A network topology discovery method and apparatus
By working in tandem with the management platform and the data collector, the problems of network reachability and firewall limitations in network topology discovery are solved, and automated network topology map generation and security risk assessment are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C SECURITY TECH CO LTD
- Filing Date
- 2024-12-04
- Publication Date
- 2026-08-04
AI Technical Summary
Existing network topology discovery schemes suffer from network reachability and firewall limitations in real-world networks, making it difficult to effectively acquire and maintain the connectivity relationships of network devices.
The management platform issues detection tasks to the data collectors bound to the area to be detected. The collectors perform device discovery and link discovery tasks and upload the results to the management platform to generate a network topology map.
It overcomes the limitations of network isolation and firewalls, achieves automated asset topology discovery, generates accurate and reliable network topology maps, and helps determine the scope of impact of network security risks.
Smart Images

Figure CN119854133B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method and apparatus for network topology discovery. Background Technology
[0002] Network topology refers to the connection relationships between various devices in a network (such as hosts, routing devices, and switching devices). Network topology is the foundation of network management and planning, helping administrators understand the network structure to facilitate network monitoring and fault location.
[0003] Network topology discovery is a network management technique whose core purpose is to acquire and maintain information about the existence of network devices and their connections, and to draw a topology map of the entire network based on this information.
[0004] Current network topology discovery schemes work by sending probe packets to devices and comparing the fingerprints returned by the devices with fingerprints in a database to determine the network topology. However, this approach has the following limitations: First, network reachability limitations: it's difficult to guarantee the reachability of probe packets in a real network; second, firewall limitations: firewalls may disable network diagnostic tools (such as PING) and port scanning functions. Summary of the Invention
[0005] To overcome the problems existing in related technologies, this application provides a network topology discovery method and apparatus.
[0006] According to a first aspect of the embodiments of this application, a network topology discovery method is provided, the method being applied to a target data collector, wherein the target data collector has a binding relationship with a target area to be detected, the method comprising:
[0007] Receive detection tasks sent by the management platform for the target area to be detected;
[0008] The detection task is executed to obtain the detection results of the target area to be detected, wherein the detection results of the target area to be detected include device detection results and link detection results;
[0009] The detection results of the target area to be detected are sent to the management platform, so that the management platform generates a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected.
[0010] According to a second aspect of the embodiments of this application, a network topology discovery method is provided, the method being applied to a management platform, the method comprising:
[0011] Generate a detection task for the area to be detected, and send the detection task to a data collector that is bound to the area to be detected;
[0012] The detection results of the area to be detected obtained by the data collector through the execution of the detection task are acquired, wherein the detection results include device detection results and link detection results;
[0013] A network topology map is generated based on the detection results of all areas to be detected.
[0014] According to a third aspect of the embodiments of this application, a network topology discovery device is provided. The device is applied to a target data collector, the target data collector having a binding relationship with a target area to be detected. The device includes:
[0015] The receiving module is used to receive the detection task for the target area to be detected sent by the management platform;
[0016] An execution module is used to execute the detection task and obtain the detection results of the target area to be detected, wherein the detection results of the target area to be detected include device discovery results and link discovery results;
[0017] The sending module is used to send the detection results of the target area to be detected to the management platform, so that the management platform can generate a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected.
[0018] According to a fourth aspect of the embodiments of this application, a network topology discovery device is provided, the device being applied to a management platform, the device comprising:
[0019] The task generation module is used to generate detection tasks for the area to be detected and to send the detection tasks to the data collectors that are bound to the area to be detected.
[0020] The acquisition module is used to acquire the detection results of the area to be detected obtained by the data collector through the execution of the detection task, wherein the detection results include device detection results and link detection results;
[0021] The topology generation module is used to generate a network topology map based on the detection results of all areas to be detected.
[0022] According to a fifth aspect of the present application, an electronic device is provided, including a processor and a machine-readable storage medium storing machine-executable instructions executable by the processor, wherein the processor is prompted by the machine-executable instructions to implement the steps of the network topology discovery method described above.
[0023] According to a sixth aspect of the embodiments of this application, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when executed by a processor, the computer program implements the steps of the network topology discovery method described above. The technical solutions provided by the embodiments of this application may include the following beneficial effects:
[0024] In this embodiment, the management platform issues probing tasks to specific areas to be probed. Data collectors bound to these areas execute the probing tasks. After completion, the data collectors upload the probe results to the management platform, which then generates a network topology map based on the probe results for all areas. This approach overcomes the limitations of active probing network isolation and firewalls, and enables automatic asset topology discovery. Therefore, the management platform can generate accurate and reliable network topology maps, which can help determine the scope of impact when facing network security risks, facilitating timely responses to network problems.
[0025] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0026] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0027] Figure 1 A schematic flowchart illustrating the network topology discovery method provided in Embodiment 1 of this application;
[0028] Figure 2 This is a flowchart illustrating the device discovery process in Embodiment 1 of this application;
[0029] Figure 3 This is a flowchart illustrating the link discovery process in Embodiment 1 of this application;
[0030] Figure 4 This is a flowchart illustrating the network topology discovery method provided in Embodiment 2 of this application;
[0031] Figure 5 This is a flowchart illustrating the binding process in Embodiment 2 of this application;
[0032] Figure 6 This is a flowchart illustrating the detection task issuance process in Embodiment 3 of this application;
[0033] Figure 7 This is a flowchart illustrating the device discovery process in Embodiment 3 of this application;
[0034] Figure 8This is a flowchart illustrating the link discovery process in Embodiment 3 of this application;
[0035] Figure 9 This is a functional block diagram of the network topology discovery device provided in Embodiment 4 of this application;
[0036] Figure 10 This is a functional block diagram of the network topology discovery device provided in Embodiment 5 of this application;
[0037] Figure 11 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0038] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0039] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0040] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the words “if” or “suppose” as used herein may be interpreted as “when…” or “when…”.
[0041] This application provides a network topology discovery method and apparatus. In this application, a management platform and data collectors cooperate to complete the entire network topology discovery scheme. Multiple data collectors are involved, and each data collector is associated with a region to be probed. During the network topology discovery process, the management platform first issues probe tasks to each data collector, instructing the data collector to probe the data to be probed that is associated with it. Then, each data collector obtains the probe results by executing the probe tasks and sends the results back to the management platform. Finally, the management platform generates a network topology map based on the probe results sent by all data collectors.
[0042] The embodiments of this application will now be described in detail.
[0043] Embodiment 1 of this application provides a network topology discovery method. This method is applied to a target data collector, where the target data collector and the target area to be detected are bound together, such as... Figure 1 As shown, Example 1 includes the following steps:
[0044] Step 110: Receive the detection task for the target area to be detected sent by the management platform;
[0045] Step 120: Execute the detection task to obtain the detection results of the target area to be detected, including the device detection results and the link detection results.
[0046] Step 130: Send the detection results of the target area to be detected to the management platform so that the management platform can generate a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected.
[0047] This embodiment provides a network topology discovery method with a target data collector as the execution subject. The target data collector can be any data collector. For ease of description, this embodiment refers to the area to be detected that has a binding relationship with the target data collector as the target area to be detected.
[0048] Specifically, in this embodiment, the detection results obtained by the target data collector through performing the detection task include device discovery results and link discovery results. The generation methods of device discovery results and link discovery results are described below.
[0049] like Figure 2 As shown, this embodiment obtains the device discovery result in the following way:
[0050] Step 210: For each device to be detected in the target area, send a PING request message to the device to be detected;
[0051] Step 220: If a PING response message is received from the device to be probed within a preset time period, determine whether the device to be probed supports the SNMP protocol; if the determination result is yes, proceed to step 230.
[0052] Step 230: Record the device to be detected in the link discovery list and obtain the basic information of the device to be detected through the SNMP protocol;
[0053] Step 240: Obtain detailed information about the device to be detected for different device types;
[0054] Step 250: Use the basic and detailed information of all devices to be detected in the link discovery list as the device discovery results.
[0055] The aforementioned SNMP (Simple Network Management Protocol) is a network management protocol that obtains network device configuration information and performance data by exchanging SNMP messages. In automatic network topology discovery, the SNMP protocol can be used to obtain information such as the IP address, device type, and connection relationships of network devices, thereby constructing the network topology. In step 230, this embodiment obtains at least the device type of the basic information of the device to be detected.
[0056] In step 240 above, the detailed information of the device to be probed obtained may include any one or more of the following: ARP (Address Resolution Protocol) table information, interface information, and IP configuration information. The ARP table stores the mapping relationship between IP addresses and their corresponding MAC addresses.
[0057] like Figure 3 As shown, this embodiment obtains the link discovery results in the following way:
[0058] Step 310: For each device to be probed in the link discovery list, determine whether the device supports the target communication protocol; if the result is yes, proceed to step 320; if the result is no, proceed to step 330.
[0059] Step 320: Determine the link layer connection relationship of the device under test based on the table entries of the target communication protocol of the device under test, and proceed to step 370;
[0060] Step 330: Determine whether the device to be detected is a routing device; if the determination result is yes, proceed to step 340; if the determination result is no, proceed to step 350.
[0061] Step 340: Determine the link layer connection relationship of the device to be detected based on the routing table of the device to be detected, and proceed to step 370;
[0062] Step 350: Determine whether the device to be detected is a switching device; if the determination result is yes, proceed to step 360.
[0063] Step 360: Determine the link layer connection relationship of the device to be detected based on the FDB table of the device to be detected, and proceed to step 370;
[0064] Step 370: Take the link layer connection relationships of all devices to be detected in the link discovery list as the link discovery result.
[0065] In step 310 above, the target communication protocol refers to a link-layer communication protocol whose protocol content includes information about network device neighbors, that is, a communication protocol that enables the device to identify and collect relevant information about neighboring devices.
[0066] As a specific implementation, this embodiment selects LLDP (Link Layer Discovery Protocol) as the target communication protocol. LLDP is a link layer protocol used to discover and exchange link information between network devices. LLDP allows network devices to exchange information about the links they connect to, thereby better understanding the network topology. Therefore, step 310 specifically determines whether the device to be probed supports the target communication protocol by: determining whether the device to be probed supports the LLDP protocol; if the determination result is yes, then determining the link layer connection relationship of the device to be probed based on the LLDP protocol entries of the device to be probed.
[0067] As another implementation, this embodiment can also use NDP (Neighbor Discovery Protocol) as the target communication protocol. Therefore, step 310 can specifically determine whether the device to be probed supports the target communication protocol in the following way: determine whether the device to be probed supports the NDP protocol; if the determination result is yes, then determine the link layer connection relationship of the device to be probed according to the NDP protocol entry of the device to be probed.
[0068] The FDB table mentioned above stands for Forwarding Database. The FDB table in a switching device is primarily used to record the mapping between the MAC addresses of devices in the network and the ports of the switching device, in order to achieve Layer 2 data forwarding.
[0069] MIB-II (Management Information Base II) is a set of standards for network management, containing multiple tables and objects for monitoring and controlling network devices. In MIB-II, the ipAddrEntry table provides IP configuration information for network device interfaces; the ipForwarding parameter is a crucial configuration parameter that controls whether the device acts as an IP gateway to forward packets destined for non-local addresses. When the ipForwarding parameter is set to true, it indicates that the device will act as an IP gateway, forwarding IP packets destined for addresses other than its own. This means the device will participate in routing functions, forwarding received packets destined for other networks or hosts to other devices.
[0070] Therefore, when a device is a routing device, it has the following characteristics: the device's ipAddrEntry table indicates that the device has more than two interfaces, and the device's ipForwarding parameter is set to true.
[0071] As a specific implementation method, this embodiment determines whether the device to be probed is a routing device in the following way: a request message for the ipAddrEntry table is sent to the device to be probed via the SNMP protocol; if a response message for the ipAddrEntry table is received from the device to be probed, and the response message indicates that the number of interfaces of the device to be probed is more than two, then the ipForwarding parameter of the device to be probed is obtained; if the value of the ipForwarding parameter of the device to be probed is a preset threshold, then the device to be probed is determined to be a routing device.
[0072] It's worth noting that to determine if a device is a switch, you can check if it supports Bridge-MIB (Bridge Management Information Base). Bridge-MIB contains the switch's topology information, including the MAC address and VLAN information for each port. Furthermore, switches typically have multiple port and VLAN configurations; you can check the number of ports and VLAN configurations to determine if a device is a switch.
[0073] Therefore, when a device is a switching device, it has the following characteristics: the device supports Bridge-MIB and has multiple ports and VLAN configurations.
[0074] As a specific implementation method, this embodiment determines whether the device to be probed is a switching device in the following way: it determines whether the device to be probed supports Bridge-MIB through the SNMP protocol; if the determination result is yes, it obtains the port configuration and VLAN configuration of the device to be probed; if the port configuration of the device to be probed indicates that there are multiple ports of the device to be probed, and the VLAN configuration of the device to be probed indicates that there are multiple VLANs of the device to be probed, then it is determined that the device to be probed is a switching device.
[0075] Understandably, depending on the actual application requirements, the target collector can first perform data operations such as compression and encryption on the detection results before uploading the results to the management platform.
[0076] As can be seen from the above technical solution, this embodiment provides a network topology discovery method applied to a target data collector, which can receive a detection task sent by a management platform for a target area to be detected; execute the detection task to obtain the detection results of the target area to be detected, which include device discovery results and link discovery results; and finally send the detection results of the target area to be detected to the management platform so that the management platform can generate a network topology map based on the detection results of all areas to be detected.
[0077] In other words, on the one hand, the network topology discovery method of this embodiment includes a management platform and a distributed data collector. The data collector is bound to the network area to be detected. The management platform issues detection tasks to specific areas to be detected. The data collector bound to the area to be detected executes the detection tasks, which include two parts: device discovery and link discovery. After the detection tasks are completed, the data collector uploads the detection results to the management platform. The management platform generates a network topology map based on the detection results of all areas to be detected.
[0078] On the other hand, the network topology discovery method in this embodiment includes two parts: device discovery and link discovery. Device discovery, based on a distributed data collector, solves the network isolation limitations of active probing, while link discovery enables automatic asset topology discovery. Therefore, the management platform can generate accurate and reliable network topology maps. When facing network security risks, the network topology map can help determine the scope of impact and facilitate timely response to network problems.
[0079] Embodiment 2 of this application provides a network topology discovery method, which is applied to a management platform, such as... Figure 4 As shown, Embodiment 2 includes the following steps:
[0080] Step 410: Generate a detection task for the area to be detected and send the detection task to the data collector that is bound to the area to be detected;
[0081] Step 420: Obtain the detection results of the area to be detected obtained by the data collector through the execution of the detection task, wherein the detection results include device detection results and link detection results;
[0082] Step 430: Generate a network topology map based on the detection results of all areas to be detected.
[0083] As a specific implementation method, such as Figure 5 As shown, in Example 3, the binding operation between the area to be detected and the data acquisition device is performed in the following manner:
[0084] Step 510: Determine whether a data acquisition device is deployed inside the area to be detected; if the result is yes, proceed to step 520; otherwise, proceed to step 530.
[0085] Step 520: Perform a binding operation between the area to be detected and the data acquisition device deployed within the area to be detected;
[0086] Step 530: Bind the area to be detected to the data collector deployed in the next higher level area of the area to be detected.
[0087] Embodiment 3 of this application provides a network topology discovery method. Embodiment 3 uses a practical application as an example to illustrate the network topology discovery process in detail.
[0088] Figure 6 This is the process of the management platform issuing detection tasks in Example 3. Figure 7 This is the device discovery process for the data acquisition device in Example 3. Figure 8 This describes the link discovery process for the data collector in Example 3. The following section will combine... Figure 6 , Figure 7 and Figure 8 The network topology discovery method of Embodiment 3 of this application will be described.
[0089] like Figure 6 As shown in this embodiment, the process of the management platform issuing detection tasks is as follows:
[0090] Step 61: According to the selection instructions, determine the area A to be explored for the new exploration mission;
[0091] Step 62: Determine whether a data acquisition device is attached to the area to be detected, A;
[0092] Step 63: If the judgment result is yes, the data collector bound to the area to be detected A is recorded as data collector 1, a new detection task A+1 is created for data collector 1, and detection task A+1 is added to the system detection task list. Detection task A+1 instructs data collector 1 to perform the detection task of the area to be detected A.
[0093] Step 64: If the result is negative, search for the parent region B of the region to be detected A, and determine whether the parent region B exists. If the parent region B exists and is already bound to data collector 2, create a new detection task A+2 for data collector 2 bound to the parent region B, and add detection task A+2 to the system detection task list. Detection task A+2 instructs data collector 2 to perform the detection task for the region to be detected A. If the parent region B does not exist, indicate that the creation of the detection task failed.
[0094] Step 65: Distribute each detection task in the system detection task list to the corresponding data acquisition device.
[0095] like Figure 7 As shown, the device discovery process of the data acquisition device in this embodiment is as follows:
[0096] Step 70: The data collector receives the detection task issued by the management platform;
[0097] Step 71: Analyze the parameters of the detection mission, determine the area to be detected, and the various devices to be detected in the area to be detected, and obtain the local device discovery list;
[0098] Step 72: Start the device discovery process;
[0099] Step 73: Remove the device n to be detected from the local device discovery list, where n is a positive integer between 1 and N, and N is the total number of devices to be detected in the local device discovery list;
[0100] Step 74: Determine whether the device n to be probed can be pinged. That is, send a PING request message to the device n to be probed and determine whether a PING response message is received from the device n to be probed within a preset time. If so, the device n to be probed is considered to be pingable and proceed to the next step; otherwise, proceed to the next device.
[0101] Step 75: Determine whether the device n to be detected supports the SNMP protocol; if yes, proceed to the next step; otherwise, add the device to the list of ordinary devices.
[0102] Step 76: Add the device to be detected n to the list of discovered devices, and obtain the basic information and sysObjectID value of the device to be detected n; through the sysObjectID value, the device model table can be obtained, thereby obtaining the device type, device model and manufacturer information corresponding to the device model, etc.
[0103] Step 77: Obtain the ARP table information, interface information, IP address information, and IP configuration information of the device n to be detected, and add them to the list of discovered devices;
[0104] Step 78: Add the device n to be detected to the link discovery list;
[0105] Step 79: Return to step 73 until n = N, complete the list of discovered devices as the device discovery result, and send it to the management platform.
[0106] like Figure 8 As shown, the link discovery process of the data collector in this embodiment is as follows:
[0107] Step 81: Retrieve device m from the link discovery list, where m is a positive integer between 1 and M, and M is the total number of devices to be detected in the link discovery list;
[0108] Step 82: Determine whether device m supports the LLDP protocol. If it does, obtain the LLDP table of device m and determine the link layer connection relationship of device m based on lldpLocalSystemData and lldpRemoteSystemData.
[0109] Here, lldpLocalSystemData refers to the information sent by the local device to the neighboring device in the LLDP protocol; lldpRemoteSystemData refers to the information received from the neighboring device in the LLDP protocol.
[0110] Step 83: If the LLDP protocol is not supported, determine whether device m is a routing device. If it is a routing device, obtain the routing table of device m, confirm the routing connection relationship, calculate the subnet range, confirm the subnet devices, and finally obtain the link layer connection relationship of device m.
[0111] Specifically, this embodiment determines whether a device is a routing device in the following way: It queries the ipAddrEntry table in the MIB-II of the device using SNMP. If no query result is returned, the device can be preliminarily identified as not being a routing device. If the device has two or more interfaces and the ipForwarding node is set to true, the device can be identified as a routing device.
[0112] Through this router, other network segments can be discovered, allowing further searches for devices on those segments.
[0113] Step 84: If it is not a routing device, determine whether device m is a switching device. If it is a switching device, obtain the FDB table of device m, and obtain the port VLAN division and interface and device connection relationship in BRIDGE-MIB (Management Information Base) to obtain the link layer connection relationship of device m.
[0114] Specifically, this embodiment determines whether a device is a switching device in the following way: After a device supports SNMP, if it is a switching device, it should implement Bridge-MIB, and should implement several main nodes, such as: the number of ports, the path value from the current bridge node to the root bridge node, the number of ports from the current bridge node to the root bridge node, etc.
[0115] Step 85: Organize the link layer connection relationships of all devices in the link discovery list to obtain the link discovery results;
[0116] Step 86: Upload the link discovery results to the management platform.
[0117] In summary, the network topology discovery method provided in this application overcomes the limitations of network isolation and firewall access control by using a distributed data collector. Compared with a single packet detection method, this application provides multiple asset detection methods, realizes automated network topology discovery, and provides a basis for automated orchestration.
[0118] Embodiment 4 of this application provides a network topology discovery device, which is applied to a target data collector, wherein the target data collector is bound to a target area to be detected.
[0119] like Figure 9 As shown, the device includes:
[0120] The receiving module 910 is used to receive the detection task for the target area to be detected sent by the management platform;
[0121] The execution module 920 is used to execute the detection task and obtain the detection results of the target area to be detected, wherein the detection results of the target area to be detected include device discovery results and link discovery results;
[0122] The sending module 930 is used to send the detection results of the target area to be detected to the management platform, so that the management platform can generate a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected.
[0123] As a specific implementation method, the execution module 920 obtains the device discovery results in the following way:
[0124] For each device to be detected in the target detection area, a PING request message is sent to the device. If a PING response message is received from the device within a preset time period, it is determined whether the device supports the SNMP protocol. If the determination result is yes, the device is recorded in the link discovery list, and basic information of the device is obtained through the SNMP protocol, wherein the basic information includes the device type. For different device types, detailed information of the device is obtained, wherein the detailed information includes any one or more of the following: ARP table information, interface information, and IP configuration information. The basic information and detailed information of all devices to be detected in the link discovery list are used as the device discovery result.
[0125] As a specific implementation method, the execution module 920 obtains the link discovery results in the following way:
[0126] For each device to be detected in the link discovery list, it is determined whether the device supports the target communication protocol, wherein the target communication protocol is a link-layer communication protocol whose protocol content includes network device neighbor information. If the determination result is yes, the link-layer connection relationship of the device to be detected is determined according to the entry of the target communication protocol of the device to be detected. If the determination result is no, it is determined whether the device to be detected is a routing device. If the determination result is yes, the link-layer connection relationship of the device to be detected is determined according to the routing table of the device to be detected. If the determination result is no, it is determined whether the device to be detected is a switching device. If the determination result is yes, the link-layer connection relationship of the device to be detected is determined according to the FDB table of the device to be detected. The link-layer connection relationships of all devices to be detected in the link discovery list are used as the link discovery result.
[0127] As a specific implementation method, the execution module 920 determines whether the device to be detected supports the target communication protocol in the following way:
[0128] Determine whether the device to be probed supports the LLDP protocol; if the result is yes, determine the link layer connection relationship of the device to be probed based on the LLDP protocol entry of the device to be probed.
[0129] As a specific implementation method, the execution module 920 determines whether the device to be detected is a routing device in the following way:
[0130] A request message for the ipAddrEntry table is sent to the device to be probed via the SNMP protocol; if a response message for the ipAddrEntry table is received from the device to be probed, and the response message indicates that the number of interfaces of the device to be probed is more than two, then the ipForwarding parameter of the device to be probed is obtained; if the value of the ipForwarding parameter of the device to be probed is a preset threshold, then the device to be probed is determined to be a routing device.
[0131] As a specific implementation method, the execution module 920 determines whether the device to be detected is a switching device in the following way:
[0132] The system uses the SNMP protocol to determine whether the device under test supports Bridge-MIB. If the result is yes, it obtains the port configuration and VLAN configuration of the device under test. If the port configuration of the device under test indicates that there are multiple ports, and the VLAN configuration of the device under test indicates that there are multiple VLANs, then the device under test is determined to be a switch.
[0133] Embodiment 5 of this application provides a network topology discovery device, which is applied to a management platform.
[0134] like Figure 10 As shown, the device includes:
[0135] The task generation module 1010 is used to generate a detection task for the area to be detected and to send the detection task to a data collector that is bound to the area to be detected.
[0136] The acquisition module 1020 is used to acquire the detection results of the area to be detected obtained by the data collector through the execution of the detection task, wherein the detection results include device detection results and link detection results;
[0137] A topology generation module 1030 is used to generate a network topology map based on the detection results of all areas to be detected. As a specific implementation, the device further includes:
[0138] Binding module 1000 is used to perform binding operations between the area to be detected and the data acquisition device;
[0139] The binding module 1000 performs the binding operation between the area to be detected and the data acquisition device in the following ways:
[0140] Determine whether a data collector is deployed inside the area to be detected; if the result is yes, perform a binding operation between the area to be detected and the data collector deployed inside the area to be detected; if the result is no, perform a binding operation between the area to be detected and the data collector deployed inside the upper-level area of the area to be detected.
[0141] This application also provides an electronic device, such as... Figure 11 As shown, it includes a processor 1110 and a machine-readable storage medium 1120, the machine-readable storage medium 1120 storing machine-executable instructions that can be executed by the processor 1110, the processor 1110 being prompted by the machine-executable instructions to implement the steps of any of the above network topology discovery methods.
[0142] The aforementioned machine-readable storage medium may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the machine-readable storage medium may also be at least one storage device located remotely from the aforementioned processor.
[0143] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0144] In another embodiment provided in this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed by a processor, implements the steps of any of the above-described network topology discovery methods.
[0145] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A network topology discovery method, characterized by, The method is applied to a target data collector, wherein the target data collector is bound to a target area to be detected, and the method includes: Receive detection tasks sent by the management platform for the target area to be detected; The detection task is executed to obtain the detection results of the target area to be detected, wherein the detection results of the target area to be detected include device detection results and link detection results; The detection results of the target area to be detected are sent to the management platform, so that the management platform generates a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected; The method specifically obtains device discovery results in the following ways: For each device to be detected in the target detection area, send a PING request message to the device to be detected; If a PING response message is received from the device to be probed within a preset time period, it is determined whether the device to be probed supports the SNMP protocol. If the determination result is yes, the device to be detected is recorded in the link discovery list, and the basic information of the device to be detected is obtained through the SNMP protocol, wherein the basic information includes the device type; For different types of devices to be probed, obtain detailed information about the devices to be probed, wherein the detailed information includes any one or more of the following: ARP table information, interface information, and IP configuration information; The basic and detailed information of all devices to be detected in the link discovery list are used as the device discovery results; The method specifically obtains the link discovery results in the following ways: For each device to be detected in the link discovery list, determine whether the device supports the target communication protocol, wherein the target communication protocol is a link layer communication protocol whose protocol content includes network device neighbor information; the target communication protocol is LLDP protocol or NDP protocol; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the table entries of the target communication protocol of the device to be detected; If the result is negative, then determine whether the device to be detected is a routing device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the routing table of the device to be detected; If the result is negative, then determine whether the device to be detected is a switching device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the FDB table of the device to be detected; The link layer connection relationships of all devices to be detected in the link discovery list are used as the link discovery results.
2. The method of claim 1, wherein, The method specifically determines whether the device to be detected is a routing device in the following ways: Send a request message for the ipAddrEntry table to the device to be probed via the SNMP protocol; If a response message from the ipAddrEntry table of the device to be probed is received, and the response message indicates that the number of interfaces of the device to be probed is two or more, then the ipForwarding parameter of the device to be probed is obtained. If the value of the ipForwarding parameter of the device to be probed is a preset threshold, then the device to be probed is determined to be a routing device.
3. The method of claim 1, wherein, The method specifically determines whether the device to be detected is a switching device in the following ways: Determine whether the device to be probed supports Bridge-MIB using the SNMP protocol; If the determination result is yes, then obtain the port configuration and VLAN configuration of the device to be detected; If the port configuration of the device to be detected indicates that there are multiple ports on the device to be detected, and the VLAN configuration of the device to be detected indicates that there are multiple VLANs on the device to be detected, then the device to be detected is determined to be a switching device.
4. A network topology discovery method characterized by, The method is applied to a management platform, and the method includes: Generate a detection task for the target area to be detected, and send the detection task to a data acquisition device that is bound to the target area to be detected; The detection results of the target area to be detected obtained by the data collector through the execution of the detection task are acquired, wherein the detection results include device detection results and link detection results; Based on the detection results of all areas to be detected, a network topology map is generated; The data acquisition device obtains the device discovery results in the following ways: For each device to be detected in the target detection area, send a PING request message to the device to be detected; If a PING response message is received from the device to be probed within a preset time period, it is determined whether the device to be probed supports the SNMP protocol. If the determination result is yes, the device to be detected is recorded in the link discovery list, and the basic information of the device to be detected is obtained through the SNMP protocol, wherein the basic information includes the device type; For different types of devices to be probed, obtain detailed information about the devices to be probed, wherein the detailed information includes any one or more of the following: ARP table information, interface information, and IP configuration information; The basic and detailed information of all devices to be detected in the link discovery list are used as the device discovery results; The data collector obtains the link discovery results in the following ways: For each device to be detected in the link discovery list, determine whether the device supports the target communication protocol, wherein the target communication protocol is a link layer communication protocol whose protocol content includes network device neighbor information; the target communication protocol is LLDP protocol or NDP protocol; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the table entries of the target communication protocol of the device to be detected; If the result is negative, then determine whether the device to be detected is a routing device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the routing table of the device to be detected; If the result is negative, then determine whether the device to be detected is a switching device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the FDB table of the device to be detected; The link layer connection relationships of all devices to be detected in the link discovery list are used as the link discovery results.
5. The method of claim 4, wherein, The method specifically performs a binding operation between the target area to be detected and the data acquisition device in the following manner: Determine whether data acquisition devices are deployed inside the target area to be detected; If the judgment result is yes, then a binding operation is performed on the target area to be detected and the data collector deployed inside the target area to be detected; If the judgment result is negative, then the target area to be detected will be bound to the data collector deployed in the upper-level area of the target area to be detected.
6. A network topology discovery apparatus, characterized by comprising: The device is applied to a target data collector, which is bound to a target area to be detected. The device includes: The receiving module is used to receive the detection task for the target area to be detected sent by the management platform; An execution module is used to execute the detection task and obtain the detection results of the target area to be detected, wherein the detection results of the target area to be detected include device discovery results and link discovery results; The sending module is used to send the detection results of the target area to be detected to the management platform, so that the management platform can generate a network topology map based on the detection results of all areas to be detected, wherein the detection results of all areas to be detected include at least the detection results of the target area to be detected; The execution module obtains the device discovery results in the following ways: For each device to be detected in the target detection area, send a PING request message to the device to be detected; If a PING response message is received from the device to be probed within a preset time period, it is determined whether the device to be probed supports the SNMP protocol. If the determination result is yes, the device to be detected is recorded in the link discovery list, and the basic information of the device to be detected is obtained through the SNMP protocol, wherein the basic information includes the device type; For different types of devices to be probed, obtain detailed information about the devices to be probed, wherein the detailed information includes any one or more of the following: ARP table information, interface information, and IP configuration information; The basic and detailed information of all devices to be detected in the link discovery list are used as the device discovery results; The execution module obtains the link discovery results in the following ways: For each device to be detected in the link discovery list, determine whether the device supports the target communication protocol, wherein the target communication protocol is a link layer communication protocol whose protocol content includes network device neighbor information; the target communication protocol is LLDP protocol or NDP protocol; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the table entries of the target communication protocol of the device to be detected; If the result is negative, then determine whether the device to be detected is a routing device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the routing table of the device to be detected; If the result is negative, then determine whether the device to be detected is a switching device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the FDB table of the device to be detected; The link layer connection relationships of all devices to be detected in the link discovery list are used as the link discovery results.
7. A network topology discovery apparatus, characterized by comprising: The device is used in a management platform, and the device includes: The task generation module is used to generate detection tasks for the target area to be detected and to send the detection tasks to the data collectors that are bound to the target area to be detected. The acquisition module is used to acquire the detection results of the target area to be detected obtained by the data collector through the execution of the detection task, wherein the detection results include device detection results and link detection results; The topology generation module is used to generate a network topology map based on the detection results of all areas to be detected. The data acquisition device obtains the device discovery results in the following ways: For each device to be detected in the target detection area, send a PING request message to the device to be detected; If a PING response message is received from the device to be probed within a preset time period, it is determined whether the device to be probed supports the SNMP protocol. If the determination result is yes, the device to be detected is recorded in the link discovery list, and the basic information of the device to be detected is obtained through the SNMP protocol, wherein the basic information includes the device type; For different types of devices to be probed, obtain detailed information about the devices to be probed, wherein the detailed information includes any one or more of the following: ARP table information, interface information, and IP configuration information; The basic and detailed information of all devices to be detected in the link discovery list are used as the device discovery results; The data collector obtains the link discovery results in the following ways: For each device to be detected in the link discovery list, determine whether the device supports the target communication protocol, wherein the target communication protocol is a link layer communication protocol whose protocol content includes network device neighbor information; the target communication protocol is LLDP protocol or NDP protocol; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the table entries of the target communication protocol of the device to be detected; If the result is negative, then determine whether the device to be detected is a routing device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the routing table of the device to be detected; If the result is negative, then determine whether the device to be detected is a switching device; If the judgment result is yes, then the link layer connection relationship of the device to be detected is determined according to the FDB table of the device to be detected; The link layer connection relationships of all devices to be detected in the link discovery list are used as the link discovery results.
8. An electronic device, characterized in that, The method includes a processor and a machine-readable storage medium storing machine-executable instructions that can be executed by the processor, the processor being prompted by the machine-executable instructions to perform the method steps of any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the method steps of any one of claims 1-5.