Distributed network delay measurement method and system
Through distributed network delay measurement methods and systems, dynamically identify and classify network abnormalities and optimize measurement solutions, the problems of untimely response and inaccurate measures in the existing technology are solved, and the intelligence and adaptive capabilities of network management are improved.
Patent Information
- Application Number
- CN202510128208.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-05
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-05
AI Technical Summary
The prior art has shortcomings in dynamically identifying and classifying network abnormalities and defining corresponding network measurement scenarios, resulting in untimely responses or inaccurate measures in the face of new or complex network abnormalities, which affects the rapid positioning and resolution of network problems.
Through distributed network delay measurement methods and systems, the operating scenario data of network equipment is collected for real-time detection, abnormal reports are generated, key influencing factors are identified, response schemes are matched, and measurement schemes are optimized to adapt to actual scenarios.
It realizes timely detection and handling of network abnormal events, improves the intelligence and adaptability of network management, and ensures the reliability and effectiveness of network measurement processes.
Smart Images

Figure CN119996259A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network delay measurement, and in particular to a distributed network delay measurement method and system. Background Art
[0002] With the rapid development of information technology, computer networks have become the core infrastructure for the operation of modern enterprises and organizations, carrying massive amounts of data transmission, application services and business processes. Especially driven by emerging technologies such as cloud computing, big data, and the Internet of Things, network architectures are becoming increasingly complex, their scale is constantly expanding, and the dynamics and diversity of network environments are significantly enhanced. This complex network environment places higher demands on the stability and reliability of network quality, and real-time monitoring and precise management of network performance have become key tasks to ensure efficient network operation. In order to fully grasp the network status, it is particularly important to define different types of network measurement scenarios. Various measurement scenarios such as delay measurement, bandwidth measurement, packet loss rate measurement, and device performance measurement provide multi-dimensional data collection and analysis methods for specific network abnormalities, ensuring that the network management system can flexibly apply the most appropriate measurement solution for different operating environments and device status, and achieve comprehensive monitoring and optimization of network performance.
[0003] In the Chinese invention patent application publication number CN106961365A, a network delay measurement method based on the TCP protocol is provided, the method comprising: establishing a first optimization objective function of forward delay; establishing a second optimization objective function of return delay; weighting the first and second objectives to obtain a total optimization objective function; using an ant colony algorithm to iteratively optimize and search the total objective function to solve the estimated value of the network delay. The present invention proposes a network delay measurement method based on the TCP protocol, which does not require sending a large number of probe packets, nor does it require global clock calibration, and can simply and effectively calculate network transmission delay.
[0004] Combined with the above application and the contents of the prior art:
[0005] Although existing technologies have made some progress in network anomaly detection and response, there are still significant deficiencies in dynamically identifying and classifying network anomalies and defining corresponding network measurement scenarios. Specifically, the traditional static rule-based response mechanism relies on preset thresholds and conditions, lacks the ability to adapt to real-time data changes, and is difficult to dynamically adjust measurement scenarios to cope with complex and changing network environments. This results in the existing system not responding in a timely manner or taking inaccurate measures when faced with new or complex network anomalies, affecting the rapid location and resolution of network problems.
[0006] In addition, most existing measurement schemes are statically designed and lack optimization mechanisms, making it difficult to quickly generate the optimal measurement scheme under multiple constraints, which in turn affects the efficiency and reliability of network management. Therefore, there is an urgent need for an automated system that can dynamically identify and classify network anomalies and optimize corresponding network measurement scenarios and response measures based on real-time data and intelligent algorithms, in order to enhance the intelligence and adaptability of network management and meet the urgent needs of modern complex network environments for efficient and accurate management.
[0007] To this end, the present invention provides a distributed network delay measurement method and system. Summary of the invention
[0008] 1. Technical issues to be resolved
[0009] In view of the deficiencies of the prior art, the present invention provides a distributed network delay measurement method and system, which predicts and generates anomaly reports after assigning corresponding topics to network abnormal events, generates abnormal density of abnormal events from network abnormal event data, and when the abnormal density exceeds expectations, selects key influencing factors from correlation data, and generates corresponding response plans for matching network abnormal events by target features; after abnormal detection of network quality, if there is an abnormality in network quality, generates a network quality analysis report from visualized network quality data, identifies the current network measurement scenario, and outputs and optimizes the corresponding measurement plan when the current network measurement scenario meets the preset rule conditions, and executes the measurement plan to complete the current delay measurement process. The measurement plan is more adapted to the actual scenario, effectively preventing abnormal measurement environment and network quality from interfering with the network measurement process; thereby solving the technical problems recorded in the background technology.
[0010] (II) Technical solution
[0011] To achieve the above objectives, the present invention is implemented through the following technical solutions: a distributed network delay measurement method and system, the distributed network delay measurement method includes collecting the operation scenario data of the network device and performing real-time detection of network abnormal events. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued;
[0012] After assigning corresponding topics to network abnormal events, predictions are made and abnormal reports are generated. The abnormal density D(t,x) of abnormal events is generated from the network abnormal event data. When the abnormal density D(t,x) exceeds expectations, key factor extraction instructions are sent to the outside.
[0013] After selecting key influencing factors from correlation data, the sparse regression model and variance inflation factor are used to screen out target features, and the corresponding response plans are generated by matching the target features to network abnormal events.
[0014] After abnormal network quality detection, if there is any abnormality in the network quality, the network data changes of each network device are visualized;
[0015] After the network quality analysis report is generated from the visualized network quality data, the current network measurement scenario is identified. When the current network measurement scenario meets the preset rule conditions, the corresponding measurement scheme is output and optimized, and the measurement scheme is executed to complete the current delay measurement process; wherein, the network quality of each node is mapped to the corresponding color intensity I(Q), and the contrast of the middle area is enhanced through smooth transition, wherein,
[0016]
[0017] Where: I(Q) is the color intensity after mapping, ranging from [0, I max ], usually I max =255, Q is the network quality index, normalized to [0, 1]; k is the slope parameter, which controls the steepness of the Sigmoid function, and Q0 is the midpoint parameter, which determines the center position of the Sigmoid function.
[0018] Furthermore, a sensor network is deployed on the network equipment to collect the environmental conditions of each link and the operating status data of the network equipment in real time, and to obtain the operating scenario data of the network equipment;
[0019] The formats of operating scenario data from different sources are converted, and after time alignment of multi-source data through timestamp synchronization, the Bayesian network is applied to fuse the multi-source data.
[0020] Furthermore, network abnormal events are defined and detected in real time based on the event-driven architecture, and the types of abnormal events are pre-defined. Each type of abnormal event should have the following attributes: event ID, type, timestamp, source, details and priority. After aggregation, a collection of network abnormal events is generated; a rule engine is integrated in the real-time processing framework, and detection rules for network abnormal events are defined according to preset thresholds and conditions.
[0021] Furthermore, after receiving the alarm instruction, the topic mechanism of Apache Kafka is used to assign different types of network abnormal events to corresponding topics, and multiple event receiving ends are configured so that the event receiving ends pay attention to the corresponding event topics and are responsible for receiving and processing network abnormal events;
[0022] Use the trained abnormal event prediction model to predict network abnormal events; regularly generate abnormal reports of network abnormal events, including event type, frequency of occurrence, processing effect, etc., abnormal events that may occur in the next stage, and send the abnormal reports to the event receiving end.
[0023] Furthermore, the network abnormal event data in the current stage is collected and recorded, including the abnormal time node, abnormal location node and the corresponding abnormal degree, and the abnormal density D(t,x) of the abnormal event is generated from the network abnormal event data in the following way:
[0024]
[0025] Where: D(t,x) is the density of anomalies at time t and location x, T is the time window length, Ω is the spatial inspection area; s(τ,y) is the severity of anomalies at time τ and location y, K t (t-τ) is the time kernel function; K x (xy) is the spatial kernel function; x, y represent vectors of spatial positions, τ is the integral variable representing time, and y is the integral variable representing spatial position.
[0026] Further, after receiving the key factor extraction instruction, the influencing factors highly correlated with the network status are preliminarily screened out; the principal component analysis is applied to perform dimensionality reduction processing on the preliminarily screened influencing factors to obtain the corresponding key influencing factors;
[0027] The sparse regression model is used to further screen the key influencing factors using the least absolute shrinkage and LASSO selection operator regression to obtain the screened key influencing factors.
[0028] Further, the variance inflation factor (VIF) of the selected key influencing factors is calculated, and the key influencing factors whose VIF values exceed the preset threshold are eliminated or merged, and the selected key factors are used as target features;
[0029] After marking the network abnormal events with target features, automatic response rules are defined based on the event types and attributes of the network abnormal events. After the network abnormal events occur, response plans are automatically generated according to the event types and automatic response rules.
[0030] Furthermore, each network device in the network is used as an independent node in the flow chart to measure and collect network quality data of each independent node; using the real-time network quality data as input, the trained abnormal network detection model is used to perform anomaly detection to obtain anomaly detection data;
[0031] Each node is assigned network quality data, environmental condition data and equipment operation status data of the corresponding stage; each node is connected by directed edges to represent the change status of network quality; on the basis of the flow chart, a heat map element is superimposed on each node, and color gradient is used to represent the degree of network quality.
[0032] Furthermore, the network quality data is bound in time series, the key time points and stages of network quality data growth or decrease are automatically identified and marked, and a network quality analysis report is automatically generated based on changes in network quality;
[0033] Identify and classify current network quality anomalies and define different types of network measurement scenarios. Build a rule-based automated response engine, use genetic algorithms to optimize the current matching measurement scheme based on current equipment operation data and environmental condition data as feedback, and quickly generate the optimal measurement scheme for specific abnormal situations.
[0034] The distributed network delay measurement system includes an abnormal event detection unit, which collects the operation scenario data of the network equipment and performs real-time detection of network abnormal events. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued;
[0035] The event topic allocation unit allocates corresponding topics to network abnormal events, makes predictions and generates abnormal reports. It generates abnormal density of abnormal events from network abnormal event data. When the abnormal density exceeds expectations, it sends key factor extraction instructions to the outside.
[0036] The factor identification unit selects key influencing factors from the correlation data, and then uses the sparse regression model and variance inflation factor to screen out the target features, and generates corresponding response plans based on the target features for matching network abnormal events;
[0037] The network quality detection unit detects abnormalities in the network quality and visualizes the changes in network data of each network device if there are any abnormalities in the network quality.
[0038] The measurement scheme generation unit generates a network quality analysis report from the visualized network quality data, identifies the current network measurement scenario, and outputs and optimizes the corresponding measurement scheme when the current network measurement scenario meets the preset rule conditions, and executes the measurement scheme to complete the current delay measurement process.
[0039] (III) Beneficial effects
[0040] The present invention provides a distributed network delay measurement method and system, which has the following beneficial effects:
[0041] 1. Collect and detect existing network anomalies in the current stage, mark and classify various types of network anomalies, send alarms to the outside when network anomalies occur, and handle existing network anomalies in a timely manner.
[0042] 2. When an abnormal event occurs, a topic describing the abnormal event is added to the corresponding abnormal event, so as to select and match the corresponding processing personnel for the network abnormal event, which can improve the processing efficiency of the abnormal event.
[0043] 3. After collecting the status data of network abnormal events, the abnormality density D(t,x) is constructed. Based on the abnormality density D(t,x), a comprehensive evaluation is conducted on the status of continuous abnormalities in the current stage to determine the density and comprehensive severity of network abnormalities. Based on the comprehensive judgment, it can be determined whether each network device needs to be adjusted, controlled or maintained, which plays a guiding role in subsequent network optimization control and test measurement.
[0044] 4. When it is necessary to handle network anomalies, the corresponding processing strategies are formulated or matched by extracting key influencing factors, and targeted optimization or control is performed; several external factors that may cause the current network status to be abnormal are determined, and the reliability of the influencing factors can be guaranteed by extracting and screening multi-level key factors; on this basis, when handling network equipment and network abnormal events, the processing effect can be improved.
[0045] 5. Through the visualization of network equipment and corresponding network quality data, the current network status can be displayed in real time, which is also convenient for tracing the source when network abnormal events occur, thus improving the targeted processing.
[0046] 6. When there are abnormalities in the current network quality, based on the environmental conditions of the current network equipment, the key factors leading to the abnormalities, and the current network measurement scenario, targeted output and optimization are performed to obtain the corresponding measurement plan. When the network needs to be measured, the measurement plan is more adapted to the actual scenario, effectively preventing the current abnormal measurement environment and network quality from interfering with the current network measurement process and affecting the reliability and effectiveness of the network measurement. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a schematic diagram of the flow of the distributed network delay measurement method of the present invention;
[0048] Figure 2 It is a schematic diagram of the structure of the distributed network delay measurement system of the present invention. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0050] See also Figure 1 The present invention provides a distributed network delay measurement method, comprising:
[0051] Step 1: After collecting the operation scenario data of the network equipment, real-time detection of network abnormal events is performed. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued;
[0052] The step 1 includes the following contents:
[0053] Step 101: construct an electronic map covering the network area, and mark each network device on the electronic map; deploy a sensor network on the network device, such as an environmental sensor, a device status monitoring sensor, etc., to collect environmental conditions of each link and network device operation status data in real time, and obtain operation scenario data of the network device;
[0054] The operating scenario data from different sources are converted into different formats, and after the multi-source data are time-aligned through timestamp synchronization, the multi-source data are fused using the Bayesian network.
[0055] When using it, when measuring the distributed network, the environmental conditions of the network equipment are detected, and when the environmental conditions are abnormal, targeted processing is carried out;
[0056] Step 102: Define network abnormal events based on the event-driven architecture and detect them in real time, predefine abnormal event types, where each type of abnormal event should have the following attributes: event ID, type, timestamp, source, details and priority; for example, network equipment failure events and power supply abnormal events, etc., are aggregated to generate a network abnormal event set;
[0057] Integrate the rule engine in the real-time processing framework to define the detection rules for network abnormal events based on preset thresholds and conditions. When the real-time data meets a certain rule condition, the corresponding event is generated and an alarm instruction is issued.
[0058] When using, combine the contents in steps 101 and 102:
[0059] After determining the current environmental conditions, existing network anomalies are collected and detected during the current stage, and various types of network anomalies are marked and classified. When network anomalies occur, alarms are sent out to the outside world, so that existing network anomalies can be handled in a timely manner.
[0060] Step 2: After assigning corresponding topics to network abnormal events, predictions are made and abnormal reports are generated. The abnormal density D(t,x) of abnormal events is generated from the network abnormal event data. When the abnormal density D(t,x) exceeds expectations, key factor extraction instructions are sent to the outside.
[0061] The step 2 includes the following contents:
[0062] Step 201: After receiving the alarm instruction, use the topic mechanism of Apache Kafka to assign different types of network abnormal events to corresponding topics, configure multiple event receiving ends, and the event receiving ends pay attention to the corresponding event topics and are responsible for receiving and processing network abnormal events. For example, the event receiving end of the network equipment failure abnormal event is responsible for recording the fault information, triggering the maintenance process, and adjusting the production parameters to adjust the current network status;
[0063] When using it, considering that there are many types of network abnormal events, a subject describing the abnormal event is added to the corresponding abnormal event when the abnormal event occurs, so as to select and match the corresponding processing personnel for the network abnormal event, which can improve the processing efficiency of the abnormal event;
[0064] Step 202: After annotating the historical event data, a neural network is trained using the annotated data to obtain a trained abnormal event prediction model; the trained abnormal event prediction model is used to predict possible network abnormal events in the future to obtain prediction data;
[0065] Generate exception reports of network abnormal events regularly, including event type, frequency of occurrence, processing effect, etc., and send exception reports to the event receiving end for abnormal events that may occur in the next stage; by predicting abnormal events, handle network abnormalities in advance when they may occur;
[0066] Step 203: collect and record the network abnormal event data in the current stage, including abnormal time nodes, abnormal location nodes and corresponding abnormal degrees, etc., and generate the abnormal density D(t,x) of the abnormal event from the network abnormal event data in the following manner:
[0067]
[0068] Where: D(t,x) is the density of anomalies at time t and location x, T is the length of the time window, indicating the past time range considered; Ω is the spatial investigation area, indicating the geographical or network topological range where the anomaly occurs; s(τ,y) is the severity of the anomaly at time τ and location y, K t (t-τ) is the time kernel function, and Gaussian kernel function is usually selected to smooth abnormal events in the time dimension; K x (xy) is a spatial kernel function, usually a Gaussian kernel function, which is used to smooth abnormal events in the spatial dimension; x, y represent vectors of spatial positions, and the specific dimensions are determined according to the network topology (such as two-dimensional or three-dimensional coordinates); τ is an integral variable representing time, and y is an integral variable representing spatial position;
[0069] The specific form of the kernel function, in order to achieve smooth processing of time and space dimensions, the Gaussian kernel function is often used, and its specific form is as follows:
[0070]
[0071] Where: t is the bandwidth parameter of the time kernel function, which controls the degree of smoothness in the time dimension; σ x is the bandwidth parameter of the spatial kernel function, which controls the degree of smoothness in the spatial dimension; n is the number of spatial dimensions (for example, n=2 in two-dimensional space); ∥xy∥ is the Euclidean distance between the position vectors x and y;
[0072] Pre-set density thresholds based on historical data and management expectations for network anomalies;
[0073] When the acquired abnormal density D(t,x) exceeds the expectation, it means that the current network abnormal events are frequent and the density is high. At this time, a key factor extraction instruction is sent to the outside.
[0074] When using, combine the contents in steps 201 to 203:
[0075] Based on the continuous occurrence of network abnormal events, the status data of network abnormal events is collected to construct the abnormality density D(t,x). According to the abnormality density D(t,x), a comprehensive evaluation is made on the status of continuous abnormalities in the current stage to judge the density and comprehensive severity of network abnormalities. Based on the comprehensive judgment, it can be determined whether it is necessary to adjust, control or maintain each network device, which plays a guiding role in subsequent network optimization control and test measurement.
[0076] Step 3: After selecting key influencing factors from the correlation data, use the sparse regression model and variance inflation factor to screen out the target features, and generate corresponding response plans based on the target features to match the network abnormal events;
[0077] The step three includes the following contents:
[0078] Step 301: After receiving the key factor extraction instruction, the influencing factors highly correlated with the network status are preliminarily screened out in the operating environment and the equipment operating status by using correlation analysis; the principal component analysis is applied to reduce the dimension of the preliminarily screened influencing factors, and the multidimensional features are converted into a few principal components by constructing a principal component matrix to retain the main variation information of the data and obtain the corresponding key influencing factors;
[0079] When in use, through key factor extraction, the key factors affecting the current network anomaly are determined from among many factors. When the network anomaly needs to be processed, the corresponding processing strategy can be formulated or matched based on the extracted key influencing factors, and targeted optimization or control can be performed;
[0080] Step 302: Use the sparse regression model to further screen the key influencing factors using the least absolute shrinkage and LASSO selection operator regression to obtain the screened key influencing factors in the following manner:
[0081] By introducing L1 regularization terms and penalty regression coefficients, insignificant feature coefficients are automatically compressed to zero, achieving feature selection and model simplification;
[0082]
[0083] Among them, y i is the correlation coefficient, x ij is the jth feature, β j is the regression coefficient, λ is the regularization parameter, and the optimal value is determined by cross-validation;
[0084] After the key influencing factors are initially screened, further screening of the key influencing factors can be achieved, which helps to improve the efficiency of maintenance and reduce the corresponding workload;
[0085] Step 303: Calculate the variance inflation factor (VIF) of the selected key influencing factors, remove or merge the selected key influencing factors whose VIF values exceed a preset threshold (such as 10) to reduce the linear correlation between features, and use the selected key factors as target features; in, is the regression determination coefficient of feature j and all other features;
[0086] After marking the network abnormal events with target features, automatic response rules are defined based on the event types and attributes of the network abnormal events. After the network abnormal events occur, response plans are automatically generated according to the event types and automatic response rules; for example, automatic control of corresponding equipment or control of current environmental conditions;
[0087] When using, combine the contents in steps 301 to 303:
[0088] When network abnormal events occur frequently in the current stage, several external factors that may cause the current network status abnormality are determined, such as environmental conditions, etc. By extracting and screening multi-level key factors, several influencing factors with the greatest impact on network abnormalities are finally determined, which can ensure the reliability of the influencing factors; on this basis, when processing network equipment and network abnormal events, the processing effect can be improved.
[0089] Step 4: After abnormality detection of network quality, if there is any abnormality in network quality, visualize the changes in network data of each network device;
[0090] The step 4 includes the following contents:
[0091] Step 401: train the isolation forest algorithm with the labeled sample data to obtain a trained abnormal network detection model;
[0092] Treat each network device in the network as an independent node in the flow chart, measure and collect network quality data of each independent node, including network performance indicators, connection quality indicators and service quality indicators, etc.;
[0093] Taking real-time network quality data as input, the trained abnormal network detection model is used to perform anomaly detection, verify whether the current network quality data has anomalies, and obtain anomaly detection data; thus, the current network anomaly events are verified based on the actual anomaly detection data;
[0094] It is also possible to obtain corresponding detection feedback data, such as reliability and accuracy, after verifying the anomaly detection data; introduce an adaptive threshold setting method based on dynamic statistical analysis, and adjust the anomaly detection threshold in real time based on the change trend of historical data and detection feedback data to reduce false positives and false negatives;
[0095] Step 402: assign network quality data, environmental condition data and equipment operation status data of the corresponding stage to each node; connect each node through directed edges to indicate the change status of network quality; superimpose a heat map element on each node based on the flow chart, and use color gradient to indicate the degree of network quality;
[0096] When using, combine the contents in steps 401 and 402:
[0097] When in use, based on obtaining the current specific network quality data, the network equipment and the corresponding network quality data are visualized, which can display the current network status in real time, and facilitate tracing when network abnormal events occur, further improving the targeted processing.
[0098] Step 5: After the network quality analysis report is generated from the visualized network quality data, the current network measurement scenario is identified. When the current network measurement scenario meets the preset rule conditions, the corresponding measurement plan is output and optimized, and the measurement plan is executed to complete the current delay measurement process;
[0099] The step five includes the following contents:
[0100] Step 501: Map the network quality of each node to the corresponding color intensity I(Q), and use a linear or nonlinear mapping function to enhance the color contrast and improve the degree of easy identification. The Sigmoid function enhances the contrast of the middle area through smooth transition, which is suitable for scenes that require balanced contrast in the entire range.
[0101]
[0102] Where: I(Q) is the color intensity after mapping, ranging from [0, I max ], usually I max =255, Q is the network quality index, normalized to [0, 1]; k is the slope parameter, which controls the steepness of the Sigmoid function, and Q0 is the midpoint parameter, which determines the center position of the Sigmoid function;
[0103] Bind network quality data in time series, automatically identify and mark key time points and stages where network quality data increases or decreases, and automatically generate network quality analysis reports based on changes in network quality;
[0104] When in use, systematic data integration improves data readability and comprehension, provides powerful visualization tools, supports efficient handling of network anomalies, and ensures the consistency and efficiency of network anomaly handling.
[0105] Step 502: Identify and classify the current network quality abnormality and define different types of network measurement scenarios, including network equipment operation abnormality, environmental condition abnormality, and network security abnormality.
[0106] Build a rule-based automated response engine. When the current network measurement scenario meets the preset rule conditions, re-output the corresponding measurement plan. Based on the current equipment operation data and environmental condition data as feedback, use the genetic algorithm to optimize the current matching measurement plan, quickly generate the optimal measurement plan for specific abnormal situations, and execute the measurement plan to complete the current delay measurement process.
[0107] When using, combine the contents in steps 501 and 502:
[0108] When there is an abnormality in the current network quality, after combining the environmental conditions of the current network equipment, the key factors causing the abnormality and the current network measurement scenario, targeted output and optimization are performed to obtain the corresponding measurement plan. Therefore, when it is necessary to measure the network, the optimized measurement plan is executed to make the measurement plan more adapted to the actual scenario. It can also effectively prevent the current abnormal measurement environment and network quality from interfering with the current network measurement process and affecting the reliability and effectiveness of the network measurement.
[0109] See also Figure 2 The present invention provides a distributed network delay measurement system, comprising:
[0110] The abnormal event detection unit collects the operation scenario data of the network equipment and performs real-time detection of network abnormal events. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued;
[0111] The event topic allocation unit allocates corresponding topics to network abnormal events, makes predictions and generates abnormal reports. It generates abnormal density of abnormal events from network abnormal event data. When the abnormal density exceeds expectations, it sends key factor extraction instructions to the outside.
[0112] The factor identification unit selects key influencing factors from the correlation data, and then uses the sparse regression model and variance inflation factor to screen out the target features, and generates corresponding response plans based on the target features for matching network abnormal events;
[0113] The network quality detection unit detects abnormalities in the network quality and visualizes the changes in network data of each network device if there are any abnormalities in the network quality.
[0114] The measurement scheme generating unit generates a network quality analysis report from the visualized network quality data, identifies the current network measurement scenario, outputs and optimizes the corresponding measurement scheme when the current network measurement scenario meets the preset rule conditions, and executes the measurement scheme to complete the current delay measurement process;
[0115] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0116] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0117] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only some logical function divisions. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0118] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0119] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A distributed network delay measurement method, characterized in that: include, After collecting the operation scenario data of network equipment, real-time detection of network abnormal events is performed. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued; After assigning corresponding topics to network abnormal events, predictions are made and abnormal reports are generated. The abnormal density D(t,x) of abnormal events is generated from the network abnormal event data. When the abnormal density D(t,x) exceeds expectations, key factor extraction instructions are sent to the outside. Select key influencing factors from correlation data, use sparse regression model and variance inflation factor to screen out target features, and generate corresponding response plans based on target features to match network abnormal events; Perform abnormality detection on network quality. If there is any abnormality in network quality, visualize the changes in network data of each network device. Generate a network quality analysis report from the visualized network quality data, identify the current network measurement scenario, and when the current network measurement scenario meets the preset rule conditions, output the corresponding measurement plan and optimize it, and execute the measurement plan to complete the current delay measurement process; wherein, the network quality of each node is mapped to the corresponding color intensity I(Q), and the contrast of the middle area is enhanced through smooth transition, wherein, Where: I(Q) is the color intensity after mapping, ranging from [0, I max ], I max =255, Q is the network quality index, normalized to [0, 1]; k is the slope parameter, which controls the steepness of the Sigmoid function, and Q0 is the midpoint parameter, which determines the center position of the Sigmoid function.
2. The distributed network delay measurement method according to claim 1, characterized in that: Deploy sensor networks on network devices to collect environmental conditions and network equipment operating status data of each link in real time, and combine them with the acquired network equipment operating scenario data; convert the format of operating scenario data from different sources, time-align multi-source data through timestamp synchronization, and then use Bayesian network to fuse multi-source data.
3. The distributed network delay measurement method according to claim 2, characterized in that: Define network abnormal events based on event-driven architecture and detect them in real time. Predefine abnormal event types. Each type of abnormal event should have the following attributes: event ID, type, timestamp, source, details and priority. After aggregation, a collection of network abnormal events is generated. Integrate the rule engine in the real-time processing framework to define the detection rules for network abnormal events based on preset thresholds and conditions.
4. The distributed network delay measurement method according to claim 3, characterized in that: After receiving the alarm instruction, the topic mechanism of Apache Kafka is used to assign different types of network abnormal events to corresponding topics, and multiple event receiving ends are configured so that the event receiving ends pay attention to the corresponding event topics and are responsible for receiving and processing network abnormal events; Use the trained abnormal event prediction model to predict network abnormal events; Generate exception reports of network abnormal events regularly, including event type, frequency of occurrence, and processing effect, abnormal events that may occur in the next stage, and send the exception reports to the event receiving end.
5. The distributed network delay measurement method according to claim 4, characterized in that: Collect and record the network abnormal event data in the current stage, including the abnormal time node, abnormal location node and the corresponding abnormal degree, and generate the abnormal density D(t,x) of the abnormal event from the network abnormal event data in the following way: Where: D(t,x) is the density of anomalies at time t and location x, T is the time window length, Ω is the spatial inspection area; s(τ,y) is the severity of anomalies at time τ and location y, K t (t-τ) is the time kernel function, K x (xy) is the spatial kernel function; x, y are spatial position vectors, τ is the integral variable representing time, and y is the integral variable representing spatial position.
6. The distributed network delay measurement method according to claim 5, characterized in that: After receiving the key factor extraction instruction, the influencing factors highly correlated with the network status are preliminarily screened out; principal component analysis is applied to reduce the dimension of the preliminarily screened influencing factors to obtain the corresponding key influencing factors; The sparse regression model is used to screen the key influencing factors using the least absolute shrinkage and LASSO selection operator regression to obtain the screened key influencing factors.
7. The distributed network delay measurement method according to claim 6, characterized in that: Calculate the variance inflation factor (VIF) of the key influencing factors after screening, remove or merge the key influencing factors whose VIF values exceed the preset threshold, and use the screened key factors as target features; After marking the network abnormal events with target features, automatic response rules are defined based on the event types and attributes of the network abnormal events. After the network abnormal events occur, response plans are automatically generated according to the event types and automatic response rules.
8. The distributed network delay measurement method according to claim 7, characterized in that: Treat each network device in the network as an independent node in the flow chart, measure and collect network quality data of each independent node; use the real-time network quality data as input, use the trained abnormal network detection model to perform anomaly detection, and obtain anomaly detection data; Each node is assigned network quality data, environmental condition data and equipment operation status data of the corresponding stage. The nodes are connected by directed edges to represent the change status of network quality. On the basis of the flow chart, a heat map element is superimposed on each node, and color gradient is used to represent the degree of network quality.
9. The distributed network delay measurement method according to claim 8, characterized in that: Bind network quality data in time series, automatically identify and mark key time points and stages where network quality data increases or decreases, and automatically generate network quality analysis reports based on changes in network quality; Identify and classify current network quality anomalies, define different types of network measurement scenarios, build a rule-based automated response engine, use current equipment operation data and environmental condition data as feedback, use genetic algorithms to optimize the current matching measurement scheme, and quickly generate the optimal measurement scheme for specific abnormal situations.
10. A distributed network delay measurement system, characterized in that: include, The abnormal event detection unit collects the operation scenario data of the network equipment and performs real-time detection of network abnormal events. If the network abnormal event meets the preset rule conditions, a corresponding event is generated and an alarm instruction is issued; The event topic allocation unit allocates corresponding topics to network abnormal events, makes predictions and generates abnormal reports. It generates abnormal density of abnormal events from network abnormal event data. When the abnormal density exceeds expectations, it sends key factor extraction instructions to the outside. The factor identification unit selects key influencing factors from the correlation data, and then uses the sparse regression model and variance inflation factor to screen out the target features, and generates corresponding response plans based on the target features for matching network abnormal events; The network quality detection unit detects abnormalities in the network quality and visualizes the changes in network data of each network device if there are any abnormalities in the network quality. The measurement scheme generation unit generates a network quality analysis report from the visualized network quality data, identifies the current network measurement scenario, and outputs and optimizes the corresponding measurement scheme when the current network measurement scenario meets the preset rule conditions, and executes the measurement scheme to complete the current delay measurement process.
Citation Information
Patent Citations
Network delay measurement method based on TCP protocol
CN106961365A
Remote fault monitoring method, device and equipment of router and storage medium
CN117675691A
Abnormality detection method and device, electronic equipment and computer program product
CN118804029A
Classification of detected network anomalies using additional data
US20160254944A1
Event-triggered machine learning for rare event forecasting in a software defined wide area network (sd-wan)
US20210160148A1