Method for effectively monitoring connectivity of virtual network
By deploying the connection status tracking module and hook module in the virtual network, the virtual network connection status is monitored by passive monitoring, which solves the problems of high resource consumption and limited monitoring range, and achieves efficient and extensive virtual network connectivity monitoring.
Patent Information
- Application Number
- CN202510774069.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-11
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art has problems of high resource consumption and limited monitoring range when monitoring virtual network connectivity, especially the active monitoring method leads to waste of bandwidth and the inability to cover external networks of the resource pool.
Deploy the connection status tracking module between the Nat gateway of the virtual network and the network manager, and add a hook module to the virtual machine's network protocol stack to monitor the newly created network connection in real time. Passive monitoring method is adopted to monitor the network status through TCP connection status transition and UDP connection's icmp echo request packets, and monitor it only when active connections are performed.
It realizes network state detection with low bandwidth and low resource consumption, can cover internal and public network resources of the virtual network, avoid waste of monitoring resources for inactive virtual machines, and improves monitoring quality and scope.
Smart Images

Figure CN120301798A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computers, and in particular to a method for effectively monitoring virtual network connectivity. Background Art
[0002] With the popularization of cloud computing, more and more manufacturers have joined the cloud computing industry. At the same time, as the scale of cloud computing services expands, the network topology of virtual networks has become increasingly complex, and the probability of virtual network failures has also become increasingly high. If cloud providers fail to detect network failures in a timely manner, it will often affect enterprise services and cause economic losses to enterprises. Therefore, how to identify virtual network failures at low cost and high efficiency has become an urgent problem to be solved in the cloud computing industry. Currently, most existing cloud computing providers use active listening methods such as network probe monitoring or network traffic statistics to solve this problem.
[0003] The network probe monitoring method mainly deploys network probes in different VPCs, and then different network probes continuously send detection information to the target end. Finally, the network status is determined based on the obtained preset monitoring metrics. This implementation method will cause monitoring traffic to occupy precious network bandwidth. In addition, if more sensitive detection effects and larger-scale detection activities are to be achieved, more probes must be deployed, which will inevitably further exacerbate the waste of cloud resources.
[0004] The network traffic statistics method dyes the service traffic, and performs relevant metric statistics on the dyed data at both the sending and receiving ends. Finally, the network status is calculated based on the statistical information. This method not only requires dyeing all service traffic, but also requires deploying traffic statistics modules at both the sending and receiving ends of the traffic, and both the sending and receiving ends must be within the same cloud resource pool. Although it solves the problem of bandwidth occupied by invalid traffic, it limits the monitoring scope and cannot monitor the external network of the resource pool. Summary of the Invention
[0005] The purpose of the present invention is to provide a method for effectively monitoring virtual network connectivity with low resource consumption and high sensitivity.
[0006] To achieve the above object, the present invention adopts the following technical solution: A method for effectively monitoring virtual network connectivity, including a virtual network and a network manager, deploying a connection status tracking module between the Nat gateway of the virtual network and the network manager, or adding a hook module to the network protocol stacks of each virtual machine in the virtual network; Both the connection status tracking module and the hook module are used to monitor newly established network connections in the network in real time, obtain the network status of the network connection, and report the network status to the network manager. The network manager processes the network status according to the obtained network status and a preset alarm threshold; The network manager is used to store, display, and manage network status logs, and to send alarm messages.
[0007] Preferably, when the connection status tracking module and the hook module detect a newly established TCP connection in the network, the following monitoring can be performed for the TCP connection: If the network status of TCP cannot be changed from the NEW state to the ESTABLISHED state within a preset time, it is determined that the network status is poor; If the network status of TCP is in the ESTABLISHED state within a preset time, listen to the ack response in the TCP packet, start the first timer. If the ack value is in an increasing state within the first preset period, it is determined that the network status is normal. If the value of ack remains unchanged within the first preset period, it is determined that the network status is abnormal; When the network status of TCP is in the Finished state, delete the first timer.
[0008] Preferably, when the connection status tracking module and the hook module detect a UDP connection in the network, the following monitoring can be performed for the UDP connection: Record the destination address and source address of the current UDP network status, and start the second timer. The trigger period of the second timer is T seconds. When the second timer is triggered, an icmp echo request message is sent to the destination address at the same time. If an icmp response message is received, set the trigger period of the second timer to T seconds * the number of cycles N. Otherwise, reset the trigger period of the second timer to T seconds. If the preset trigger period upper limit or the preset number of times of not receiving a response message is reached, it is determined that the network status is abnormal; If the tracked UDP link is cleared, delete the second timer of the link.
[0009] Preferably, the connection status tracking module is the nf_conntrack module or the eBPF module.
[0010] Preferably, the alarm message includes a short message or network information.
[0011] By adopting the foregoing design solution, the beneficial effects of the present invention are as follows: For TCP connections, when the connection status tracking module and the hook module detect a newly established TCP connection in the network, they monitor whether the network status of the TCP connection undergoes a status transition within a preset time and whether the ACK value of the TCP connection is in an increasing state within a first preset period, so as to determine whether the TCP connection is abnormal. This monitoring method only starts monitoring for a specific TCP connection when a newly established TCP connection is detected in the network, rather than monitoring TCP connections in real time. That is, the present application monitors TCP connections in a passive listening manner. Compared with active listening, this listening method has a network status detection function with low bandwidth and low resource consumption. For UDP connections, the network is monitored by sending ICMP echo request packets. After receiving an ICMP response packet, the time for sending ICMP echo request packets is gradually increased. Compared with sending ICMP echo request packets in real time or at regular intervals, the present application can effectively reduce the occupation of network bandwidth and the consumption of network resources. By presetting the upper limit of the trigger period and the number of times of not receiving response packets, the monitoring quality is improved, and the situation of not being detected in time when the network is disconnected is avoided. Compared with active listening, the present application only monitors a connection when a TCP or UDP connection is detected in the network. That is, the present application only monitors the network status of active virtual machines in the virtual network, avoiding monitoring inactive virtual machines and causing resource waste. The present application not only monitors the internal network of the virtual network but also can monitor public network resources, and the monitoring scope is more extensive and universal. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 It is the network topology diagram of the network status tracking of the present invention; Figure 2 It is the flow chart of the network status tracking of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0013] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0014] In the description and claims of the present invention and the above-mentioned drawings, the terms "first", "second", "third", etc. are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices.
[0015] As Figure 1 - Figure 2 shown, a method for effectively monitoring virtual network connectivity includes a virtual network and a network manager. A connection status tracking module (ConnectionTracking Unit) is deployed between the Nat gateway of the virtual network and the network manager, or hook modules are respectively added to the network protocol stacks of each virtual machine in the virtual network; all network traffic in the virtual network passes through the Nat gateway. Therefore, only by deploying a connection status tracking module in the Nat gateway of the virtual network can the network connectivity of the entire virtual network be monitored. In this embodiment, a conventional call policy can be configured on the network manager to enable the system to adaptively start the connection status tracking module or hook module, so that this method can be applicable to different network topologies and save network resources.
[0016] Both the connection status tracking module and the hook module are used to detect newly established network connections in the network in real time, obtain the network status of the network connection, and report the network status to the network manager. The network manager processes the network status according to the obtained network status and a preset alarm threshold; the network status here includes poor network status, abnormal network status, and normal network status. The poor network status here means that the network status of TCP cannot be converted from the NEW state to the ESTABLISHED state, and the abnormal network status means that the ack value of the TCP connection remains unchanged or the UDP connection fails to receive response packets multiple times.
[0017] In this embodiment, when the connection status tracking module and the hook module detect that there is a newly established TCP connection in the network, the following monitoring can be performed on the TCP connection: If the network status of TCP cannot be converted from the NEW state to the ESTABLISHED state within a preset time, it is determined that the network status is poor; the preset time here can be preset to 1 second or can be set according to actual network monitoring requirements.
[0018] If the network state of TCP is in the ESTABLISHED state within the preset time, then listen for the ack response in the TCP packet, start the first timer. If the ack value is in an increasing state within the first preset period, it is determined that the network state is normal. If the ack value remains unchanged within the first preset period, it is determined that the network state is abnormal. Here, the first preset period is 1 second, and it can also be set according to the actual network monitoring requirements.
[0019] When the network state of TCP is in the Finished state, then delete the first timer. Deleting the timer in a timely manner can reduce the number of system interface calls and lower resource consumption.
[0020] In this embodiment, when the connection status tracking module and the hook module detect a newly established UDP connection in the network, the following monitoring can be performed for all UDP connections: Record the destination address and source address of the current UDP network state, and start the second timer. The trigger period of the second timer is T seconds. When the second timer is triggered, it simultaneously sends an icmp echo request packet to the destination address. If an icmp response packet is received, then set the trigger period of the second timer to T seconds * the number of cycles N. Otherwise, reset the trigger period of the second timer to T seconds. If the preset trigger period upper limit or the preset number of times of not receiving a response packet is reached, it is determined that the network state is abnormal. In this embodiment, the preset trigger period upper limit means that T of the trigger period of the second timer is 3 seconds, and the number of cycles N is 100, that is, the preset is 5 minutes, and it can also be set otherwise according to the actual monitoring requirements.
[0021] If the tracked UDP link is cleared, then delete the second timer of the link. Deleting the timer in a timely manner can reduce the number of system interface calls and lower resource consumption.
[0022] The alarm threshold in this embodiment is the preset time and the first preset period during TCP link tracking, and the preset number of times of not receiving a response packet during UDP link tracking.
[0023] In this embodiment, the connection status tracking module is the nf_conntrack module or the eBPF module.
[0024] The network manager is used to store, display, and manage network status logs, and is used to send alarm information. Here, the network manager can be a conventional software or web service, which can meet the customer's remote access. The alarm information includes SMS information or network information.
[0025] In summary, for the TCP connection, when the connection status tracking module and the hook module detect a newly established TCP connection in the network, they monitor whether the network status of the TCP connection undergoes a status transition within a preset time and whether the ACK value of the TCP connection is in an increasing state within a first preset period, so as to determine whether there is an abnormality in the TCP connection. This monitoring method only starts the monitoring of the TCP connection when a newly established TCP connection is detected in the network, rather than monitoring the TCP connection in real time. That is, the present application monitors the TCP connection in a passive listening manner. Compared with active listening, this listening method has a network status detection function with low bandwidth and low resource consumption; For the UDP connection, the network is monitored by sending icmp echo request packets. After receiving the icmp response packet, the time for sending the icmp echo request packet is gradually increased. Compared with sending icmp echo request packets in real time or at regular intervals, the present application can effectively reduce the occupation of network bandwidth and the consumption of network resources, and improve the monitoring quality by presetting the upper limit of the trigger period and the preset number of times of not receiving the response packet, so as to avoid the situation that the network disconnection is not detected in time; Compared with active listening, the present application only monitors the connection when a TCP or UDP connection is detected in the network. That is, the present application only monitors the network status of the active virtual machines in the virtual network, avoiding monitoring the inactive virtual machines and causing resource waste; The connection status tracking module and the hook module of the present application can both monitor the newly established TCP connections and UDP connections in the network, realizing the monitoring of the entire network. It not only monitors the internal network of the virtual network, but also can monitor the public network resources, and the monitoring range is more extensive and universal.
[0026] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for effectively monitoring virtual network connectivity, characterized in that: It includes a virtual network and a network manager. A connection status tracking module is deployed between the Nat gateway of the virtual network and the network manager, or hook modules are respectively added to the network protocol stacks of each virtual machine in the virtual network; Both the connection status tracking module and the hook module are used to monitor newly created network connections in real time, obtain the network status of the network connection, and report the network status to the network manager. The network manager processes the network status according to the obtained network status and a preset alarm threshold; The network manager is used to store, display, and manage network status logs, and is used to send alarm information.
2. The method for effectively monitoring virtual network connectivity according to claim 1, wherein: When the connection status tracking module and the hook module detect a newly created TCP connection in the network, the following monitoring can be performed for the TCP connection: If the network status of TCP cannot be converted from the NEW state to the ESTABLISHED state within a preset time, it is determined that the network status is poor; If the network status of TCP is in the ESTABLISHED state within a preset time, then listen to the ack response in the TCP packet, start the first timer. If the ack value is in an increasing state within the first preset period, it is determined that the network status is normal. If the ack value remains unchanged within the first preset period, it is determined that the network status is abnormal; When the network status of TCP is in the Finished state, the first timer is deleted.
3. The method for effectively monitoring virtual network connectivity according to claim 2, characterized in that: When the connection status tracking module and the hook module detect a UDP connection in the network, the following monitoring can be performed for the UDP connection: Record the destination address and source address of the current UDP network status, and start the second timer. The trigger period of the second timer is T seconds. When the second timer is triggered, an icmp echo request packet is sent to the destination address at the same time. If an icmp response packet is received, the trigger period of the second timer is set to T seconds * the number of cycles N. Otherwise, the trigger period of the second timer is reset to T seconds. If the preset trigger period upper limit or the preset number of times of not receiving a response packet is reached, it is determined that the network status is abnormal; If the tracked UDP link is cleared, the second timer of the link is deleted.
4. The method for effectively monitoring virtual network connectivity according to claim 3, wherein: The connection status tracking module is an nf_conntrack module or an eBPF module.
5. The method for effectively monitoring virtual network connectivity according to claim 3, characterized in that: The alarm information includes SMS information or network information.
Citation Information
Patent Citations
Detection method for carrier network
CN101001179A
A state monitoring system of a power utilization acquisition virtual private channel link
CN109600276A
Network diagnosis method and electronic equipment
CN116708148A
Network quality monitoring method, electronic device, client device and storage medium
CN118827468A
Suspending and resuming virtual machines in a network
US20180013651A1