Dual-unit configuration compliance detection method and system for BRAS (Broadband Remote Access Server) in metropolitan area network

Through the compliance detection method and system of the dual-machine configuration of the metropolitan area network BRAS, the problem of timely discovery of hidden dangers and configuration caused by the complex use environment of the metropolitan area network is solved, and timely discovery and risk assessment of hidden dangers of the metropolitan area network are realized to ensure network stability.

CN120186064AInactive Publication Date: 2025-06-20HUASHI TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510407577.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-06-20
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The use environment of metropolitan area network is complex, and the existing detection is difficult to detect various types of metropolitan area network networks in a timely manner, which may cause further failures.

Method used

It provides a compliance detection method and system for the dual-machine configuration of the metropolitan area network. Through daily business inspection, dual-machine status inspection, dual-machine network inspection and dual-machine data inspection, a patrol report is generated, and the metropolitan area network protection management tool is used to discover networking and configuration hidden dangers, forming a fault risk rating.

Benefits of technology

It can promptly detect hidden dangers of the metropolitan area network and configure the hidden dangers, give priority to dealing with hidden dangers with greater failure risks, avoid further failures caused by hidden dangers, and ensure stable operation of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186064A_ABST
    Figure CN120186064A_ABST
Patent Text Reader

Abstract

The invention discloses a metropolitan area network BRAS dual-computer configuration compliance detection method and system, and relates to the technical field of information security, and the method comprises the steps: carrying out the daily business inspection in the reconstruction and daily maintenance links of BRAS dual-computer backup; checking the compliance of the BRAS dual-computer operation state; checking the logical relationship and configuration of the BRAS dual-unit networking; checking the basic configuration data of the operation of the BRAS dual-computer system; generating an inspection report; and forming a metropolitan area network dual-machine guarantee management tool, discovering various networking and configuration hidden dangers of the metropolitan area network by using the metropolitan area network dual-machine guarantee management tool, and forming metropolitan area network fault risk rating and family wide complaint risk rating. By arranging the daily inspection module, the inspection classification module, the hidden danger query module and the risk assessment module, various networking and configuration hidden dangers of the metropolitan area network can be found in time, hidden dangers with higher fault risks are processed preferentially, and further faults possibly caused by the hidden dangers are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and specifically relates to a method and system for detecting the compliance of dual-machine configuration of BRAS in a metropolitan area network. Background Art

[0002] CMNET and the IP bearer network are the main carriers of the company's data services and are important links in implementing the "big connection" strategy and deepening the integrated development of "four-wheel drive". With the development of home broadband and 5G, the traffic demand will continue to grow rapidly; with the continuous advancement of network flattening, the network structure will be increasingly optimized; with the emergence of new services such as telecom cloud, Internet of Things, and cloud network integration, the service requirements will be more diverse, and ensuring the stable operation of the network is the top priority of maintenance work. Among them, the CMNET metropolitan area network accesses 85% of the total network traffic. To ensure the stable services of millions of such users is one of the current challenges.

[0003] The usage environment of the metropolitan area network is complex, and existing detections are difficult to timely discover various networking and configuration hidden dangers in the metropolitan area network, resulting in potential further failures caused by the hidden dangers. Summary of the Invention

[0004] To solve the above technical problems, a method and system for detecting the compliance of dual-machine configuration of BRAS in a metropolitan area network are provided. The technical solution solves the problem that the usage environment of the metropolitan area network is complex, and existing detections are difficult to timely discover various networking and configuration hidden dangers in the metropolitan area network, resulting in potential further failures caused by the hidden dangers as mentioned in the above background art.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] A method for detecting the compliance of dual-machine configuration of BRAS in a metropolitan area network, including:

[0007] During the transformation and daily maintenance of BRAS dual-machine backup, daily business inspections are carried out, where BRAS is a broadband access server;

[0008] The daily business inspections include dual-machine status inspection, dual-machine networking inspection, and dual-machine local data inspection;

[0009] When performing the dual-machine status inspection, the compliance of the operation status of the BRAS dual-machine is inspected;

[0010] When performing the dual-machine networking inspection, the logical relationship and configuration of the BRAS dual-machine networking are inspected;

[0011] When performing the dual-machine local data inspection, the basic configuration data of the BRAS dual-machine system operation is inspected;

[0012] According to the results of the daily business inspections, an inspection report is generated.

[0013] Form a dual - machine guarantee management tool for the metropolitan area network. Use the dual - machine guarantee management tool for the metropolitan area network to discover various networking and configuration hidden dangers in the metropolitan area network, and form a failure risk rating for the metropolitan area network and a risk rating for home broadband complaints.

[0014] Preferably, when performing the dual - machine status check, the compliance check of the BRAS dual - machine running status includes the following steps:

[0015] When performing the compliance check of the BRAS dual - machine running status, check the address pool, hot - standby sub - interface, hot - standby interface, and alarm;

[0016] Address pool check: Check for missing or incomplete address pool configurations, and obtain the failed hot - standby user routes caused by address pool failures;

[0017] Hot - standby sub - interface check: Check the standardization of the Virtual Router Redundancy Protocol (VRRP) and the standardization of the VRRP tracking of the uplink monitoring group and Bidirectional Forwarding Detection (BFD). Conduct a hot - standby service handover check, where BFD is a bidirectional forwarding detection mechanism;

[0018] Hot - standby interface check: Check whether there are overlapping or failed hot - standby interfaces;

[0019] Alarm check: Conduct an alarm check on the unilateral handover on the optical line terminal side, obtain the historical unilateral failures of the optical line terminal, and compare the results of the alarm check with the historical unilateral failures of the optical line terminal to obtain the actual unilateral failures of the optical line terminal.

[0020] Preferably, when performing the dual - machine networking check, the check of the logical relationship and configuration of the BRAS dual - machine networking includes the following steps:

[0021] Conduct a dual - homing networking check for the optical line terminal. Based on the characteristics of the hot - standby state in the dual - homing networking, develop a dual - homing check algorithm, where the dual - homing check algorithm satisfies non - repeated checking of the BRAS dual - machine;

[0022] Check the dual - homing information of the optical line terminal under the dual - machine BRAS daily, and check the logical relationship between the optical line terminal and the BRAS.

[0023] Preferably, when performing the dual - machine local data check, the check of the basic configuration data of the BRAS dual - machine system operation includes the following steps:

[0024] Obtain the pre - established dual - machine configuration specifications, and in accordance with the established dual - machine configuration specifications, check the naming, address specifications, and configuration logical relationships in the configuration;

[0025] Generate customized scripts for optical line terminal access and hot standby address pool expansion, backup and store the customized scripts as sample customized scripts, and use the customized scripts to configure optical line terminal access and hot standby address pool expansion;

[0026] During inspection, compare the actually used customized script with the sample customized script. When there are differences between the two, the configuration of optical line terminal access and hot standby address pool expansion is abnormal.

[0027] Preferably, generating an inspection report based on the daily business inspection results includes the following steps:

[0028] Generate an inspection report for the abnormalities existing in the daily business inspection. The inspection report consists of three parts, namely the dual-machine status part, the dual-machine networking part, and the dual-machine office data part;

[0029] In the dual-machine status part, summarize and list the results of the address pool inspection, hot standby sub-interface inspection, hot standby interface inspection, and alarm inspection with abnormalities;

[0030] In the dual-machine networking part, summarize and list the abnormal logical relationships and the dual-homing information of the optical line terminals with abnormalities;

[0031] In the dual-machine office data part, summarize and list the naming, address specifications, configuration logical relationships, and customized scripts with abnormalities.

[0032] Preferably, the steps for forming the dual-machine guarantee management tool for the metropolitan area network include the following:

[0033] The dual-machine guarantee management tool for the metropolitan area network consists of a client, an analysis program, and an authentication end. The authentication end verifies the user login. The user who passes the verification logs in to the client to obtain the data generated by the analysis program;

[0034] Based on historical data, obtain the devices, circuits, ports, and potential trouble spots used by the BRAS dual-machine, store and establish a database model, sort out the association relationships among the devices, circuits, ports, and potential trouble spots in the database model, and classify the associated devices, circuits, ports, and potential trouble spots into the inspection item sets;

[0035] The analysis program conducts itemized inspections on the inspection item sets;

[0036] Develop API interfaces to establish an inter-access channel between the client and the analysis program;

[0037] Develop the authentication end and set the user authentication function in the authentication end.

[0038] Preferably, the steps for using the dual-machine guarantee management tool for the metropolitan area network to discover various networking and configuration potential troubles in the metropolitan area network include the following:

[0039] The dual - machine guarantee management tool for the metropolitan area network detects the dual - machines of the metropolitan area network, collects the status of all backbone network devices based on the Secure Shell Protocol, connects the Secure Shell Protocol channels of all network devices, and realizes batch - timed collection and log storage;

[0040] Record the business key indicators into the database on a daily granularity, and generate a hidden - trouble list of the dual - machines of the metropolitan area network every day;

[0041] Based on the hidden - trouble list of the dual - machines of the metropolitan area network, excavate the hidden network faults, and generate at least one networking hidden - trouble fault and at least one configuration hidden - trouble fault.

[0042] Preferably, the formation of the metropolitan area network fault risk rating and the home broadband complaint risk rating includes the following steps:

[0043] Based on big data, obtain the first risk value caused by the networking hidden - trouble faults and the second risk value caused by the configuration hidden - trouble faults;

[0044] Superimpose the first risk values of at least one networking hidden - trouble fault to obtain the metropolitan area network fault score;

[0045] Superimpose the second risk values of at least one configuration hidden - trouble fault to obtain the home broadband complaint score;

[0046] Based on historical data, obtain the value range of the metropolitan area network fault score, evenly divide the value range of the metropolitan area network fault score, and obtain at least one first rating interval;

[0047] Sort and number the first rating intervals in ascending order of the mid - points of the first rating intervals, and the level of the first rating interval is equal to its number;

[0048] Based on historical data, obtain the value range of the home broadband complaint score, evenly divide the value range of the home broadband complaint score, and obtain at least one second rating interval;

[0049] Sort and number the second rating intervals in ascending order of the mid - points of the second rating intervals, and the level of the second rating interval is equal to its number;

[0050] Obtain the level of the first rating interval containing the metropolitan area network fault score as the metropolitan area network fault risk rating;

[0051] Obtain the level of the second rating interval containing the home broadband complaint score as the home broadband complaint risk rating.

[0052] A metropolitan area network BRAS dual - machine configuration compliance detection system for implementing the above - mentioned metropolitan area network BRAS dual - machine configuration compliance detection method, includes:

[0053] Daily inspection module, which conducts daily business inspections during the transformation and daily maintenance of BRAS dual-machine backup;

[0054] Inspection classification module, which classifies daily business inspections into dual-machine status check, dual-machine networking check, and dual-machine local data check;

[0055] Status check module, which checks the compliance of the running status of BRAS dual-machines when conducting dual-machine status checks;

[0056] Networking check module, which checks the logical relationship and configuration of BRAS dual-machine networking when conducting dual-machine networking checks;

[0057] Local data check module, which checks the basic configuration data of the BRAS dual-machine system when conducting dual-machine local data checks;

[0058] Report generation module, which generates inspection reports based on the results of daily business inspections;

[0059] Tool formation module, which forms a dual-machine guarantee management tool for the metropolitan area network;

[0060] Hidden danger query module, which uses the dual-machine guarantee management tool for the metropolitan area network to discover various networking and configuration hidden dangers in the metropolitan area network;

[0061] Risk assessment module, which forms a failure risk rating for the metropolitan area network and a risk rating for home broadband complaints.

[0062] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0063] By setting up a daily inspection module, an inspection classification module, a hidden danger query module, and a risk assessment module, all situations involved in the complex metropolitan area network usage environment are classified and inspected, and a dual-machine guarantee management tool for the metropolitan area network is generated accordingly. With the help of the dual-machine guarantee management tool for the metropolitan area network, various networking and configuration hidden dangers in the metropolitan area network are discovered. At the same time, a failure risk rating for the metropolitan area network and a risk rating for home broadband complaints are formed. Furthermore, potential hidden dangers can be evaluated, and the handling order of hidden dangers can be determined based on the evaluation results. Thus, various networking and configuration hidden dangers in the metropolitan area network can be discovered in a timely manner, and hidden dangers with greater failure risks can be given priority treatment, thereby avoiding further failures that may be caused by hidden dangers. Description of the Drawings

[0064] Figure 1 It is a flow schematic diagram of the method for detecting the compliance of the BRAS dual-machine configuration in the metropolitan area network of the present invention;

[0065] Figure 2It is a schematic flow chart for checking the compliance of the running status of the BRAS dual machines during the dual-machine status check of the present invention;

[0066] Figure 3 It is a schematic flow chart for checking the logical relationship and configuration of the BRAS dual-machine networking during the dual-machine networking check of the present invention;

[0067] Figure 4 It is a schematic flow chart for checking the basic configuration data of the BRAS dual-machine system operation during the dual-machine local data check of the present invention;

[0068] Figure 5 It is a schematic flow chart for generating an inspection report according to the results of daily business inspections of the present invention;

[0069] Figure 6 It is a schematic flow chart for forming a dual-machine guarantee management tool for the metropolitan area network of the present invention;

[0070] Figure 7 It is a schematic flow chart for using the dual-machine guarantee management tool for the metropolitan area network to discover various networking and configuration hidden dangers in the metropolitan area network of the present invention;

[0071] Figure 8 It is a schematic flow chart for forming the failure risk rating of the metropolitan area network and the home broadband complaint risk rating of the present invention. Detailed implementation manners

[0072] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.

[0073] Referring to Figure 1 As shown, a method for detecting the compliance of the BRAS dual-machine configuration in the metropolitan area network includes:

[0074] During the transformation and daily maintenance of the BRAS dual-machine backup, daily business inspections are carried out, where BRAS is a broadband access server;

[0075] The daily business inspections include dual-machine status checks, dual-machine networking checks, and dual-machine local data checks;

[0076] When performing a dual-machine status check, the compliance of the running status of the BRAS dual machines is checked;

[0077] When performing a dual-machine networking check, the logical relationship and configuration of the BRAS dual-machine networking are checked;

[0078] When performing a dual-machine local data check, the basic configuration data of the BRAS dual-machine system operation is checked;

[0079] Generate an inspection report based on the results of daily business inspections;

[0080] Form a dual - machine guarantee management tool for the metropolitan area network. Use the dual - machine guarantee management tool for the metropolitan area network to discover various networking and configuration hidden dangers in the metropolitan area network, and form a failure risk rating for the metropolitan area network and a risk rating for home broadband complaints.

[0081] Refer to Figure 2 As shown, when performing a dual - machine status check, the compliance check of the BRAS dual - machine operating status includes the following steps:

[0082] When performing a compliance check on the BRAS dual - machine operating status, check the address pool, hot - standby sub - interface, hot - standby interface, and alarm;

[0083] Address pool check: Check for missing or incomplete address pool configurations, and obtain failed hot - standby user routes caused by address pool failures;

[0084] Hot - standby sub - interface check: Check the standardization of the Virtual Router Redundancy Protocol (VRRP) and the standardization of the VRRP tracking of the upstream monitoring group and Bidirectional Forwarding Detection (BFD). Conduct a hot - standby service switchover check, where BFD is a bidirectional forwarding detection mechanism;

[0085] Hot - standby interface check: Check whether there are overlapping or failed hot - standby interfaces;

[0086] Alarm check: Conduct an alarm check on the single - side switchover of the optical line terminal side, obtain the historical faults of the single - side of the optical line terminal, compare the results of the alarm check with the historical faults of the single - side of the optical line terminal, and obtain the actual faults of the single - side of the optical line terminal.

[0087] When performing a compliance check on the BRAS dual - machine operating status, classify and check various nodes involved in the operating status, so as to determine whether there are abnormalities in the BRAS dual - machine operating status. Since various situations are classified, there will be no omissions, and the inspection is more hierarchical.

[0088] Refer to Figure 3 As shown, when performing a dual - machine networking check, the check of the logical relationship and configuration of the BRAS dual - machine networking includes the following steps:

[0089] Conduct a dual - homing networking check for the optical line terminal. Based on the characteristics of the hot - standby status in the dual - homing networking, develop a dual - homing check algorithm, where the dual - homing check algorithm satisfies non - repetitive checking of the BRAS dual - machine;

[0090] Check the dual - homing information of the optical line terminal under the dual - machine BRAS daily, and check the logical relationship between the optical line terminal and the BRAS.

[0091] In a dual - machine networking scenario, the logical relationship of the networking and its basic configuration information have the greatest impact on the networking. Therefore, based on the logical relationship of the networking and its basic configuration information, it is possible to determine whether there is an abnormality in the dual - machine networking. To ensure non - repetitive checking, a dual - homing checking algorithm is set up. The area of the dual - machine networking is divided to obtain at least one checking area. The reference points of the checking area are obtained, and the maximum value of the distance from the points within the checking area to the reference points is taken as the characteristic distance. Furthermore, the algorithm is set to perform checks within each reference point and the range where the distance to the reference point is less than the characteristic distance.

[0092] Refer to Figure 4 As shown, when performing dual - machine bureau data checking, the checking of the basic configuration data of the BRAS dual - machine system includes the following steps:

[0093] Obtain the pre - formulated dual - machine configuration specifications, and in accordance with the formulated dual - machine configuration specifications, check the naming, address specifications, and configuration logical relationships in the configuration;

[0094] Generate customized scripts for optical line terminal access and hot - standby address pool expansion, back up and store the customized scripts as sample customized scripts, and use the customized scripts to configure optical line terminal access and hot - standby address pool expansion;

[0095] During the checking, compare the actually used customized script with the sample customized script. When there are differences between the two, it indicates that there are abnormalities in the configuration of optical line terminal access and hot - standby address pool expansion.

[0096] Optical line terminal access and hot - standby address pool expansion are extremely important steps. Therefore, instead of manual setting, customized scripts are used for setting. However, due to network attacks, the actually used customized script may be modified by network attacks. Therefore, regular comparison and detection are required.

[0097] Refer to Figure 5 As shown, according to the results of daily business inspections, generating an inspection report includes the following steps:

[0098] Generate an inspection report for the abnormalities found in daily business inspections. The inspection report consists of three parts, namely the dual - machine status part, the dual - machine networking part, and the dual - machine bureau data part;

[0099] In the dual - machine status part, summarize and list the results of the abnormal address pool check, hot - standby sub - interface check, hot - standby interface check, and alarm check;

[0100] In the dual - machine networking part, summarize and list the abnormal logical relationships and the abnormal optical line terminal dual - homing information;

[0101] In the data section of the dual - machine office, summarize and list the naming, address specifications, configuration logic relationships, and customized scripts with anomalies.

[0102] The inspection report is used to overall display the anomalies in the BRAS dual - machine configuration. Thus, the overall situation of the anomalies can be obtained.

[0103] Refer to Figure 6 As shown, the steps to form the management tool for dual - machine guarantee in the metropolitan area network are as follows:

[0104] The management tool for dual - machine guarantee in the metropolitan area network consists of a client, an analysis program, and an authentication end. The authentication end verifies the user login. The user who passes the verification logs in to the client and obtains the data generated by the analysis program.

[0105] Based on historical data, obtain the devices, circuits, ports, and potential trouble spots used by the BRAS dual - machine, store them and establish a database model, sort out the association relationships among the devices, circuits, ports, and potential trouble spots in the database model, and classify the related devices, circuits, ports, and potential trouble spots into the inspection sub - item sets.

[0106] The analysis program conducts sub - item inspections on the inspection sub - item sets.

[0107] Develop API interfaces to establish an inter - access channel between the client and the analysis program.

[0108] Develop the authentication end and set up the user authentication function at the authentication end.

[0109] In the BRAS dual - machine configuration, there are not only anomalies but also potential troubles, that is, problems that may become anomalies. Therefore, in order to give early warnings about potential troubles, a complete mechanism for early warning is needed. Thus, the management tool for dual - machine guarantee in the metropolitan area network is formed to classify and detect the nodes involved in the BRAS dual - machine configuration from multiple perspectives, so as to discover all potential troubles without omission, and accordingly, evaluate the potential troubles, sort them according to the urgency of the potential troubles, and give priority to dealing with more urgent potential troubles. Therefore, major failures caused by potential troubles can be avoided.

[0110] Refer to Figure 7 As shown, the steps to discover various networking and configuration potential troubles in the metropolitan area network using the management tool for dual - machine guarantee in the metropolitan area network are as follows:

[0111] The management tool for dual - machine guarantee in the metropolitan area network detects the dual - machines in the metropolitan area network, collects the status of all - volume bearer network devices based on the Secure Shell Protocol, connects the Secure Shell Protocol channels of all network devices, and realizes batch timed collection and log storage.

[0112] Record the business key indicators into the database at a daily granularity and generate a list of potential troubles for the dual - machines in the metropolitan area network every day.

[0113] Based on the hidden trouble list of the dual machines in the MAN, mine the hidden network faults, and generate at least one networking hidden trouble fault and at least one configuration hidden trouble fault.

[0114] Refer to Figure 8 As shown, forming the MAN fault risk rating and the home broadband complaint risk rating includes the following steps:

[0115] Based on big data, obtain the first risk value caused by the networking hidden trouble fault and the second risk value caused by the configuration hidden trouble fault;

[0116] Superimpose the first risk values of at least one networking hidden trouble fault to obtain the MAN fault score;

[0117] Superimpose the second risk values of at least one configuration hidden trouble fault to obtain the home broadband complaint score;

[0118] Based on historical data, obtain the value range of the MAN fault score, evenly divide the value range of the MAN fault score, and obtain at least one first rating interval;

[0119] Sort and number the first rating intervals in ascending order of the midpoints of the first rating intervals, and the level of the first rating interval is equal to its number;

[0120] Based on historical data, obtain the value range of the home broadband complaint score, evenly divide the value range of the home broadband complaint score, and obtain at least one second rating interval;

[0121] Sort and number the second rating intervals in ascending order of the midpoints of the second rating intervals, and the level of the second rating interval is equal to its number;

[0122] Obtain the level of the first rating interval containing the MAN fault score as the MAN fault risk rating;

[0123] Obtain the level of the second rating interval containing the home broadband complaint score as the home broadband complaint risk rating.

[0124] A MAN BRAS dual - machine configuration compliance detection system for implementing the above - mentioned MAN BRAS dual - machine configuration compliance detection method, includes:

[0125] Daily inspection module, which conducts daily service inspections during the transformation and daily maintenance of BRAS dual - machine backup;

[0126] Inspection classification module, which classifies daily service inspections into dual - machine status inspection, dual - machine networking inspection, and dual - machine office data inspection;

[0127] Status inspection module, which checks the compliance of the running status of the BRAS dual - machines when conducting dual - machine status inspections;

[0128] A networking inspection module. When the networking inspection module performs dual - machine networking inspection, it checks the logical relationship and configuration of the BRAS dual - machine networking.

[0129] An office data inspection module. When the office data inspection module performs dual - machine office data inspection, it checks the basic configuration data for the operation of the BRAS dual - machine system.

[0130] A report generation module. The report generation module generates an inspection report based on the results of daily business inspections.

[0131] A tool formation module, which forms a dual - machine guarantee management tool for the metropolitan area network.

[0132] A hidden danger query module. The hidden danger query module uses the dual - machine guarantee management tool for the metropolitan area network to discover various types of networking and configuration hidden dangers in the metropolitan area network.

[0133] A risk assessment module. The risk assessment module forms a risk rating for metropolitan area network failures and a risk rating for home broadband complaints.

[0134] Furthermore, this solution also proposes a storage medium, on which a computer - readable program is stored. When the computer - readable program is called, it executes the above - mentioned method for detecting the compliance of the BRAS dual - machine configuration in the metropolitan area network.

[0135] It can be understood that the storage medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a DVD; or a semiconductor medium, such as a solid - state drive (SSD).

[0136] In summary, the advantages of the present invention are as follows: By setting up a daily inspection module, an inspection classification module, a hidden danger query module, and a risk assessment module, all situations involved in the complex metropolitan area network usage environment are classified and inspected. Then, a dual - machine guarantee management tool for the metropolitan area network is generated. With the help of this tool, various types of networking and configuration hidden dangers in the metropolitan area network are discovered. At the same time, a risk rating for metropolitan area network failures and a risk rating for home broadband complaints are formed. Furthermore, the possible hidden dangers can be evaluated, and the handling order of the hidden dangers can be determined according to the evaluation results. Thus, various types of networking and configuration hidden dangers in the metropolitan area network can be discovered in a timely manner, and the hidden dangers with greater failure risks can be processed preferentially, thereby avoiding further failures that may be caused by the hidden dangers.

[0137] The basic principles, main features and advantages of the present invention have been shown and described above. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, various changes and improvements will occur to the present invention, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection required by the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for detecting compliance of dual-machine configuration of BRAS in a metropolitan area network, characterized in that: include: During the transformation and daily maintenance of BRAS dual-machine backup, daily business inspections are carried out, where BRAS is a broadband access server; Daily business inspections include dual-machine status inspection, dual-machine networking inspection, and dual-machine station data inspection; When performing a dual-machine status check, check the compliance of the BRAS dual-machine operating status; When checking the dual-machine networking, check the logical relationship and configuration of the BRAS dual-machine networking; When checking the dual-machine station data, check the basic configuration data of the BRAS dual-machine system operation; Generate inspection reports based on daily business inspection results; Create a metropolitan area network dual-machine security management tool, use the metropolitan area network dual-machine security management tool to discover various networking and configuration risks in the metropolitan area network, and form a metropolitan area network fault risk rating and home broadband complaint risk rating.

2. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 1, characterized in that: When performing the dual-machine status check, checking the compliance of the BRAS dual-machine operation status includes the following steps: When checking the compliance of the BRAS dual-machine operation status, check the address pool, hot standby sub-interface, hot standby interface, and alarms; Address pool check: Checks address pool misconfiguration and shortage, and obtains invalid hot standby user routes caused by address pool failure. Hot standby sub-interface check: Check the compliance of the virtual routing redundancy protocol and the compliance of the virtual routing redundancy protocol tracking uplink monitoring group and BFD, and perform hot standby service switching checks. BFD is a bidirectional forwarding detection mechanism. Hot standby interface check: Check whether there is overlap or failure in the hot standby interface; Alarm check: perform alarm check on unilateral switching on the optical line terminal side, obtain historical unilateral faults of the optical line terminal, compare the alarm check result with the historical unilateral faults of the optical line terminal, and obtain the actual unilateral faults of the optical line terminal.

3. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 2, characterized in that: When performing the dual-machine networking inspection, the logical relationship and configuration of the BRAS dual-machine networking are inspected, including the following steps: Conduct dual-homing network inspection of optical line terminals. Based on the characteristics of hot standby status in dual-homing network, develop a dual-homing inspection algorithm, where the dual-homing inspection algorithm is sufficient to perform non-duplication inspection on dual BRAS machines. Check the dual-home information of the optical line terminals under the dual-machine BRAS every day, and check the logical relationship between the optical line terminals and the BRAS.

4. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 3, characterized in that: When performing the dual-machine station data check, checking the basic configuration data of the BRAS dual-machine system operation includes the following steps: Obtain the pre-defined dual-machine configuration specification, and check the naming, address specification, and configuration logic relationship in the configuration according to the defined dual-machine configuration specification; A customized script is formed for optical line terminal access and hot standby address pool expansion, the customized script is backed up and stored as a sample customized script, and the customized script is used to configure optical line terminal access and hot standby address pool expansion; During the inspection, the customized script actually used is compared with the sample customized script. If there is a difference between the two, there is an abnormality in the configuration of optical line terminal access and hot standby address pool expansion.

5. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 4, characterized in that: Generating an inspection report based on the daily business inspection results includes the following steps: Generate inspection reports for abnormalities found in daily business inspections. The inspection reports consist of three parts: dual-machine status, dual-machine networking, and dual-machine station data. In the dual-machine status section, the results of abnormal address pool checks, hot standby sub-interface checks, hot standby interface checks, and alarm checks are summarized and listed; In the dual-machine networking part, the abnormal logical relationships and the abnormal dual-home information of optical line terminals are summarized and listed; In the dual-machine data section, the abnormal naming, address specifications, configuration logic relationships and customized scripts are summarized and listed.

6. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 5, characterized in that: The formation of the metropolitan area network dual-machine security management tool comprises the following steps: The metropolitan area network dual-machine security management tool consists of a client, an analysis program, and an authentication terminal. The authentication terminal verifies user logins. Verified users log in to the client and obtain data generated by the analysis program. Based on historical data, the equipment, circuits, ports and potential hazards used by the two BRAS machines are obtained, stored and a database model is established. The associations among the equipment, circuits, ports and potential hazards in the database model are sorted out, and the associated equipment, circuits, ports and potential hazards are classified into the inspection sub-item set. The analytical procedure performs sub-item inspection on the inspection item set; Develop API interfaces to establish mutual access channels between clients and analysis programs; Develop the authentication end and set up the user authentication function on the authentication end.

7. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 6, characterized in that: The use of the metropolitan area network dual-machine security management tool to discover various networking and configuration risks of the metropolitan area network includes the following steps: The metropolitan area network dual-machine security management tool detects the dual machines in the metropolitan area network, collects the status of all bearer network devices based on the secure shell protocol, connects the secure shell protocol channel of all network devices, and realizes batch timing collection and log storage; Key business indicators are recorded in the database at a daily granularity, and a list of hidden dangers of dual machines in the metropolitan area network is generated every day; Based on the dual-machine hidden danger list of the metropolitan area network, the hidden network faults are excavated to generate at least one networking hidden danger fault and at least one configuration hidden danger fault.

8. A method for detecting compliance of BRAS dual-machine configuration in a metropolitan area network according to claim 7, characterized in that: The forming of the metropolitan area network failure risk rating and the home broadband complaint risk rating comprises the following steps: Based on big data, a first risk value caused by a networking hidden danger failure and a second risk value caused by a configuration hidden danger failure are obtained; Superimposing the first risk value of at least one networking hidden danger fault to obtain a metropolitan area network fault score; The second risk value of at least one configuration hidden danger fault is superimposed to obtain a home broadband complaint score; Based on historical data, a value range of the metropolitan area network fault score is obtained, and the value range of the metropolitan area network fault score is evenly divided to obtain at least one first rating interval; Sort and number the first rating intervals from small to large according to the midpoint of the first rating interval, and the grade of the first rating interval is equal to its number; Based on the historical data, a value range of the home broadband complaint score is obtained, and the value range of the home broadband complaint score is evenly divided to obtain at least one second rating interval; Sort and number the second rating intervals from small to large according to the midpoints of the second rating intervals, and the level of the second rating interval is equal to its number; Obtaining the level of the first rating interval including the metropolitan area network fault score as the metropolitan area network fault risk rating; The level of the second rating interval including the home broadband complaint score is obtained as the home broadband complaint risk rating.

9. A metropolitan area network BRAS dual-machine configuration compliance detection system, used to implement the metropolitan area network BRAS dual-machine configuration compliance detection method according to any one of claims 1 to 8, characterized in that: include: A daily inspection module, which performs daily business inspections during the transformation and daily maintenance of BRAS dual-machine backup; Inspection classification module, the inspection classification module divides daily business inspection into dual-machine status inspection, dual-machine networking inspection and dual-machine station data inspection; A status check module, wherein when performing a dual-machine status check, the status check module checks the compliance of the BRAS dual-machine operating status; A network inspection module, when performing a dual-machine network inspection, the network inspection module inspects the logical relationship and configuration of the BRAS dual-machine network; A local data checking module, wherein when the local data checking module performs a dual-machine local data check, the basic configuration data of the BRAS dual-machine system operation is checked; A report generation module, wherein the report generation module generates an inspection report according to the daily business inspection results; A tool forming module, which forms a metropolitan area network dual-machine security management tool; A hidden danger query module, which uses a metropolitan area network dual-machine security management tool to discover various networking and configuration hidden dangers in the metropolitan area network; A risk assessment module forms a metropolitan area network failure risk rating and a home broadband complaint risk rating.