Network path detection system
By designing a multi-modular network path detection system, the accuracy, completeness and efficiency problems in the prior art are solved, and the efficiency and accuracy of network path detection are achieved, and the limitations of traditional methods and existing fingerprint technology are overcome.
Patent Information
- Application Number
- CN202510174271.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network path detection system has problems in accuracy, completeness and efficiency. The traditional Traceroute tool does not consider router load balancing, resulting in false connections and loops, and multiple measurements are inefficient and topological information is incomplete.
A network path detection system is designed, including a detection node collaboration module, a path data acquisition module, a path data processing module, a router alias identification module and topology analysis and evaluation module. Through dynamic adjustment of task allocation strategies, real-time identification of false connections and loops, standardized data processing, alias identification and hierarchical topology analysis based on monotonic boundary testing technology, network path detection is achieved efficient and accurate.
It improves the accuracy and efficiency of network path detection, solves the problems of false connections and loops, inefficient multiple measurements and incomplete topological information in traditional methods, and overcomes the limitations of existing fingerprint technology to detect high and low measurement efficiency in large-scale detection scenarios.
Smart Images

Figure CN120075099A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cyberspace mapping, and specifically to a network path detection system. Background Art
[0002] With the continuous expansion of the scale and the continuous improvement of the complexity of computer networks, network path detection systems have emerged as the times require. It originated from the early network management requirements and aimed to solve network fault troubleshooting and performance monitoring problems. Initially, simple tools such as the Ping command were the preliminary exploration means, which could only provide basic connectivity information. With the development of network technology, it has gradually expanded from basic detection based on the ICMP protocol to comprehensive detection using multiple protocols and algorithms. Nowadays, network path detection systems can accurately locate fault points in network links and analyze the locations of network congestion, playing a crucial role in ensuring the efficient and stable operation of the network.
[0003] However, network path detection systems have various uses, including topology analysis, especially cyberspace topology mapping; but the existing technologies for cyberspace topology mapping often have the following technical drawbacks:
[0004] There are problems with the accuracy, integrity, and efficiency of network path detection technologies. Traditional Traceroute tools do not consider router load balancing, which easily leads to false connections and loops, and the efficiency of obtaining end-to-end paths through multiple measurements is low, and the topology information is incomplete.
[0005] In large-scale router alias identification, existing fingerprint technologies such as Ally and RadarGun have problems of high detection volume and low efficiency. Ally requires an O(n2) detection volume and cannot meet large-scale requirements; due to the limitations of the IPID field, the controlled detection efficiency of RadarGun is still insufficient. Summary of the Invention
[0006] In view of the deficiencies of the prior art, the present invention provides a network path detection system, which solves the technical drawbacks mentioned in the background art.
[0007] To achieve the above objectives, the present invention is realized through the following technical solutions: A network path detection system includes a detection node cooperation module, a path data acquisition module, a path data processing module, a router alias identification module, and a topology analysis and evaluation module;
[0008] The detection node cooperation module is used for network path detection based on the cooperation of multiple detection nodes, dynamically balancing the detection load by distributing detection tasks; at the same time, monitoring the detection status and data quality of each detection node;
[0009] The path data collection module is used to collect hop information, delay data, and packet loss rate data in the network path, and at the same time support real-time identification of false connections and loop problems in a dynamically load-balanced network; finally, through a specific flow identification generation mechanism, the complete hop information of the network path is obtained;
[0010] The path data processing module is used to preprocess the collected hop information, delay data, and packet loss rate data, and combine dimensionless processing technology to standardize the hop information, delay data, and packet loss rate data. After eliminating the data format differences of multi-source detection nodes, a network path-related data set with a unified format is constructed;
[0011] The router alias identification module is used to extract the interface IPs in the network path-related data set and perform alias analysis based on the monotonicity boundary test technology and the sliding window detection method. By calculating the IPID change rate IPbh, and then collaborating with multiple detection nodes to complete alias identification; at the same time, extract the router hop count feature Lhs, IP traffic feature Fls, alias matching rate Blp, and interface coverage rate Jfl to generate an alias identification result set;
[0012] The topology analysis and evaluation module is used to perform hierarchical analysis of the network topology according to the network path-related data set and the alias identification result set; by calculating and correlating the detection node distribution parameter Jdfc and the detection coverage rate Tcfg, generate the network path detection evaluation index Azb; finally, evaluate the network path detection evaluation index Azb and form a complete topology analysis result.
[0013] Preferably, the detection node collaboration module dynamically adjusts the task allocation strategy by analyzing the geographical location, network connection status, and computing resource status of each detection node; among them, the task allocation strategy specifically includes: optimizing the task coverage area according to the geographical distribution of the detection nodes, and preferentially allocating the nodes in the neighboring target area to undertake the path detection task; allocating tasks in real time according to the network connection status; dynamically balancing the task load according to the computing resource usage of the nodes;
[0014] At the same time, by real-time monitoring the running status of the detection nodes, including the task completion progress, the integrity and accuracy of the detection data, identify and handle possible abnormal situations during task execution; the monitoring content includes: task timeout reminder, status warning of abnormal node operation, and integrity check of detection results.
[0015] Preferably, the detection node cooperation module also performs consistency check and quality analysis on the detection data uploaded by each node through a data quality assessment mechanism. Finally, the specific content of the data quality assessment mechanism includes: cross-verifying the duplicate path data from different detection nodes to screen out the data with the highest consistency; comprehensively checking the timestamps, hop information, and path consistency of the detection data to eliminate unreliable data caused by network jitter or anomalies; detecting false alarm paths through statistical analysis, including false connections and loops.
[0016] Preferably, the path data acquisition module is used to collect hop information, delay data, and packet loss rate data in the network path from multiple detection nodes in real time; by initializing the detection task associated with the target IP and using specific detection protocols, including ICMP, UDP, and TCP, to send detection packets to the target path and collect interface IPs and related hop information in the path hop by hop; at the same time, by calculating the round-trip delay of the detection packets to record the delay characteristics of each hop in the path, and by analyzing the loss rate of the returned packets to monitor the stability of the path; secondly, combined with the dynamic load balancing algorithm, adjust the detection packet sending frequency and traffic distribution according to the real-time collected network load status, identify and locate the false connections and loop problems caused by router load balancing; finally, through a specific flow identification generation mechanism, obtain the complete hop information of the target network path.
[0017] Preferably, the path data processing module first performs integrity check and anomaly detection on the collected hop information, delay data, and packet loss rate data, including removing duplicate path records, repairing incomplete path data, and marking abnormal values; subsequently, through the dimensionless processing technology, convert the collected hop information, delay data, and packet loss rate data into a standardized form with a unified dimension, including converting the delay data into a unitized time ratio, unifying the packet loss rate data into a percentage format, and performing consistency verification and error correction on the data from different sources; after the preprocessing is completed, construct a network path-related data set according to the topological characteristics of the network path data, including the sequence information of hops, the delay value of each hop, and the corresponding packet loss rate characteristics.
[0018] Preferably, the router alias identification module includes an alias analysis unit and a feature extraction unit;
[0019] The alias analysis unit is used to perform alias matching on the interface IP in the path data based on the monotonicity boundary test technology, screen and match the interface IPs with similar IPID change characteristics through the sliding window detection method, and extract the IPID value sequence IDse and the timestamp sequence Tse, and calculate and obtain the IPID change rate IPbh by combining the following formula:
[0020]
[0021] In the formula, ΔIDse represents the change in IPID value between adjacent detection response packets within the sliding window, and ΔTse represents the time difference between adjacent detection response packets within the sliding window.
[0022] Preferably, after the alias recognition is completed by the detection node, the feature extraction unit is used to extract the router hop count feature Lhs, the IP traffic feature Fls, the alias matching rate Blp, and the interface coverage rate Jfl, and then perform data summarization and structuring processing to generate a complete alias recognition result set.
[0023] Preferably, the topology analysis and evaluation module includes a node distribution calculation unit, a coverage rate calculation unit, and an evaluation and analysis unit;
[0024] The node distribution calculation unit is used to calculate the detection node distribution parameter Jdfc of the detection nodes in the target network area according to the detection node information in the network path related data set; by analyzing the geographical location, path coverage range, and connection status of the detection nodes, obtain the geographical location distribution density Ld, the total number of path coverage Pc, the node connection status value Cn, and the node task load ratio Lt, and then combine the following formula to obtain the detection node distribution parameter Jdfc;
[0025]
[0026] Preferably, the coverage rate calculation unit is used to calculate the detection coverage rate Tcfg of the target network based on the alias recognition result set, and the specific calculation formula is as follows:
[0027]
[0028] Preferably, the evaluation and analysis unit is used to fit the node distribution parameter Jdfc and the detection coverage rate Tcfg, and calculate and obtain the network path detection evaluation index Azb through the following formula:
[0029]
[0030] Then, through a preset network path detection evaluation threshold Q, further comprehensively evaluate the network path detection evaluation index Azb, identify the hierarchical structure characteristics of the network topology, including the uniformity of node distribution, the integrity of path coverage, and the effectiveness of topology information, and generate a complete topology analysis result, and its specific content is as follows:
[0031] If the network path detection evaluation index Azb ≥ the network path detection evaluation threshold Q: it means that the node distribution is uniform, the path coverage is complete, and the topology information is effective. At this time, generate an analysis result of "the network topology integrity meets the target";
[0032] If the network path detection evaluation index Azb < the network path detection evaluation threshold Q: It indicates that the node distribution is uneven, the path coverage is incomplete, or the topology information is invalid. At this time, improvement suggestions for adjustment are generated;
[0033] Among them, the complete topology analysis result includes the following specific contents:
[0034] S1. The uniformity score of node distribution and optimization suggestions;
[0035] S2. The path coverage rate evaluation report, marking the uncovered areas and key paths;
[0036] S3. The topology information validity check result, including false connection and loop analysis;
[0037] S4. The comprehensive evaluation conclusion, clarifying the completion status and optimization direction of the current network detection task.
[0038] The present invention provides a network path detection system. It has the following beneficial effects:
[0039] (1) This network path detection system, through modular design, solves the problems of accuracy, integrity, and efficiency existing in network path detection technology from multiple levels of detection node collaboration, path data collection, data processing, router alias identification, and topology analysis and evaluation; the detection node collaboration module dynamically adjusts the task allocation strategy, combines the geographical location distribution density Ld, the total number of path coverage Pc, the node connection status value Cn, and the node task load ratio Lt to ensure the balanced distribution and efficient cooperation of detection nodes; the path data collection module uses ICMP, UDP, and TCP protocols, combines a specific flow identification generation mechanism, and real-time collects hop information, delay data, and packet loss rate data, and combines a dynamic load balancing algorithm to accurately identify false connection and loop problems; the path data processing module standardizes the hop information, delay data, and packet loss rate data through integrity check, anomaly detection, and dimensionless processing to generate a network path-related data set with a unified dimension, laying a foundation for subsequent analysis;
[0040] (2) The network path detection system. The router alias recognition module, based on the monotonicity boundary test technology and the sliding window detection method, combines the IPID value sequence IDseq and the timestamp sequence Tseq to calculate the IPID change rate IPbh, collaborates with multiple detection nodes to accurately complete alias matching, and extracts the router hop count feature Lhs, the IP traffic feature Fls, the alias matching rate Blp, and the interface coverage rate Jfl to generate a complete alias recognition result set. The topology analysis and evaluation module calculates the detection node distribution parameter Jdfc and the detection coverage rate Tcfg through the node distribution calculation unit and the coverage rate calculation unit respectively, and the evaluation and analysis unit fits and generates the network path detection evaluation index Azb. By comparing with the network path detection evaluation threshold Q, it comprehensively evaluates the node distribution uniformity, path coverage integrity, and topology information effectiveness of the network topology, and finally generates a complete topology analysis result. The above system realizes the accurate and efficient execution of the network path detection task, solves the problems of false connections and loops caused by the traditional Traceroute tool not considering router load balancing, low efficiency of multiple measurements, and incomplete topology information, and at the same time overcomes the limitations of the existing fingerprint technologies Ally and RadarGun, which have high detection volume and low efficiency in large-scale detection scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a schematic diagram of the framework structure of a network path detection system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0042] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0043] Embodiment 1
[0044] Please refer to Figure 1 , a network path detection system, including a detection node collaboration module, a path data acquisition module, a path data processing module, a router alias recognition module, and a topology analysis and evaluation module;
[0045] The detection node collaboration module is used for network path detection based on the collaboration of multiple detection nodes, dynamically balancing the detection load by distributing detection tasks; at the same time, monitoring the detection status and data quality of each detection node;
[0046] The path data collection module is used to collect hop information, delay data, and packet loss rate data in the network path, and at the same time support real-time identification of false connections and loop problems in a dynamically load-balanced network; finally, through a specific flow identification generation mechanism, the complete hop information of the network path is obtained;
[0047] The path data processing module is used to preprocess the collected hop information, delay data, and packet loss rate data, and combine dimensionless processing technology to standardize the hop information, delay data, and packet loss rate data. After eliminating the data format differences of multi-source detection nodes, a network path-related data set with a unified format is constructed;
[0048] The router alias identification module is used to extract the interface IP in the network path-related data set and perform alias analysis based on the monotonicity boundary test technology and the sliding window detection method. By calculating the IPID change rate IPbh, and then collaborating with multiple detection nodes to complete alias identification; at the same time, extract the router hop count feature Lhs, IP traffic feature Fls, alias matching rate Blp, and interface coverage rate Jfl to generate an alias identification result set;
[0049] The topology analysis and evaluation module is used to perform hierarchical analysis of the network topology according to the network path-related data set and the alias identification result set; by calculating and correlating the detection node distribution parameter Jdfc and the detection coverage rate Tcfg, generate the network path detection evaluation index Azb; finally, evaluate the network path detection evaluation index Azb and form a complete topology analysis result.
[0050] In this embodiment, the detection node cooperation module realizes network path detection through the cooperation of multiple detection nodes, which can dynamically balance the detection load, effectively improve the detection efficiency and accuracy, monitor the status and data quality of each detection node, and ensure the reliability of data; the path data collection module collects hop information, delay data and packet loss rate data in the network path, and supports real-time identification of false connections and loop problems, ensuring the integrity of path data and eliminating the deficiencies in traditional methods; the path data processing module standardizes the collected data through dimensionless processing technology, eliminates the differences in data formats of multi-source detection nodes, and thus forms a network path data set with a unified format, improving the data processing efficiency and consistency; the router alias recognition module extracts interface IPs and performs alias analysis through monotonicity boundary testing technology and sliding window detection method, calculates the IPID change rate (IPbh), and combines the cooperation of multiple detection nodes to identify aliases, improving the efficiency of router alias recognition and avoiding the problem of high detection volume in traditional methods; the topology analysis and evaluation module performs hierarchical topology analysis based on path data and alias recognition results, generates network path detection evaluation indicators (Azb) by calculating the detection node distribution parameter (Jdfc) and detection coverage rate (Tcfg), further optimizing the network topology analysis results, and improving the accuracy and efficiency of network space mapping; the cooperation of these modules not only improves the efficiency and accuracy of network path detection, but also enhances the scalability in a large-scale network environment, ensuring the integrity and real-time nature of network space mapping results.
[0051] Embodiment 2
[0052] The detection node cooperation module dynamically adjusts the task allocation strategy by analyzing the geographical location, network connection status and computing resource situation of each detection node; among them, the task allocation strategy specifically includes: optimizing the task coverage range according to the geographical distribution of detection nodes, and preferentially allocating nodes near the target area to undertake path detection tasks; allocating tasks in real time according to the network connection status; dynamically balancing the task load according to the computing resource usage of nodes;
[0053] At the same time, by monitoring the running status of detection nodes in real time, including the task completion progress, the integrity and accuracy of detection data, identifying and handling possible abnormal situations during task execution; the monitoring content includes: task timeout reminder, status warning of abnormal node operation, and integrity check of detection results;
[0054] The detection node collaboration module also performs consistency checks and quality analysis on the detection data uploaded by each node through a data quality assessment mechanism; finally, the specific content of the data quality assessment mechanism includes: cross-verifying the duplicate path data from different detection nodes and screening out the data with the highest consistency; comprehensively checking the timestamps, hop information, and path consistency of the detection data, and eliminating unreliable data caused by network jitter or anomalies; detecting false alarm paths through statistical analysis, including false connections and loops.
[0055] The path data acquisition module is used to collect hop information, delay data, and packet loss rate data in the network path in real time from multiple detection nodes; by initializing the detection task associated with the target IP and using specific detection protocols, including ICMP, UDP, and TCP, to send detection packets to the target path and collect the interface IP and related hop information in the path hop by hop; at the same time, by calculating the round-trip delay of the detection packet to record the delay characteristics of each hop in the path, and by analyzing the loss rate of the returned packet to monitor the stability of the path; secondly, combined with the dynamic load balancing algorithm, adjust the detection packet sending frequency and traffic distribution according to the real-time collected network load status, identify and locate the false connections and loop problems caused by router load balancing; finally, through a specific flow identification generation mechanism, obtain the complete hop information of the target network path.
[0056] The path data processing module first performs integrity checks and anomaly detection on the collected hop information, delay data, and packet loss rate data, including removing duplicate path records, repairing incomplete path data, and marking abnormal values; subsequently, through the dimensionless processing technology, convert the collected hop information, delay data, and packet loss rate data into a standardized form with a unified dimension, including converting the delay data into a unitized time ratio, unifying the packet loss rate data into a percentage format, and performing consistency verification and error correction on the data from different sources; after the preprocessing is completed, construct a network path-related data set according to the topological characteristics of the network path data, including the sequence information of the hops, the delay value of each hop, and the corresponding packet loss rate characteristics.
[0057] In this embodiment, the task allocation strategy is specifically embodied as follows: when the network latency of a certain node is too high or the bandwidth is limited, the task load of this node is dynamically reduced, and some of its tasks are transferred to other nodes with better connection conditions; the specific monitoring content for detecting the running state of the detection nodes is as follows: detecting whether there are packet losses or missing paths, and for the detected abnormal situations, error logs will be automatically generated and a reallocation or retry mechanism will be triggered to ensure the smooth execution of the tasks. At the same time, the module monitors the running state of the detection nodes in real time, including but not limited to the task completion progress, the integrity and accuracy of the detection results, and identifies and processes the possible abnormal situations during the task execution; through the data quality evaluation mechanism, consistency checks and quality analysis are carried out on the detection data uploaded by each node, including cross-verifying and screening the data with the highest consistency for duplicate path data, comprehensively checking the timestamp, hop information and path consistency, removing unreliable data caused by network jitter or abnormalities, and detecting false alarm paths such as false connections and loops through statistical analysis; the design of the detection node collaboration module ensures the efficiency and data quality of the detection task execution, providing a reliable basic support for the subsequent modules;
[0058] The path data acquisition module collects the hop information, delay data and packet loss rate data in multiple detection nodes in real time, sends detection packets to the target path using ICMP, UDP and TCP protocols, collects the interface IPs and related hop information in the path hop by hop, calculates the round-trip delay of the detection packets and records the delay characteristics of each hop in the path, and monitors the stability of the path by analyzing the loss rate of the returned packets; combined with the dynamic load balancing algorithm, adjusts the sending frequency and traffic distribution of the detection packets according to the network load status, and identifies and locates the false connections and loop problems caused by router load balancing; through the specific flow identification generation mechanism, obtains the complete hop information of the target network path; this module effectively ensures the real-time and integrity of the collected data, providing basic data for the dynamic analysis of the network path;
[0059] The path data processing module conducts integrity checks and anomaly detections on the collected hop information, delay data and packet loss rate data, including removing duplicate path records, repairing incomplete path data and marking abnormal values, to ensure the accuracy and integrity of the data; subsequently, through the dimensionless processing technology, the hop information, delay data and packet loss rate data are converted into a standardized form with a unified dimension, including converting the delay data into a unitized time ratio, unifying the packet loss rate data into a percentage format, and performing consistency verification and error correction on data from different sources; finally, a network path-related data set is constructed according to the topological characteristics of the network path, including the sequence information of the hops, the delay value of each hop and the corresponding packet loss rate characteristics; this module realizes the standardization and consistency processing of the data, providing reliable and standardized data support for the subsequent topological analysis.
[0060] Example 3
[0061] The router alias recognition module includes an alias analysis unit and a feature extraction unit;
[0062] The alias analysis unit is used to perform alias matching on the interface IP in the path data based on the monotonicity boundary test technology, screen and match the interface IP with similar IPID change characteristics through the sliding window detection method, extract the IPID value sequence IDse and the timestamp sequence Tse, and calculate and obtain the IPID change rate IPbh by combining the following formula:
[0063]
[0064] In the formula, ΔIDse represents the change amount of the IPID value between adjacent probe response packets within the sliding window, and ΔTse represents the time difference between adjacent probe response packets within the sliding window;
[0065] The feature extraction unit is used to extract the router hop count feature Lhs, the IP traffic feature Fls, the alias matching rate Blp, and the interface coverage rate Jfl after the probe node completes alias recognition, and then perform data aggregation and structured processing to generate a complete alias recognition result set.
[0066] The topology analysis and evaluation module includes a node distribution calculation unit, a coverage rate calculation unit, and an evaluation and analysis unit;
[0067] The node distribution calculation unit is used to calculate the probe node distribution parameter Jdfc of the probe node in the target network area according to the probe node information in the network path related data set; by analyzing the geographical location, path coverage range, and connection status of the probe node, obtain the geographical location distribution density Ld, the total number of path covers Pc, the node connection status value Cn, and the node task load ratio Lt, and then combine the following formula to obtain the probe node distribution parameter Jdfc;
[0068]
[0069] The coverage rate calculation unit is used to calculate the probe coverage rate Tcfg of the target network based on the alias recognition result set, and the specific calculation formula is as follows:
[0070]
[0071] The evaluation and analysis unit is used to fit the node distribution parameter Jdfc and the probe coverage rate Tcfg, and calculate and obtain the network path probe evaluation index Azb through the following formula:
[0072]
[0073] Next, by presetting the network path detection evaluation threshold Q, the network path detection evaluation index Azb is further comprehensively evaluated to identify the hierarchical structure characteristics of the network topology, including the uniformity of node distribution, the integrity of path coverage, and the effectiveness of topology information, and a complete topology analysis result is generated. The specific content is as follows:
[0074] If the network path detection evaluation index Azb ≥ the network path detection evaluation threshold Q: It indicates that the node distribution is uniform, the path coverage is complete, and the topology information is effective. At this time, an analysis result of "the network topology integrity meets the target" is generated;
[0075] If the network path detection evaluation index Azb < the network path detection evaluation threshold Q: It indicates that the node distribution is uneven, the path coverage is incomplete, or the topology information is invalid. At this time, improvement suggestions for adjustment are generated;
[0076] Among them, the complete topology analysis result includes the following specific content:
[0077] S1. The uniformity score of node distribution and optimization suggestions;
[0078] S2. The path coverage rate evaluation report, marking the uncovered areas and key paths;
[0079] S3. The topology information effectiveness inspection results, including false connection and loop analysis;
[0080] S4. The comprehensive evaluation conclusion, clarifying the completion status and optimization direction of the current network detection task.
[0081] In this embodiment, the router alias recognition module uses the alias analysis unit to perform alias matching on the interface IP in the path data by using the monotonicity boundary test technology and the sliding window detection method. By extracting the IPID value sequence IDseq and the timestamp sequence Tseq and combining with the formula to calculate the IPID change rate IPbh, the accurate screening and matching of interface IPs with similar change characteristics are realized; after the alias recognition is completed, the feature extraction unit extracts the router hop count feature Lhs, the IP traffic feature Fls, the alias matching rate Blp, and the interface coverage rate Jfl, performs data aggregation and structured processing, and generates a complete alias recognition result set, thereby improving the accuracy of the network topology;
[0082] The topology analysis and evaluation module calculates the detection node distribution parameter Jdfc and the detection coverage rate Tcfg through the node distribution calculation unit, the coverage rate calculation unit, and the evaluation and analysis unit respectively, to achieve a comprehensive evaluation of the network path detection evaluation index Azb. Among them, the node distribution parameter Jdfc is calculated by analyzing the geographical location distribution density Ld of the detection nodes, the total number of path covers Pc, the node connection status value Cn, and the node task load ratio Lt, reflecting the uniform distribution and load balance of the detection nodes. The detection coverage rate Tcfg is calculated through path analysis based on the alias recognition result set, quantifying the detection coverage range of the target network. The network path detection evaluation index Azb synthesizes the fitting results of the detection node distribution parameter Jdfc and the detection coverage rate Tcfg, and combines the preset network path detection evaluation threshold Q to further identify the hierarchical structure characteristics of the network topology. The finally generated topology analysis results, including the uniformity score of node distribution and optimization suggestions, the path coverage rate evaluation report, the topology information validity check result, and the comprehensive evaluation conclusion, clarify the completion status and optimization direction of the current network detection task, providing comprehensive support for the accuracy, integrity, and efficiency improvement of network path detection.
[0083] Among them, the topology analysis and evaluation module mainly conducts hierarchical analysis of the network topology by analyzing the network path-related data set and the alias recognition result set, calculates and correlates the detection node distribution parameter Jdfc and the detection coverage rate Tcfg, and generates the network path detection evaluation index Azb, thus forming a complete topology analysis result. This analysis method can accurately depict the structure of the network, the connection relationship between each node, and the data flow situation, which is the core part of network space mapping.
[0084] In network space mapping, the topology analysis and evaluation module not only focuses on the integrity of network paths but also needs to perform detailed spatial mapping of the network structure in a large-scale network environment. To conduct mapping more efficiently, in addition to the collection and processing of path data, it is also necessary to monitor the network status and node distribution in real time. This enables the topology analysis and evaluation module to generate a network topology map with in-depth analysis, including but not limited to dynamic monitoring of aspects such as the interaction relationship between nodes, the node load balancing status, and the efficiency of data transmission. Through this module, the network space mapping system can achieve real-time monitoring and optimization of complex network environments, improve the efficiency of network management and fault troubleshooting, and at the same time provide data support for network optimization and resource scheduling.
[0085] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A network path detection system, characterized in that: It includes a detection node coordination module, a path data collection module, a path data processing module, a router alias identification module and a topology analysis and evaluation module; The detection node coordination module is used for network path detection based on the collaborative work of multiple detection nodes, dynamically balancing the detection load by distributing detection tasks, and monitoring the detection status and data quality of each detection node at the same time; The path data collection module is used to collect the hop information, delay data and packet loss rate data in the network path, and supports real-time identification of false connections and loop problems in the dynamic load balancing network; finally, the complete hop information of the network path is obtained through the specific flow identification generation mechanism; The path data processing module is used to pre-process the collected hop information, delay data and packet loss rate data, and standardize the hop information, delay data and packet loss rate data in combination with dimensionless processing technology, and after eliminating the differences in data formats of multi-source detection nodes, construct a network path related data set with a unified format; The router alias identification module is used to extract the interface IP in the network path related data set and perform alias analysis based on the monotonic boundary test technology and the sliding window detection method, calculate the IPID change rate IPbh, and then cooperate with multiple detection nodes to complete the alias identification; at the same time, the router hop count feature Lhs, IP traffic feature Fls, alias matching rate Blp and interface coverage rate Jfl are extracted to generate an alias identification result set; The topology analysis and evaluation module is used to perform hierarchical analysis of network topology based on a network path related data set and an alias identification result set; generate a network path detection evaluation index Azb by calculating and associating the detection node distribution parameter Jdfc and the detection coverage rate Tcfg; finally, evaluate the network path detection evaluation index Azb and form a complete topology analysis result.
2. A network path detection system according to claim 1, characterized in that: The detection node coordination module dynamically adjusts the task allocation strategy by analyzing the geographical location, network connection status and computing resource status of each detection node; the task allocation strategy specifically includes: optimizing the task coverage according to the geographical distribution of the detection nodes, giving priority to assigning nodes near the target area to undertake path detection tasks; allocating tasks in real time according to the network connection status; and dynamically balancing the task load according to the computing resource usage of the node; At the same time, by real-time monitoring of the operating status of the detection nodes, including the progress of task completion, the integrity and accuracy of the detection data, abnormal situations that may occur during task execution are identified and handled; the monitoring content includes: task timeout reminders, abnormal node operation status warnings and integrity checks of detection results.
3. A network path detection system according to claim 1, characterized in that: The detection node collaboration module also uses a data quality assessment mechanism to perform consistency checks and quality analysis on the detection data uploaded by each node; finally, the specific contents of the data quality assessment mechanism include: cross-validation of repeated path data from different detection nodes to screen out the data with the highest consistency; comprehensive checks on the timestamp, hop information and path consistency of the detection data to eliminate unreliable data caused by network jitter or anomalies; and detection of false alarm paths, including false connections and loops, through statistical analysis.
4. A network path detection system according to claim 1, characterized in that: The path data collection module is used to collect the hop information, delay data and packet loss rate data in the network path from multiple detection nodes in real time; by initializing the detection task associated with the target IP, using specific detection protocols, including ICMP, UDP and TCP, to send detection packets to the target path, and collect the interface IP and related hop information in the path hop by hop; at the same time, by calculating the round-trip delay of the detection packet to record the delay characteristics of each hop in the path, and by analyzing the loss rate of the return packet, the stability of the path is monitored; secondly, combined with the dynamic load balancing algorithm, the detection packet sending frequency and traffic distribution are adjusted according to the real-time collected network load status, and the false connection and loop problems caused by router load balancing are identified and located; finally, through a specific flow identifier generation mechanism, the complete hop information of the target network path is obtained.
5. A network path detection system according to claim 1, characterized in that: The path data processing module first performs integrity check and anomaly detection on the collected hop information, delay data and packet loss rate data, including removing duplicate path records, repairing incomplete path data and marking abnormal values; Then, the collected hop information, delay data and packet loss rate data are converted into a standardized form with unified dimensions through dimensionless processing technology, including converting delay data into unitized time ratio and unifying packet loss rate data into percentage format, and performing consistency check and error correction on data from different sources; After the preprocessing is completed, a network path related data set is constructed according to the topological characteristics of the network path data, which includes the sequence information of the hops, the delay value of each hop and the corresponding packet loss rate characteristics.
6. A network path detection system according to claim 1, characterized in that: The router alias identification module includes an alias analysis unit and a feature extraction unit; The alias analysis unit is used to perform alias matching on the interface IP in the path data based on the monotonic boundary test technology, screen and match the interface IP with similar IPID change characteristics through the sliding window detection method, and extract the IPID value sequence IDse and the timestamp sequence Tse, and calculate the IPID change rate IPbh in combination with the following formula: Where ΔIDse represents the change in the IPID value between adjacent probe response packets in the sliding window, and ΔTse represents the time difference between adjacent probe response packets in the sliding window.
7. A network path detection system according to claim 6, characterized in that: The feature extraction unit is used to extract the router hop count feature Lhs, IP traffic feature Fls, alias matching rate Blp and interface coverage rate Jfl after the detection node completes alias identification, and then perform data aggregation and structured processing to generate a complete alias identification result set.
8. A network path detection system according to claim 1, characterized in that: The topology analysis and evaluation module includes a node distribution calculation unit, a coverage calculation unit and an evaluation and analysis unit; The node distribution calculation unit is used to calculate the detection node distribution parameter Jdfc of the detection node in the target network area according to the detection node information in the network path related data set; by analyzing the geographical location, path coverage and connection status of the detection node, the geographical location distribution density Ld, the total number of path coverage Pc, the node connection status value Cn and the node task load ratio Lt are obtained, and then combined with the following formula to obtain the detection node distribution parameter Jdfc; 9. A network path detection system according to claim 8, characterized in that: The coverage calculation unit is used to calculate the detection coverage Tcfg of the target network based on the alias identification result set. The specific calculation formula is as follows:
10. A network path detection system according to claim 9, characterized in that: The evaluation and analysis unit is used to fit the node distribution parameter Jdfc and the detection coverage rate Tcfg, and obtain the network path detection evaluation index Azb by calculating the following formula: Next, by presetting the network path detection evaluation threshold Q, the network path detection evaluation index Azb is further comprehensively evaluated to identify the hierarchical structural characteristics of the network topology, including the uniformity of node distribution, the integrity of path coverage, and the effectiveness of topological information, and generate a complete topological analysis result. The specific contents are as follows: If the network path detection evaluation index Azb ≥ the network path detection evaluation threshold Q: it means that the nodes are evenly distributed, the path coverage is complete, and the topology information is valid. At this time, the analysis result of "network topology integrity meets the target" is generated; If the network path detection evaluation index Azb is less than the network path detection evaluation threshold Q, it means that the node distribution is uneven, the path coverage is incomplete, or the topology information is invalid. At this time, an improvement suggestion for adjustment is generated; The complete topology analysis results include the following specific contents: S1. Uniformity score of node distribution and optimization suggestions; S2, path coverage assessment report, marking uncovered areas and key paths; S3, topology information validity check results, including false connection and loop analysis; S4. Comprehensively evaluate the conclusions and clarify the completion status and optimization direction of the current network detection task.
Citation Information
Patent Citations
Topology discovery system of next generation Internet based on IPv6 (Internet Protocol Version 6) and realizing method thereof
CN101945043A
Distributed IP level network topology detection method based on a plurality of protocols
CN109617728A
Region PoP dividing method based on subnet analysis
CN109639510A
Network path detection method and device, electronic equipment and storage medium
CN118677815A
Cited By
Router alias identification system
CN120750909A
Network traffic forwarding path visualization method and system based on active detection
CN121907745A