Intelligent network management configuration verification method and system

By adopting multimodal verification pulse wave and spatiotemporal graph neural network model in network management, combining three-level repair strategies and three-dimensional topological sandboxes, the bottlenecks in traditional network management tools in detection, repair and prediction are solved, comprehensive detection and efficient repair of network status are achieved, and the level of management intelligence is improved.

CN120223534AInactive Publication Date: 2025-06-27XINJIANG BOXUN COMM ENG CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510488608.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In modern network environments, equipment heterogeneity is high and policy dependencies are complex. Traditional network management tools have significant bottlenecks in comprehensive detection, collaborative repair and dynamic prediction. Especially in the industrial Internet and 5G edge computing scenarios, it is difficult to effectively identify network blind spots, cross-device policy conflicts and architecture-level defects.

Method used

Multimodal verification pulse waves are used to detect network status, including broadcast pulses across the network, directional focus pulses and camouflage penetration pulses. A network blind spot topology map is built through the time difference positioning method, abnormal configuration sources are identified, and a three-level repair strategy is activated according to the type, including micro self-healing, distributed negotiation protocols and digital twin engine generation and reconstruction scheme. The spatial and temporal graph neural network model is used to deduce the network state change trend and generate a three-dimensional topological sandbox for visual interaction.

Benefits of technology

It realizes comprehensive detection and repair of network status, quickly identify and locate configuration errors and security risks, improves the network's adaptability and management intelligence level, and reduces the failure recovery time and human intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223534A_ABST
    Figure CN120223534A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of computer network management, and provides an intelligent network management configuration verification method and system, and the method comprises the steps: transmitting a multi-mode verification pulse wave containing a full-network broadcast pulse, a directional focusing pulse and a camouflage penetration pulse to network equipment, constructing a network blind area topological map through a time difference positioning method, and carrying out the verification of the network blind area topological map. Identifying the position and the type of the abnormal configuration source; activating a three-level repair strategy based on the exception type, wherein the three-level repair strategy comprises single-device microcosmic self-healing, a multi-device distributed negotiation protocol and architecture-level digital twinning reconstruction; deducing a network state change trend by using the space-time diagram neural network model, and generating network prediction data; and fusing the primary verification result, the repair result and the prediction data to generate a three-dimensional topological sand table, and displaying a space-time influence path of configuration change through a visual interface. Omnibearing detection, intelligent repair and active prediction of network configuration are realized, and efficiency, safety and adaptivity of network management are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention belongs to the technical field of computer network management, and in particular relates to an intelligent network management configuration verification method and system. Background Art

[0002] With the acceleration of digital transformation, network architecture is becoming increasingly complex, covering the integration needs of multiple scenarios such as cloud computing, Internet of Things, and industrial control. In this context, the accuracy of network configuration is directly related to business continuity and security. At present, network management technology is gradually developing in the direction of automation and intelligence. The mainstream technologies include policy-based configuration management, network simulation tools, and automated repair systems.

[0003] However, in modern network environments, devices are highly heterogeneous and policy dependencies are complex, and traditional methods have significant bottlenecks in comprehensive detection, collaborative repair, and dynamic prediction. Especially in the scenarios of industrial Internet and 5G edge computing, network blind spot detection, cross-device policy conflict identification, and architecture-level defect repair have become core issues that need to be solved urgently.

[0004] Traditional detection tools rely on a single protocol or local scanning, and cannot effectively identify abnormal configurations in network blind spots (such as cross-device ACL rule conflicts and disguised penetration vulnerabilities), and have weak threat level assessment capabilities for non-standard configuration items. In addition, existing simulation tools are mostly based on static modeling of historical data, and cannot deduce the propagation impact of configuration changes in real time. The early warning mechanism for short-term traffic fluctuations and long-term policy conflicts is imperfect, resulting in passive response to operations and maintenance. Summary of the invention

[0005] The purpose of the present invention is to provide an intelligent network management configuration verification method, aiming to solve the technical problems existing in the prior art identified in the background technology.

[0006] The present invention is implemented in this way: a method for verifying intelligent network management configuration, the method comprising:

[0007] Sending a multi-modal verification pulse wave to the network device, wherein the verification pulse wave includes three forms: a full network broadcast pulse, a directional focus pulse, and a disguised penetration pulse;

[0008] By receiving the verification echo data fed back by the device, a network blind spot topology map is constructed based on the time difference positioning method to identify the location and type of the abnormal configuration source as the primary verification result;

[0009] Activate the three-level repair strategy according to the type of abnormal configuration source to obtain the repair verification results, including: perform micro self-healing for simple errors of a single device, start the distributed negotiation protocol for multi-device linkage problems, and call the digital twin engine to generate a reconstruction plan for architecture-level defects;

[0010] After the execution of the three-level repair strategy, the spatio-temporal graph neural network model is used to deduce the changing trend of the network state and obtain network prediction data. The deduction includes three prediction mechanisms: instantaneous impact chain analysis, short-cycle acceleration simulation, and long-cycle conflict warning;

[0011] The primary verification result, repair verification result, and network prediction data are fused to generate a three-dimensional topological sand table, and a visual interaction interface is provided to display the spatio-temporal impact path of the configuration change.

[0012] As a further solution of the present invention, a multi-modal verification pulse wave is sent to the network device, where:

[0013] The full-network broadcast pulse encapsulates a lightweight verification instruction set using the UDP protocol, including three basic verification tasks: device fingerprint collection, basic policy verification, and connectivity test, and performs full-network broadcast at a period of 15 minutes;

[0014] The directional focusing pulse encapsulates a deep verification payload through the TCP protocol, and applies multi-layer verification pressure tests including BGP policy tree parsing, ACL rule conflict detection, and QoS policy stack analysis to the core routing device;

[0015] The disguised penetration pulse constructs a detection packet with protocol bionic characteristics, including simulating HTTP requests to detect load balancing policies, forging Modbus instructions to discover industrial network shadow devices, and generating false update packets with legal signatures to verify the firmware verification mechanism.

[0016] As a further solution of the present invention, the multi-modal verification pulse wave is executed at the device side:

[0017] Based on the multi-vendor configuration syntax rule library, abstract syntax tree analysis is performed to detect the threat level of unconventional configuration items;

[0018] The strategy dependency relationship network is constructed through the graph isomorphism algorithm to identify cross-device ACL rule conflict points;

[0019] In the sandbox environment, a mixed test traffic including financial transaction messages and industrial control instructions is injected, and the packet loss rate and delay deviation indicators are recorded to verify business continuity.

[0020] As a further solution of the present invention, the micro self-healing of single-device simple errors is specifically as follows:

[0021] When creating a temporary isolation area, a virtual firewall is deployed at the entrance of the target network segment through the SDN controller, and the service traffic of the abnormal device is dynamically redirected to the standby node based on the traffic fingerprint recognition technology;

[0022] A three-dimensional index template library built based on device manufacturers, operating system versions, and service types uses a fuzzy matching algorithm combined with device historical configuration features to generate a standardized correction instruction set;

[0023] When implementing gradual migration, establish a phased traffic monitoring channel, verify the repair stability through gradient business traffic recovery strategy, and generate a traceable verification log after each migration cycle.

[0024] As a further solution of the present invention, the initiation of a distributed negotiation protocol for the multi-device linkage problem specifically includes:

[0025] The abnormal configuration is abstracted into a feature vector containing the policy type and the impact range, and a negotiation request is sent to the associated device group through the multicast protocol;

[0026] Collect the computing load margin and policy compatibility scores returned by each device to build a multi-dimensional evaluation matrix;

[0027] A multi-objective optimization model is established based on the Pareto optimal principle, and the improved NSGA-II algorithm is used to solve the optimal repair path. The final execution plan is confirmed by digital signatures between devices:

[0028] ;

[0029] in, Indicates The repair operation is time-consuming. Represents the equipment criticality weight factor, represents the policy conflict indication function, represents the strategy type weight obtained from the multidimensional evaluation matrix, Represents the load balancing factor obtained by gradient service traffic recovery. Indicates the device The resource consumption rate, and They are CPU threshold and memory threshold respectively. Indicates the device CPU utilization, Indicates the device The memory usage of is the total number of devices in the current network topology, is the network connectivity, It is a network topology diagram.

[0030] As a further solution of the present invention, the deducing the network state change trend through the spatiotemporal graph neural network model specifically includes:

[0031] Calculate the 1-3 hop propagation range of change impact based on the improved Floyd-Warshall algorithm, and introduce a device criticality weight factor to adjust the weight distribution of impact values:

[0032] ;

[0033] Among them, represents the change impact value after hops from device to device , represents the criticality weight factor of device , represents the change amplification coefficient, is the protocol attenuation coefficient, represents the connection strength value from device to device ;

[0034] Inject historical 72-hour load data into the digital twin, and use the time compression algorithm to implement a 200-fold speed simulation of the network state in the next 2 hours;

[0035] Combine the special periods marked in the business calendar and the device maintenance plan to construct a long-term warning index system containing 12 risk dimensions.

[0036] As a further solution of the present invention, the generation of the three-dimensional topological sand table is specifically:

[0037] Use OpenGL to construct a hierarchical and expandable three-dimensional network model, and the core device is equipped with a thermal coloring system in the shape of an octahedron to display the risk level in real time;

[0038] The dynamic particle flow system maps the predicted bandwidth utilization rate into the movement trajectory of colored particles, and reflects the future traffic trend through the change of particle density and speed;

[0039] Support multi-touch gestures to realize topological rotation and scaling operations, and associate with the verification database to trigger the playback of configuration changes at any time point.

[0040] Another object of the present invention is to provide an intelligent network management configuration verification system, and the system includes:

[0041] A multi-modal verification pulse wave sending module for sending multi-modal verification pulse waves to network devices, and the verification pulse waves include three forms: full network broadcast pulse, directional focusing pulse, and camouflage penetration pulse;

[0042] A verification echo data receiving module for constructing a topological map of network blind areas based on the time difference positioning method by receiving the verification echo data fed back by the device, identifying the location and type of abnormal configuration sources as the primary verification result;

[0043] A three - level repair strategy activation module, which is used to activate a three - level repair strategy according to the type of abnormal configuration source to obtain a repair verification result, including: performing micro self - healing on simple errors of a single device, starting a distributed negotiation protocol for problems of multi - device linkage, and invoking a digital twin engine to generate a reconstruction plan for architecture - level defects;

[0044] A network status change trend deduction module, which is used to deduce the network status change trend through a spatio - temporal graph neural network model after the execution of the three - level repair strategy to obtain network prediction data. The deduction includes three prediction mechanisms: instantaneous impact chain analysis, short - cycle acceleration simulation, and long - cycle conflict warning;

[0045] A three - dimensional topological sand table generation module, which is used to fuse the primary verification result, the repair verification result, and the network prediction data to generate a three - dimensional topological sand table, and provide a visual interaction interface to display the spatio - temporal impact path of configuration changes.

[0046] The beneficial effects of the present invention are:

[0047] The application of multi - modal verification pulse waves ensures a comprehensive detection of the network status. The full - network broadcast pulse covers the entire network using the UDP protocol, the directional focusing pulse performs in - depth verification on core devices, and the disguised penetration pulse simulates real attacks, enhancing the network's security protection.

[0048] In terms of abnormal configuration identification, the system creates a network blind - area topological map through the time - difference positioning method to quickly identify the problem source. This dynamic analysis ability greatly improves the efficiency of fault repair and avoids the spread of errors.

[0049] Adopting a three - level repair strategy, simple errors of a single device are quickly isolated through micro self - healing, problems between multiple devices achieve collective decision - making through a distributed negotiation protocol, and architecture - level defects can be simulated and repaired through a digital twin engine. These strategies improve the network's adaptability.

[0050] Through the spatio - temporal graph neural network model for network status deduction, the system can actively predict potential conflicts and reduce the probability of faults. In addition, the generated three - dimensional topological sand table provides an intuitive visual interface, enhancing the interactivity of network management and helping administrators analyze the network status in real time. Brief Description of the Drawings

[0051] Figure 1 It is a flowchart of an intelligent network management configuration verification method provided by an embodiment of the present invention;

[0052] Figure 2 It is a flowchart of performing micro self - healing on simple errors of a single device provided by an embodiment of the present invention;

[0053] Figure 3 Flow chart for starting a distributed negotiation protocol for multi-device linkage problems provided by an embodiment of the present invention;

[0054] Figure 4 Flow chart for deducing the changing trend of network state through a spatio-temporal graph neural network model provided by an embodiment of the present invention;

[0055] Figure 5 Flow chart for generating a three-dimensional topological sand table provided by an embodiment of the present invention;

[0056] Figure 6 Structural block diagram of an intelligent network management configuration verification system provided by an embodiment of the present invention. Detailed implementation manners

[0057] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0058] Figure 1 Flow chart of an intelligent network management configuration verification method provided by an embodiment of the present invention, as Figure 1 shown, the method includes:

[0059] S100, sending a multi-modal verification pulse wave to a network device, where the verification pulse wave includes three forms: a full-network broadcast pulse, a directional focusing pulse, and a camouflage penetration pulse;

[0060] This step includes three forms of pulse waves: a full-network broadcast pulse, a directional focusing pulse, and a camouflage penetration pulse. Each pulse wave targets different verification tasks and device types to ensure the comprehensiveness and accuracy of the network.

[0061] First, the full-network broadcast pulse encapsulates a lightweight verification instruction set using the UDP protocol, including basic verification tasks such as device fingerprint collection, basic policy verification, and connectivity testing, and performs full-network broadcast at a period of 15 minutes. This design ensures that each device in the network can receive verification instructions regularly, thereby quickly discovering potential configuration problems and security risks.

[0062] Secondly, the directional focusing pulse encapsulates a deep verification payload through the TCP protocol, and applies multi-layer verification pressure tests to core routing devices, including BGP policy tree parsing, ACL rule conflict detection, and QoS policy stack analysis. This directional testing method can deeply explore the configuration details of key devices, identify possible configuration errors and security vulnerabilities in complex environments, and ensure the robustness of the core network structure.

[0063] The camouflaged penetration pulse constructs detection packets with protocol bionic features to simulate real network attack behaviors, verifying the defense capabilities of network devices against attack behaviors. By simulating HTTP requests, forging Modbus instructions, and generating false update packets with legitimate signatures, the system can test the response capabilities of devices and the effectiveness of security policies in the face of real attacks. This penetration testing not only enhances network security but also improves the early identification ability of potential threats.

[0064] On the device side, abstract syntax tree analysis based on the multi-vendor configuration syntax rule library can effectively detect the threat levels of unconventional configuration items. By constructing a policy dependency relationship network through the graph isomorphism algorithm, conflict points of cross-device ACL rules can be identified, providing more accurate configuration verification results. In addition, injecting mixed test traffic in the sandbox environment and recording the packet loss rate and delay deviation metrics ensure the continuity of critical services.

[0065] This step ensures the comprehensiveness and in-depth analysis of network device configurations through the implementation of multi-modal verification pulse waves, enabling the system to quickly identify and locate potential configuration errors and security risks in the initial stage. The significant advantage of this method lies in its flexibility and adaptability, which can implement corresponding verification strategies for different devices and network environments, reducing manual intervention and improving the intelligent level of network management. At the same time, this step provides a reliable data basis for subsequent identification and repair of abnormal configurations, making the entire configuration verification process more efficient and accurate. Through this systematic verification method, the security and stability of the network are significantly improved, providing strong support for the security management of complex network environments.

[0066] In this step, the multi-modal verification pulse wave is sent to the network device, where:

[0067] The full-network broadcast pulse encapsulates lightweight verification instruction sets using the UDP protocol, including three basic verification tasks: device fingerprint collection, basic policy verification, and connectivity testing, and performs full-network broadcasts at a 15-minute interval;

[0068] The directional focus pulse encapsulates deep verification payloads through the TCP protocol, imposing multi-layer verification stress tests on core routing devices, including BGP policy tree parsing, ACL rule conflict detection, and QoS policy stack analysis;

[0069] The camouflaged penetration pulse constructs detection packets with protocol bionic features, including simulating HTTP requests to detect load balancing policies, forging Modbus instructions to discover industrial network shadow devices, and generating false update packets with legitimate signatures to verify the firmware verification mechanism.

[0070] In this step, the multi-modal verification pulse wave is executed on the device side:

[0071] Implement abstract syntax tree analysis based on a multi-vendor configuration syntax rule library to detect the threat level of unconventional configuration items;

[0072] Construct a policy dependency relationship network through a graph isomorphism algorithm to identify cross-device ACL rule conflict points;

[0073] Inject mixed test traffic containing financial transaction messages and industrial control instructions into a sandbox environment, and record the packet loss rate and delay deviation metrics to verify service continuity.

[0074] S200, based on the verification echo data fed back by the device, construct a topology map of network blind spots through time difference positioning method to identify the location and type of abnormal configuration sources as the primary verification result;

[0075] The verification echo data is first processed by the time difference positioning method. This method uses the time difference required for signals to propagate between different devices to infer the relative positions between devices, thereby constructing the topology of the network. With this technology, the system can quickly identify potential configuration problems and their locations, and identify which devices have abnormal configurations, such as ACL rule conflicts or QoS policy errors. This blind spot topology map not only provides visual information about the network status, but also helps administrators quickly grasp the network health status, and thus provides a basis for subsequent decision-making.

[0076] By combining the time difference positioning method and the verification echo data, the system can quickly respond to configuration errors in the network and reduce the network failure time caused by misconfigurations. This efficient anomaly detection mechanism not only improves the network stability, but also lays a foundation for subsequent repair strategies.

[0077] S300, activate a three-level repair strategy according to the type of abnormal configuration source to obtain a repair verification result, including: perform micro self-healing for simple single-device errors, start a distributed negotiation protocol for multi-device linkage problems, and call a digital twin engine to generate a reconstruction plan for architecture-level defects;

[0078] The three-level repair strategy includes micro self-healing for simple single-device errors, a distributed negotiation protocol for multi-device linkage problems, and a digital twin engine to generate a reconstruction plan for architecture-level defects. This multi-level repair method not only covers errors at the device level, but also pays attention to the mutual influence between multiple devices, ensuring the overall consistency of network configuration.

[0079] Specifically, for simple errors in a single device, the system implements a micro self-healing process by creating a temporary isolation zone and deploying a virtual firewall at the entrance of the target network segment, using traffic fingerprinting technology to dynamically redirect the business traffic of the abnormal device to the backup node. This process ensures that even if a device fails, its impact on the entire network is minimized. At the same time, a three-dimensional index template library built based on device manufacturers, operating system versions, and service types, combined with a fuzzy matching algorithm to generate a standardized correction instruction set, helps to quickly restore the normal operation of the device. Through progressive migration and phased traffic monitoring channels, this method can also verify the stability of the repair and generate a traceable verification log to provide a reference for subsequent network management.

[0080] For the problem of multi-device linkage, the system starts a distributed negotiation protocol, abstracts the abnormal configuration into a feature vector, sends a negotiation request to the associated device group through the multicast protocol, collects the computing load margin and policy compatibility score of each device, and constructs a multi-dimensional evaluation matrix. This method not only promotes the collaborative work between devices, but also ensures that the best solution can be found through collective decision-making when facing complex problems. In addition, the multi-objective optimization model established based on the Pareto optimality principle uses the improved NSGA-II algorithm to solve the optimal repair path, providing refined guidance for the repair process.

[0081] When dealing with architectural defects, the digital twin engine is called to generate a reconstruction plan, allowing network administrators to plan and adjust based on the virtual model. This method provides a forward-looking way of thinking by simulating the entire network structure, which can evaluate the effects of different strategies before actual deployment and reduce risks.

[0082] Through multi-level repair strategies, not only the self-healing ability and reliability of the network are improved, but also the intelligent level of network management is enhanced. By quickly locating the source of the problem and formulating corresponding repair measures, the system can greatly reduce the need for human intervention and improve the efficiency of fault recovery. Compared with the traditional single repair method, this multi-level strategy makes network management more flexible and adaptable, ensuring the stability and security of the network in a complex and changing environment.

[0083] like Figure 2 As shown, the micro self-healing for a simple error of a single device specifically includes:

[0084] S311, when creating a temporary isolation zone, a virtual firewall is deployed at the entrance of the target network segment through the SDN controller, and the service traffic of abnormal devices is dynamically redirected to the backup node based on the traffic fingerprint recognition technology;

[0085] S312, a three-dimensional index template library built based on device manufacturers, operating system versions and service types, uses a fuzzy matching algorithm combined with device historical configuration features to generate a standardized correction instruction set;

[0086] S313, when implementing gradual migration, establish a phased traffic monitoring channel, verify the repair stability through a gradient business traffic recovery strategy, and generate a traceable verification log after each migration cycle.

[0087] like Figure 3 As shown, the distributed negotiation protocol is started for the multi-device linkage problem, specifically including:

[0088] S321, abstracting the abnormal configuration into a feature vector including the policy type and the impact range, and sending a negotiation request to the associated device group through a multicast protocol;

[0089] S322, collecting the computing load margin and policy compatibility score returned by each device to construct a multi-dimensional evaluation matrix;

[0090] S323, based on the Pareto optimal principle, a multi-objective optimization model is established, the improved NSGA-II algorithm is used to solve the optimal repair path, and the final execution plan is confirmed by digital signatures between devices:

[0091] ;

[0092] in, Indicates The repair operation is time-consuming. Represents the equipment criticality weight factor, represents the policy conflict indication function, represents the strategy type weight obtained from the multidimensional evaluation matrix, Represents the load balancing factor obtained by gradient service traffic recovery. Indicates the device The resource consumption rate, and They are CPU threshold and memory threshold respectively. Indicates the device CPU utilization, Indicates the device The memory usage of is the total number of devices in the current network topology, is the network connectivity, It is a network topology diagram.

[0093] S400, after the third-level repair strategy is executed, the network state change trend is deduced through the spatiotemporal graph neural network model to obtain network prediction data, wherein the deduction includes a triple prediction mechanism of instantaneous impact chain analysis, short-term acceleration simulation, and long-term conflict warning;

[0094] The three-level repair strategy includes micro-self-healing for simple errors in a single device, a distributed negotiation protocol for multi-device linkage problems, and a reconstruction solution for architectural-level defects.

[0095] When the system identifies a simple error in a single device, it will start a micro self-healing mechanism. Through the SDN controller, the system creates a temporary isolation zone and deploys a virtual firewall, using traffic fingerprinting technology to redirect the traffic of abnormal devices to backup nodes. This mechanism can quickly isolate problematic devices and reduce the impact on the overall network. At the same time, it generates a standardized set of correction instructions based on the historical configuration characteristics and manufacturer information of the device to ensure the efficiency and accuracy of the repair process. The gradually migrated traffic monitoring channel helps to verify the stability of the repair and ensure that the error can be effectively corrected.

[0096] For multi-device linkage problems, the system starts a distributed negotiation protocol. After abstracting the abnormal configuration into a feature vector, a negotiation request is sent to the associated device group through multicast, and the computing load and policy compatibility score of each device are collected to build a multi-dimensional evaluation matrix. This process promotes collaboration between devices and ensures that problems between multiple devices can be solved more effectively. The multi-objective optimization model established based on the Pareto optimality principle solves the optimal repair path through the improved NSGA-II algorithm, ensuring the efficiency and rationality of the repair solution.

[0097] When faced with architectural defects, the system will call the digital twin engine to generate a reconstruction plan. By virtualizing and simulating the network architecture, the effectiveness of various repair strategies can be evaluated before actual deployment, reducing the risks caused by incorrect repairs. This not only improves the network's resilience, but also enhances the level of intelligent management, allowing the network to adapt to complex and dynamic environments.

[0098] The improved Floyd-Warshall algorithm is used to calculate the 1-3 hop propagation range of the change, and the device criticality weight factor is introduced to adjust the weight distribution of the impact value. This method significantly improves the sensitivity to changes in network status, can reflect the impact of the status of each device in the network on the overall performance in real time, and helps network managers make timely decisions.

[0099] Through the processing of different anomaly configuration sources, the network can achieve fast and efficient self-healing and repair, greatly reducing the time cost of fault recovery. Compared with traditional single repair methods, this step not only improves the stability and security of the network, but also provides more scientific decision-making support for future network management. This comprehensive methodology lays the foundation for the intelligent management of the network, ensuring the continuous availability of the network in complex environments.

[0100] As Figure 4 shown, the deduction of the network state change trend through the spatio-temporal graph neural network model specifically includes:

[0101] S410, Calculate the 1-3 hop propagation range affected by the change based on the improved Floyd-Warshall algorithm, and introduce the device criticality weight factor to adjust the weight distribution of the influence value:

[0102] ;

[0103] Among them, represents the change influence value of device to device after hops, represents the criticality weight factor of device , represents the change amplification coefficient, is the protocol attenuation coefficient, represents the connection strength value of device to device ;

[0104] S420, Inject historical 72-hour load data into the digital twin, and use the time compression algorithm to perform a 200-fold speed simulation deduction of the network state in the next 2 hours;

[0105] S430, Combine the special periods marked by the business calendar and the device maintenance plan to construct a long-term warning index system containing 12 risk dimensions.

[0106] S500, Integrate the primary verification result, the repair verification result and the network prediction data to generate a three-dimensional topological sand table, and provide a visual interaction interface to display the spatio-temporal impact path of the configuration change.

[0107] The construction of the three-dimensional topological sand table first uses OpenGL technology to create a three-dimensional network model that can be unfolded layer by layer. In this model, the core device adopts an octahedron shape and is equipped with a thermal coloring system to display the risk level in real time. The application of this heat map enables the security status of the network to be clearly visible at a glance, allowing managers to quickly identify the areas that require the most attention and take corresponding measures. This intuitive visual representation helps to better understand the complex network architecture and the interrelationships between devices.

[0108] In addition, the introduction of the dynamic particle flow system maps the predicted bandwidth utilization into the movement trajectories of colored particles, and the changes in particle density and speed reflect the future traffic trends. This dynamic simulation not only provides real-time feedback for the prediction of network traffic but also intuitively shows the distribution of traffic among various devices, thus helping managers optimize resource allocation. This way of visualizing traffic enables network managers to more effectively identify potential bottlenecks and conflict points under high-load conditions, providing a basis for subsequent network optimization.

[0109] The interactive function that supports multi-touch gestures allows users to conveniently rotate and zoom the topological sand table, further enhancing the user experience. Managers can view the network status of different levels and regions at any time as needed, quickly replay configuration changes at any time point, and understand their impact on the current network status. This interactivity greatly enhances the flexibility and real-time nature of network management.

[0110] By converting complex data into an intuitive graphical display through three-dimensional visualization technology, network managers can quickly respond in a rapidly changing network environment. In the old network management methods, data analysis often relied on static reports and abstract numbers, lacking intuitiveness and timeliness. Through step S5, network managers can obtain the health status, traffic trends, and risk assessment of the network in real time, thus making more accurate and rapid decisions.

[0111] In addition, by combining the primary verification results with the repair verification results, a closed-loop feedback mechanism is formed, further enhancing the adaptive ability of network management. This method not only improves the stability and security of the network but also provides an effective path for future intelligent network management.

[0112] As Figure 5 shown, the generation of the three-dimensional topological sand table is specifically as follows:

[0113] S510, use OpenGL to construct a three-dimensional network model that can be unfolded layer by layer, and the core device adopts an octahedron shape and is equipped with a thermal coloring system to display the risk level in real time;

[0114] S520. The dynamic particle flow system maps the predicted bandwidth utilization into colored particle motion trajectories, and reflects the future traffic trend through the change of particle density and speed.

[0115] S530. It supports multi-touch gestures to implement topological rotation and zoom operations, and associates with the verification database to trigger the playback of configuration changes at any time point.

[0116] Figure 6 The structure block diagram of an intelligent network management configuration verification system provided by an embodiment of the present invention is shown as Figure 6 shown. The system includes:

[0117] The multimodal verification pulse wave sending module 100 is used to send multimodal verification pulse waves to network devices. The verification pulse waves include three forms: full-network broadcast pulses, directional focusing pulses, and disguised penetration pulses.

[0118] The verification echo data receiving module 200 is used to construct a network blind area topology map based on the time difference positioning method by receiving the verification echo data fed back by the receiving device, identify the location and type of abnormal configuration sources, and use it as the primary verification result.

[0119] The three-level repair strategy activation module 300 is used to activate the three-level repair strategy according to the type of abnormal configuration source to obtain the repair verification result, including: performing micro self-healing on simple errors of a single device, starting a distributed negotiation protocol for multi-device linkage problems, and calling a digital twin engine to generate a reconstruction plan for architecture-level defects.

[0120] The network state change trend deduction module 400 is used to deduce the network state change trend through a spatio-temporal graph neural network model after the three-level repair strategy is executed, obtain network prediction data. The deduction includes three prediction mechanisms: instantaneous impact chain analysis, short-cycle acceleration simulation, and long-cycle conflict warning.

[0121] The three-dimensional topology sand table generation module 500 is used to fuse the primary verification result, the repair verification result, and the network prediction data to generate a three-dimensional topology sand table, and provide a visual interaction interface to display the spatio-temporal impact path of configuration changes.

[0122] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0123] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0124] The above embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent for the present invention should be subject to the appended claims.

[0125] The above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for verifying intelligent network management configuration, characterized in that: The method comprises: Sending a multi-modal verification pulse wave to the network device, wherein the verification pulse wave includes three forms: a full network broadcast pulse, a directional focus pulse, and a disguised penetration pulse; By receiving the verification echo data fed back by the device, a network blind spot topology map is constructed based on the time difference positioning method to identify the location and type of the abnormal configuration source as the primary verification result; Activate the three-level repair strategy according to the type of abnormal configuration source to obtain the repair verification results, including: perform micro self-healing for simple errors of a single device, start the distributed negotiation protocol for multi-device linkage problems, and call the digital twin engine to generate a reconstruction plan for architecture-level defects; After the three-level repair strategy is executed, the network status change trend is deduced through the spatiotemporal graph neural network model to obtain network prediction data. The deduction includes a triple prediction mechanism of instantaneous impact chain analysis, short-term acceleration simulation and long-term conflict warning. The primary verification results, repair verification results and network prediction data are integrated to generate a three-dimensional topology sandbox, providing a visual interactive interface to display the spatiotemporal impact path of configuration changes.

2. The method according to claim 1, characterized in that The multi-modal verification pulse wave is sent to the network device, wherein: The full network broadcast pulse uses the UDP protocol to encapsulate a lightweight verification instruction set, including three basic verification tasks: device fingerprint collection, basic policy verification, and connectivity test, and is broadcast to the entire network in a 15-minute cycle; The directional focused pulse encapsulates a deep verification payload through the TCP protocol, and applies a multi-layer verification stress test including BGP policy tree parsing, ACL rule conflict detection, and QoS policy stack analysis to the core routing equipment; The disguised penetration pulse constructs a detection packet with protocol bionic features, including simulating HTTP requests to detect load balancing strategies, forging Modbus instructions to discover industrial network shadow devices, and generating false update packages with legal signatures to verify the firmware verification mechanism.

3. The method according to claim 1, characterized in that The multimodal verification pulse wave is executed on the device side: Implement abstract syntax tree analysis based on multi-vendor configuration syntax rule base to detect the threat level of unconventional configuration items; Build a policy dependency network through graph isomorphism algorithm to identify cross-device ACL rule conflict points; Inject mixed test traffic containing financial transaction messages and industrial control instructions into the sandbox environment, and record the packet loss rate and delay deviation indicators to verify business continuity.

4. The method according to claim 1, characterized in that The micro self-healing for a simple error of a single device specifically includes: When creating a temporary isolation zone, a virtual firewall is deployed at the entrance of the target network segment through the SDN controller, and the service traffic of abnormal devices is dynamically redirected to the backup node based on traffic fingerprint recognition technology; A three-dimensional index template library built based on device manufacturers, operating system versions, and service types uses a fuzzy matching algorithm combined with device historical configuration features to generate a standardized correction instruction set; When implementing gradual migration, establish a phased traffic monitoring channel, verify the repair stability through gradient business traffic recovery strategy, and generate a traceable verification log after each migration cycle.

5. The method according to claim 1, characterized in that The distributed negotiation protocol is initiated for the multi-device linkage problem, specifically including: The abnormal configuration is abstracted into a feature vector containing the policy type and the impact range, and a negotiation request is sent to the associated device group through the multicast protocol; Collect the computing load margin and policy compatibility scores returned by each device to build a multi-dimensional evaluation matrix; A multi-objective optimization model is established based on the Pareto optimal principle, and the improved NSGA-II algorithm is used to solve the optimal repair path. The final execution plan is confirmed by digital signatures between devices: ; in, Indicates The repair operation is time-consuming. Represents the equipment criticality weight factor, represents the policy conflict indication function, represents the strategy type weight obtained from the multidimensional evaluation matrix, Represents the load balancing factor obtained by gradient service traffic recovery. Indicates the device The resource consumption rate, and They are CPU threshold and memory threshold respectively. Indicates the device CPU utilization, Indicates the device The memory usage of is the total number of devices in the current network topology, is the network connectivity, It is a network topology diagram.

6. The method according to claim 1, characterized in that The deducing of the network state change trend through the spatiotemporal graph neural network model specifically includes: The 1-3 hop propagation range of the change impact is calculated based on the improved Floyd-Warshall algorithm, and the device criticality weight factor is introduced to adjust the impact value weight distribution: ; in, Indicates the device To device go through The change impact value of the jump, Indicates the device The key weight factor of Indicates the change of magnification factor, is the protocol attenuation coefficient, Indicates the device To device The connection strength value of Inject 72 hours of historical load data into the digital twin, and use a time compression algorithm to simulate the network status in the next two hours at 200 times the speed. By combining the special time periods marked in the business calendar with the equipment maintenance plan, a long-term early warning indicator system with 12 risk dimensions is constructed.

7. The method according to claim 1, characterized in that The generating of the three-dimensional topological sandbox is specifically as follows: OpenGL is used to build a hierarchically expandable three-dimensional network model, and the core equipment is equipped with an octahedral thermal shading system to display the risk level in real time; The dynamic particle flow system maps the predicted bandwidth utilization into the movement trajectory of colored particles, reflecting the future traffic trend through the changes in particle density and speed; Supports multi-touch gestures to implement topology rotation and zoom operations, and associates the verification database to trigger configuration change playback at any time point.

8. An intelligent network management configuration verification system, characterized in that: The system comprises: A multi-modal verification pulse wave sending module is used to send a multi-modal verification pulse wave to a network device, wherein the verification pulse wave includes three forms: a full network broadcast pulse, a directional focus pulse, and a camouflage penetration pulse; The verification echo data receiving module is used to construct a network blind spot topology map based on the time difference positioning method by receiving the verification echo data fed back by the device, and identify the location and type of the abnormal configuration source as the primary verification result; The three-level repair strategy activation module is used to activate the three-level repair strategy according to the type of abnormal configuration source and obtain the repair verification results, including: performing micro self-healing for simple errors of a single device, starting a distributed negotiation protocol for multi-device linkage problems, and calling the digital twin engine to generate a reconstruction plan for architecture-level defects; The network status change trend deduction module is used to deduce the network status change trend through the spatiotemporal graph neural network model after the execution of the three-level repair strategy to obtain network prediction data. The deduction includes a triple prediction mechanism of instantaneous impact chain analysis, short-term acceleration simulation and long-term conflict warning; The three-dimensional topology sand table generation module is used to fuse the primary verification results, repair verification results and network prediction data to generate a three-dimensional topology sand table, and provide a visual interactive interface to display the spatiotemporal impact path of configuration changes.

Citation Information

Cited By

  • Network configuration information changing method and system

    CN122293508A