Method and device for determining service path based on stream detection, and electronic equipment
By obtaining and analyzing the flow detection data of network equipment based on the flow detection method, the problem of difficult traffic paths in complex network environments is solved, and the accurate restoration and monitoring of business paths is achieved.
Patent Information
- Application Number
- CN202510183852.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-23
AI Technical Summary
In complex network environments, traditional network management and monitoring tools are difficult to accurately restore and track business paths, and cannot meet the needs of the current network environment.
Using a method based on flow detection, by obtaining the flow detection data of each target device, multiple transmission devices corresponding to each service flow are determined, and the interfaces of the transmission device are sorted and connected according to the flow node identification information, time stamp information, flow direction information, interface information, and LLDP information to determine the service path.
It realizes the accurate restoration of a single service path from complex network traffic, solving the problem that traditional methods cannot accurately restore the service path in complex network environments.
Smart Images

Figure CN120034481A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network communications, and in particular to a method, device and electronic device for determining a service path based on flow detection. Background Art
[0002] In the field of modern network communications, with the rapid development of the Internet and the diversification of network applications, the network structure has become extremely complex; in order to provide more stable and efficient network services, enterprises and service providers continue to implement multi-layer, multi-protocol network architectures. Such a network environment makes the service path, that is, the route of data from the sender to the receiver, difficult to track and analyze, and traditional network management and monitoring tools can usually only provide static network topology information. Therefore, existing technologies are difficult to meet the needs of accurately restoring service paths in the current network environment. Summary of the invention
[0003] The object of the present invention is to provide a method, device and electronic device for determining a service path based on flow detection, so as to accurately restore a single service path from complex network traffic.
[0004] The present invention provides a method for determining a service path based on flow detection, the method comprising:
[0005] Acquire the flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function;
[0006] According to each flow detection data, multiple transmission devices corresponding to each service flow are determined from multiple target devices; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, and interface information;
[0007] According to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, the interfaces of multiple transmission devices corresponding to each business flow are sorted and connected to determine the business path corresponding to each business flow; wherein the LLDP information pre-configured by each transmission device is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
[0008] Furthermore, the step of obtaining the in-flow detection data of at least one service flow corresponding to each target device includes:
[0009] Obtain a configuration message of a first device; the first device is a disabled device;
[0010] Send each configuration message to the corresponding first device through NETCONF to perform global configuration of the flow detection on each first device to obtain a target device list; wherein the target device list includes multiple target devices configured with the flow detection function;
[0011] Based on at least one pre-configured flow detection task, determine a source device corresponding to each flow detection task from a plurality of target devices; wherein each flow detection task corresponds to a service flow; and the flow detection task includes reporting configuration information;
[0012] Each flow detection task is sent to the corresponding source device, and the flow detection data of at least one service flow reported to the collector by each target device according to the reporting configuration information is obtained.
[0013] Furthermore, each flow detection data further includes: flow identification information and cycle ID information; and the step of determining multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data includes:
[0014] The target devices corresponding to the flow detection data with the same flow identification information and period ID information are grouped into one group to obtain a grouping result corresponding to at least one flow identification information, wherein each grouping result includes multiple transmission devices corresponding to the flow identification information.
[0015] Further, according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, the interfaces of multiple transmission devices corresponding to each service flow are sorted and connected to determine the service path corresponding to each service flow. The step includes:
[0016] For each service flow, according to the flow node identification information, flow direction information, and interface information in the flow detection data corresponding to the service flow, determine the source device and terminal device corresponding to the service flow from multiple transmission devices corresponding to the service flow, as well as the inbound interface and outbound interface of the source device, and the inbound interface and outbound interface of the terminal device;
[0017] If the number of transmission devices corresponding to the business flow is two, according to the pre-set first connection order, the input interface of the source device, the output interface of the source device, the input interface of the terminal device, and the output interface of the terminal device are connected in sequence to obtain the business path corresponding to the business flow.
[0018] Furthermore, the method also includes:
[0019] If the number of transmission devices corresponding to the service flow is greater than two, determine the intermediate device corresponding to the service flow based on the source device, the terminal device, and the multiple transmission devices corresponding to the service flow; where the intermediate device is other devices among the multiple transmission devices except the source device and the terminal device.
[0020] According to the flow node identification information, timestamp information, flow direction information, and interface information in the target flow detection data of the service flow corresponding to the intermediate device, sort and connect the interfaces of the intermediate device corresponding to the service flow in ascending order of the timestamp to obtain the first intermediate path corresponding to the service flow.
[0021] Obtain the second intermediate path corresponding to the service flow according to the pre-acquired LLDP information of the intermediate device.
[0022] If the first intermediate path is the same as the second intermediate path, determine the first intermediate path as the target intermediate path; if the first intermediate path is different from the second intermediate path, determine the second intermediate path as the target intermediate path.
[0023] Based on the target intermediate path, the inbound interface and outbound interface of the source device, and the inbound interface and outbound interface of the terminal device, determine the service path corresponding to the service flow.
[0024] Further, the steps of determining the service path corresponding to the service flow based on the target intermediate path, the inbound interface and outbound interface of the source device, and the inbound interface and outbound interface of the terminal device include:
[0025] If the target intermediate path is the first intermediate path, sequentially connect the inbound interface of the source device, the outbound interface of the source device, and the inbound interface of the first intermediate device; then sequentially connect the outbound interface of the second intermediate device, the inbound interface of the terminal device, and the outbound interface of the terminal device to obtain the service path corresponding to the service flow; where the inbound interface of the first intermediate device is the interface indicated by the interface information corresponding to the first target flow detection data with the smallest timestamp in the target flow detection data of the service flow corresponding to the intermediate device; the outbound interface of the second intermediate device is the interface indicated by the interface information corresponding to the second target flow detection data with the largest timestamp in the target flow detection data of the service flow corresponding to the intermediate device.
[0026] If the target intermediate path is the second intermediate path, determine the inbound interface of the third intermediate device to be connected to the source device according to the pre-acquired LLDP information of the source device; determine the outbound interface of the fourth intermediate device to be connected to the terminal device according to the pre-acquired LLDP information of the terminal device.
[0027] Connect the input direction interface of the source device, the output direction interface of the source device, and the input direction interface of the third intermediate device in sequence; then connect the output direction interface of the fourth intermediate device, the input direction interface of the terminal device, and the output direction interface of the terminal device in sequence to obtain the service path corresponding to the service flow; wherein the input direction interface of the third intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the source device; and the output direction interface of the fourth intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the terminal device.
[0028] Furthermore, each flow detection data also includes message quantity information; each flow detection task also includes service source information and customer information; the method also includes:
[0029] Restore the in-stream detection data of each service flow to the corresponding transmission equipment on the service path in real time;
[0030] According to the message quantity information, timestamp information and interface information corresponding to each flow detection data, the state information of the transmission path between each two adjacent transmission devices in the service path corresponding to each service flow is determined in real time; wherein the state information includes delay information, packet loss information and jitter information; the state information is presented in the form of a time axis;
[0031] According to the state information of the transmission path between every two adjacent transmission devices and the preset state information threshold, the abnormal transmission path is determined in real time, and the abnormal interface is determined according to the abnormal transmission path;
[0032] Determine an average value of state information of a service path corresponding to each service flow according to state information of a transmission path between every two adjacent transmission devices;
[0033] According to the average value of the service source information, customer information of the accompanying detection task corresponding to each service flow and the status information of the service path corresponding to each service flow, the average service information corresponding to each customer information and each service source information is obtained;
[0034] According to the average business information corresponding to each customer information and each business source information, each customer information and business source information is sorted according to multiple preset sorting requirements to obtain customer sorting results and business source sorting results corresponding to each sorting requirement.
[0035] The present invention provides a device for determining a service path based on flow detection, the device comprising:
[0036] An acquisition module, used to acquire the flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function;
[0037] A first determination module is used to determine multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, and interface information;
[0038] The second determination module is used to sort and connect the interfaces of multiple transmission devices corresponding to each business flow according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, so as to determine the business path corresponding to each business flow; wherein the LLDP information pre-configured by each transmission device is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
[0039] The present invention provides an electronic device, which includes a processor and a memory, wherein the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement any of the above-mentioned methods for determining a service path based on in-flight detection.
[0040] The present invention provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement any of the above-mentioned methods for determining a service path based on in-flight detection.
[0041] The present invention provides a method, device and electronic device for determining a service path based on flow detection, the method comprising: obtaining flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function; according to each flow detection data, determining multiple transmission devices corresponding to each service flow from multiple target devices; according to flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and LLDP information pre-configured for each transmission device, sorting and connecting the interfaces of multiple transmission devices corresponding to each service flow, so as to determine the service path corresponding to each service flow; in this way, service path restoration is performed based on flow detection, so that a single service path can be accurately restored from complex network traffic, thereby solving the problem that traditional network monitoring methods cannot accurately restore service paths in complex network environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0043] Figure 1 A flow chart of a method for determining a service path based on flow detection provided by an embodiment of the present invention;
[0044] Figure 2 A flowchart of another method for determining a service path based on flow detection provided by an embodiment of the present invention;
[0045] Figure 3 A schematic diagram of configuring a flow detection task provided by an embodiment of the present invention;
[0046] Figure 4 A schematic diagram of flow detection data provided by an embodiment of the present invention;
[0047] Figure 5 A schematic diagram of a visualized business topology diagram provided by an embodiment of the present invention;
[0048] Figure 6 Another schematic diagram of a visualized service topology diagram provided by an embodiment of the present invention;
[0049] Figure 7 A schematic diagram of the structure of a device for determining a service path based on flow detection provided by an embodiment of the present invention;
[0050] Figure 8 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0051] The technical solution of the present invention is clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0052] In the field of modern network communications, with the rapid development of the Internet and the diversification of network applications, the network structure has become extremely complex; in order to provide more stable and efficient network services, enterprises and service providers continue to implement multi-layer, multi-protocol network architectures. Such a network environment makes the service path, that is, the route of data from the sender to the receiver, difficult to track and analyze, and traditional network management and monitoring tools, such as the Simple Network Management Protocol (SNMP) and the Network Monitoring System (NMS), usually can only provide static network topology information, but cannot track dynamically changing service flows in real time. Therefore, how to accurately restore a single service path from complex network traffic is still a technical challenge.
[0053] In summary, the existing technology is difficult to meet the needs of accurate tracking and restoration of service paths in the current network environment. Therefore, it is necessary to develop a method that can effectively cope with complex network environments and accurately restore service paths. This has important practical significance for improving network management level and ensuring service quality.
[0054] Based on this, the present invention provides a method, device and electronic device for determining a service path based on flow detection, which can accurately restore the service path in a complex network environment through flow detection technology.
[0055] To facilitate understanding of this embodiment, a method for determining a service path based on flow detection disclosed in an embodiment of the present invention is first introduced in detail; Figure 1 As shown, the method comprises the following steps:
[0056] Step S102, acquiring the in-flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with the in-flow detection function.
[0057] Flow-Based Detection can be understood as a network traffic monitoring technology that can identify and track specific traffic in the network based on data packet header information.
[0058] A service path refers to the routing path that transmits specific service or application data from the source to the destination in the network.
[0059] In the specific implementation process, the in-flow detection data of the specific service flow detected by each target device can be obtained. The specific service flow can be one or more, which can be set according to actual needs.
[0060] Step S104, determining multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, and interface information.
[0061] In actual implementation, the transmission device corresponding to each business flow is actually the target device through which the business flow passes when transmitting specific services or application data in the network. It should be noted that there are multiple transmission devices corresponding to each business flow because there are at least two target devices through which each business flow passes when transmitting specific services or application data in the network.
[0062] In the specific implementation process, each target device may detect the along-flow detection data of one business flow, or may detect the along-flow detection data of multiple business flows; therefore, each target device may correspond to one along-flow detection data, or may correspond to multiple along-flow detection data; based on the acquired one or more along-flow detection data corresponding to each target device, the target device (that is, the multiple transmission devices corresponding to each business flow) through which each business flow passes when transmitting specific services or application data in the network can be determined from the multiple target devices.
[0063] Step S106, according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, the interfaces of multiple transmission devices corresponding to each business flow are sorted and connected to determine the business path corresponding to each business flow; wherein the LLDP information of each transmission device is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
[0064] In actual implementation, each flow detection data may include: flow node identification information, timestamp information, flow direction information, and interface information.
[0065] The above-mentioned flow node identification information can be understood as the identification information of the target device corresponding to the currently acquired flow detection data;
[0066] The above-mentioned flow direction information may be any one of Ingress (starting direction), Trans Input (input direction), Trans Output (output direction), and Egress (end direction);
[0067] The above timestamp information may be understood as the time point when the target device corresponding to the currently acquired flow detection data acquires the flow detection data.
[0068] The above interface information may be an inbound interface name or an outbound interface name of a target device corresponding to the currently acquired flow detection data.
[0069] LLDP (Link Layer Discovery Protocol) is a data link layer protocol. Network devices can notify other devices of their own status by sending LLDP information in the local network.
[0070] In the specific implementation process, after determining multiple transmission devices corresponding to each service flow from multiple target devices, the LLDP information of each transmission device can be obtained in advance. The LLDP information is used to indicate the target transmission device (that is, the neighboring device) connected to the transmission device and the interface information of the target transmission device (such as interface name, type, etc.).
[0071] Then, combined with the flow node identification information, timestamp information, flow direction information, interface information of the flow detection data of the business flow corresponding to each transmission device, and the LLDP information corresponding to each transmission device, the interfaces of multiple transmission devices corresponding to each business flow are sorted (that is, the arrival and departure order of each business flow on the corresponding multiple transmission devices is determined) and the interfaces of multiple transmission devices are connected according to the sorting to obtain the business path corresponding to each business flow.
[0072] As an emerging network traffic monitoring method, flow detection can identify specific business flows based on data packet header information. Through real-time analysis of data packets, flow detection can provide information such as the source / destination address, port number, and protocol type of the business flow. This technology has the ability to track the path of the business flow and is the key to achieving business path restoration.
[0073] The method for determining a service path based on flow detection provided by an embodiment of the present invention comprises: obtaining flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function; according to each flow detection data, determining multiple transmission devices corresponding to each service flow from multiple target devices; according to flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and LLDP information pre-configured for each transmission device, sorting and connecting the interfaces of multiple transmission devices corresponding to each service flow, so as to determine the service path corresponding to each service flow; in this method, service path restoration is performed based on flow detection, so that a single service path can be accurately restored from complex network traffic, thereby solving the problem that traditional network monitoring methods cannot accurately restore service paths in complex network environments.
[0074] The embodiment of the present invention also provides another method for determining a service path based on flow detection, which is implemented on the basis of the method in the above embodiment; Figure 2 As shown, the method comprises the following steps:
[0075] Step S202: Acquire in-flow detection data of at least one service flow corresponding to each target device.
[0076] In the specific implementation process, the above step S202 can be implemented by following the steps 1 to 4:
[0077] Step 1: Obtain a configuration message of a first device; the first device is a disabled device.
[0078] In actual implementation, the first device can be a device in the first device list. Specifically, the selected device list (equivalent to the first device list) can be obtained first, and the selected device list includes disabled devices (equivalent to the above-mentioned first device, that is, devices that have not yet been configured with the flow detection function); the information presented in the selected device list includes the device name, device address, device manufacturer, device model, device type, and affiliation of each disabled device. According to the device manufacturer of each disabled device, the configuration message corresponding to the manufacturer information of each disabled device can be obtained; then the configuration message corresponding to the manufacturer information of each disabled device can be determined as the configuration message corresponding to the disabled device (first device).
[0079] Step 2: Send each configuration message to the corresponding first device through NETCONF to perform global configuration of the flow detection on each first device to obtain a target device list; wherein the target device list includes multiple target devices configured with the flow detection function.
[0080] Specifically, when obtaining the selected device list, you can select the devices that support and need to perform flow detection from the list of devices to be selected in the form of header filtering according to the network topology corresponding to the current network environment, and then add the devices in the list of devices to be selected to the list of selected devices in batches in the form of a shuttle box, or delete the devices in the selected device list to the list of devices to be selected; among them, the devices presented in the list of devices to be selected are all unenabled devices, that is, devices that have not yet been configured with the flow detection function; the information presented in the selected device list includes the device name, device address, device manufacturer, device model, device type, and affiliation. It also supports reset operations. Click Reset and OK in turn to confirm twice, clear the list of selected devices, and add the device again.
[0081] The devices presented in the obtained selected device list (that is, each first device in the first device list) are actually devices that support and need to perform in-flight detection. In actual implementation, batch enabling configurations can be asynchronously issued to all devices in the selected device list to obtain an enabled device list (equivalent to a target device list).
[0082] NETCONF (Network Configuration Protocol) provides a set of protocols for communication between network management and network devices. The network management uses the NETCONF protocol to issue, modify, and delete the configuration of remote devices.
[0083] NETCONF can obtain configuration messages of each vendor's information based on the custom message template management function configuration, making the messages sent by new vendors configurable. This makes the management information a database that can be understood by computers, improves the computer's ability to process network management data, and thus improves network management capabilities.
[0084] In the specific implementation process, according to the device manufacturer of each device in the selected device list (that is, manufacturer information, such as Huawei, ZTE, etc.), the configuration message of each manufacturer can be obtained through NETCONF configuration, and then each configuration message is sent to the device of the corresponding manufacturer in the selected device list through NETCONF, that is, the devices in the selected device list are batch enabled, and the global configuration of flow detection is sent through NETCONF to realize the ability of adding and deleting devices to enable flow detection, and the devices (that is, target devices) to which the global configuration of flow detection has been sent are presented in the enabled device list (that is, the target device list). The information presented in the enabled device list includes device name, device address, device manufacturer, device model, device type, affiliation, and sending status.
[0085] Step three: based on at least one pre-configured flow detection task, determine the source device corresponding to each flow detection task from multiple target devices; wherein each flow detection task corresponds to a service flow; and the flow detection task includes reporting configuration information.
[0086] Specifically, it supports querying the issued flow detection tasks, and the query results are presented in the form of a list. The information presented in the flow detection task list generally includes the task name, source device name (that is, the name of the source device), VPN instance name, measurement period, measurement type, delay detection switch, task creation time, and delivery status. It also supports viewing the task details and reported data corresponding to each task in the flow detection task list; the task details can include task information, source network element, and flow information.
[0087] In actual implementation, it also supports the addition of new operations for flow detection tasks. Specifically, it supports customization and selection of existing business methods to configure flow detection tasks, and then the configured flow detection tasks can be sent to the corresponding source devices through NETCONF.
[0088] See Figure 3The configuration diagram of a flow detection task shown in the figure includes 5 parts, namely, selecting network elements, configuring detection flows, binding detection inflow ports, configuring flow detection information, and configuring flow detection reporting. Specifically, the network element selection includes the source device and the instance name. The target to which the flow detection task is to be issued is the source device, that is, the head node of the flow detection, and the source device can be selected from the enabled device list. The instance name refers to Huawei and ZTE instance, in the form of a string, case-sensitive, and does not support spaces. The length range is 1 to 31. ZTE and Huawei both have the instance name attribute, that is, when the manufacturer of the source device is Huawei or ZTE, its instance name is instance. In actual implementation, the source device and instance name can be configured according to actual needs.
[0089] When configuring the detection flow, you can customize the service flow to be detected (that is, the service flow corresponding to the flow detection task) according to the 5-tuple information. In actual implementation, you can configure the following information according to actual needs:
[0090] (1) Source IP, destination IP; IPv4 address, a dotted decimal string; IPv6 address, a hexadecimal string; blank means Any: no address is specified;
[0091] (2) Source port and destination port;
[0092] (3) IP address type: supports IPv4 address and IPv6 address;
[0093] (4) Protocol number, Differentiated Service Code (dscp);
[0094] (5) VRF / VPN name: Huawei VPN name, ZTE VRF name.
[0095] It should be noted that when configuring the detection flow, it also supports selecting defined services from the SDN controller as the target flow for in-flow detection, that is, the business flow to be detected. Specifically, the information presented in the list of services to be selected includes the business name, deployment city, customer name, IPv4 address segment, and IPv6 address segment. Single-select a defined service in the list of services to be selected, and generate the parameter information corresponding to the above (1)-(5) based on the business information corresponding to the selected service and fill it back into the custom form.
[0096] When binding the incoming port, it supports the operation of selecting the target incoming port for binding, and can be filtered by port name and address. Specifically, ordinary sub-interfaces are deployed in the form of vrf and main interface; for aggregated interfaces, they are bound according to the Trunk logical main interface; for sub-interfaces, they are usually sent down according to the main interface to which they belong; if the bound interface sent down is a sub-interface, the device side needs to convert the bound interface into a main interface according to the sub-interface name, and send it up and down on the main interface.
[0097] When configuring the flow detection information, you can configure the following information according to actual needs:
[0098] (1) Task name; (2) Measurement type, which can be end-to-end (e2e) or hop-by-hop trace; (3) Measurement period, which is usually 10s, 30s, or 60s; (4) Latency detection switch, which can be on or off.
[0099] When configuring the flow detection report, you can configure the following information according to actual needs:
[0100] (1) Telemetry subscription (which can be understood as a technology for remotely collecting data from physical or virtual devices at high speed) including opening and closing;
[0101] (2) Telemetry collector IP: supports IPv4 and IPv6;
[0102] (3)Telemetry collector listening port: default is 10100;
[0103] (4) Sampling period: 30s or 60s.
[0104] In actual implementation, the deletion of flow detection tasks is also supported. Specifically, you can check the box in the flow detection task list to delete the flow detection tasks and configurations. Batch deletion is supported. Click Delete for secondary confirmation, and the result will be returned after the deletion is successful.
[0105] Step 4: Send each in-flow detection task to the corresponding source device, and obtain the in-flow detection data of at least one business flow reported to the collector by each target device according to the reporting configuration information.
[0106] In the specific implementation process, after the flow detection task configuration is completed, one or more flow detection tasks can be selected for distribution. Specifically, each flow detection task corresponds to a target device for distribution (that is, the source device of the flow detection task), and different flow detection tasks can be distributed to the same target device.
[0107] After each configured flow detection task is sent to the corresponding source device, each target device can report the data of the business flow corresponding to each sent flow detection task (that is, flow detection data) to the probe analyzer through the telemetry collector according to the configured flow detection reporting data, and perform real-time collection and analysis. It can also perform multi-instance collection, and independently realize the real-time collection and analysis of telemetry reporting data of measurement results of devices from multiple manufacturers, including Huawei, ZTE, H3C, etc., and realize high availability and load balancing solutions for collection instances.
[0108] In actual implementation, each target device can generate measurement results according to the statistical period Period (that is, the flow detection data of the business flow corresponding to each issued flow detection task), and the generated measurement results are reported to the analyzer through the GPB mode of telemetry. Specifically, they can be reported according to the detection period or the subscription period. Among them, the inbound interface and the outbound interface of the target device usually generate a group of data respectively, that is, the flow detection data of any business flow detected by each target device includes two groups of data.
[0109] The deployment of flow detection at key nodes of the network is the basis of this solution. The deployment strategy takes into account network topology, traffic distribution and performance requirements to ensure that the information of key business flows is fully monitored while avoiding unnecessary resource consumption and network interference. The flow detection function is uniformly configured and managed among different network equipment manufacturers to ensure accurate tracking and reporting of data flows.
[0110] Step S204: Determine multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data.
[0111] For details, please refer to Figure 4 A schematic diagram of flow detection data is shown; the flow detection data of any service flow detected by each target device includes FlowMonID (flow identification information, which can be understood as the identification of the service flow corresponding to the currently acquired flow detection data), FlowNodeID (flow node identification information, that is, the identification of the target device that detects the flow detection data of the current service flow), Period (period information, that is, the statistical period, in seconds, the value is generally 1s, 10s, 30s, 60s, 300s, etc.), PeriodID (period ID information, the number of seconds from 1970 to the start time of the statistical period divided by Period; used to mark the same time period for the entire network), Direction (flow direction information, generally including Ingress, Trans Input, Trans Output, Egress), IfName (interface information, that is, the interface name of the message carried by the current service flow in the ingress or egress direction, for the trunk interface, it is reported according to the trunk member port), timestamp information (consisting of seconds and nanoseconds, Figure 4In which, TimestampSecond represents the integer value of the second part from 1970 to the moment when the delay measurement message is received, and TimestampNanoSecond represents the remaining nanosecond part); this information is the basis for path restoration; in specific implementation, the target devices corresponding to the flow detection data with the same flow identification information and cycle ID information can be grouped into a group to obtain a grouping result corresponding to at least one flow identification information, wherein each grouping result includes multiple transmission devices corresponding to the flow identification information; that is, the flow information from different target devices can be associated through FlowMonID and cycle ID, because FlowMonID and cycle ID are the same for the detection of the same flow on different target devices.
[0112] Specifically, after obtaining the accompanying flow detection data corresponding to each target device, assuming that through comparison it is found that the FlowMonID of the accompanying flow detection data corresponding to the target device A and the target device B are both a and the cycle ID are both b, it can be considered that the target device A and the target device B are the two transmission devices corresponding to the business flow a, that is, when the business flow a is transmitted over the network, it passes through the target device A and the target device B, and the target device A and the target device B are both transmission devices in the business path corresponding to the business flow a.
[0113] Step S206, according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, the interfaces of multiple transmission devices corresponding to each service flow are sorted and connected to determine the service path corresponding to each service flow.
[0114] In the specific implementation process, the above step S206 can be implemented by following the steps five to eleven:
[0115] Step 5: For each service flow, determine the source device, terminal device, inbound interface and outbound interface of the source device, and inbound interface and outbound interface of the terminal device corresponding to the service flow from multiple transmission devices corresponding to the service flow based on the flow node identification information, flow direction information, and interface information in the flow detection data corresponding to the service flow.
[0116] In fact, the transmission path of the message (ie, the service flow) in the network can be reconstructed using the collected flow detection data, thereby obtaining the service path of the service flow corresponding to each issued flow detection task.
[0117] In a specific implementation, for the flow identification information corresponding to each grouping result (that is, for each service flow), according to the flow node identification information and flow direction information in the accompanying flow detection data of each transmission device corresponding to the flow identification information, the source device (also called the source device, the head node of the transmission path) and the terminal device (that is, the tail node of the transmission path) corresponding to the flow identification information can be determined from the grouping result corresponding to the flow identification information; and according to the interface information and flow direction information in the accompanying flow detection data of the source device corresponding to the flow identification information, the input direction interface and the output direction interface of the source device corresponding to the flow identification information, as well as the input direction interface and the output direction interface of the terminal device corresponding to the flow identification information can be determined; wherein, the input direction interface of the source device is the starting point of the transmission path (that is, the service path), and the output direction interface of the terminal device is the end point of the transmission path.
[0118] In the specific implementation process, the accompanying flow detection data of any service flow detected by each target device includes two groups of data, and the flow direction information and interface information in the two groups of data are different; assuming that the flow identification information corresponding to a grouping result is a, the grouping result includes two transmission devices, one transmission device is the target device A, and the other transmission device is the target device B; the accompanying flow detection data corresponding to the target device A includes two groups of data A1 and data A2, respectively, and the accompanying flow detection data corresponding to the target device B includes two groups of data B1 and data B2, respectively; and the flow direction information in the data A1 is Ingress (starting direction), and the interface information is a1; the flow direction information in the data A2 is Trans Output (outgoing direction), and the interface information is a2; the flow direction information in the data B1 is Trans Input (incoming direction), and the interface information is b1; the flow direction information in the data B2 is Egress (ending direction), and the interface information is b2.
[0119] Then the transmission device corresponding to the flow detection data with the flow direction information of Ingress (that is, the target device A) can be determined as the source device of the business flow a, and the transmission device corresponding to the flow detection data with the flow direction information of Egress (that is, the target device B) can be determined as the terminal device of the business flow a; because the flow direction information in the data A1 is Ingress and the flow direction information in the data A2 is Trans Output, the interface information a1 in the data A1 is actually the input direction interface of the target device A (that is, the input direction interface of the source device), and the interface information a2 in the data A2 is actually the output direction interface of the target device A (that is, the output direction interface of the source device); and because the flow direction information in the data B1 is Trans Input and the flow direction information in the data B2 is Egress, the interface information b1 in the data B1 is actually the input direction interface of the target device B (that is, the input direction interface of the terminal device), and the interface information b2 in the data B2 is actually the output direction interface of the target device B (that is, the output direction interface of the terminal device).
[0120] Step six: If the number of transmission devices corresponding to the service flow is two, connect the input interface of the source device, the output interface of the source device, the input interface of the terminal device, and the output interface of the terminal device in sequence according to the pre-set first connection order to obtain the service path corresponding to the service flow.
[0121] In actual implementation, if the measurement type is configured as end-to-end when configuring the flow detection information of a flow detection task, the number of transmission devices corresponding to the service flow detected by the flow detection task is two, one as the source device and the other as the terminal device; if the measurement type is configured as hop-by-hop, the number of transmission devices corresponding to the service flow detected by the flow detection task is generally greater than two (for example, three, four, etc.), one as the source device, one as the terminal device, and the rest as intermediate devices.
[0122] Therefore, the above-mentioned first connection sequence is generally set to: the input interface of the source device-the output interface of the source device-the input interface of the terminal device-the output interface of the terminal device; it should be noted that the input interface and the output interface of each device need to be connected through the device. Taking the target device A as an example, when connecting the input interface a1 and the output interface a2 of the target device A, it is necessary to pass through the target device A. When connected according to the above-mentioned first connection sequence, the first intermediate path corresponding to the service flow a is actually: a1-a2-b1-b2.
[0123] Step 7: If the number of transmission devices corresponding to the business flow is greater than two, determine the intermediate device corresponding to the business flow based on the source device, terminal device, and multiple transmission devices corresponding to the business flow; wherein the intermediate device is other devices among the multiple transmission devices except the source device and the terminal device.
[0124] Step 8: According to the flow node identification information, timestamp information, flow direction information, and interface information in the target flow detection data of the business flow corresponding to the intermediate device, sort and connect the interfaces of the intermediate devices corresponding to the business flow in ascending order of timestamps to obtain the first intermediate path corresponding to the business flow.
[0125] In actual implementation, by comparing the timestamps in the target flow detection data corresponding to the intermediate devices, the interfaces of the intermediate devices (that is, the interfaces indicated by the interface information in the target flow detection data) can be arranged in ascending order according to the timestamps to determine the arrival and departure order of the messages carried by the corresponding business flow on each intermediate device, which helps to determine the transmission path of the message in the network, that is, to determine the business path corresponding to the business flow.
[0126] In the specific implementation process, the number of intermediate devices may be one or more; it is assumed that the grouping result corresponding to the flow identification information a includes four transmission devices, namely, target device A, target device B, target device C, and target device D; target device A is a source device, target device B is a terminal device, and target device C and target device D are intermediate devices; the two groups of data included in the flow detection data corresponding to target device C are data C1 and data C2, and the two groups of data included in the flow detection data corresponding to target device D are data D1 and data D2; and the flow node identification information in data C1 is C, the timestamp information is t1, the flow direction information is Trans Input, and the interface information is c1, and the flow node identification information in data C2 is also C, the timestamp information is t2, the flow direction information is Trans Output, and the interface information is c2; the flow node identification information in data D1 is D, the timestamp information is t3, the flow direction information is Trans Input, and the interface information is d1, and the flow node identification information in data D2 is also D, the timestamp information is t4, the flow direction information is Trans Output, and the interface information is d2.
[0127] Assume that after comparing the timestamp information t1, t2, t3, and t4, it is obtained that t2>t1>t4>t3. Since the interface information corresponding to t1 is c1, the interface information corresponding to t2 is c2, the interface information corresponding to t3 is d1, and the interface information corresponding to t4 is d2, then the interfaces of the intermediate devices are sorted in order from small to large according to the timestamps and connected in sequence to obtain the first intermediate path corresponding to the business flow a: d1-d2-c1-c2; that is, the arrival and departure order of the message carried by the business flow a on the above-mentioned intermediate devices (target device C and target device D) is: the message arrives at the target device D via the inbound interface d1 of the target device D, and then arrives at the target device C via the outbound interface d2 of the target device D and the inbound interface c1 of the target device C, and finally is received via the outbound interface c2 of the target device C.
[0128] Step nine: According to the pre-acquired LLDP information of each transmission device, obtain the second intermediate path corresponding to the service flow.
[0129] In actual implementation, the LLDP information of each transmission device is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device. If the transmission devices of business flow a include target device A (source device), target device B (terminal device), target device C (intermediate device) and target device D (intermediate device), and the LLDP information of target device A indicates that target device A is connected to interface c1 of target device C, the LLDP information of target device C indicates that target device C is connected to interface a2 of target device A and to d1 of target device D, the LLDP information of target device D indicates that target device D is connected to interface c2 of target device C and to b1 of target device B, and the LLDP information of target device B indicates that target device B is connected to interface d2 of target device D; then it can be determined that the second intermediate path corresponding to the above-mentioned business flow a is: c1-c2-d1-d2.
[0130] Step 10: If the first intermediate path is the same as the second intermediate path, the first intermediate path is determined as the target intermediate path; if the first intermediate path is different from the second intermediate path, the second intermediate path is determined as the target intermediate path.
[0131] In the specific implementation process, the timestamp information in the target flow detection data of the service flow corresponding to the intermediate device may be different from the actual situation. Therefore, according to the order of timestamps from small to large, the first intermediate path obtained may not be accurate; in this regard, the LLDP information of each transmission device can be combined to obtain the information of the neighboring device (that is, the target transmission device) directly connected to each transmission device itself, and obtain the second intermediate path, so as to better understand the network topology structure, discover device neighbors to determine the transmission path of the message in the network. Then, by comparing the first intermediate path and the second intermediate path, the target intermediate path is determined, which can avoid the problem of the first intermediate path being inaccurate due to incorrect timestamp information obtained.
[0132] Specifically, when the second intermediate path corresponding to the business flow is obtained based on the LLDP information of each transmission device obtained in advance, the second intermediate path is generally considered to have a higher accuracy because the timestamp does not need to be considered; therefore, when comparing the first intermediate path and the second intermediate path, if the first intermediate path is the same as the second intermediate path, it is generally considered that the timestamp information is consistent with the actual situation, and the first intermediate path can be determined as the target intermediate path; if the first intermediate path is different from the second intermediate path, it is generally considered that the timestamp information is inconsistent with the actual situation, that is, according to the order of timestamps from small to large, the accuracy of the obtained first intermediate path is low, and the second intermediate path can be determined as the target intermediate path.
[0133] It should be noted that, during actual execution, the LLDP information of a transmission device corresponding to the business flow may be missing, and the LLDP information of each transmission device cannot be obtained. Therefore, the second intermediate path corresponding to the business flow cannot be obtained. In this regard, the first intermediate path corresponding to the business flow can be directly determined as the target intermediate path.
[0134] Step 11: Based on the target intermediate path, the inbound interface and the outbound interface of the source device, and the inbound interface and the outbound interface of the terminal device, determine the service path corresponding to the service flow.
[0135] In the specific implementation process, the above step 11 can be implemented by following steps A to B:
[0136] Step A: If the target intermediate path is the first intermediate path, the inbound interface of the source device, the outbound interface of the source device, and the inbound interface of the first intermediate device are connected in sequence; and then the outbound interface of the second intermediate device, the inbound interface of the terminal device, and the outbound interface of the terminal device are connected in sequence to obtain the service path corresponding to the service flow; wherein the inbound interface of the first intermediate device is the interface indicated by the interface information corresponding to the first target with-flow detection data with the smallest timestamp in the target with-flow detection data of the service flow corresponding to the intermediate device; and the outbound interface of the second intermediate device is the interface indicated by the interface information corresponding to the second target with-flow detection data with the largest timestamp in the target with-flow detection data of the service flow corresponding to the intermediate device.
[0137] In actual implementation, the analyzer can begin to reconstruct the actual transmission path of the message (that is, the business path of the business flow) by using the target intermediate path of the business flow, the input interface and output interface of the source device, and the input interface and output interface of the terminal device.
[0138] Specifically, when the target intermediate path of service flow a is the first intermediate path, assuming that the first intermediate path is d1-d2-c1-c2, the input direction interface of the source device is the input direction interface a1 of the target device A, and the output direction interface of the source device is the output direction interface a2 of the target device A; the input direction interface of the terminal device is the input direction interface b1 of the target device B, and the output direction interface of the terminal device is the output direction interface b2 of the target device B; the input direction interface of the first intermediate device is the input direction interface d1 of the target device D, and the output direction interface of the second intermediate device is the output direction interface c2 of the target device C; then after connecting according to the above step A, the service path corresponding to the service flow a is: a1-a2-d1-d2-c1-c2-b1-b2.
[0139] Step B: If the target intermediate path is the second intermediate path, determine the input direction interface of the third intermediate device to be connected to the source device according to the LLDP information of the source device obtained in advance; determine the output direction interface of the fourth intermediate device to be connected to the terminal device according to the LLDP information of the terminal device obtained in advance; connect the input direction interface of the source device, the output direction interface of the source device, and the input direction interface of the third intermediate device in sequence; then connect the output direction interface of the fourth intermediate device, the input direction interface of the terminal device, and the output direction interface of the terminal device in sequence to obtain the service path corresponding to the service flow; wherein, the input direction interface of the third intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the source device; and the output direction interface of the fourth intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the terminal device.
[0140] Specifically, when the target intermediate path of service flow a is the second intermediate path, assuming that the second intermediate path is c1-c2-d1-d2, the input direction interface of the source device is the input direction interface a1 of the target device A, and the output direction interface of the source device is the output direction interface a2 of the target device A; the input direction interface of the terminal device is the input direction interface b1 of the target device B, and the output direction interface of the terminal device is the output direction interface b2 of the target device B; the input direction interface of the third intermediate device is the input direction interface c1 of the target device C, and the output direction interface of the fourth intermediate device is the output direction interface d2 of the target device D; then after connecting according to the above step B, the service path corresponding to the service flow a is: a1-a2-c1-c2-d1-d2-b1-b2.
[0141] Step S208: restore the in-flight detection data of each service flow to the corresponding transmission device on the service path in real time.
[0142] Step S210: According to the message quantity information, timestamp information and interface information corresponding to each flow detection data, the status information of the transmission path between every two adjacent transmission devices in the service path corresponding to each service flow is determined in real time; wherein the status information includes delay information, packet loss information, and jitter information; the status information is presented in the form of a timeline.
[0143] In the specific implementation process, each flow detection data also includes the number of packets (for details, see Figure 4 PacketCount in, i.e., the number of packets in the detection cycle); each flow detection task also includes service source information and customer information. By using the timestamp data on each device, the analyzer can calculate the processing time of the packet on each transmission device (i.e., the difference result of the timestamp information in the two groups of data included in the flow detection data corresponding to the transmission device) and the transmission delay between nodes (i.e., the delay information of the transmission path between two adjacent transmission devices, specifically, it can be understood as the difference result of the timestamp information corresponding to the inbound interface of the transmission device in the sequence behind the two adjacent transmission devices and the timestamp information corresponding to the outbound interface of the transmission device in the sequence ahead), and calculate the jitter between nodes according to the transmission delay between nodes (i.e., the difference result of the transmission delay between the nodes corresponding to the current detection cycle and the transmission delay between the nodes corresponding to the previous detection cycle); by using the message quantity information on each device, the analyzer can calculate the packet loss rate between nodes (i.e., the difference value of the message quantity information corresponding to the inbound interface of the transmission device in the sequence behind the two adjacent transmission devices and the message quantity information corresponding to the outbound interface of the transmission device in the sequence ahead).
[0144] Step S212: According to the state information of the transmission path between every two adjacent transmission devices and a preset state information threshold, an abnormal transmission path is determined in real time, and an abnormal interface is determined according to the abnormal transmission path.
[0145] The above-mentioned status information thresholds generally include a delay threshold, a jitter threshold, and a packet loss threshold; specifically, the status information threshold can be set according to actual conditions. Normally, the delay threshold is configured to 10us, the jitter threshold is configured to 10us, and the packet loss threshold is configured to 0.2%; if the status information of the transmission path between two adjacent transmission devices is greater than the status information threshold, that is, the three conditions of the delay information being greater than the delay threshold, the packet loss information being greater than the packet loss threshold, and the jitter information being greater than the jitter threshold are satisfied at the same time, then the transmission path between the two adjacent transmission devices is determined to be an abnormal transmission path, and the outbound interface and the inbound interface at both ends of the abnormal transmission path are abnormal interfaces.
[0146] In order to help network administrators better understand the transmission path and network performance of messages, the analyzer may generate a visual business topology diagram to display the transmission path of messages (that is, the business path corresponding to the business flow), the delay, jitter, and packet loss rate of each segment (that is, the status information of the transmission path between every two adjacent transmission devices in the business path), possible congestion points and other information (that is, the abnormal interface corresponding to the above-mentioned abnormal transmission path); in actual implementation, the data reported by each node of the flow detection can be restored to the topology, and the status information of the day can be presented in the form of a timeline; the latest status information is presented by default, and the timeline can be dragged to query the historical situation.
[0147] In actual implementation, it supports viewing the performance data reported by different flow detections, and the topology presents performance data linkage when switching flows. It also supports viewing flow summary data, which aggregates all flow detection performance reporting data to present the maximum end-to-end delay, jitter, and packet loss. Moreover, the transmission path, device interface, timeline, and business status in the business topology diagram can be presented in different colors according to the threshold configuration results. Specifically, the green business status is normal, and red and yellow are abnormal.
[0148] For a better understanding of the above embodiments, please refer to Figure 5 A schematic diagram of a visualized business topology diagram is shown; Figure 5What is presented in the figure is the relevant data of the service flow corresponding to the end-to-end flow detection task, including the service path corresponding to the service flow PE1_GigabitEthemet8 / 0 / 4-PE5_GigabitEthemet8 / 0 / 5, the status information of the transmission path between the two adjacent transmission devices PE1 and PE5 in the service path (wherein the delay is 102us, the jitter is 89us, and the packet loss rate is 0%); the end-to-end maximum packet loss rate, maximum delay and maximum jitter of the service path. Since the packet loss rate is less than the preset packet loss threshold, there is no display of abnormal transmission paths and abnormal interfaces, so the service status is displayed as normal. Since the time axis is displayed as the time point 9:37 in the time period from 00:00 to 24:00 on 2024-3-18, it can be known that what is presented in the figure is the relevant data of the corresponding service flow at that time point.
[0149] For details, please refer to Figure 6 Another visualized business topology diagram is shown; Figure 6 The figure shows the data of the service flow corresponding to the hop-by-hop flow detection task, including the service path corresponding to the service flow PE1_GigabitEthemet8 / 0 / 4-PE5_GigabitEthemet8 / 0 / 5. According to the service path, PE1 is the source device, PE5 is the terminal device, PC1 and PB1 are the intermediate devices. The status information of the transmission path between the two adjacent transmission devices PE1 and PC1 corresponds to: the delay is 531us, the jitter is 99us, and the packet loss rate is 26.31%; the status information of the transmission path between the two adjacent transmission devices PC1 and PB1 corresponds to: the delay is 313us, the jitter is 56us, and the packet loss rate is 0%; the status information of the transmission path between the two adjacent transmission devices PB1 and PE5 corresponds to: the delay is 132us, the jitter is 23us, and the packet loss rate is 0%. The end-to-end maximum packet loss rate of the path is 26.31%, the maximum delay is 531us, and the maximum jitter is 99us. Since the delay 531us corresponding to the transmission path between the two adjacent transmission devices PE1 and PC1 is greater than the delay threshold, the jitter 99us is greater than the jitter threshold, and the packet loss rate 26.31% is greater than the packet loss threshold; therefore, the transmission path between the two adjacent transmission devices PE1 and PC1 is displayed as an abnormal transmission path, and the outbound interface of the transmission device PE1 and the inbound interface of the transmission device PC1 (PC1_GigabitEthemet8 / 0 / 1) corresponding to the abnormal transmission path are displayed as abnormal interfaces, so the service status is displayed as abnormal. Since the time axis is displayed as the time point 15:31 in the time period from 00:00 to 24:00 on 2024-3-18, it can be known that the relevant data presented in the figure is the corresponding service flow at this time point.
[0150] In fact, due to problems such as uneven link quality, equipment performance differences, configuration errors or congestion that may exist in the network, the quality of service (QoS) often varies significantly between different network segments. These quality differences not only affect the user experience, but may also hide deeper network problems. However, existing network monitoring solutions often focus on the overall performance indicators of the network, such as total bandwidth utilization, equipment load, etc., rather than quality difference analysis for specific business flows, making it impossible to accurately locate the source of the problem and optimize network performance. In summary, existing technologies are difficult to meet the needs of quality difference analysis for business paths in the current network environment.
[0151] The present application can perform service path restoration and quality difference analysis based on flow detection, solving the problem that traditional network monitoring methods cannot accurately track service paths and evaluate service quality differences in complex network environments. Through advanced data collection, processing and analysis technologies, high-accuracy service path restoration and quality analysis of network service flows can be achieved (that is, analysis of differences in network service quality at different links), thereby improving the network's management level and service quality.
[0152] Step S214: Determine an average value of the state information of the service path corresponding to each service flow according to the state information of the transmission path between every two adjacent transmission devices.
[0153] In fact, each target flow of the flow detection (that is, the business flow to be detected) also corresponds to the business source and customer information (customer name); the flow detection data can be counted according to the business dimension, including business ID, business name, business source, deployment city, classification, customer name, ipv4 address segment, ipv6 address segment, maximum delay, minimum delay, average delay, maximum jitter, minimum jitter, average jitter, maximum packet loss, minimum packet loss, and average packet loss. Specifically, each flow detection task corresponds to a business (the business information of the business may include business ID, business name, business source, deployment city, classification, customer name, ipv4 address segment, and ipv6 address segment), and the business corresponds to a business flow. Based on the delay information, packet loss information, and jitter information of the transmission path between each two adjacent transmission devices in the business path corresponding to the business flow, the average value of the delay information, the average value of the packet loss information, and the average value of the jitter information corresponding to the business flow are calculated (equivalent to determining the average value of the state information of the business path corresponding to each business flow. Generally, an integer is taken by default).
[0154] Specifically, you can Figure 6 The delay information, packet loss information, and jitter information of the transmission path between each two adjacent transmission devices in the service path corresponding to the service flow shown in FIG. Figure 6As shown, the delay information of the transmission paths between every two adjacent transmission devices in the service path corresponding to the service flow of PE1_GigabitEthemet8 / 0 / 4 - PE5_GigabitEthemet8 / 0 / 5 is 531us, 313us, and 132us respectively, the jitter information is 99us, 56us, and 23us respectively, and the packet loss information is 26.31%, 0%, and 0% respectively. Therefore, the average value of the delay information corresponding to this service flow is (531 + 313 + 132) / 3 = 325us, the average value of the corresponding jitter information is (99 + 56 + 23) / 3 = 59us, and the average value of the corresponding packet loss information is (26.31% + 0% + 0%) / 3 = 9%.
[0155] Step S216: Obtain the average service information corresponding to each customer information and each service source information according to the service source information, customer information of the in - flow detection task corresponding to each service flow, and the average value of the status information of the service path corresponding to each service flow.
[0156] In actual implementation, the average delay, average packet loss, and average jitter of all customers can be statistically calculated according to the customers to which the services belong (i.e., customer information); the average delay, average packet loss, and average jitter corresponding to the four service sources of in - province self - owned, out - of - province self - owned, in - province external, and out - of - province external can also be statistically calculated according to the service sources to which they belong (including in - province self - owned, out - of - province self - owned, in - province external, and out - of - province external).
[0157] Specifically, the customer information of the in - flow detection task corresponding to each service flow can be obtained, and then the service flows with the same customer information can be grouped into one group to obtain at least one first grouping result. For each first grouping result, according to the average value of the delay information, the average value of the packet loss information, and the average value of the jitter information corresponding to each service flow in this grouping result, the average delay information, the average packet loss information, and the average jitter information corresponding to the customer information of the service flows in this grouping result can be calculated (equivalent to determining the average service information corresponding to each customer information. Generally, the integer value is taken by default).
[0158] Assuming that the customer information of business flows a, b, and c are all Kunming XX Game Company, business flows a, b, and c can be grouped together. If the average value of the delay information corresponding to business flow a is 20us, the average value of the packet loss information is 10%, and the average value of the jitter information is 10us; the average value of the delay information corresponding to business flow b is 5us, the average value of the packet loss information is 5%, and the average value of the jitter information is 15us; the average value of the delay information corresponding to business flow c is 5us, the average value of the packet loss information is 0%, and the average value of the jitter information is 5us; then the average delay information corresponding to the customer information of Kunming XX Game Company can be calculated to be (20+5+5) / 3=10us, the average packet loss information is (10+5+0) / 3=5%, and the average jitter information is (10+15+5) / 3=10us. Similarly, the average delay information, average packet loss information, and average jitter information corresponding to other customer information can also be calculated using the same calculation method, which will not be repeated here.
[0159] During the specific implementation process, it is also possible to obtain the service source information of the in-flow detection task corresponding to each service flow, and then group the service flows with the same service source information into a group to obtain at least one second grouping result. For each second grouping result, the average delay information, average packet loss information, and average jitter information corresponding to each service flow in the second grouping result can be used to calculate the average delay information, average packet loss information, and average jitter information corresponding to the service source information of the service flow in the grouping result (equivalent to determining the average service information corresponding to each service source information. Generally, an integer is taken by default).
[0160] Assuming that the service source information of service flows a, b, and d are all owned by the province, service flows a, b, and d can be divided into a group. If the average delay information corresponding to service flow a is 20us, the average packet loss information is 10%, and the average jitter information is 10us; the average delay information corresponding to service flow b is 5us, the average packet loss information is 5%, and the average jitter information is 15us; the average delay information corresponding to service flow d is 14us, the average packet loss information is 0%, and the average jitter information is 5us; then it can be calculated that the average delay information corresponding to the service source information owned by the province is (20+5+14) / 3=13us, the average packet loss information is (10+5+0) / 3=5%, and the average jitter information is (10+15+5) / 3=10us; similarly, the same calculation method can be used to calculate the average delay information, average packet loss information, and average jitter information corresponding to other service source information, which will not be repeated here.
[0161] Step S218: sort each customer information and each business source information according to the average business information respectively corresponding to each customer information and each business source information according to multiple preset sorting requirements to obtain customer sorting results and business source sorting results respectively corresponding to each sorting requirement.
[0162] The above-mentioned sorting requirements can be set according to actual conditions. For example, it can be ranked in ascending order (from small to large) or descending order according to the average delay, or it can be ranked in ascending order or descending order according to the average jitter information, or it can be ranked in ascending order or descending order according to the average packet loss information. However, in actual implementation, after obtaining the average delay information, average packet loss information, and average jitter information corresponding to each customer information and each business source information, it is generally prioritized to prioritize in ascending order according to the average delay.
[0163] Specifically, when obtaining customer sorting results, the default ranking can be based on the average delay in ascending order. Clicking the indicator triangle can switch to reverse order or switch indicator sorting (that is, switch sorting requirements). According to the customer sorting results, differences in customer service quality can be reflected, that is, when ranking in ascending order by average delay, the customer service quality of the customers at the front is better, while the customer service quality of the customers at the back is worse. Similarly, the service source sorting results can also reflect differences in customer service quality, that is, when ranking in ascending order by average delay, the service quality of the service sources at the front is better, while the service quality of the service sources at the back is worse.
[0164] In the specific implementation process, by comparing the service traffic quality indicators between different nodes, such as delay, jitter, packet loss rate, throughput, etc., quality difference analysis is performed. By building a quality scoring model, the performance differences between different network segments can be quantified and performance bottlenecks or potential failure points can be located. Quality difference analysis not only supports real-time monitoring, but also historical data analysis to reveal performance change trends and provide data support for network optimization.
[0165] The present application provides a method for determining a service path based on flow detection. Through the efficient deployment strategy of flow detection probes, not only can key network nodes be covered, but also resource waste can be avoided; through the efficient service path calculation algorithm, the path can be quickly restored with minimal computing cost; through the multi-dimensional quality indicator comparison method, the quality differences of network services can be comprehensively evaluated.
[0166] This application scheme integrates in-band performance monitoring data. Due to the large amount of data and the need for real-time and high accuracy, this scheme adopts Flink (Apache Flink is an open source stream processing framework developed by the Apache Software Foundation. Its core is a distributed stream data flow engine written in Java and Scala. Flink executes any stream data program in a data parallel and pipeline manner. Flink's pipeline runtime system can execute batch and stream processing programs. In addition, Flink's runtime itself also supports the execution of iterative algorithms) as the data processing engine, Telemetry-》Probe-》Kafka (a high-throughput distributed publish-subscribe messaging system that can process all action stream data of consumers on the website)-》Flink-》mysql. The entire processing architecture is reasonably designed and can realize real-time network log analysis. Since this scheme requires the association between large amounts of real-time data to ensure the accuracy of the program, it becomes very important to ensure the reliability of the association and the speed to adapt to real-time in the process of ensuring real-time processing of large amounts of data. In addition, you can also customize the NETCONF message template management function to make the configuration messages sent by new manufacturers configurable; make the management information a database that can be understood by computers, improve the computer's ability to process network management data, and thus improve network management capabilities.
[0167] The system functional architecture, design and development of this solution are all independently developed. Through testing, the visual configuration and issuance of Tencent game-specific network monitoring instance tasks have been achieved.
[0168] Redis: (Remote Dictionary Service) is an open source log-type, Key-Value database written in ANSI C, supporting the network, memory-based or persistent, and providing APIs in multiple languages.
[0169] IFIT (in-situ Flow Information Telemetry) is a passive detection technology that follows the flow. Its basic principle is similar to IPFPM and it uses the RFC 8321 coloring mechanism for performance measurement.
[0170] The embodiment of the present invention also provides a device for determining a service path based on flow detection, such as Figure 7As shown, the apparatus includes: an acquisition module 10, used to acquire the flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function; a first determination module 11, used to determine multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, interface information; a second determination module 12, used to sort and connect the interfaces of multiple transmission devices corresponding to each service flow according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and LLDP information pre-configured for each transmission device, so as to determine the service path corresponding to each service flow; wherein the LLDP information of each transmission device is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
[0171] The device for determining a service path based on flow detection provided by an embodiment of the present invention comprises: obtaining flow detection data of at least one service flow corresponding to each target device; wherein each target device is pre-configured with a flow detection function; according to each flow detection data, determining multiple transmission devices corresponding to each service flow from multiple target devices; according to flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and LLDP information pre-configured for each transmission device, sorting and connecting the interfaces of multiple transmission devices corresponding to each service flow, so as to determine the service path corresponding to each service flow; the device, based on flow detection, performs service path restoration, and can accurately restore a single service path from complex network traffic, thereby solving the problem that traditional network monitoring methods cannot accurately restore service paths in complex network environments.
[0172] The implementation principle and technical effect of the device for determining a service path based on in-flow detection provided in the embodiment of the present invention are the same as those of the aforementioned method for determining a service path based on in-flow detection. For the embodiment of the device for determining a service path based on in-flow detection, reference can be made to the corresponding contents in the aforementioned method for determining a service path based on in-flow detection, which will not be repeated here.
[0173] The embodiment of the present invention further provides an electronic device, see Figure 8 As shown, the electronic device includes a processor 130 and a memory 131 , wherein the memory 131 stores machine executable instructions that can be executed by the processor 130 , and the processor 130 executes the machine executable instructions to implement the above-mentioned method for determining a service path based on in-flow detection.
[0174] Further, Figure 8The electronic device shown further includes a bus 132 and a communication interface 133 , and the processor 130 , the communication interface 133 and the memory 131 are connected via the bus 132 .
[0175] The memory 131 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage. The communication connection between the system network element and at least one other network element is realized through at least one communication interface 133 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used. The bus 132 may be an ISA bus, a PCI bus, or an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0176] The processor 130 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 130. The above processor 130 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present invention can be implemented or executed. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in conjunction with the embodiments of the present invention can be directly embodied as a hardware decoding processor for execution, or a combination of hardware and software modules in the decoding processor for execution. The software module may be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 131, and the processor 130 reads the information in the memory 131 and completes the steps of the method of the above embodiment in combination with its hardware.
[0177] An embodiment of the present invention further provides a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to implement the above-mentioned method for determining a service path based on in-flight detection. For specific implementation, please refer to the method embodiment, which will not be repeated here.
[0178] The method, device and electronic device for determining a service path based on in-flow detection provided in the embodiments of the present invention include a computer-readable storage medium storing program code, and the instructions included in the program code can be used to execute the method described in the previous method embodiment. The specific implementation can be referred to the method embodiment, which will not be repeated here.
[0179] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.
[0180] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for determining a service path based on flow detection, characterized in that: The method comprises: Acquire the flow detection data of at least one service flow corresponding to each target device; wherein each of the target devices is pre-configured with a flow detection function; According to each flow detection data, multiple transmission devices corresponding to each service flow are determined from the multiple target devices; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, and interface information; According to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each of the transmission devices, the interfaces of multiple transmission devices corresponding to each business flow are sorted and connected to determine the business path corresponding to each business flow; wherein the LLDP information pre-configured by each of the transmission devices is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
2. The method according to claim 1, characterized in that The step of obtaining the in-flow detection data of at least one service flow corresponding to each target device includes: Obtain a configuration message of a first device; the first device is a disabled device; Send each of the configuration messages to the corresponding first device through NETCONF to perform global configuration of the flow detection on each of the first devices, and obtain a target device list; wherein the target device list includes multiple target devices configured with the flow detection function; Based on at least one pre-configured flow detection task, determine a source device corresponding to each flow detection task from a plurality of target devices; wherein each flow detection task corresponds to a service flow; and the flow detection task includes reporting configuration information; Each along-flow detection task is sent to the corresponding source device, and along-flow detection data of at least one service flow reported to the collector by each target device according to the reporting configuration information is obtained.
3. The method according to claim 2, characterized in that Each of the accompanying flow detection data further includes: flow identification information and cycle ID information; and the step of determining, according to each of the accompanying flow detection data, a plurality of transmission devices corresponding to each service flow from a plurality of the target devices includes: The target devices corresponding to the flow detection data with the same flow identification information and period ID information are grouped into one group to obtain a grouping result corresponding to at least one flow identification information, wherein each grouping result includes multiple transmission devices corresponding to the flow identification information.
4. The method according to claim 1, characterized in that: According to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each transmission device, the interfaces of multiple transmission devices corresponding to each service flow are sorted and connected to determine the service path corresponding to each service flow. The steps include: For each service flow, according to the flow node identification information, flow direction information, and interface information in the flow detection data corresponding to the service flow, determine the source device and terminal device corresponding to the service flow from multiple transmission devices corresponding to the service flow, as well as the inbound interface and outbound interface of the source device, and the inbound interface and outbound interface of the terminal device; If the number of transmission devices corresponding to the business flow is two, according to the pre-set first connection order, the input interface of the source device, the output interface of the source device, the input interface of the terminal device, and the output interface of the terminal device are connected in sequence to obtain the business path corresponding to the business flow.
5. The method according to claim 4, characterized in that The method further comprises: If the number of transmission devices corresponding to the business flow is greater than two, determine the intermediate device corresponding to the business flow according to the source device and the terminal device corresponding to the business flow, and multiple transmission devices corresponding to the business flow; wherein the intermediate device is other device among the multiple transmission devices except the source device and the terminal device; According to the flow node identification information, timestamp information, flow direction information, and interface information in the target flow detection data of the service flow corresponding to the intermediate device, the interfaces of the intermediate devices corresponding to the service flow are sorted and connected in ascending order of timestamps to obtain a first intermediate path corresponding to the service flow; Obtaining a second intermediate path corresponding to the service flow according to the LLDP information of the intermediate device obtained in advance; If the first intermediate path is the same as the second intermediate path, determining the first intermediate path as the target intermediate path; if the first intermediate path is different from the second intermediate path, determining the second intermediate path as the target intermediate path; Based on the target intermediate path, the inbound interface and the outbound interface of the source device, and the inbound interface and the outbound interface of the terminal device, a service path corresponding to the service flow is determined.
6. The method according to claim 5, characterized in that The step of determining the service path corresponding to the service flow based on the target intermediate path, the inbound interface and the outbound interface of the source device, and the inbound interface and the outbound interface of the terminal device comprises: If the target intermediate path is the first intermediate path, the inbound interface of the source device, the outbound interface of the source device, and the inbound interface of the first intermediate device are connected in sequence; and then the outbound interface of the second intermediate device, the inbound interface of the terminal device, and the outbound interface of the terminal device are connected in sequence to obtain the service path corresponding to the service flow; wherein the inbound interface of the first intermediate device is the interface indicated by the interface information corresponding to the first target with-flow detection data with the smallest timestamp in the target with-flow detection data of the service flow corresponding to the intermediate device; and the outbound interface of the second intermediate device is the interface indicated by the interface information corresponding to the second target with-flow detection data with the largest timestamp in the target with-flow detection data of the service flow corresponding to the intermediate device; If the target intermediate path is the second intermediate path, determining the inbound interface of the third intermediate device to be connected to the source device according to the LLDP information of the source device obtained in advance; determining the outbound interface of the fourth intermediate device to be connected to the terminal device according to the LLDP information of the terminal device obtained in advance; The inbound interface of the source device, the outbound interface of the source device, and the inbound interface of the third intermediate device are connected in sequence; and then the outbound interface of the fourth intermediate device, the inbound interface of the terminal device, and the outbound interface of the terminal device are connected in sequence to obtain the service path corresponding to the service flow; wherein the inbound interface of the third intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the source device; and the outbound interface of the fourth intermediate device is the interface indicated by the interface information of the target transmission device corresponding to the LLDP information of the terminal device.
7. The method according to claim 2, characterized in that Each flow detection data also includes message quantity information; each flow detection task also includes service source information and customer information; the method also includes: Restore the in-stream detection data of each service flow to the corresponding transmission equipment on the service path in real time; According to the message quantity information, timestamp information and interface information corresponding to each flow detection data, the state information of the transmission path between each two adjacent transmission devices in the service path corresponding to each service flow is determined in real time; wherein the state information includes delay information, packet loss information and jitter information; the state information is presented in the form of a time axis; According to the state information of the transmission path between every two adjacent transmission devices and the preset state information threshold, the abnormal transmission path is determined in real time, and the abnormal interface is determined according to the abnormal transmission path; Determine an average value of state information of a service path corresponding to each service flow according to state information of a transmission path between every two adjacent transmission devices; According to the average value of the service source information, customer information of the accompanying detection task corresponding to each service flow and the status information of the service path corresponding to each service flow, the average service information corresponding to each customer information and each service source information is obtained; According to the average business information corresponding to each customer information and each business source information, each customer information and business source information is sorted according to multiple preset sorting requirements to obtain customer sorting results and business source sorting results corresponding to each sorting requirement.
8. A device for determining a service path based on flow detection, characterized in that: The device comprises: An acquisition module, used to acquire the flow detection data of at least one service flow corresponding to each target device; wherein each of the target devices is pre-configured with a flow detection function; A first determination module is used to determine multiple transmission devices corresponding to each service flow from multiple target devices according to each flow detection data; wherein each flow detection data includes: flow node identification information, timestamp information, flow direction information, and interface information; The second determination module is used to sort and connect the interfaces of multiple transmission devices corresponding to each business flow according to the flow node identification information, timestamp information, flow direction information, interface information of each flow detection data, and the LLDP information pre-configured by each of the transmission devices, so as to determine the business path corresponding to each business flow; wherein the LLDP information pre-configured by each of the transmission devices is used to indicate the target transmission device connected to the transmission device and the interface information of the target transmission device.
9. An electronic device, characterized in that: The electronic device includes a processor and a memory, the memory stores computer executable instructions that can be executed by the processor, and the processor executes the computer executable instructions to implement the method for determining a service path based on in-flow detection according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by the processor, the computer-executable instructions prompt the processor to implement the method for determining a service path based on in-flight detection according to any one of claims 1 to 7.
Citation Information
Patent Citations
Real-time service diagnosis method and device based on stream detection
CN115914041A
Service topology generation method and device for stream detection
CN115987802A
Path overlap detection method and device
CN118590404A
Enterprise network security test and evaluation method and system
CN119051990A
Diagnosing and resolving issues in a network using probe packets
US20210226879A1