Network device configuration checking method, system, device and storage medium
By building a knowledge graph and command inspector based on a large language model, the problem of insufficient scalability and reliability in network device configuration verification is solved, and intelligent and automated configuration verification is realized, reducing the risk of human error.
Patent Information
- Application Number
- CN202510305358.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-11
AI Technical Summary
The existing technology has low scalability and reliability in network equipment configuration verification, insufficient intelligence and automation levels, and there is a risk and loss of artificial configuration errors.
By analyzing the network equipment manual, configuration information, parameter value constraints and instruction attribute relationships are extracted, knowledge graphs are built based on large language models, command inspectors are dynamically built, and dependency conflict relationships are determined through the relationship reasoning and indexing mechanism of the knowledge graph.
It improves the scalability and reliability of configuration verification, improves the intelligence and automation level of network equipment configuration verification, and reduces the risk of human error.
Smart Images

Figure CN120301770A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network device configuration verification, and in particular, to a network device configuration verification method, system, device, and storage medium. Background Art
[0002] The large-scale application of network devices can promote the emergence of new industries, new business forms, and new models, and contribute to the rapid development of the digital economy and the promotion of the social informatization process. However, as the carrier supporting the business development of various industries in the Internet era, whether the network devices operate safely and stably directly affects whether various services can be carried out smoothly. Therefore, users have put forward higher requirements for the equipment, management, maintenance, etc. of network manufacturers. As one of the potential threats affecting the normal operation of network devices, configuration errors usually require a lot of time to check configuration files and configuration commands to locate faults. Moreover, with the further expansion of the network scale and the update and iteration of network devices, their configuration commands show the characteristics of diversification and complexity, and manual configuration becomes increasingly challenging, easily causing problems such as spelling mistakes, parameter value violations of constraint conditions, and ignoring the dependency conflict relationships between commands. In this context, how to accurately locate and repair configuration errors, that is, to achieve configuration verification, has become a key problem that needs to be solved urgently.
[0003] Traditional configuration verification methods focus on program analysis and machine learning. ConfDebugger and ManifestInspector, etc. use static analysis methods to detect software configuration errors, but they rely on predefined rules and are difficult to adapt to frequently updated scenarios, with poor adaptability and flexibility. Some machine learning methods using decision trees or support vector machines require high-quality labeled data for training, and the cost of obtaining and maintaining these data is relatively high, which hinders their application in practice. In addition, there are also some methods based on databases or knowledge bases that detect configuration faults by comparing similarities. This method relies on existing data for simple matching and comparison and cannot handle complex configuration problems. In recent years, large language models have made remarkable progress in many tasks, providing a new direction for automated configuration verification. In the prior art, the scalability and reliability of configuration verification are relatively low, the intelligent and automated level of network device configuration verification is insufficient, and there are risks and losses brought by human configuration errors. Summary of the Invention
[0004] Based on this, it is necessary to address the above problems and propose a network device configuration verification method, system, device, and storage medium.
[0005] A network device configuration verification method, the method comprising:
[0006] Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0007] Construct a knowledge graph by fine-tuning a large model based on the configuration information, the parameter value constraints, and the instruction attribute relationships;
[0008] Dynamically construct a command checker based on the knowledge graph and verify the command instances in the network device manual;
[0009] Based on the relationship reasoning and indexing mechanism of the knowledge graph, determine the dependency conflict relationships between the instances to be verified.
[0010] In one embodiment, the parsing of the network device manual and the extraction of configuration information include:
[0011] Based on the semi-structured data stored in the network device manual and combined with the configuration verification requirements, use a web parsing tool to extract configuration information from the network device manual; the configuration information includes: command class, command set, command, command format, parameter, parent view, usage guide, usage example, command function, parameter value, and parameter description.
[0012] In one embodiment, the parsing of the network device manual and the extraction of parameter value constraints and instruction attribute relationships include:
[0013] Construct an instruction fine-tuning dataset according to the text information stored in the network device manual, and the instruction fine-tuning dataset includes: entering the view, parameter constraint generation, command relationship extraction, and command function Q&A;
[0014] Fine-tune the Chinese large model according to the instruction fine-tuning dataset to obtain the instruction fine-tuning large model;
[0015] Generate target triples corresponding to the instruction fine-tuning dataset according to the text information and the instruction fine-tuning large model;
[0016] Determine the parameter value constraints and instruction attribute relationships according to the target triples.
[0017] In one embodiment, the constructing of the knowledge graph according to the configuration information, the parameter value constraints, and the instruction attribute relationships includes:
[0018] Establish a many-to-many mapping relationship between the command format and the parameters;
[0019] Use the command set as the first layer of entities in the knowledge graph;
[0020] Based on specific keywords, classify the commands in the command set into configuration commands and negative commands, and use the configuration commands and the negative commands as the second layer of entities in the knowledge graph;
[0021] The command format of each command serves as the third-level entity in the knowledge graph;
[0022] Associate the command format with the second-level entity in the knowledge graph according to structural similarity and specific keywords.
[0023] In one embodiment, the dynamically constructing a command checker according to the knowledge graph includes:
[0024] Determine each command format stored in the knowledge graph and construct a subgraph for the command format;
[0025] The starting nodes of the subgraphs are all connected to the global starting node, and each node in the subgraph represents a keyword, sub-parameter, or symbol in the command format;
[0026] All the subgraphs constitute a command checker.
[0027] In one embodiment, the verifying the command instances in the network device manual includes:
[0028] Starting from the global starting node of the command checker, verify the command instances by using a breadth-first traversal search method;
[0029] If the command instance matches a path and is consistent with the path, Figure 1 then the command instance passes the verification, and the verification includes syntax, semantic check, and consistency check; the command format of the command instance is the command format corresponding to the subgraph where the path is located; Figure 1 If the command instance matches multiple paths and there is a conflict in the same-name commands, compare the current view where the command instance is located with the parent views of multiple candidate command formats. If the current view is equal to or included in a certain parent view, then the command format of the command instance is the candidate command format;
[0030] If the command instance matches multiple paths and the keyword elements exactly satisfy the string parameter node constraints in the multiple paths, then the command format of the command instance is the command format corresponding to the longest keyword subsequence;
[0031] If the command instance does not match any path, perform configuration error location and repair recommendation according to the current line number where the command instance is located and the information stored in the last matched node.
[0032]
[0033] A network device configuration verification system, the system includes:
[0034] A parsing module, configured to parse a network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0035] A first construction module for constructing a knowledge graph by fine-tuning a large model based on the configuration information, the parameter value constraints, and the instruction attribute relationships.
[0036] A verification module for dynamically constructing a command checker based on the knowledge graph and verifying the command instances in the network device manual.
[0037] A determination module for determining the dependency conflict relationships between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0038] A computer device includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor performs the following steps:
[0039] Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships.
[0040] Construct a knowledge graph by fine-tuning a large model based on the configuration information, the parameter value constraints, and the instruction attribute relationships.
[0041] Dynamically construct a command checker based on the knowledge graph and verify the command instances in the network device manual.
[0042] Determine the dependency conflict relationships between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0043] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor performs the following steps:
[0044] Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships.
[0045] Construct a knowledge graph by fine-tuning a large model based on the configuration information, the parameter value constraints, and the instruction attribute relationships.
[0046] Dynamically construct a command checker based on the knowledge graph and verify the command instances in the network device manual.
[0047] Determine the dependency conflict relationships between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0048] The present invention analyzes network device manuals and extracts configuration information, parameter value constraints, and instruction attribute relationships; constructs a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and using an instruction fine-tuning large model; dynamically constructs a command checker based on the knowledge graph and verifies command instances in the network device manual; and determines the dependency conflict relationships between instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph. This improves the scalability and reliability of configuration verification and the intelligence and automation levels of network device configuration verification, and avoids risks and losses caused by human configuration errors. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following-described drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0050] Among them:
[0051] Figure 1 is an application environment diagram of the network device configuration verification method in one embodiment;
[0052] Figure 2 is a flowchart of the network device configuration verification method in one embodiment;
[0053] Figure 3 is a structural block diagram of the network device configuration verification system in one embodiment;
[0054] Figure 4 is a schematic diagram of knowledge graph construction in one embodiment;
[0055] Figure 5 is a flowchart of the construction of the instruction fine-tuning data set in one embodiment;
[0056] Figure 6 is a schematic diagram of the knowledge graph in one embodiment;
[0057] Figure 7 is a schematic diagram of the operation of the command checker in one embodiment;
[0058] Figure 8 is a structural block diagram of a computer device in one embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.
[0060] Figure 1 It is an application environment diagram of the network device configuration verification method in an embodiment. Refer to Figure 1 This network device configuration verification method is applied to a network device configuration verification system. The network device configuration verification system includes a terminal 110 and a server 120. The terminal 110 and the server 120 are connected through a network. The terminal 110 may specifically be a desktop terminal or a mobile terminal, and the mobile terminal may specifically be at least one of a mobile phone, a tablet computer, a laptop computer, etc. The server 120 may be implemented by an independent server or a server cluster composed of multiple servers. The terminal 110 is used to parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships; construct a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and based on an instruction fine-tuning large model; the server 120 is used to dynamically construct a command checker according to the knowledge graph and verify the command instances in the network device manual; determine the dependency conflict relationship between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0061] Traditional configuration verification methods focus on program analysis and machine learning. ConfDebugger and ManifestInspector, etc. use static analysis methods to detect software configuration errors, but they rely on predefined rules and are difficult to adapt to frequently updated scenarios, with poor adaptability and flexibility. Some machine learning methods using decision trees or support vector machines require high-quality labeled data for training, and the cost of obtaining and maintaining these data is relatively high, which hinders their application in practice. In addition, there are also some methods based on databases or knowledge bases that detect configuration faults by comparing similarities. This method relies on existing data for simple matching and comparison and cannot handle complex configuration problems. In recent years, large language models have made remarkable progress in many tasks, providing a new direction for automated configuration verification. In the prior art, the scalability and reliability of configuration verification are relatively low, the intelligence and automation level of network device configuration verification are insufficient, and there are risks and losses brought by human configuration errors. To solve the above technical problems, this application provides a network device configuration verification method. As Figure 2 shown, this method can be applied to both the terminal and the server. This embodiment takes the application to the terminal as an example for illustration. The network device configuration verification method specifically includes the following steps:
[0062] S10: Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0063] S20: Based on the configuration information, the parameter value constraints, and the instruction attribute relationships, and based on the instruction fine-tuning large model, construct a knowledge graph;
[0064] S30: Dynamically construct a command checker according to the knowledge graph, and verify the command instances in the network device manual;
[0065] S40: Based on the relationship reasoning and indexing mechanism of the knowledge graph, determine the dependency conflict relationships between the instances to be verified.
[0066] This application verifies the network configuration based on the above method, improves the scalability and reliability of the configuration verification, and the intelligent and automated level of the network device configuration verification, and avoids the risks and losses brought by human configuration errors.
[0067] In one embodiment, parsing the network device manual and extracting configuration information in the above step S10 includes: based on the semi-structured data stored in the network device manual, combined with the configuration verification requirements, using a web parsing tool to extract configuration information from the network device manual; the configuration information includes: command class, command set, command, command format, parameter, parent view, usage guide, usage example, command function, parameter value, parameter description.
[0068] Specifically, as Figure 4 shown, based on the semi-structured data stored in the network device manual of the manufacturer, combined with the configuration verification requirements, use web parsing tools such as BeautifulSoup to extract entities such as command class, command set, command, command format, parameter, etc. in the network device manual, as well as corresponding attributes such as parent view, usage guide, usage example, command function, parameter value, parameter description.
[0069] In another embodiment, parsing the network device manual and extracting parameter value constraints and instruction attribute relationships in the above step S10 includes:
[0070] S101: Construct an instruction fine-tuning data set according to the text information stored in the network device manual, and the instruction fine-tuning data set includes: Enter View (EV), Parameter Constraint Generation (PG), Command Relationship Extraction (RE), Command Function Question Answering (QA);
[0071] S102: Fine-tune the Chinese large model according to the instruction fine-tuning data set to obtain the instruction fine-tuning large model;
[0072] S103: Fine-tune the large model according to the text information and the instruction to generate the target triples corresponding to the instruction fine-tuning dataset;
[0073] S104: Determine the parameter value constraints and instruction attribute relationships according to the target triples.
[0074] Specifically, use the text information stored in the network device manuals of manufacturers to construct 4 instruction fine-tuning datasets, specifically including: Enter View (EV), Parameter Constraint Generation (PG), Command Relationship Extraction (RE), and Command Function Q&A (QA). As Figure 5 shown, the Enter View (EV) task and the Parameter Constraint Generation (PG) adopt prompt engineering, and use the GLM4 large model to generate the first triples corresponding to (command format, enter view, view) and (parameter, sub-parameter, sub-parameter constraint) respectively, where the sub-parameter constraint adopts a dual-label strategy to achieve unified verification of multiple parameter types. The dual-label strategy includes: integer parameter label <integer> and non-integer parameters <regex>; The integer parameter is marked as <integer>[(MIN_VALUE,MAX_VALUE),DISCRETE_VALUE]< / integer> Assist in continuous and discrete value verification, and non-integer parameters are marked as <regex>REGULAR_EXPRESSION< / regex> Semantic verification of auxiliary parameters is performed through regular expression matching. The relationship extraction (RE) task between commands defines 5 types of relationships between commands, including: pre-command, pre-command (optional), post-command, post-command (optional), and mutually exclusive commands. High-frequency syntactic structures are collected, a standardized relationship template is established, and the second triple (command A, relationship type, command B) is generated. The above three datasets of entering view (EV), parameter constraint generation (PG), and relationship extraction between commands (RE) have all been manually verified to ensure the data quality when fine-tuning the instruction model. The command function question answering (QA) dataset is constructed by splitting commands and command functions using a program to form command question-answer pairs, which is used to improve the semantic understanding of configuration commands in Chinese large models. Four instruction fine-tuning datasets of entering view (EV), parameter constraint generation (PG), relationship extraction between commands (RE), and command function question answering (QA) are used to fine-tune the Chinese large model to achieve multi-task learning and structured output. Each task instance contains 4 key fields: task instruction, predefined label (optional), input text, and expected output. In addition, a program is used to split commands and their functions into question-answer pairs to construct the QA dataset, enhancing the semantic understanding ability of the large model for configuration commands. Based on the two triples generated by the Chinese large model, the "command format - entering view" attribute, the "sub-parameter - sub-parameter constraint" attribute relationship, and 5 types of dependency conflict relationships between commands are supplemented in the knowledge graph to complete the construction of the knowledge graph.
[0075] In one embodiment, constructing the knowledge graph according to the configuration information, the parameter value constraint, and the instruction attribute relationship in step S20 above includes:
[0076] S201: Establish a many-to-many mapping relationship between the command format and the parameters;
[0077] S202: Use the command set as the first layer of entities in the knowledge graph;
[0078] S203: Based on specific keywords, classify the commands in the command set into configuration commands and negative commands, and use the configuration commands and the negative commands as the second layer of entities in the knowledge graph;
[0079] S204: The command format of each command is used as the third layer of entities in the knowledge graph;
[0080] S205: Associate the command format to the second layer of entities in the knowledge graph according to the structural similarity and specific keywords.
[0081] Specifically, since a command format may contain multiple parameters, and a parameter may also exist in multiple command formats. According to whether the parameter exists in the command format, a many-to-many mapping relationship between the command format and the parameter is established in the knowledge graph, and the command hierarchy structure of the knowledge graph is constructed. In the knowledge graph, the command set is used as the first-level entity, and the commands in the command set are classified into configuration commands and negative commands based on specific keywords (such as undo) as the second-level entities. The command format of each command is used as the third-level entity, and the command format is associated with the second-level entity based on the structural similarity and specific keywords. Finally, the hierarchical relationship of "command set - configuration command / negative command - command format" is constructed in the knowledge graph, and the basic part of the knowledge graph is completed, as Figure 6 shown.
[0082] In one embodiment, the dynamically constructing a command checker according to the knowledge graph in the above step S30 includes:
[0083] S301: Determine each command format f∈F stored in the knowledge graph, and construct a subgraph G f ;
[0084] S302: The starting nodes of the subgraph G f are all connected to the global starting node START, and each node in the subgraph G f represents a keyword, sub-parameter or symbol in the command format f;
[0085] S303: All the subgraphs G f constitute the command checker G.
[0086] Specifically, query whether the queried matching command format f has the "enter view" attribute in the knowledge graph. If it exists, store the entered view in the view stack, and perform view switching when the indentation before the configuration command changes. Based on the configuration command knowledge graph, for each command format f∈F, construct a subgraph G f , and the starting nodes of each subgraph G f are all connected to the global starting node START, and each node in the subgraph G f represents a keyword, sub-parameter or symbol in the command format f, stores the associated command information, and the three types of edges, the forward edge, the reverse edge, and the counting edge, respectively correspond to [], {} or {}*, & in the command format f <m-n>, used to control the check of optional, repeated once or more, or repeated a limited number of times for configuration fragments within a range. All sub-graphs G f constitute a command checker G, such as Figure 7 shown. This command checker is dynamically constructed based on the knowledge graph. The update of the command format f and parameters only occurs in the knowledge graph and is regenerated during verification.
[0087] In one embodiment, the verification of the command instance in the network device manual in step S30 above includes:
[0088] S301’: Starting from the global start node START of the command checker G, the command instance C i is verified using a breadth-first traversal search method;
[0089] S302’: If the command instance C i matches a path p and is consistent with the view of the path p Figure 1 , then the command instance C i passes the verification, and the verification includes syntax, semantic checks, and consistency checks; the command format of the command instance C Figure 1 is the command format f i corresponding to the sub-graph G f where the path p is located; i ;
[0090] S303’: If the command instance C i matches multiple paths and there is a conflict in the commands with the same name, then compare the current view v i where the command instance C is located with the parent views v c of multiple candidate command formats. If v f is equal to or included in a certain v c , then the command format of the command instance C f is the candidate command format; i ;
[0091] S304’: If the command instance C i matches multiple paths and the keyword element w ij exactly satisfies the string parameter node constraints in the multiple paths, then the command format of the command instance C i is the command format corresponding to the longest keyword subsequence;
[0092] S305’: If the command instance C i does not match a path, then based on the current line number where the command instance C i is located and the information stored in the last matched node, configuration error location and repair recommendations are made.
[0093] Specifically, command instance C is stored in the network device manual of the manufacturer i ={w i1 , w i2 ,…, w in}, starting from the global start node START of the command checker G, parsing and verification are performed using a breadth-first traversal search method. Each element w i in command instance C ij is sequentially matched with the nodes, requiring that the keyword nodes satisfy exact text matching, and the parameter nodes satisfy the constraints defined by the label expression. If there is a unique path p that exactly matches the command instance C i and is consistent Figure 1 , it is considered that the command instance C i has passed the syntax, semantic check and consistency check, and the command format f Figure 1 corresponding to the subgraph G f where the path p is located i is the parsing result. If the command instance C i matches multiple paths, there may be the following two situations: one is the conflict of commands with the same name, that is, multiple command formats in different views have the same elements and structures. Compare the current view v i where the command instance C is located with the parent views v c of multiple candidate command formats. If v f is equal to or included in a certain v c , the matching command format can be determined as this candidate command format; the other is that the keyword element w f exactly satisfies the constraints of the string parameter nodes in the path, and the command format corresponding to the longest keyword subsequence is selected as the parsing result. The id of the successfully parsed command format and the line number index ij where the current command instance is located i are stored in the index table for verification. If the matching fails midway, according to the information stored in the current line number and the last successfully matched node (the node stores the command format, parameter value, and parameter description), configuration error location and repair recommendations are implemented
[0094] After the command instance C i is successfully parsed, the command instance C i If the corresponding command format f has the "enter view" attribute relationship in the knowledge graph, its view attribute is stored in the view stack (the initial view is the system view). When an increase in indentation before a configuration command in the configuration file is detected during parsing, it indicates that a new view needs to be entered, and the top element of the stack is obtained as the current view; when a decrease in indentation is detected, it means exiting the current view and returning to the previous view, popping the top element from the view stack and updating the current view; if there is no indentation before the current configuration command, the view stack is reset to the initial system view to achieve correct view switching, view matching, and view Figure 1 consistency check.
[0095] The knowledge graph contains a command set P, a command P', and a command format P", following the hierarchical relationship P → P' → P", where P i ∈ {P, P', P"}, and based on the 5 types of dependency conflict relationships R = {r1, r2, r3, r4, r5} constructed between commands, for each command format P" obtained by parsing, relationship reasoning is performed on the knowledge graph, and all commands Q i that have a relationship r k ∈ R with P i are retrieved, and through hierarchical reasoning, they are mapped to the corresponding command format Q" to form a relationship list {r k : {ID(Q")}}, where ID(Q") represents the id of the command format Q" in the knowledge graph, achieving the relationship mapping at the "command format - command format" level.
[0096] Based on the index mechanism, query the line number index of the current command format P" in the constructed index table p , and check whether the command format Q" involved in its relationship list exists in the index table. If it exists, take its corresponding line number index q , and verify the dependency conflict relationship between commands by comparing the index sizes. The specific verification rules are as follows: If P" has a set of prerequisite commands {ID(Q")}, then all Q" are required to satisfy index q < index p , that is, all prerequisite commands Q" must have been executed before the current command P". If this condition is not met, the unexecuted commands and the commands with dependency errors are output, prompting to complete or correct the command order; if P" has an optional set of prerequisite commands {ID(Q")}, then at least one Q" satisfies index q < index p , that is, at least one prerequisite command Q" has been executed before the execution of the command P"; if P" has a set of post-requisite commands {ID(Q")}, then all Q" are required to satisfy index q > index p , that is, all subsequent commands "Q" must be executed after the current command "P". If not satisfied, output the unexecuted commands and the commands with dependency errors, and prompt to complete or correct the command order; if "P" has an optional set of subsequent commands {ID(q")}, then there must be at least one q" that satisfies index q > index p , that is, at least one subsequent command q" is executed after the execution of command "P"; if "P" has a set of mutually exclusive commands {ID(Q")}, then it is required that all Q" do not exist in the index table, otherwise it is determined that there is a command conflict, and prompt to delete the conflicting commands.
[0097] This application also provides a network device configuration verification system, as Figure 4 shown, the system includes:
[0098] Parsing module 10, which is used to parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0099] The first construction module 20 is used to construct a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and based on the instruction fine-tuning large model;
[0100] Verification module 30, which is used to dynamically construct a command checker according to the knowledge graph and verify the command instances in the network device manual;
[0101] Determination module 40, which is used to determine the dependency conflict relationship between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0102] In one embodiment, a computer device is proposed, including a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the following steps:
[0103] S10: Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0104] S20: Construct a knowledge graph according to the configuration information, the parameter value constraints, and the instruction attribute relationships and based on the instruction fine-tuning large model;
[0105] S30: Dynamically construct a command checker according to the knowledge graph and verify the command instances in the network device manual;
[0106] S40: Determine the dependency conflict relationship between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
[0107] In one embodiment, a computer-readable storage medium is provided, storing a computer program, which, when executed by a processor, causes the processor to perform the following steps:
[0108] S10: Parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships;
[0109] S20: Based on the configuration information, the parameter value constraints, and the instruction attribute relationships, construct a knowledge graph based on an instruction fine-tuning large model;
[0110] S30: Dynamically construct a command checker according to the knowledge graph, and verify the command instances in the network device manual;
[0111] S40: Based on the relationship reasoning and indexing mechanism of the knowledge graph, determine the dependency conflict relationships between the instances to be verified.
[0112] Figure 8 The internal structure diagram of a computer device in one embodiment is shown. The computer device may specifically be a terminal or a server. As Figure 8 shown, the computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the computer device stores an operating system and may also store a computer program, which, when executed by the processor, can cause the processor to implement the network device configuration verification method. The internal memory may also store a computer program, which, when executed by the processor, can cause the processor to perform the network device configuration verification method. Those skilled in the art can understand that Figure 8 the structure shown in
[0113] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0114] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0115] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims. < / regex>
Claims
1. A method for verifying network device configuration, characterized in that The method includes: Parsing the network device manual and extracting configuration information, parameter value constraints, and instruction attribute relationships; Constructing a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and based on an instruction fine-tuning large model; Constructing a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and based on an instruction fine-tuning large model; Determining the dependency conflict relationships between the instances to be verified based on the relationship reasoning and indexing mechanism of the knowledge graph.
2. The network device configuration verification method according to claim 1, wherein The parsing the network device manual and extracting configuration information includes: Based on the semi-structured data stored in the network device manual, combined with the configuration verification requirements, using a web parsing tool to extract configuration information from the network device manual; the configuration information includes: command class, command set, command, command format, parameter, parent view, usage guide, usage example, command function, parameter value, and parameter description.
3. The network device configuration verification method according to claim 2, wherein The parsing the network device manual and extracting parameter value constraints and instruction attribute relationships includes: Constructing an instruction fine-tuning dataset according to the text information stored in the network device manual, the instruction fine-tuning dataset includes: entering the view, parameter constraint generation, command relationship extraction, and command function Q&A; Performing instruction fine-tuning on the Chinese large model according to the instruction fine-tuning dataset to obtain the instruction fine-tuning large model; Generating target triples corresponding to the instruction fine-tuning dataset according to the text information and the instruction fine-tuning large model; Determining the parameter value constraints and instruction attribute relationships according to the target triples.
4. The network device configuration verification method according to claim 3, wherein The constructing a knowledge graph according to the configuration information, the parameter value constraints, and the instruction attribute relationships includes: Establishing a many-to-many mapping relationship between the command format and the parameters; Taking the command set as the first layer of entities in the knowledge graph; Based on specific keywords, classifying the commands in the command set into configuration commands and negative commands, and taking the configuration commands and the negative commands as the second layer of entities in the knowledge graph; The command format of each command is used as the third layer of entities in the knowledge graph; Associating the command format to the second layer of entities in the knowledge graph according to the structural similarity and specific keywords.
5. The network device configuration verification method according to claim 1, characterized in that, The dynamically constructing a command checker according to the knowledge graph includes: Determining a subgraph for each command format stored in the knowledge graph; The starting nodes of the subgraphs are all connected to the global starting node, and each node in the subgraph represents a keyword, sub-parameter, or symbol in the command format; All the subgraphs constitute a command checker.
6. The network device configuration verification method according to claim 5, wherein The verifying the command instances in the network device manual includes: Starting from the global starting node of the command checker, verifying the command instances by using a breadth-first traversal search method; If the command instance matches a path and is consistent with the view of the path, the command instance passes the verification, and the verification includes syntax, semantic check, and view consistency check; the command format of the command instance is the command format corresponding to the subgraph where the path is located. If the command instance matches multiple paths and there are conflicts among commands with the same name, then compare the view where the command instance is currently located with the parent views of multiple candidate command formats. If the said view is equal to or included in a certain parent view, then the command format of the command instance is the said candidate command format; If the command instance matches multiple paths and the keyword elements exactly satisfy the string parameter node constraints in the multiple paths, then the command format of the command instance is the command format corresponding to the longest keyword subsequence; If the command instance does not match any path, then perform configuration error location and repair recommendation according to the current line number where the command instance is located and the information stored in the last matched node.
7. A network device configuration verification system, characterized in that, The system includes: A parsing module, configured to parse the network device manual and extract configuration information, parameter value constraints, and instruction attribute relationships; A first construction module, configured to construct a knowledge graph based on the configuration information, the parameter value constraints, and the instruction attribute relationships and based on an instruction fine-tuning large model; An inspection module, configured to dynamically construct a command checker according to the knowledge graph and inspect the command instances in the network device manual; A determination module, configured to determine the dependency conflict relationship among the instances to be inspected based on the relationship reasoning and indexing mechanism of the knowledge graph.
8. A computer device, including a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor is caused to execute the steps of the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, storing a computer program. When the computer program is executed by a processor, the processor is caused to execute the steps of the method according to any one of claims 1 to 6.