Micro burst traffic identification method and related equipment
By implementing micro burst monitoring strategies in network devices, filtering and compressing traffic data, identifying and monitoring micro burst traffic, the problem of difficult to identify and monitor micro burst traffic in the prior art is solved, and more efficient data processing and storage is achieved, and network overhead is reduced.
Patent Information
- Application Number
- CN202311805234.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-25
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art is difficult to effectively identify and monitor micro-burst traffic in communication networks, resulting in insufficient cache of network equipment and congestion and packet loss.
By implementing micro-burst monitoring strategies in network equipment, including reporting conditions, traffic indicators and thresholds, periodically collecting traffic data, filtering out preset percentage data with a value greater than the threshold as reporting data, and determining whether micro-burst traffic occurs based on reporting conditions.
It reduces the amount of data processed by network equipment, reduces storage pressure and network overhead, and improves the recognition efficiency and accuracy of micro burst traffic.
Smart Images

Figure CN120223644A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and in particular, to a method for identifying microburst traffic and related devices. Background Art
[0002] Microburst traffic is a type of short-duration and intense burst traffic in a communication network. Microburst traffic is the main cause of insufficient buffer in network devices, leading to congestion packet loss. Microburst traffic features a high burst rate and short duration, and is often not detected in time until a network device fails, thus affecting user services.
[0003] Currently, the monitoring of communication networks mainly uses telemetry technology. Telemetry technology is a network monitoring technology for remotely and rapidly collecting traffic data from network devices. With only one subscription request and one parsing request, it can continuously push data (such as interface traffic or memory data, etc.) according to the specified collection period, and its collection period can reach the millisecond level.
[0004] Although telemetry technology supports millisecond-level collection, it generates a huge amount of data, which is a huge pressure on the network devices themselves and also causes a huge network overhead. Summary of the Invention
[0005] Embodiments of this application provide a method for identifying microburst traffic and related devices.
[0006] In a first aspect of this application, a method for identifying microburst traffic is provided. In this application, a network device obtains a microburst monitoring policy, where the microburst monitoring policy includes a reporting condition, a traffic metric, and a corresponding threshold. The reporting condition is used to identify microburst traffic, and the traffic metric is a data type indicating the collected traffic data. Then, the network device periodically collects traffic data based on the traffic metric to obtain metric data, and determines reporting data from the metric data based on the threshold. The reporting data is traffic data in the metric data whose value is greater than a preset percentage of the threshold. If the reporting data meets the reporting condition, the network device determines that the microburst traffic has occurred.
[0007] Then, when the network device determines whether to send microburst traffic, it filters out the reporting data from the metric data based on the threshold, and then determines whether the reporting data meets the reporting condition. Compared with determining microburst traffic from the metric data, the amount of data that the network device needs to process is reduced.
[0008] In some possible implementation manners, the network device may receive the microburst monitoring policy sent by a network management device to obtain the microburst monitoring policy.
[0009] In some possible implementation manners, the network device includes a main control board and multiple chips. The multiple chips include a chip. After the network device determines the reported data from the metric data based on the threshold, the chip may perform data compression on the reported data to obtain compressed data, and send the compressed data to the main control board. Then, the main control board may decompress the compressed data to obtain the reported data. Through the above method, the storage pressure of the chip is reduced, and the situation of congestion packet loss caused by insufficient cache is reduced.
[0010] In some possible implementation manners, the compressed data includes prefix coding, a preset value, and the ratio between each traffic data in the reported data and the preset value. The prefix coding is used to represent the compressed data, thereby realizing the compression of the reported data.
[0011] In some possible implementation manners, the preset value is the threshold, thereby realizing the compression method specified by the network management device for the reported data.
[0012] In some possible implementation manners, the reporting condition is that there are at least two metric data not less than the threshold in the reported data, and the time interval between the at least two metric data is not greater than a preset duration. The at least two metric data are collected by the same chip, or the at least two metric data are collected by different chips respectively, thereby realizing the determination of microburst traffic.
[0013] In some possible implementation manners, after the network device determines that the microburst traffic has occurred, the network device determines the target data to be reported in the reported data according to the reporting condition. The target data is the data in the reported data whose value is greater than the threshold and the data of several cycles before and after it, and sends the target data to the network management device. Since the target data is selected from the reported data, the amount of data to be processed is further reduced, and the network overhead is reduced.
[0014] In some possible implementation manners, after the network device determines that the microburst traffic has occurred, the network device sends an alarm message. The alarm message is used to indicate that the microburst traffic has occurred. Then, the network device does not need to interact with an external network management device, that is, after the network device detects the microburst traffic, it saves the on-site data for operation and maintenance personnel to view and analyze.
[0015] In some possible implementation manners, the metric is the number of packet losses.
[0016] The second aspect of this application provides a network device for executing the method described in any one of the foregoing first aspects.
[0017] In a third aspect of the present application, a computer-readable storage medium is provided. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer, the computer is caused to execute the method provided in the first aspect or any possible implementation manner of the first aspect.
[0018] In a fourth aspect of the present application, a computer program product is provided. The computer program product includes computer-executable instructions, and the computer-executable instructions are stored in a computer-readable storage medium. At least one processor of a device can read the computer-executable instructions from the computer-readable storage medium, and execution of the computer-executable instructions by at least one processor causes the device to implement the method provided in the first aspect or any possible implementation manner of the first aspect.
[0019] In a fifth aspect of the present application, a communication device is provided. The communication device may include at least one processor, a memory, and a communication interface. At least one processor is coupled to the memory and the communication interface. The memory is used to store instructions, at least one processor is used to execute the instructions, and the communication interface is used to communicate with other communication devices under the control of at least one processor. When the instructions are executed by at least one processor, at least one processor is caused to execute the method in the first aspect or any possible implementation manner of the first aspect.
[0020] In a sixth aspect of the present application, a chip system is provided. The chip system includes a processor for supporting the implementation of the functions involved in the first aspect or any possible implementation manner of the first aspect.
[0021] In a possible design, the chip system may further include a memory for storing necessary program instructions and data. The chip system may be composed of chips or may include chips and other discrete devices.
[0022] Wherein, for the technical effects brought by the second to sixth aspects or any possible implementation manner thereof, reference may be made to the technical effects brought by the first aspect or different possible implementation manners of the first aspect, which will not be elaborated herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1-1 It is a schematic diagram of the composition structure of a communication system provided by an embodiment of the present application;
[0024] Figure 1-2 It is another schematic diagram of the composition structure of a communication system provided by an embodiment of the present application;
[0025] Figure 1-3 It is another schematic diagram of the composition structure of a communication system provided by an embodiment of the present application;
[0026] Figure 1-4Another schematic diagram of the composition structure of a communication system provided by an embodiment of the present application;
[0027] Figure 2-1 A schematic flowchart of a method for identifying microburst traffic provided by an embodiment of the present application;
[0028] Figure 2-2 A schematic diagram of a chip reporting compressed data in an embodiment of the present application;
[0029] Figure 3 Another schematic flowchart of a method for identifying microburst traffic provided by an embodiment of the present application;
[0030] Figure 4 Another schematic flowchart of a method for identifying microburst traffic provided by an embodiment of the present application;
[0031] Figure 5 A schematic diagram of the structure of a network device provided by an embodiment of the present application;
[0032] Figure 6 A schematic diagram of the structure of a communication device provided by an embodiment of the present application. Detailed implementation manners
[0033] Embodiments of the present application provide a method for identifying microburst traffic and related devices for identifying microburst traffic.
[0034] The embodiments of the present application will be described below with reference to the accompanying drawings.
[0035] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of the present application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.
[0036] Please refer to Figure 1-1 , embodiments of the present application can be applied to a communication system, including a network management device 110 and one or more network devices 120.
[0037] In some possible implementations, the network management device 110 can be a server or a functional module deployed in a server, which is not limited herein. In some possible implementations, the network management device 110 can be connected to a communication network to enable communication with multiple network devices 120.
[0038] The server mentioned above can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc., but is not limited thereto. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods, and the terminal and the server can be connected to form a blockchain network, which is not limited in this application.
[0039] Servers can vary significantly due to differences in configuration or performance. They can include at least one central processing unit (CPUs) (e.g., at least one processor) and a memory, and at least one storage medium (e.g., at least one mass storage device) for storing applications or data. Among them, the memory and the storage medium can be transient storage or persistent storage. The program stored in the storage medium can include at least one module, and each module can include a series of instruction operations on the server. Further, the central processor can be configured to communicate with the storage medium and execute a series of instruction operations in the storage medium on the server. The server can also include at least one power supply, at least one wired or wireless network interface, at least one input / output interface, and / or at least one operating system, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, NetWare, etc. In some feasible implementations, the server can also be a cloud server, which is not limited herein.
[0040] In some possible implementations, the network device 120 can be a router / switch in a communication network.
[0041] Among them, a router / switch is a hardware device that connects two or more user devices and acts as a gateway between the user devices. A router / switch is a dedicated intelligent network device that can read the destination address in a packet and determine how to transmit the packet according to the destination address; a router / switch can understand different protocols, such as the Ethernet protocol used in a local area network, the Transmission Control Protocol / Internet Protocol (TCP / IP) protocol used on the Internet, etc. In this way, a router / switch can analyze the destination addresses of packets transmitted from various different types of networks, convert non-TCP / IP addresses into TCP / IP addresses, or vice versa; and then, according to the routing algorithm, transmit each packet to the destination address along the optimal transmission path. Therefore, a router / switch can connect a non-TCP / IP network to the Internet.
[0042] Microburst traffic is a type of short-duration and intense burst traffic in a communication network. Microburst traffic is the main cause of insufficient cache in network devices, leading to congestion packet loss. Microburst traffic is characterized by a high burst rate and a short duration, and it is often impossible to be detected in time when it occurs until a network device fails, thus affecting user services.
[0043] Currently, the monitoring of communication networks mainly uses telemetry technology. Telemetry technology is a network monitoring technology that remotely and rapidly collects traffic data from network devices. With only 1 subscription request and 1 parsing request, it can continuously push data (such as interface traffic or memory data, etc.) according to the specified collection period, and its collection period can reach the millisecond level.
[0044] Although telemetry technology supports millisecond-level collection, it will generate a huge amount of data, which is a huge pressure on the network devices themselves and will also cause a huge network overhead.
[0045] Therefore, this application proposes a microburst traffic identification method and related devices for identifying microburst traffic.
[0046] In this application, a network device obtains a microburst monitoring policy, where the microburst monitoring policy includes a reporting condition, a traffic metric, and a corresponding threshold. The reporting condition is used to identify microburst traffic, and the traffic metric is a data type indicating the collected traffic data. Then, the network device periodically collects traffic data based on the traffic metric to obtain metric data, and determines reporting data from the metric data based on the threshold. The reporting data is traffic data in the metric data whose value is greater than a preset percentage of the threshold. If the reporting data meets the reporting condition, the network device determines that the microburst traffic has occurred.
[0047] Then, when the network device determines whether to send microburst traffic, it filters out the reporting data from the metric data based on the threshold, and then determines whether the reporting data meets the reporting condition. Compared with determining microburst traffic from the metric data, it reduces the amount of data that the network device needs to process.
[0048] In some possible implementation manners, as Figure 1-2 shown, a network device 120 includes a main control board 121 and one or more chips 122. Among them, an embedded monitoring center can run in the main control board 121, and the embedded monitoring center is a software entity.
[0049] Then, as Figure 1-3 shown, a network management device 110 is connected to one or more network devices 120. Then, based on Figure 1-2 and Figure 1-3 , the network management device 110, the main control board 121, and the chip 122 form a three-layer data reporting architecture. Among them, the network management device 110 can send the microburst monitoring policy to the network device 120; the main control board 121 in the network device 120 analyzes the microburst monitoring policy through the embedded monitoring center to obtain the reporting condition, one or more metrics, and the corresponding threshold, and sends the corresponding metrics and thresholds to the chip 122. In some possible implementation manners, the network management device 110 can internally store the microburst monitoring policy, the chip 122 can internally store one or more metrics and the corresponding thresholds, and the embedded monitoring center can internally store the reporting condition, which is not limited here.
[0050] Then, the chip 122 can collect traffic data according to the received metrics to obtain metric data, and filter out the reported data from the collected traffic data according to the threshold, and send the reported data to the embedded monitoring center in the main control board 121; alternatively, the chip 122 can compress the reported data to obtain compressed data, and send the compressed data to the embedded monitoring center in the main control board 121. After receiving the compressed data sent by the chip 122, the embedded monitoring center can, after decompression, determine the target data according to the reporting conditions (or first determine the target data and then decompress); alternatively, after receiving the reported data sent by the chip 122, the embedded monitoring center can determine the target data according to the reporting conditions. Then, the embedded monitoring center can send the target data to the network management device 110, and the network management device 110 can determine the microburst traffic based on the target data and analyze its cause.
[0051] Through the above method, the amount of reported data is gradually reduced layer by layer, reducing the storage capacity and also reducing the network overhead. Finally, only a small amount of high-value target data related to the microburst traffic is presented to the network management device.
[0052] In some possible implementation manners, such as Figure 1-4 shown, an embedded monitoring center and an embedded alarm center can run in the main control board 121, where the embedded alarm center is a software entity. Then, the embedded alarm center, the embedded monitoring center and the chip 122 in the main control board 121 form a three-layer data reporting architecture.
[0053] Among them, the network management device 110 can send the microburst monitoring policy to the network device 120; the main control board 121 in the network device 120 parses the microburst monitoring policy through the embedded monitoring center to obtain the reporting conditions, one or more metrics and the corresponding thresholds, and sends the corresponding metrics and thresholds to the chip 122. In some possible implementation manners, the network management device 110 can internally store the microburst monitoring policy, the chip 122 can internally store one or more metrics and the corresponding thresholds, and the embedded monitoring center can internally store the reporting conditions, which is not limited herein.
[0054] Among them, the chip 122 can collect traffic data according to the received metrics to obtain metric data, screen out the reported data from the collected traffic data according to the threshold, and send the reported data to the embedded monitoring center in the main control board 121; alternatively, the chip 122 can compress the reported data to obtain compressed data, and send the compressed data to the embedded monitoring center in the main control board 121. After receiving the compressed data sent by the chip 122, the embedded monitoring center can, after decompression, determine the target data according to the reporting conditions (or first determine the target data and then decompress); alternatively, after receiving the reported data sent by the chip 122, the embedded monitoring center can determine the target data according to the reporting conditions. Then, the embedded monitoring center can send the target data to the embedded alarm center, and the embedded alarm center can alarm the microburst traffic that occurs based on the target data, thereby identifying the microburst traffic.
[0055] The above method gradually reduces the amount of reported data, reducing the storage capacity and network overhead.
[0056] In some possible implementation manners, the embedded monitoring center or the embedded alarm center may not run in the main control board 121, but directly transparently transmit the reported data / compressed data sent by the chip 122 to the network management device 110. Then, as Figure 1-1 shown, the network management device 110 and the chip 122 in the network device 120 form a two-layer data reporting architecture.
[0057] Among them, the network management device 110 can send down the microburst monitoring policy to the network device 120; the chip 122 parses the microburst monitoring policy to obtain the reporting conditions, one or more metrics, and the corresponding thresholds. In some possible implementation manners, the network management device 110 may internally store the microburst monitoring policy, the chip 122 internally stores one or more metrics and the corresponding thresholds, and the network management device 110 internally stores the reporting conditions, which are not limited herein.
[0058] Among them, the chip 122 can collect traffic data according to the received metrics to obtain metric data, screen out the reported data from the collected traffic data according to the threshold, determine the target data based on the reporting conditions, and send the target data to the network management device 110; alternatively, the chip 122 can compress the reported data to obtain compressed data, and send the compressed data to the network management device 110. After receiving the compressed data sent by the chip 122, the network management device 110 decompresses it and determines the target data according to the reporting conditions (or first determines the target data and then decompresses); alternatively, after receiving the target data sent by the chip 122, the network management device 110 identifies the microburst traffic based on the target data.
[0059] The above method gradually reduces the amount of reported data, reducing the storage capacity and network overhead.
[0060] In the embodiments of the present application, based on different data reporting architectures, Embodiment 1, Embodiment 2, and Embodiment 3 are respectively described. Among them, Embodiment 1 is an embodiment implemented based on a three-layer data reporting architecture formed by a network management device 110, a main control board 121, and a chip 122. Embodiment 2 is an embodiment implemented based on a three-layer data reporting architecture formed by an embedded alarm center, an embedded monitoring center, and a chip 122. Embodiment 3 is an embodiment implemented based on a two-layer data reporting architecture formed by a chip 122 in a network management device 110 and a network device 120.
[0061] Please refer to Figure 2-1 , a method for identifying microburst traffic provided by Embodiment 1 of the present application mainly includes the following steps:
[0062] 201. The network management device sends a microburst monitoring policy to the network device.
[0063] In some possible implementation manners, the microburst monitoring policy is set by the user on the network management device or can be preset on the network management device, and no limitation is made here.
[0064] In some possible implementation manners, the network management device can send one or more microburst monitoring policies to each of one or more connected network devices, so that the one or more network devices determine whether to send microburst traffic according to the received one or more microburst monitoring policies. In some possible implementation manners, the microburst monitoring policies received by different network devices can be the same or can be different, and no limitation is made here.
[0065] In some possible implementation manners, the microburst monitoring policy sent by the network management device can be a file based on json / yaml / yang, and no limitation is made here. In some possible implementation manners, the network management device can send the microburst monitoring policy (file based on yang) through a network management protocol such as NETCONF or RESTCONF. The network management device can also send the microburst monitoring policy (when using json / yaml format) through a file transfer protocol such as FTP or SFTP, and no limitation is made here.
[0066] 202. The main control board in the network device parses the microburst monitoring policy through the embedded monitoring center to obtain the reporting conditions, one or more metrics, and the thresholds corresponding to each metric.
[0067] In some possible implementation manners, when the network device receives the microburst monitoring policy, the main control board in the network device can parse the microburst monitoring policy through the built-in embedded monitoring center to obtain the reporting conditions, one or more metrics, and the thresholds corresponding to each metric.
[0068] In some possible implementations, the embedded monitoring center may generate a monitoring instance according to the microburst monitoring policy. The monitoring instance is used to store the reporting condition, one or more metrics, and the thresholds corresponding to each metric, record the received data, and record the data sent by the embedded monitoring center to the network management device.
[0069] In the embodiments of the present application, the embedded monitoring center subscribes to the reporting condition and at least one metric and the corresponding threshold corresponding to each chip based on the microburst monitoring policy.
[0070] In some possible implementations, the metric is used to indicate the data type of the traffic data collected by the chip, such as the packet loss rate. Among them, the metrics indicated to different chips in the same network device may be different, and the same chip may also be indicated multiple different metrics, which is not limited here.
[0071] In some possible implementations, the threshold corresponding to the metric is used to indicate whether the chip needs to report the collected traffic data. That is, when the chip collects traffic data according to the metric, if the value of the traffic data is greater than or equal to the preset percentage of the threshold corresponding to the metric, it is determined that the traffic data is metric data. Among them, the thresholds corresponding to different metrics are not the same, or the thresholds corresponding to the same metric indicated in different chips under the network device are different, which is not limited here.
[0072] In some possible implementations, the reporting condition is used to identify microburst traffic based on the reported data.
[0073] Exemplarily, one or more metrics in the microburst monitoring policy may include: {metric 1, metric 2,..., metric N}; the thresholds corresponding to each metric may include: {threshold 1, threshold 2,..., threshold N}, where threshold 1 corresponds to metric 1, threshold 2 corresponds to metric key3,..., and threshold N corresponds to metric N; the reporting condition may include: {condition 1}.
[0074] 203. The main control board sends the metric and the corresponding threshold to the chip through the embedded monitoring center.
[0075] In some possible implementations, the embedded monitoring center may subscribe to at least one metric and the corresponding threshold from the microburst monitoring policy based on the need and distribute them to each chip. In some possible implementations, different chips may subscribe to the same or different one or more metrics and the corresponding thresholds.
[0076] In the embodiments of the present application, the embedded monitoring center may distribute the metric and the corresponding threshold through the internal message middleware between the main control board and the chip, which will not be elaborated here.
[0077] Exemplarily, the metrics assigned to the chip include Metric 1 and Metric 2, and the thresholds include Threshold 1 and Threshold 2, where Metric 1 corresponds to Threshold 1 and Metric 2 corresponds to Threshold 2. No limitation is made here.
[0078] 204. The chip collects traffic data based on the metrics to obtain metric data.
[0079] In some possible implementation manners, the chip may collect data based on the metrics at a millisecond-level period to obtain metric data. No limitation is made here.
[0080] Exemplarily, if the metrics include Metric 1 and Metric 2, then the metric data includes Metric Data 1 and Metric Data 2, where Metric Data 1 is the traffic data collected by the chip based on Metric 1, and Metric Data 2 is the traffic data collected by the chip based on Metric 2.
[0081] 205. The chip filters the metric data based on the thresholds to obtain the reported data.
[0082] In some possible implementation manners, after the chip collects the metric data, it may filter the metric data based on the thresholds to obtain the reported data, thereby implementing downsampling and reducing the amount of stored data. The reported data is the traffic data in the metric data whose value is greater than a preset percentage of the threshold.
[0083] Exemplarily, continuing the above example, after the chip collects Metric Data 1 based on Metric 1, it determines the data in Metric Data 1 whose value is greater than the preset percentage 1 of Threshold 1 to obtain Reported Data 1; after the chip collects Metric Data 2 based on Metric 2, it determines the data in Metric Data 2 whose value is greater than the preset percentage 2 of Threshold 2 to obtain Reported Data 2. Then, the reported data includes Reported Data 1 and Reported Data 2. Exemplarily, percentage 1 is equal to 50%, and percentage 2 is equal to 60%. No limitation is made here.
[0084] In some possible implementation manners, the reported data may further include the traffic data for several milliseconds before and after the metric data whose value is greater than the preset percentage of the threshold. Exemplarily, if the metric data t collected by the chip at time t is greater than the threshold * preset percentage, then the reported data includes the metric data t and the metric data for the previous and next 3 milliseconds.
[0085] In some possible implementation manners, the chip may record the metrics other than the reported data in the metric data as 0, thereby greatly reducing the amount of data stored and reducing the cache pressure of the chip.
[0086] 206. The chip compresses the reported data to obtain compressed data.
[0087] In some possible implementation manners, if the total amount of the reported data is large, the chip may perform data compression on the reported data to obtain compressed data. In some possible implementation manners, if the total amount of the reported data is not large, the chip may not perform compression on the reported data either, which is not limited herein.
[0088] In some possible implementation manners, the compression mode may be sent by an embedded monitoring center to the chip, or may be built in the chip, or may be carried by a network management device in a microburst monitoring policy, so that the chip can perform data compression on the reported data based on the compression mode to obtain compressed data. This is not limited herein.
[0089] In some possible implementation manners, the compression mode may be to record the reported data as a ratio to a corresponding preset value. Then, if the reported data includes multiple traffic data, the chip only needs to store one preset value and multiple compressed data. Since the encoding length of the compressed data is reduced compared to the reported data, the storage amount of the data is reduced. In some possible implementation manners, the preset value may be a threshold value or other preset values, which is not limited herein.
[0090] Exemplarily, the value of reported data 1 is 100, its binary value is 1100100, and the encoding length is 8 bits. The value of threshold 1 is 25, its binary value is 11001, and the encoding length is 5 bits. Then, the ratio of reported data 1 to threshold 1 is 125 / 25 = 5, its binary value is 101, and the encoding length is 3 bits. Then, the storage amount of the reported data is 8*N, and the storage amount of the compressed data is 5 + 3*N, where N is the number of reported data in the reported data. Then, if 5 + 3*N < 8*N, that is, N > 1, the storage amount of the data is reduced, and compression of the reported data is achieved. From another perspective, under the same storage amount of data, more reported data can be collected, or more metrics can be indicated, so as to achieve more accurate monitoring of microburst traffic.
[0091] Exemplarily, if reported data 1 is a decimal number (including an integer part and a decimal part), reported data 1 may be recorded as a.b times of preset value 1, where a is the integer part of the reported data, and b is the value of the first few digits of the decimal part of the reported data. Let reported data 1 be d times of preset value 1, then d = a + b%, a is the integer part of d, b is the first two digits of the decimal part of d, and both a and b are positive integers. If a does not exceed 100, the encoding length of a may be 7 bits; if b does not exceed 100, the encoding length of b may be 7 bits; then the encoding length of d is 7 + 7 = 14 bits.
[0092] For example, the value of the reported data 1 is 1,155,000, and its binary value is 100,011,001,111,110,111,000, that is, the coding length is 21 bits. If the preset value 1 is 100,000, its binary value is 11,000,011,010,100,000, that is, the coding length is 17 bits. Then, the reported data 1 is 11.55 times the preset value 1. Among them, the binary value of the integer part 11 of 11.55 is 0,001,011, and the binary value of 55 is 0,110,111, that is, the coding length of 11.55 is 14 bits, that is, 00,010,110,110,111.
[0093] In some possible implementation manners, when the chip obtains the compressed data, when storing the compressed data, a prefix code can be added to the compressed data to indicate that it is compressed data, so that the embedded monitoring center that receives the compressed data restores the compressed data to the reported data. Continuing the above example, the prefix code 1 can be 10, and then adding the 14-bit compressed data 1 to obtain 16 bits. Exemplarily, the compression code of the compressed data 1 is shown in Table 1 below.
[0094] Table 1
[0095]
[0096] In some possible implementation manners, the chip can record other metric data other than the reported data in the metric data as 0, and after compressing the reported data to obtain the compressed data, the number of bits of a single data of the preset value, the compressed data, and the metric data other than the reported data in the metric data is shown in Table 2 below.
[0097] Table 2
[0098] Preset value Indicator data other than the reported data Compressed data Number of bits 17 0 16
[0099] Among them, the preset value only needs to be recorded once, and its coding length is 21 bits. The metric data other than the reported data in the metric data is recorded as 0, and its coding length is 1 bit. The record of the compressed data is a.b, and its coding length is 16 bits. Then, if the number of metric data is 1 million and each metric data occupies 21 bits, it needs to occupy 21 million bits; if the coding length of the preset value is 17 bits, the number of compressed data is 500,000, and the number of metric data other than the reported data in the metric data is 500,000, then it needs 17 + 500,000 + 16 * 500,000 = (8.5 million + 17) bits, which greatly reduces the storage pressure compared with 21 million bits.
[0100] In some possible implementation manners, the encoding length of the compressed data can be set according to the degree of fluctuation of the reported data around a preset value. For example, if the value of the reported data fluctuates around 1000 times the preset value, since the binary value of 1000 is 1,111,101,000, the encoding length of the integer part of the compressed data is 10 bits. Then, according to prior knowledge, if the range of fluctuation of the reported data around the preset value is small when the reported data is abnormal, the encoding length of the compressed data can be further reduced.
[0101] In some possible implementation manners, the encoding length of the fractional part of the compressed data can be set according to the precision required for the compressed data. For example, if the precision of the compressed data is 3 digits after the decimal point, the encoding length of the fractional part of the compressed data is 10 bits.
[0102] 207. The chip sends the compressed data to the embedded monitoring center of the main control board.
[0103] In the embodiments of the present application, after the chip obtains the compressed data, it can report the compressed data to the embedded monitoring center in the main control board. Compared with reporting the reported data or the metric data to the embedded monitoring center, the amount of data is greatly reduced.
[0104] 208. The embedded monitoring center of the main control board decompresses the compressed data to obtain the reported data.
[0105] In the embodiments of the present application, when the embedded monitoring center receives the compressed data, it can decompress the compressed data to obtain the reported data. Exemplarily, various information in the compressed data is shown in Table 2. Then, the embedded monitoring center can multiply the compressed data by the preset value to obtain the reported data.
[0106] 209. The embedded monitoring center of the main control board determines the target data to be reported in the reported data according to the reporting condition.
[0107] In some possible implementation manners, the reporting condition may be that there are at least two metric data in the reported data that are not less than the threshold, and the time interval between the at least two metric data is not greater than the preset duration, the at least two metric data are all collected by the same chip, or the at least two metric data are collected by different chips respectively.
[0108] Then, if the reported data meets the reporting condition, the embedded monitoring center determines that there is a microburst traffic in the network device, and then the embedded monitoring center determines the target data to be reported in the reported data. In some possible implementation manners, the target data is the data in the reported data whose value is greater than the threshold and the data of several cycles before and after it.
[0109] Exemplarily, after the reported data includes metric data 1 and metric data 2, metric data 1 and metric data 2 are collected by the same chip, or metric data 1 is collected by chip 1 and metric data 2 is collected by chip 2. If the values of metric data 1 and metric data 2 are both greater than the threshold, and the time interval between the two metric data is not greater than the preset duration, then the embedded monitoring center determines that a microburst traffic has occurred in the network device, and the embedded monitoring center determines that the metric data 1 and metric data 2 are the target data to be reported.
[0110] Exemplarily, as Figure 2-2 shown, after the embedded monitoring center receives the compressed data, it can perform waveform restoration on the compressed data, that is, decompress it, to obtain the reported data. Then, the embedded monitoring center performs waveform operations on the reported data based on the reporting condition, that is, determines the target data to be reported in the reported data, and obtains the target data to be reported.
[0111] 210. The embedded monitoring center sends the target data to the network management device.
[0112] In the embodiment of the present application, when the embedded monitoring center determines the target data, it can report the target data to the network management device. Since the target data is sent to the network management device only after the reporting condition is met, that is, after it is determined that a microburst traffic has occurred, compared with directly sending the reported data, the amount of data is greatly reduced, that is, the network overhead is reduced.
[0113] In some possible implementation manners, when the embedded monitoring center sends the target data to the network management device, it adopts the static subscription mode of telemetry, that is, the embedded monitoring center actively establishes a connection with the network management device and sends the target data to the network management device.
[0114] 211. The network management device analyzes the microburst traffic based on the target data.
[0115] In some possible implementation manners, when the network management device receives the target data, since the target data meets the reporting condition, the network management device can determine that a microburst traffic has occurred, and then the network management device can further analyze the cause of the microburst traffic based on the target data.
[0116] Through the above method, the amount of reported data is reduced layer by layer, reducing the storage amount and also reducing the network overhead. Finally, only a small amount of high-value target data related to the microburst traffic is presented to the network management device.
[0117] Please refer to Figure 3 , a microburst traffic recognition method provided in the second embodiment of the present application mainly includes the following steps:
[0118] 301. The main control board sends metrics and corresponding thresholds to the chip through the embedded monitoring center.
[0119] 302. The chip collects traffic data based on the metrics to obtain metric data.
[0120] 303. The chip filters the metric data based on the thresholds to obtain the reported data.
[0121] 304. The chip compresses the reported data to obtain compressed data.
[0122] 305. The chip sends the compressed data to the embedded monitoring center of the main control board.
[0123] 306. The embedded monitoring center of the main control board decompresses the compressed data to obtain the reported data.
[0124] 307. The embedded monitoring center of the main control board determines the target data to be reported in the reported data according to the reporting conditions.
[0125] For steps 301 - 307, please refer to steps 203 - 209, which will not be elaborated here.
[0126] 308. The embedded monitoring center of the main control board sends the target data to the embedded alarm center of the main control board.
[0127] In the embodiments of the present application, when the embedded monitoring center determines the target data, it can report the target data to the embedded alarm center. Since the target data is sent to the embedded alarm center only after the reporting conditions are met, that is, after it is determined that a microburst traffic has occurred, compared with directly sending the reported data, the amount of data is greatly reduced, that is, the network overhead is reduced.
[0128] 309. The embedded alarm center of the main control board sends an alarm message based on the target data.
[0129] In some possible implementation manners, when the embedded alarm center receives the target data, the embedded alarm center can send an alarm message based on the target data, so that relevant personnel can locate and repair the problem based on the alarm information.
[0130] In the embodiments of the present application, when the embedded monitoring center uploads the target data to the embedded alarm center, the network device does not need to interact with an external network management device, that is, after the network device detects the microburst traffic, it saves the on-site data for the operation and maintenance personnel to view and analyze.
[0131] Please refer to Figure 4 , a method for identifying microburst traffic provided in Embodiment 3 of the present application mainly includes the following steps:
[0132] 401. The network management device sends a microburst monitoring policy to the network device.
[0133] Please refer to step 201 for step 401.
[0134] 402. The chip in the network device analyzes the microburst monitoring policy to obtain reporting conditions, one or more metrics, and thresholds corresponding to each metric.
[0135] For the process and results of the chip analyzing the microburst monitoring policy in step 402, please refer to the process and results of the main control board analyzing the microburst monitoring policy through the embedded monitoring center in 202, which will not be elaborated here.
[0136] 403. The chip collects traffic data based on the metrics to obtain metric data.
[0137] 404. The chip filters the metric data based on the thresholds to obtain reporting data.
[0138] Please refer to steps 204 - 205 for steps 403 - 404.
[0139] 405. The chip sends the reporting data to the network management device.
[0140] In the embodiments of the present application, when the chip obtains the reporting data, it can report the reporting data to the network management device. Compared with reporting the metric data to the network management device, the data volume is greatly reduced.
[0141] 406. The network management device determines the target data in the reporting data according to the reporting conditions.
[0142] Specifically, for the method by which the network management device determines the target data in the reporting data according to the reporting conditions, please refer to the method in step 209 where the embedded monitoring center determines the target data to be reported in the reporting data according to the reporting conditions, which will not be elaborated here.
[0143] 407. The network management device analyzes the microburst traffic based on the target data.
[0144] In some possible implementation manners, when the network management device determines the target data, since the target data meets the reporting conditions, the network management device can determine that microburst traffic has occurred. Then, the network management device can further analyze the cause of the microburst traffic based on the target data. Through the above method, the reported data volume is filtered, reducing the network overhead.
[0145] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0146] To facilitate better implementation of the above solutions of the embodiments of this application, relevant devices for implementing the above solutions are also provided below.
[0147] Please refer to Figure 5 As shown, a network device 500 provided by an embodiment of this application may include:
[0148] An acquisition module 501, configured to acquire a microburst monitoring policy, where the microburst monitoring policy includes a reporting condition, a traffic metric, and a corresponding threshold, the reporting condition is used to identify microburst traffic, and the traffic metric is a data type indicating the collected traffic data;
[0149] A processing module 502, configured to periodically collect traffic data based on the traffic metric to obtain metric data;
[0150] The processing module 502 is further configured to determine reported data from the metric data based on the threshold, where the reported data is traffic data in the metric data whose value is greater than a preset percentage of the threshold;
[0151] The processing module 502 is further configured to determine that the microburst traffic has occurred if the reported data meets the reporting condition.
[0152] In some possible implementation manners, the acquisition module 501 is specifically configured to: receive the microburst monitoring policy sent by a network management device.
[0153] In some possible implementation manners, the processing module 502 further includes a main control board 5021 and a chip 5022; the chip 5022 is configured to perform data compression on the reported data to obtain compressed data, and send the compressed data to the main control board; the main control board 5021 is configured to decompress the compressed data to obtain the reported data.
[0154] In some possible implementation manners, the processing module 502 is further configured to determine target data to be reported in the reported data according to the reporting condition, where the target data is data in the reported data whose value is greater than the threshold value and data of several cycles before and after the data; the network device 500 further includes a transceiver module 503, configured to send the target data to a network management device.
[0155] In some possible implementation manners, the transceiver module 503 is configured to send an alarm message, where the alarm message is used to indicate that the microburst traffic has occurred.
[0156] It should be noted that for the information interaction, execution process, etc. between the above-mentioned device modules / units, since they are based on the same concept as the method embodiments of the present application, the technical effects brought by them are the same as those of the method embodiments of the present application. For specific content, reference may be made to the description in the method embodiments shown above in the present application, and details are not described herein again.
[0157] The embodiment of the present application further provides a computer storage medium, where the computer storage medium stores a program, and the program executes some or all of the steps recorded in the above method embodiments.
[0158] Next, another communication device provided by the embodiment of the present application will be introduced. Please refer to Figure 6 As shown, the communication device 600 includes:
[0159] A receiver 601, a transmitter 602, a processor 603, and a memory 604. In some embodiments of the present application, the receiver 601, the transmitter 602, the processor 603, and the memory 604 may be connected through a bus or other means. Among them, Figure 6 taking the connection through the bus as an example.
[0160] The memory 604 may include a read-only memory and a random access memory, and provide instructions and data to the processor 603. A part of the memory 604 may further include a non-volatile random access memory (NVRAM). The memory 604 stores an operating system and operation instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof. Among them, the operation instructions may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic services and processing hardware-based tasks.
[0161] The processor 603 controls the operation of the communication device 600, and the processor 603 may also be referred to as a central processing unit (CPU). In a specific application, the various components of the communication device 600 are coupled together through a bus system, where the bus system may include, in addition to a data bus, a power bus, a control bus, a status signal bus, etc. However, for the sake of clarity, all kinds of buses are referred to as the bus system in the figure.
[0162] The method disclosed in the embodiments of the present application described above can be applied to the processor 603 or implemented by the processor 603. The processor 603 may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method can be completed by the integrated logic circuit in hardware or instructions in software form in the processor 603. The above-mentioned processor 603 may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 604, and the processor 603 reads the information in the memory 604 and combines its hardware to complete the steps of the above method.
[0163] The receiver 601 can be used to receive input digital or character information, and generate signal inputs related to relevant settings and function controls. The transmitter 602 may include a display device such as a display screen, and the transmitter 602 can be used to output digital or character information through an external interface.
[0164] In the embodiments of the present application, the processor 603 is used to execute the foregoing microburst traffic identification method.
[0165] In addition, it should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided in this application, the connection relationships between the modules indicate that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.
[0166] Through the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general hardware. Of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures used to implement the same function can also be various, such as analog circuits, digital circuits or dedicated circuits. However, for this application, software program implementation is a better implementation method in more cases. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk or optical disc of a computer, and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of this application.
[0167] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.
[0168] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are wholly or partially generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired means (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless means (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).
Claims
1. A method for identifying microburst traffic, characterized in that, including: The network device obtains a microburst monitoring policy, which includes a reporting condition, a traffic metric, and a corresponding threshold. The reporting condition is used to identify microburst traffic, and the traffic metric is a data type indicating the collected traffic data; The network device periodically collects traffic data based on the traffic metric to obtain metric data; The network device determines reporting data from the metric data based on the threshold. The reporting data is traffic data in the metric data whose value is greater than a preset percentage of the threshold; If the reporting data meets the reporting condition, the network device determines that the microburst traffic has occurred.
2. The method according to claim 1, wherein The network device obtaining the microburst monitoring policy includes: The network device receives the microburst monitoring policy sent by the network management device.
3. The method according to claim 1 or 2, characterized in that, The network device includes a main control board and a chip. After the network device determines reporting data from the metric data based on the threshold, the method further includes: The chip compresses the reporting data to obtain compressed data; The chip sends the compressed data to the main control board; The main control board decompresses the compressed data to obtain the reporting data.
4. The method according to claim 3, wherein The compressed data includes prefix coding, a preset value, and the ratio between each traffic data in the reporting data and the preset value. The prefix coding is used to characterize the compressed data.
5. The method according to claim 4, characterized in that, The preset value is the threshold.
6. The method according to any one of claims 1-5, characterized in that The reporting condition is that there are at least two metric data in the reporting data that are not less than the threshold, and the time interval between the at least two metric data is not greater than a preset duration. The at least two metric data are collected by the same chip, or the at least two metric data are collected by different chips respectively.
7. The method according to any one of claims 1-6, characterized in that, After the network device determines that the microburst traffic has occurred, the method further includes: The network device determines target data to be reported in the reporting data according to the reporting condition. The target data is the data in the reporting data whose value is greater than the threshold and the data in several cycles before and after it; The network device sends the target data to the network management device.
8. The method according to any one of claims 1 to 6, characterized in that, After the network device determines that the microburst traffic has occurred, the method further includes: The network device sends an alarm message, which is used to indicate that the microburst traffic has occurred.
9. A network device, characterized in that, including: An obtaining module, configured to obtain a microburst monitoring policy, which includes a reporting condition, a traffic metric, and a corresponding threshold. The reporting condition is used to identify microburst traffic, and the traffic metric is a data type indicating the collected traffic data; A processing module, configured to periodically collect traffic data based on the traffic metric to obtain metric data; The processing module is further configured to determine reporting data from the metric data based on the threshold. The reporting data is traffic data in the metric data whose value is greater than a preset percentage of the threshold; The processing module is further configured to determine that the microburst traffic has occurred if the reporting data meets the reporting condition.
10. The network device according to claim 9, characterized in that, The obtaining module is specifically configured to: Receive the microburst monitoring policy sent by the network management device.
11. The network device according to claim 9 or 10, wherein the processing module further includes a main control board and a chip; the chip is configured to compress the reported data to obtain compressed data, and send the compressed data to the main control board; the main control board is configured to decompress the compressed data to obtain the reported data.
12. The network device according to any one of claims 9-11, wherein the processing module is further configured to determine target data to be reported in the reported data according to the reporting condition, and the target data is data in the reported data whose value is greater than the threshold value and data in several cycles before and after the data; the network device further includes: a transceiver module, configured to send the target data to a network management device.
13. The network device according to any one of claims 9-11, characterized in that, It further includes: a transceiver module, configured to send an alarm message, and the alarm message is used to indicate that the microburst traffic has occurred.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a program, and the program causes a computer device to execute the method according to any one of claims 1-8.
15. A computer program product, characterized in that, The computer program product includes computer execution instructions, and the computer execution instructions are stored in a computer-readable storage medium; at least one processor of the device reads the computer execution instructions from the computer-readable storage medium, and the at least one processor executes the computer execution instructions to cause the device to execute the method according to any one of claims 1-8.
16. A communication device, characterized in that, The communication device includes at least one processor, a memory, and a communication interface; the at least one processor is coupled to the memory and the communication interface; the memory is used to store instructions, the processor is used to execute the instructions, and the communication interface is used to communicate with other communication devices under the control of the at least one processor; when the instructions are executed by the at least one processor, the at least one processor executes the method according to any one of claims 1-8.
17. A chip system, characterized in that, The chip system includes a processor and a memory, the memory and the processor are interconnected by a line, the memory stores instructions, and the processor is used to execute the method according to any one of claims 1-8.