device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the terminal device to implement the link monitoring method as described above.
[0027] In this embodiment, the control device injects a first monitoring program into the target host to be monitored, enabling the target host to obtain host-side packet loss data based on the call status of its kernel functions and report the host-side packet loss data to the control device. This allows the control device to eliminate the influence of host-side packet loss data during link monitoring, ensuring the accuracy of network packet loss data on the monitored link and improving the accuracy of link monitoring. Attached Figure Description
[0028] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0029] Figure 1 This illustration shows a schematic diagram of an implementation environment provided by an exemplary embodiment of this application;
[0030] Figure 2 A flowchart of a link monitoring method provided in an exemplary embodiment of this application is shown;
[0031] Figure 3 A schematic diagram illustrating an implementation of the process for determining the link to be monitored provided in an exemplary embodiment of this application is shown.
[0032] Figure 4 A flowchart illustrating a control device side link monitoring process provided in an exemplary embodiment of this application is shown;
[0033] Figure 5 A flowchart illustrating the link monitoring process on the target host side provided in an exemplary embodiment of this application is shown.
[0034] Figure 6 A flowchart illustrating a link monitoring process provided in an exemplary embodiment of this application is shown;
[0035] Figure 7 A structural block diagram of a link monitoring device provided in an exemplary embodiment of this application is shown;
[0036] Figure 8 A structural block diagram of a link monitoring device provided in another exemplary embodiment of this application is shown;
[0037] Figure 9 A schematic diagram of the structure of a computer device provided in an exemplary embodiment of this application is shown. Detailed Implementation
[0038] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0039] Please refer to Figure 1 This illustration shows a schematic diagram of an implementation environment provided by an exemplary embodiment of this application. The implementation environment includes a control device 110, a source host 120 to be monitored, and a destination host 130 to be monitored.
[0040] The source host 120 and the destination host 130 to be monitored are connected via a monitoring link 140, as are the control device 110 and the host. The monitoring link 140 is a data link, which may include network devices such as network cards, bridges, routers, and switches, as well as network connection cables. It may also include communication programs and communication protocols, such as TCP / IP (Transmission Control Protocol / Internet Protocol) and UDP (User Datagram Protocol).
[0041] Control device 110 is used to control the source host 120 and the destination host 130 to perform link monitoring. It can be a workstation, personal computing device, etc., with network device control capabilities. Control device 110 controls the source host 120 to send probe data packets and receives response data packets sent by the destination host 130. Control device 110 is also used to send a first program injection instruction to the destination host 130 to inject a first monitoring program into the kernel of the destination host 130. Control device 110 is also used to receive host-side packet loss data sent by the destination host 130, and further obtain network packet loss data characterizing the network packet loss situation of the link 140 to be monitored. Control device 110 is also used to receive kernel stack data sent by the destination host 130 and then determine the cause of host-side packet loss. Control device 110 is also used to send a second program injection instruction to the destination host 130 and then receive detailed data from the destination host 130.
[0042] The source host 120 to be monitored is a server that sends probe data packets. The source host 120 to be monitored is used to send probe data packets to the destination host 130 to be monitored through the link 140 to be monitored, and is also used to receive response data packets returned by the destination host 130 to be monitored.
[0043] The target host 130 is a server that receives probe data packets. After receiving a probe data packet from the source host 120, the target host 130 sends a response data packet to the source host 120. In the event of packet loss on the host side, the source host 120 cannot receive the response data packet sent by the target host 130. The target host 130 is also used to receive a first program injection instruction from the control device 110, and then inject the first monitoring program into the kernel to collect host-side packet loss data and kernel stack data based on kernel function call patterns. The target host 130 is also used to report the host-side packet loss data and kernel stack data to the control device 110. Upon receiving a second program injection instruction, the target host 130 injects and executes a second monitoring program into the kernel to obtain detailed data corresponding to the cause of host-side packet loss, and then reports the detailed data to the control device 110.
[0044] It should be noted that the source host 120 and the destination host 130 to be monitored mainly achieve the above functions through their respective host agents.
[0045] The following embodiments illustrate the application of the link monitoring method to the control device 110 and the target host 130 to be monitored.
[0046] Please refer to Figure 2The diagram illustrates a flowchart of a link monitoring method provided in an exemplary embodiment of this application. The method includes the following steps.
[0047] Step 201: The control device determines the link to be monitored, which is the link between the source host to be monitored and the destination host to be monitored.
[0048] In some embodiments, the source host to be monitored sends probe data packets to the destination host to be monitored via the monitored link. Upon receiving the probe data packets, the destination host to be monitored sends a response data packet to the source host to be monitored via the monitored link. The control device analyzes the packet loss situation based on the transmission and response of data packets on the monitored link, thereby achieving link monitoring.
[0049] Optionally, the source host to be monitored can perform link monitoring on a single destination host or on at least two destination hosts. When monitoring a single destination host, the monitored link is the link between the source host and the destination host. When monitoring at least two destination hosts, the control device determines the monitored link to be a link where an abnormal probe flow (the probe flow is the data flow between the source host and the destination host) exists. The following describes networks with at least two destination hosts to be monitored.
[0050] In one possible implementation, the control device controls the source host to be monitored to send probe data packets to other hosts to be monitored in the network. Each destination host to be monitored, upon receiving a probe data packet, sends a response data packet to the source host. The source host then stores the probe results (i.e., the responses from the destination hosts) within a fixed time period in a probe record database for subsequent packet loss statistics. If an abnormal probe flow is detected, the control device determines that there may be a network fault in the link between the source host and the destination host. The control device obtains the destination IP address of the abnormal probe flow and identifies the link between the source host and the corresponding destination host as the link to be monitored.
[0051] Regarding the method for determining abnormal probe flows, in one possible implementation, the control device counts the number of probe data packets sent from the source host to the destination host and the number of response data packets received by the source host from the destination host based on the probe records stored in the probe record database. It then calculates the packet loss rate of the probe flow between the source and destination hosts (the ratio of the difference between the data packets sent and received by the source host to the data packets it sends). If the packet loss rate exceeds a packet loss rate threshold, the probe flow is determined to be an abnormal probe flow.
[0052] For example, such as Figure 3 As shown, the control device 310 controls the source host 320 to send probe data packets to the target hosts 321, 322, and 323, and then receives response data packets from them. The source host 320 reports the records of probe data packets sent to each target host and the records of response data packets received to each target host to the probe record database 330. Then, the control device 310 retrieves probe records from the probe record database 330 and calculates the packet loss rate of each probe flow on links 301, 302, and 303. If the packet loss rate of the probe flow on link 302 exceeds the packet loss rate threshold, the control device 310 determines link 302 as the link to be monitored.
[0053] Step 202: The control device sends a first program injection instruction to the destination host agent of the destination host to be monitored in the monitoring link. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the destination host side based on the kernel function call situation.
[0054] Step 203: The target host to be monitored receives the first program injection command sent by the control device through the target host agent.
[0055] Step 204: The target host to be monitored injects the first monitoring program into the kernel through the target host agent based on the first program injection instruction. The first monitoring program is used to count the packet loss data on the target host side based on the kernel function call status.
[0056] In some embodiments, all hosts on the network link have a host agent deployed. The host agent is used to realize communication and interaction between the source host to be monitored and the destination host to be monitored, as well as management and control between the control device and the host. The destination host agent is deployed on the destination host to be monitored in the monitoring link, and is used to parse the first program injection instruction and execute the program injection operation indicated by the first program injection instruction, that is, to inject the first monitoring program into the kernel of the destination host to be monitored.
[0057] In some embodiments, kernel functions are used to access the kernel and assist the host in sending and receiving data packets, as well as handling packet loss. The calling logic of kernel functions is pre-defined by the operating system, which makes function calls based on the services requested by the user program.
[0058] Since the kernel function calls differ depending on whether the target host responds normally or when packet loss occurs, the first monitoring program can statistically analyze packet loss data on the target host based on the kernel function call patterns.
[0059] Optionally, the first monitoring program can determine packet loss based on the name of the kernel function being called. For example, packet loss can be determined when the kfree_skb function is called.
[0060] Optionally, the first monitoring program can also count the number of calls to specific kernel functions to obtain packet loss data on the target host side. For example, the number of packet losses can be determined based on the number of calls to the kfree_skb function, and the number of packets without loss can be determined based on the number of calls to the consume_skb function.
[0061] Optionally, the packet loss data on the destination host side may include the total number of packets, the number of packets lost, the source host IP address, the destination host IP address, the kernel version number, and kernel function call information.
[0062] Step 205: The target host to be monitored reports host-side packet loss data to the control device through the target host agent, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the target host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0063] Step 206: The control device receives packet loss data from the destination host agent on the host side.
[0064] Step 207: The control device determines the network packet loss data of the link to be monitored based on the packet loss data on the host side, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0065] In some embodiments, the packet loss situation determined by the control device can be divided into host-side packet loss and network link packet loss. Therefore, the packet loss data counted by the control device can include host-side packet loss data and network packet loss data, wherein host-side packet loss data is the packet loss data generated by host-side packet loss, and network packet loss data is the packet loss data generated by network link packet loss.
[0066] In one possible implementation, the control device isolates the destination host with host-side packet loss based on the host-side packet loss data, excludes the host-side packet loss data generated by the destination host from all packet loss data on the link to be monitored as counted by the control device, and obtains the network packet loss data of the link to be monitored.
[0067] Optionally, network packet loss data may include the number of network packet losses, network packet loss rate, cause of network packet loss, and packet loss address.
[0068] Optionally, network packet loss data can be used to record and alarm on network packet loss situations. For example, control devices can generate alarm information based on network packet loss data, so that control devices can isolate faulty devices or implement repair measures based on the alarm information.
[0069] Optionally, network packet loss data can also be used to determine the network quality of a data center. For example, if the network packet loss rate is higher than the network packet loss rate threshold, it can be determined that the data center network quality is poor.
[0070] Optionally, network packet loss data can also be used to identify network fault areas. For example, control equipment can determine the network quality on each monitored link based on network packet loss data from multiple monitored links, and then analyze whether the network devices on each monitored link are faulty based on the network quality when the network devices are operating on each monitored link.
[0071] In summary, in this embodiment of the application, the control device injects a first monitoring program into the target host to be monitored, enabling the target host to obtain host-side packet loss data based on the call status of its kernel functions, and report the host-side packet loss data to the control device. This allows the control device to eliminate the influence of host-side packet loss data during link monitoring, ensuring the accuracy of network packet loss data on the monitored link and improving the accuracy of link monitoring.
[0072] In the above embodiments, the steps executed by the control device can be implemented separately as a link monitoring method on the control device side, and the steps executed by the target host to be monitored can be implemented separately as a link monitoring method on the target host side. The link monitoring process on the control device side will be described below.
[0073] Please refer to Figure 4 The diagram illustrates a flowchart of a control device sidelink monitoring process provided in an exemplary embodiment of this application. The process includes the following steps.
[0074] Step 401: Determine the link to be monitored. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored.
[0075] The implementation method of this step can be referred to step 201, and will not be described in detail here.
[0076] Step 402: Send a first program injection instruction to the destination host agent of the destination host to be monitored in the monitoring link. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the destination host side based on the kernel function call situation.
[0077] Optionally, the first monitoring program can be generated by the target host or by the control device. When injecting the program, the control device can adopt one of the following two implementation processes.
[0078] The first type, the first monitoring program is generated by the control equipment.
[0079] The implementation process may include the following sub-steps.
[0080] Sub-step 1: Based on the target kernel function and the host IP address of the source host to be monitored, generate the first monitoring program. The first monitoring program is used to count the number of times the target kernel function is called to handle packet loss when data packets sent by the source host to be monitored are lost.
[0081] In some embodiments, when the first monitoring program calls the target kernel function and the source IP address of the probe stream is the host IP address of the source host to be monitored, it counts the number of times the target kernel function is called to perform packet loss processing on the data packets sent by the source host to be monitored.
[0082] Regarding the generation method of the first monitoring program, in one possible implementation, the control device fills the target kernel function and the host IP address of the source host to be monitored into the program template to generate the first monitoring program.
[0083] In some embodiments, the target kernel function is the kernel function called in the kernel protocol stack for packet loss handling. During the sending and receiving of data packets, the kernel uses the skb(struct sk_buff) data structure for packet management. Specifically, the kernel calls the kfree_skb function to discard packets in case of errors and calls the consume_skb function to release the skb data structure normally.
[0084] Optionally, the target kernel function can be the kfree_skb function. The first monitoring program is used to count the number of times the kfree_skb function is called and packet loss processing is performed on packets sent by the source host to be monitored, when the source IP address of the probe stream is the host IP address of the source host to be monitored.
[0085] Sub-step 2: The control device sends a first program injection instruction containing the first monitoring program to the target host agent.
[0086] In one possible implementation, after generating a first monitoring program, the control device incorporates the first monitoring program into a first program injection instruction, and then sends the first program injection instruction to the target host agent of the target host to be monitored. Upon receiving the first program injection instruction, the target host agent extracts the first monitoring program from the first program injection instruction and then injects the first monitoring program into the kernel.
[0087] The second type involves the first monitoring program being generated by the target host.
[0088] Optionally, the control device may send a first program injection instruction containing target parameters to the destination host agent, which is used by the destination host agent to generate a first monitoring program based on the target parameters.
[0089] In one possible implementation, after receiving a first program injection instruction from the control device, the target host agent extracts the target parameters from the first program injection instruction. Subsequently, the target host to be monitored fills the target parameters into the program template to obtain the first monitoring program.
[0090] Furthermore, the target parameters may include the target kernel function and the host IP address of the source host to be monitored. The control device sends a first program injection instruction containing the target kernel function and the host IP address of the source host to be monitored to the destination host agent, wherein the destination host agent is used to generate a first monitoring program based on the target kernel function and the host IP address.
[0091] In one possible implementation, after receiving the first program injection instruction sent by the control device, the target host agent extracts the target kernel function and the host IP address of the source host to be monitored from the first program injection instruction, and fills them into the program template to obtain the first monitoring program.
[0092] In some embodiments, the first monitoring program is a program capable of tracing kernel function calls. Optionally, the first monitoring program can utilize debugging tools built into the operating system kernel to trace kernel function calls, such as the ftrace tool in the Linux kernel. Optionally, the first monitoring program can also achieve kernel function tracing by extending kernel functionality, such as using eBPF (extended Berkeley Packet Filter) technology to write the first monitoring program, thereby tracing kernel functions called by the Linux kernel. Optionally, the first monitoring program can also be a custom program, which will not be elaborated in this embodiment.
[0093] In some embodiments, since different hosts have different kernel versions, the first monitoring program needs to be adapted to the kernel environment to avoid disturbing the kernel. Furthermore, injecting a program into the kernel has a high technical threshold, requiring technicians to have a deep understanding of the kernel. To improve the convenience and security of injecting the first monitoring program into the kernel, this embodiment uses the eBPF program as the kernel of the target host into which the first monitoring program is injected.
[0094] In some embodiments, eBPF programs can both extend kernel functionality to enable kernel function tracing and withdraw from the kernel to maintain kernel stability. Compared to other techniques that inject programs into the kernel for kernel function tracing, eBPF programs offer higher security. eBPF programs can also be written in C, making development relatively easy.
[0095] In one possible implementation, the eBPF program stores the collected packet loss data in kernel space as an eBPF map structure. The destination host agent outside the kernel accesses the eBPF map to obtain the packet loss data statistically analyzed by the eBPF program.
[0096] Step 403: Receive packet loss data reported by the destination host agent on the host side.
[0097] Step 404: Determine the network packet loss data of the link to be monitored based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0098] This step may include the following steps.
[0099] Step 1: Obtain the link packet loss data reported by the source host to be monitored during the operation of the first monitoring program.
[0100] In some embodiments, during the execution of the first monitoring program, the target host on each link uses the first monitoring program injected into the kernel to collect host-side packet loss data, and the source host to be monitored collects link packet loss data based on the response status of the target host on each link. Here, link packet loss data refers to the packet loss data across all links on which the source host to be monitored resides.
[0101] In one possible implementation, the control device collects packet loss data reported by the source host to be monitored from the statistical detection record database to obtain link packet loss data.
[0102] Step 2: Correct the link packet loss data based on the host-side packet loss data to obtain the network packet loss data.
[0103] In some embodiments, the link packet loss data reported by the source host to be monitored includes packet loss data caused by host-side packet loss and packet loss data caused by link-side packet loss. Since the packet loss data caused by host-side packet loss counted by the source host to be monitored corresponds to the host-side packet loss data counted by the destination host to be monitored, the control device can identify the packet loss data caused by host-side packet loss from the link packet loss data based on the host-side packet loss data.
[0104] In one possible implementation, the control device acquires the link packet loss data reported by the source host to be monitored within a fixed monitoring period, and acquires the host-side packet loss data reported by the destination host to be monitored within the same time period. Then, based on the host-side packet loss data, it removes the packet loss data caused by the host-side packet loss from the link packet loss data to obtain the network packet loss data.
[0105] In this embodiment, the control device sends a first program injection instruction to the target host to be monitored. After receiving packet loss data from the host side, it excludes packet loss caused by host-side packet loss on the link and obtains network packet loss data characterizing the network packet loss situation of the link to be monitored. This improves the accuracy of packet loss data on the end-to-end link to be monitored, thereby improving the accuracy of the control device in alarming the link packet loss situation.
[0106] In some embodiments, the first monitoring program statistically analyzes packet loss data within the monitoring duration. To reduce the impact of the first monitoring program on the kernel and maintain kernel stability, the first monitoring program is rolled back when the monitoring duration is reached, i.e., the injection into the first monitoring program is revoked.
[0107] Optionally, the first monitoring program can be reverted via a command sent by the control device. When the program injection duration of the first monitoring program reaches the monitoring duration, the control device sends a revert command to the destination host agent, which then performs the program injection revert based on the revert command.
[0108] Optionally, the first monitoring program can also be rolled back by the destination host agent of the target host to be monitored. That is, the control device includes the monitoring duration in the first program injection instruction and sends it to the destination host agent. The destination host agent is used to roll back the program injection when the program injection duration of the first monitoring program reaches the monitoring duration.
[0109] Furthermore, if the first monitoring program is an eBPF program, and the target host agent performs program injection rollback, the target host to be monitored releases the eBPF map in the kernel space.
[0110] The solution provided in the above embodiments avoids the first monitoring program from affecting the kernel and maintains kernel stability by rolling back the first monitoring program.
[0111] Optionally, in addition to counting packet loss data, the first monitoring program can also record kernel stack data. The control device can determine the cause of packet loss on the host side based on the kernel stack data.
[0112] In some embodiments, kernel stack data may include the kernel functions called by the kernel and the offsets of each kernel function. For example, the following is the kernel stack data printed by the first monitoring program:
[0113] kfree_skb+1
[0114] dev_hard_start_xmit+262
[0115] sch_direct_xmit+282
[0116] __dev_queue_xmit+1169
[0117] dev_queue_xmit+16
[0118] neigh_resolve_output+285
[0119] ip_finish_output+636
[0120] ip_output+115
[0121] ip_local_out_sk+55
[0122] ip_send_skb+22
[0123] ip_push_pending_frames+51
[0124] icmp_push_reply+238
[0125] icmp_send+1280
[0126] __udp4_lib_rcv+2582
[0127] udp_rcv+26
[0128] ip_local_deliver_finish+189
[0129] ip_local_deliver+89
[0130] ip_rcv_finish+144
[0131] ip_rcv+697
[0132] __netif_receive_skb_core+1833
[0133] __netif_receive_skb+24
[0134] netif_receive_skb_internal+64
[0135] napi_gro_receive+216
[0136] i40e_clean_rx_irq+974
[0137] i40e_napi_poll+830
[0138] net_rx_action+623
[0139] __do_softirq+245
[0140] call_softirq+28
[0141] do_softirq+101
[0142] irq_exit+261
[0143] __irqentry_text_start+86
[0144] ret_from_intr+0
[0145] cpuidle_idle_call+222
[0146] arch_cpu_idle+14
[0147] cpu_startup_entry+330
[0148] start_secondary+503
[0149] start_cpu+5
[0150] The process by which the control equipment determines the cause of packet loss on the host side includes the following steps.
[0151] Step 1: Receive kernel stack data reported by the destination host agent.
[0152] Optionally, kernel stack data can be reported to the control device along with host-side packet loss data when the target host reports host-side packet loss data, so that the control device can determine the cause of packet loss corresponding to the host-side packet loss data.
[0153] In one possible implementation, if the first monitoring program is an eBPF program, the eBPF program in the kernel records packet loss data and kernel stack data. Subsequently, the destination host agent stores the packet loss data and kernel stack data according to the eBPF map structure and reports it to the controller.
[0154] Optionally, kernel stack data can also be reported additionally if the control device needs to determine the cause of packet loss on the host side.
[0155] Step 2: Determine the cause of packet loss on the host side of the target host to be monitored based on kernel stack data.
[0156] Optionally, the control device can input kernel stack data into the packet loss analysis model to obtain the host-side packet loss cause output by the model. The packet loss analysis model is trained based on sample kernel stack data and the corresponding packet loss cause labels.
[0157] Optionally, the control device can also establish a packet loss cause knowledge base, and analyze the cause of packet loss on the host side by querying the packet loss cause knowledge base, thereby improving the efficiency of determining the cause of packet loss on the host side.
[0158] Optionally, when the cause of packet loss on the host side is difficult to determine, the control device can print kernel stack data, which can then be manually analyzed by network experts to determine the cause of the host-side packet loss. Furthermore, the control device can use this host-side packet loss cause to supplement its packet loss cause knowledge base, or to train a packet loss analysis model, thereby improving the accuracy of the control device in determining the cause of host-side packet loss.
[0159] In some embodiments, the control device may further analyze the cause of packet loss on the host side, including the following steps.
[0160] The first step is to send a second program injection instruction to the target host agent. The target host agent injects a second monitoring program into the kernel of the target host according to the second program injection instruction. The second monitoring program is used to collect detailed data corresponding to the causes of packet loss on the host side based on kernel function call patterns.
[0161] In some embodiments, the detailed data corresponding to the cause of packet loss on the host side can characterize the detailed information of the cause of packet loss on the host side. Since the detailed data corresponding to different causes of packet loss on the host side may be different, the specific content of the detailed data needs to be determined according to the specific cause of packet loss on the host side.
[0162] It should be noted that detailed data corresponding to the cause of packet loss on the host side may or may not exist. For example, under ICMP (Internet Control Message Protocol) acknowledgment rate limiting, the detailed data may be the rate limiting threshold, while if the destination host is configured not to send acknowledgment packets, there will be no detailed data for the cause of packet loss on the host side.
[0163] Optionally, the second program injection instruction may include target parameters so that the destination host agent can generate a second monitoring program based on the target parameters. The second program injection instruction may also include a second monitoring program generated by a control device.
[0164] In some embodiments, the second monitoring program statistically analyzes packet loss data within the monitoring duration. To reduce the impact of the second monitoring program on the kernel and maintain kernel stability, the second monitoring program is rolled back when the monitoring duration is reached, i.e., the injection of the second monitoring program is revoked.
[0165] Optionally, the second monitoring program can be reverted via instructions sent by the control device. When the program injection duration of the second monitoring program reaches the monitoring duration, the control device sends a revert instruction to the destination host agent, which then performs the program injection revert based on the revert instruction.
[0166] Optionally, the second monitoring program can also be rolled back by the target host agent of the target host to be monitored. That is, the control device includes the monitoring duration in the second program injection command and sends it to the target host agent. The target host agent is used to roll back the program injection when the program injection duration of the second monitoring program reaches the monitoring duration.
[0167] In some embodiments, the kernel function monitored by the second monitoring program differs from that monitored by the first monitoring program. The target kernel function monitored by the first monitoring program can determine that packet loss exists on the host side, and thus statistically analyzes the host-side packet loss data based on the number of times the target kernel function is called. The kernel function monitored by the second monitoring program, however, is related to the cause of packet loss on the host side, and this kernel function may not be usable to determine whether the destination host is experiencing packet loss. By monitoring the calls to this kernel function, the second monitoring program statistically analyzes the detailed data corresponding to the cause of packet loss on the host side, thereby enabling further analysis of the cause of packet loss on the host side.
[0168] For example, the kernel function monitored by the first monitoring program can be the kfree_skb function, which represents packet loss on the host side due to an error in the destination host; the kernel function monitored by the second monitoring program can include the icmp_send function, which is used to determine whether there is ICMP response rate limiting on the host side.
[0169] The second step is to receive detailed data on the reasons for packet loss on the host side reported by the destination host agent.
[0170] In some embodiments, after receiving the segmented data, the control device can further analyze the cause of packet loss on the host side based on the segmented data, thereby improving the accuracy of the control device in locating the cause of packet loss on the host side.
[0171] In this embodiment, the control device determines the cause of packet loss on the host side based on the kernel stack data recorded by the first monitoring program. Furthermore, the control device utilizes detailed data collected by the second monitoring program to further analyze the cause of packet loss on the host side, improving the accuracy of locating the cause of packet loss on the host side and reducing the difficulty for the control device to determine the cause of packet loss in the monitored link.
[0172] Please refer to Figure 5 This document illustrates a flowchart of a target host-side link monitoring process provided in an exemplary embodiment of this application. The process includes the following steps.
[0173] Step 501: Receive the first program injection instruction sent by the control device through the destination host agent.
[0174] Step 502: Based on the first program injection instruction, inject the first monitoring program into the kernel through the target host agent. The first monitoring program is used to collect packet loss data on the target host side based on the kernel function call status.
[0175] For an explanation of the target host proxy and the first program injection instruction, please refer to steps 203 to 204 above. This application embodiment will not elaborate on these points.
[0176] Optionally, the first program injection instruction may include target parameters, so that the target host agent can generate a first monitoring program based on the target parameters. The injection process of the first monitoring program may include the following steps.
[0177] First, based on the target parameters contained in the first program injection instruction, a first monitoring program is generated through the target host agent.
[0178] In one possible implementation, after receiving the first program injection instruction sent by the control device, the target host agent of the target host to be monitored extracts the target parameters from the first program injection instruction and fills the target parameters into the program template to obtain the first monitoring program.
[0179] Second, inject the first monitoring program into the kernel through the destination host agent.
[0180] Because eBPF technology has high security, can perform secure extensions to the kernel, and can maintain kernel stability through rollback procedures, in some possible implementations, the first monitoring program is an eBPF program, and the target host to be monitored uses eBPF technology to inject the first monitoring program into the kernel.
[0181] Optionally, the first program injection instruction may also include a first monitoring program, which is generated by the control device.
[0182] In some embodiments, the target parameters include the target kernel function and the host IP address of the source host to be monitored. The target kernel function is the kernel function called in the kernel protocol stack during packet loss. The injection process of the first monitoring program may include the following sub-steps.
[0183] 1. Based on the target kernel function and the host IP address of the source host to be monitored, a first monitoring program is generated through the destination host proxy. The first monitoring program is used to count the number of times the target kernel function is called to handle packet loss when sending data packets to the source host to be monitored.
[0184] In some embodiments, when the first monitoring program calls the target kernel function and the source IP address of the probe stream is the host IP address of the source host to be monitored, it counts the number of times the target kernel function is called to perform packet loss processing on the data packets sent by the source host to be monitored.
[0185] Regarding the generation method of the first monitoring program, in one possible implementation, the target host agent fills the target kernel function and the host IP address of the source host to be monitored into the program template to generate the first monitoring program.
[0186] In some embodiments, the kernel uses the skb(struct sk_buff) data structure for packet management during the sending and receiving of data packets. Specifically, the kernel calls the kfree_skb function to discard packets in case of errors.
[0187] Optionally, the target kernel function can be the kfree_skb function. The first monitoring program is used to count the number of times the kfree_skb function is called and packet loss processing is performed on packets sent by the source host to be monitored, when the source IP address of the probe stream is the host IP address of the source host to be monitored.
[0188] 2. Inject the first monitoring program contained in the first program injection instruction into the kernel through the destination host agent.
[0189] Because eBPF technology has high security, in some possible implementations, the first monitoring program is an eBPF program, and the destination host agent uses eBPF technology to inject the first monitoring program contained in the first program injection instruction into the kernel.
[0190] Step 503: The host-side packet loss data is reported to the control device through the destination host agent so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0191] For an explanation of network packet loss data and host-side packet loss data, please refer to steps 205 to 207 above. This application embodiment will not repeat these details.
[0192] In this embodiment, after the target host agent injects the first monitoring program into the kernel, the target host to be monitored counts the packet loss data on the host side based on the kernel function calls made in the kernel protocol stack for packet loss, and then reports the host-side packet loss data to the control device. This allows the control device to eliminate the influence of host-side packet loss data during link monitoring, ensuring the accuracy of network packet loss data on the monitored link and improving the accuracy of link monitoring.
[0193] Optionally, the first program injection instruction may include a monitoring duration. After the first monitoring program is injected into the kernel, if the program injection duration of the first monitoring program reaches the monitoring duration, the target host to be monitored will perform program injection rollback through the target host proxy.
[0194] Optionally, the target host to be monitored can also receive a rollback command sent by the control device through a target host agent. The rollback command is sent when the program injection duration of the first monitoring program reaches the monitoring duration. Subsequently, the target host to be monitored performs program injection rollback through the target host agent based on the rollback command.
[0195] In some embodiments, the first monitoring program is further configured to record kernel stack data. The target host to be monitored reports kernel stack data to the control device through a target host agent, so that the control device can determine the cause of packet loss on the host side of the target host based on the kernel stack data.
[0196] Optionally, kernel stack data can be reported to the control device along with host-side packet loss data when the target host reports host-side packet loss data, so that the control device can determine the cause of packet loss corresponding to the host-side packet loss data.
[0197] Optionally, kernel stack data can also be reported additionally if the control device needs to determine the cause of packet loss on the host side.
[0198] In some embodiments, the control device, based on the cause of packet loss on the host side, and if further location of the cause of packet loss on the host side is determined, sends a second program injection command to the target host to be monitored. Upon receiving the second program injection command, the target host to be monitored can perform the following steps.
[0199] Step 1: Receive the second program injection command sent by the control device through the destination host agent.
[0200] Optionally, the second program injection instruction may include target parameters so that the destination host agent can generate a second monitoring program based on the target parameters. The second program injection instruction may also include a second monitoring program generated by a control device.
[0201] Step 2: Based on the second program injection instruction, the second monitoring program is injected into the kernel through the target host agent. The second monitoring program is used to collect detailed data on the causes of packet loss on the host side based on the kernel function call situation.
[0202] In some embodiments, the second monitoring program statistically analyzes packet loss data within the monitoring duration. To reduce the impact of the second monitoring program on the kernel and maintain kernel stability, the second monitoring program is rolled back when the monitoring duration is reached, i.e., the injection of the second monitoring program is revoked.
[0203] Optionally, the second monitoring program can be reverted via instructions sent by the control device. When the program injection duration of the second monitoring program reaches the monitoring duration, the control device sends a revert instruction to the destination host agent, which then performs program injection revert based on the revert instruction.
[0204] Optionally, the second monitoring program can also be rolled back by the target host agent of the target host to be monitored. That is, the control device includes the monitoring duration in the second program injection command and sends it to the target host agent. The target host agent is used to roll back the program injection when the program injection duration of the second monitoring program reaches the monitoring duration.
[0205] In some embodiments, the kernel function monitored by the second monitoring program differs from that monitored by the first monitoring program. The target kernel function monitored by the first monitoring program can determine that packet loss exists on the host side, and thus statistically analyzes the host-side packet loss data based on the number of times the target kernel function is called. The kernel function monitored by the second monitoring program, however, is related to the cause of packet loss on the host side, and this kernel function may not be usable to determine whether the destination host is experiencing packet loss. By monitoring the calls to this kernel function, the second monitoring program statistically analyzes the detailed data corresponding to the cause of packet loss on the host side, thereby enabling further analysis of the cause of packet loss on the host side.
[0206] Step 3: Report detailed data corresponding to the cause of packet loss on the host side to the control device through the destination host agent.
[0207] In some embodiments, after receiving the segmented data, the control device can further analyze the cause of packet loss on the host side based on the segmented data, thereby improving the accuracy of the control device in locating the cause of packet loss on the host side.
[0208] In this embodiment, the target host to be monitored determines the cause of packet loss on the host side based on the kernel stack data recorded by the first monitoring program. Furthermore, the target host to be monitored reports the detailed data collected by the second monitoring program to the control device, so that the control device can use the detailed data to further analyze the cause of packet loss on the host side, improving the accuracy of locating the cause of packet loss on the host side and reducing the difficulty for the control device to determine the cause of packet loss in the monitored link.
[0209] Please refer to Figure 6 The diagram illustrates a flowchart of a link monitoring process provided in an exemplary embodiment of this application. The process includes the following steps.
[0210] Step 601: The control device sends a first program injection command to the target host to be monitored based on the IP address of the target host of the abnormal detection stream.
[0211] In some embodiments, when the control device detects an abnormal probe stream, the control device first determines the IP address of the destination host of the abnormal probe stream, and then determines the target host to be monitored based on the destination host IP address. The abnormal probe stream is a probe stream sent from the source host to the target host with a packet loss rate exceeding a threshold. After determining the target host to be monitored, the control device sends a first program injection instruction to the target host to inject a first monitoring program into the kernel of the target host.
[0212] Step 602: The target host proxy receiver of the target host to be monitored receives the injection instruction.
[0213] The program injection instructions include the first program injection instruction and the second program injection instruction.
[0214] Specifically, the first program injection instruction is used to inject a first monitoring program into the target host kernel. This first monitoring program is used to collect data on packet loss and kernel stack data on the host side. The first monitoring program is an eBPF program.
[0215] The second program injection instruction is used to inject a second monitoring program into the target host kernel. This second monitoring program is used to collect detailed data corresponding to the causes of packet loss on the host side. The second monitoring program is an eBPF program.
[0216] Step 603: The destination host agent injects the eBPF program into the kernel.
[0217] In some embodiments, the kernel is a component of the operating system, used to manage operating system processes, memory, device drivers, etc. It should be noted that, because the Linux operating system kernel technology is mature, stable, and open-source, this application uses the Linux operating system kernel as an example for illustration.
[0218] Upon receiving the first program injection instruction, the target host agent injects an eBPF program, namely the first monitoring program, into the Linux kernel to collect statistics on host-side packet loss data and kernel stack data.
[0219] Upon receiving the second program injection instruction, the target host agent injects an eBPF program, i.e., the second monitoring program, into the Linux kernel to collect detailed data on the causes of packet loss on the host side.
[0220] Step 604: The target host to be monitored determines whether the kfree_skb function is called in the Linux kernel protocol stack, and whether the source IP address of the probe stream is the host IP address of the source host to be monitored.
[0221] If the kfree_skb function is called and the source IP address of the probe stream is the host IP address of the source host to be monitored, proceed to step 605; otherwise, proceed to step 606.
[0222] Step 605: When the kfree_skb function is called and the source IP address of the probe stream is the host IP address of the source host to be monitored, the target host to be monitored performs data statistics.
[0223] Specifically, when the target host agent injects the first monitoring program into the kernel, the target host to be monitored will collect data on packet loss on the host side and kernel stack data; when the target host agent injects the second monitoring program into the kernel, the target host to be monitored will collect detailed data corresponding to the reasons for packet loss on the host side.
[0224] Step 606: No data statistics are performed on the target host to be monitored.
[0225] Step 607: The target host to be monitored updates the eBPF map based on statistical data.
[0226] Once host-side packet loss data and kernel stack data are obtained, the target host to be monitored stores the host-side packet loss data and kernel stack data into the kernel space using an eBPF map structure.
[0227] Once the statistical data is detailed, the target host to be monitored stores the detailed data in the kernel space as an eBPF map structure.
[0228] Step 608: The target host to be monitored reports the statistical data to the control device through the target host agent.
[0229] Step 609: Control the device to save statistical data.
[0230] Step 610: The target host to be monitored rolls back the eBPF program through the target host agent.
[0231] In some embodiments, when the eBPF program's runtime reaches the monitoring duration, the control device controls the destination host agent to roll back the eBPF program. Optionally, the control device may send a rollback command to the destination host agent, instructing the destination host agent to roll back the eBPF program.
[0232] Optionally, the control device can also include the monitoring duration in the program injection command. After receiving the program injection command, the destination host agent extracts the monitoring duration from the program injection command, and then rolls back the eBPF program when the running time of the eBPF program reaches the monitoring duration.
[0233] In addition, when rolling back the eBPF program, step 607 must be executed to update the eBPF map structure, that is, to release the eBPF map in the kernel space.
[0234] Step 611: The control device analyzes the cause of packet loss on the host side.
[0235] Optionally, the control device can input kernel stack data into the packet loss analysis model to obtain the host-side packet loss cause output by the model. The packet loss analysis model is trained based on sample kernel stack data and the corresponding packet loss cause labels.
[0236] Optionally, if the cause of packet loss on the host side is difficult to determine, the control device can also print kernel stack data, which can then be manually analyzed by network experts to determine the cause of packet loss on the host side. This cause of packet loss can be used to supplement the packet loss cause knowledge base, or to train a packet loss analysis model to improve the accuracy of the control device in determining the cause of packet loss on the host side.
[0237] Step 612: After obtaining the reason for packet loss on the host side, the control device establishes a knowledge base for the reason for packet loss.
[0238] In some embodiments, the packet loss cause knowledge base is used to assist the control device in querying the cause of packet loss on the host side based on kernel stack data, thereby improving the speed of determining the cause of packet loss on the host side.
[0239] Step 613: The control device controls the target host agent to perform secondary program injection.
[0240] Optionally, once the cause of packet loss on the host side is known, the control device can further analyze the cause of packet loss on the host side through secondary program injection to improve the accuracy of the cause of packet loss on the host side.
[0241] In some embodiments, when it is determined that a second program injection is to be performed, the control device sends a second program injection instruction to the target host agent, and then repeats steps 602 to 612. The embodiments of this application will not be described in detail here.
[0242] See Figure 7 The diagram illustrates a structural block diagram of a link monitoring device provided in an exemplary embodiment of this application. The device includes the following modules.
[0243] Link determination module 701 is used to determine the link to be monitored, wherein the link to be monitored is the link between the source host to be monitored and the destination host to be monitored.
[0244] The sending module 702 is used to send a first program injection instruction to the destination host agent of the destination host to be monitored in the link to be monitored. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the side of the destination host to be monitored based on the kernel function call situation.
[0245] The receiving module 703 is used to receive packet loss data on the host side reported by the destination host agent;
[0246] The data determination module 704 is used to determine the network packet loss data of the link to be monitored based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0247] Optionally, the sending module 702 is further configured to:
[0248] Send the first program injection instruction containing the first monitoring program to the target host agent;
[0249] or,
[0250] The first program injection instruction containing target parameters is sent to the target host agent, which is used to generate the first monitoring program based on the target parameters.
[0251] Optionally, the sending module 702 is further configured to:
[0252] Based on the target kernel function and the host IP address of the source host to be monitored, the first monitoring program is generated. The first monitoring program is used to count the number of times the target kernel function is called to process the packet loss of the data packets sent by the source host to be monitored.
[0253] Sending the first program injection instruction containing target parameters to the target host agent includes:
[0254] The first program injection instruction containing the target kernel function and the host IP address of the source host to be monitored is sent to the target host agent, and the target host agent is used to generate the first monitoring program based on the target kernel function and the host IP address;
[0255] The target kernel function is the kernel function called in the kernel protocol stack during packet loss.
[0256] Optionally, the first monitoring program is an eBPF program, and the target kernel function is the kfree_skb function.
[0257] Optionally, the device further includes a retraction module for:
[0258] When the program injection duration of the first monitoring program reaches the monitoring duration, a rollback command is sent to the target host agent, and the target host agent is used to roll back the program injection based on the rollback command.
[0259] Optionally, the first program injection instruction includes a monitoring duration, and the destination host agent is used to perform program injection rollback when the program injection duration of the first monitoring program reaches the monitoring duration.
[0260] Optionally, the first monitoring program is also used to record kernel stack data;
[0261] The device further includes a cause determination module, used for:
[0262] Receive the kernel stack data reported by the destination host agent;
[0263] The cause of packet loss on the host side of the target host to be monitored is determined based on the kernel stack data.
[0264] Optionally, the cause determination module is further configured to:
[0265] The kernel stack data is input into the packet loss analysis model to obtain the packet loss cause on the host side output by the packet loss analysis model. The packet loss analysis model is trained based on sample kernel stack data and the packet loss cause label corresponding to the sample kernel stack data.
[0266] Optionally, the cause determination module is further configured to:
[0267] A second program injection instruction is sent to the target host agent, which is used to inject a second monitoring program into the kernel of the target host to be monitored according to the second program injection instruction. The second monitoring program is used to collect detailed data corresponding to the cause of packet loss on the host side based on the kernel function call situation.
[0268] Receive detailed data corresponding to the cause of packet loss on the host side reported by the destination host agent.
[0269] Optionally, the data determination module 704 is further configured to:
[0270] Obtain the link packet loss data reported by the source host to be monitored during the operation of the first monitoring program;
[0271] The link packet loss data is corrected based on the host-side packet loss data to obtain the network packet loss data.
[0272] See Figure 8 This illustration shows a structural block diagram of a link monitoring device provided in another exemplary embodiment of this application. The device includes the following modules.
[0273] Receiver module 801 is used to receive the first program injection command sent by the control device through the destination host agent;
[0274] The injection module 802 is used to inject a first monitoring program into the kernel through the target host agent based on the first program injection instruction. The first monitoring program is used to count the packet loss data on the target host side to be monitored based on the kernel function call status.
[0275] The reporting module 803 is used to report host-side packet loss data to the control device through the destination host proxy, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
[0276] Optionally, the injection module 802 is further configured to:
[0277] The first monitoring program contained in the first program injection instruction is injected into the kernel through the destination host agent;
[0278] or,
[0279] Based on the target parameters contained in the first program injection instruction, the first monitoring program is generated through the target host agent; the first monitoring program is then injected into the kernel through the target host agent.
[0280] Optionally, the target parameters include the target kernel function and the host IP address of the source host to be monitored, wherein the target kernel function is the kernel function called in the kernel protocol stack to handle packet loss;
[0281] The injection module 802 is further configured to:
[0282] Based on the target kernel function and the host IP address of the source host to be monitored, the first monitoring program is generated through the destination host proxy. The first monitoring program is used to count the number of times the target kernel function is called to process packet loss when sending data packets from the source host to be monitored.
[0283] Optionally, the monitoring program is an eBPF program, and the target kernel function is the kfree_skb function.
[0284] Optionally, the first program injection instruction includes a monitoring duration;
[0285] The device further includes a retraction module for:
[0286] If the program injection duration of the first monitoring program reaches the monitoring duration, the program injection is rolled back through the target host agent.
[0287] Optionally, the retraction module is further configured to:
[0288] The control device sends a retraction command through the destination host agent. The retraction command is sent when the program injection time of the first monitoring program reaches the monitoring time.
[0289] Based on the reversal instruction, the program injection is reversed through the target host agent.
[0290] Optionally, the first monitoring program is also used to record kernel stack data;
[0291] The device further includes a cause determination module, used for:
[0292] The kernel stack data is reported to the control device by the destination host agent so that the control device can determine the cause of packet loss on the host side of the target host to be monitored based on the kernel stack data.
[0293] Optionally, the cause determination module is further configured to:
[0294] The second program injection command sent by the control device is received through the destination host agent;
[0295] Based on the second program injection instruction, a second monitoring program is injected into the kernel through the target host agent. The second monitoring program is used to collect detailed data corresponding to the reasons for packet loss on the host side based on the kernel function call situation.
[0296] The detailed data corresponding to the reason for packet loss on the host side reported to the control device by the destination host agent.
[0297] In summary, in this embodiment of the application, the control device injects a first monitoring program into the target host to be monitored, enabling the target host to obtain host-side packet loss data based on the call status of its kernel functions, and report the host-side packet loss data to the control device. This allows the control device to eliminate the influence of host-side packet loss data during link monitoring, ensuring the accuracy of network packet loss data on the monitored link and improving the accuracy of link monitoring.
[0298] It should be noted that the apparatus provided in the above embodiments is only illustrative of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the apparatus can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and their implementation process can be found in the method embodiments, which will not be repeated here.
[0299] See Figure 9 This illustration shows a schematic diagram of a computer device provided in an exemplary embodiment of this application. The computer device may be a personal computer or a server, and may include one or more components such as a processor 901 and a memory 902.
[0300] Optionally, the processor 901 connects to various parts of the electronic device using various interfaces and lines. It performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 902, and by calling data stored in the memory 902. Optionally, the processor 901 can be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 901 can integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), Neural-network Processing Unit (NPU), and baseband chip. Specifically, the CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for the touchscreen display; the NPU implements artificial intelligence (AI) functions; and the baseband chip handles wireless communication. It is understandable that the aforementioned baseband chip may not be integrated into the processor 901, but may be implemented using a separate chip.
[0301] Optionally, the processor 901 connects to various parts of the electronic device using various interfaces and lines. It performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 902, and by calling data stored in the memory 902. Optionally, the processor 901 can be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 901 can integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), Neural-network Processing Unit (NPU), and baseband chip. Specifically, the CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for the touchscreen display; the NPU implements artificial intelligence (AI) functions; and the baseband chip handles wireless communication. It is understandable that the aforementioned baseband chip may not be integrated into the processor 901, but may be implemented using a separate chip.
[0302] The memory 902 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 902 may include a non-transitory computer-readable storage medium. The memory 902 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 902 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described below, etc.; the data storage area may store data created according to the use of the electronic device (such as audio data, telephone directory, etc.).
[0303] In addition, those skilled in the art will understand that the structure of the computer device shown in the above figures does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0304] This application also provides a computer-readable storage medium storing at least one instruction, which is loaded and executed by a processor to implement the link monitoring method as described in the above embodiments.
[0305] This application also provides a computer program product, which includes computer instructions stored in a computer-readable storage medium. A processor retrieves the computer instructions from the computer-readable storage medium and executes the computer instructions to implement the link monitoring method as described in the above embodiments.
[0306] Those skilled in the art will recognize that the functions described in the embodiments of this application in one or more of the above examples can be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable storage medium or transmitted as one or more instructions or code on a computer-readable storage medium. Computer-readable storage media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.
[0307] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.
Claims
1. A link monitoring method, characterized in that, The method includes: Identify the link to be monitored, which is the link between the source host to be monitored and the destination host to be monitored; A first program injection instruction is sent to the destination host agent of the destination host to be monitored in the link to be monitored. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the side of the destination host to be monitored based on the kernel function call situation. Receive packet loss data from the target host agent on the host side; The network packet loss data of the link to be monitored is determined based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
2. The method according to claim 1, characterized in that, Sending the first program injection instruction to the destination host proxy of the destination host to be monitored in the monitored link includes: Send the first program injection instruction containing the first monitoring program to the target host agent; or, The first program injection instruction containing target parameters is sent to the target host agent, which is used to generate the first monitoring program based on the target parameters.
3. The method according to claim 2, characterized in that, Before sending the first program injection instruction containing the first monitoring program to the target host agent, the method includes: Based on the target kernel function and the host IP address of the source host to be monitored, the first monitoring program is generated. The first monitoring program is used to count the number of times the target kernel function is called to process the packet loss of the data packets sent by the source host to be monitored. Sending the first program injection instruction containing target parameters to the target host agent includes: The first program injection instruction containing the target kernel function and the host IP address of the source host to be monitored is sent to the target host agent, and the target host agent is used to generate the first monitoring program based on the target kernel function and the host IP address; The target kernel function is the kernel function called in the kernel protocol stack during packet loss.
4. The method according to claim 3, characterized in that, The first monitoring program is an eBPF program, and the target kernel function is the kfree_skb function.
5. The method according to any one of claims 1 to 4, characterized in that, After sending the first program injection instruction to the destination host proxy of the destination host to be monitored in the link to be monitored, the method further includes: When the program injection duration of the first monitoring program reaches the monitoring duration, a rollback command is sent to the target host agent, and the target host agent is used to roll back the program injection based on the rollback command.
6. The method according to any one of claims 1 to 4, characterized in that, The first program injection instruction includes a monitoring duration, and the destination host agent is used to perform program injection rollback when the program injection duration of the first monitoring program reaches the monitoring duration.
7. The method according to any one of claims 1 to 4, characterized in that, The first monitoring program is also used to record kernel stack data; The method further includes: Receive the kernel stack data reported by the destination host agent; The cause of packet loss on the host side of the target host to be monitored is determined based on the kernel stack data.
8. The method according to claim 7, characterized in that, The process of determining the cause of packet loss on the host side of the target host to be monitored based on the kernel stack data includes: The kernel stack data is input into the packet loss analysis model to obtain the packet loss cause on the host side output by the packet loss analysis model. The packet loss analysis model is trained based on sample kernel stack data and the packet loss cause label corresponding to the sample kernel stack data.
9. The method according to claim 7, characterized in that, The method further includes: A second program injection instruction is sent to the target host agent, which is used to inject a second monitoring program into the kernel of the target host to be monitored according to the second program injection instruction. The second monitoring program is used to collect detailed data corresponding to the cause of packet loss on the host side based on the kernel function call situation. Receive detailed data corresponding to the cause of packet loss on the host side reported by the destination host agent.
10. The method according to any one of claims 1 to 4, characterized in that, The process of determining the network packet loss data of the link to be monitored based on the host-side packet loss data includes: Obtain the link packet loss data reported by the source host to be monitored during the operation of the first monitoring program; The link packet loss data is corrected based on the host-side packet loss data to obtain the network packet loss data.
11. A link monitoring method, characterized in that, The method includes: Receive the first program injection command sent by the control device through the destination host agent; Based on the first program injection instruction, a first monitoring program is injected into the kernel through the target host agent. The first monitoring program is used to count packet loss data on the target host side to be monitored based on the kernel function call status. The destination host agent reports host-side packet loss data to the control device, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
12. The method according to claim 11, characterized in that, The step of injecting a first monitoring program into the kernel through the target host agent based on the first program injection instruction includes: The first monitoring program contained in the first program injection instruction is injected into the kernel through the destination host agent; or, Based on the target parameters contained in the first program injection instruction, the first monitoring program is generated through the target host agent; the first monitoring program is then injected into the kernel through the target host agent.
13. The method according to claim 12, characterized in that, The target parameters include the target kernel function and the host IP address of the source host to be monitored. The target kernel function is the kernel function called in the kernel protocol stack to handle packet loss. The step of generating the first monitoring program through the target host proxy based on the target parameters contained in the first program injection instruction includes: Based on the target kernel function and the host IP address of the source host to be monitored, the first monitoring program is generated through the destination host proxy. The first monitoring program is used to count the number of times the target kernel function is called to process packet loss when sending data packets from the source host to be monitored.
14. The method according to claim 13, characterized in that, The first monitoring program is an eBPF program, and the target kernel function is the kfree_skb function.
15. The method according to any one of claims 11 to 14, characterized in that, The first program injection instruction includes the monitoring duration; After injecting the first monitoring program into the kernel through the target host agent based on the first program injection instruction, the method further includes: If the program injection duration of the first monitoring program reaches the monitoring duration, the program injection is rolled back through the target host agent.
16. The method according to any one of claims 11 to 14, characterized in that, After injecting the first monitoring program into the kernel through the target host agent based on the first program injection instruction, the method further includes: The control device sends a retraction command through the destination host agent. The retraction command is sent when the program injection time of the first monitoring program reaches the monitoring time. Based on the reversal instruction, the program injection is reversed through the target host agent.
17. The method according to any one of claims 11 to 14, characterized in that, The first monitoring program is also used to record kernel stack data; The method further includes: The kernel stack data is reported to the control device by the destination host agent so that the control device can determine the cause of packet loss on the host side of the target host to be monitored based on the kernel stack data.
18. The method according to claim 17, characterized in that, The method further includes: The second program injection command sent by the control device is received through the destination host agent; Based on the second program injection instruction, a second monitoring program is injected into the kernel through the target host agent. The second monitoring program is used to collect detailed data corresponding to the reasons for packet loss on the host side based on the kernel function call situation. The detailed data corresponding to the reason for packet loss on the host side reported to the control device by the destination host agent.
19. A link monitoring device, characterized in that, The device includes: The link determination module is used to determine the link to be monitored, wherein the link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The sending module is used to send a first program injection instruction to the destination host agent of the destination host to be monitored in the link to be monitored. The destination host agent is used to inject a first monitoring program into the kernel of the destination host to be monitored according to the first program injection instruction. The first monitoring program is used to count the packet loss data on the side of the destination host to be monitored based on the kernel function call situation. The receiving module is used to receive packet loss data reported by the destination host agent on the host side; The data determination module is used to determine the network packet loss data of the link to be monitored based on the host-side packet loss data, wherein the network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
20. A link monitoring device, characterized in that, The device includes: The receiving module is used to receive the first program injection command sent by the control device through the destination host agent; An injection module is used to inject a first monitoring program into the kernel through the target host agent based on the first program injection instruction. The first monitoring program is used to count packet loss data on the target host side to be monitored based on the kernel function call status. The reporting module is used to report host-side packet loss data to the control device through the destination host proxy, so that the control device can determine the network packet loss data of the link to be monitored based on the host-side packet loss data. The link to be monitored is the link between the source host to be monitored and the destination host to be monitored. The network packet loss data is used to characterize the network packet loss situation of the link to be monitored.
21. A computer device, characterized in that, The computer device is a control device or a host, and the computer device includes a processor and a memory. The memory stores at least one instruction, which is loaded and executed by the processor to implement the link monitoring method as described in any one of claims 1 to 10, or the link monitoring method as described in any one of claims 11 to 18.
22. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction, which is loaded and executed by a processor to implement the link monitoring method as described in any one of claims 1 to 10, or the link monitoring method as described in any one of claims 11 to 18.
23. A computer program product, characterized in that, The computer program product includes computer instructions stored in a computer-readable storage medium; the processor of the terminal device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the terminal device to implement the link monitoring method as described in any one of claims 1 to 10, or the link monitoring method as described in any one of claims 11 to 18.