Network link fault positioning method and device, medium and program product
By deploying detectors at critical nodes of the network link, collecting and analyzing network data, identifying and locating faulty nodes, the problem of inaccurate network link fault location in existing technologies is solved, achieving efficient and accurate fault location and ensuring high availability and quality of service of the network.
Patent Information
- Application Number
- CN202511205130.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-27
- Publication Date
- 2025-10-31
AI Technical Summary
Existing technologies cannot accurately locate individual faulty network nodes in a network link, making troubleshooting difficult and time-consuming.
By deploying detectors at key network nodes in the network link, feature information of network data is collected, candidate feature data of anomalies is identified, and target feature data of faults is identified through rule matching. Combined with the mapping relationship between detector identifiers and network nodes, the critical network nodes of faults can be accurately located.
It enables efficient and accurate network link fault location, ensuring high availability and quality of service for network links, and improving the efficiency and accuracy of fault location.
Smart Images

Figure CN120880889A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of financial technology, and in particular to a method, device, medium, and program product for locating network link faults. Background Technology
[0002] In network management and maintenance, network performance and service quality are monitored by listening to and analyzing actual business traffic.
[0003] In related technologies, traffic statistics are determined based on the actual business traffic monitored, and the occurrence of a fault is determined based on the traffic statistics.
[0004] However, in the above process, it is only possible to determine whether a fault has occurred based on macroscopic traffic statistics, but it is not possible to pinpoint the faulty network node in the network link, and thus it is impossible to locate the fault. Summary of the Invention
[0005] This invention provides a network link fault location method, device, medium, and program product to solve the technical problem that fault monitoring methods in related technologies cannot achieve fault location.
[0006] According to one aspect of the present invention, a method for locating network link faults is provided, the method comprising:
[0007] Determine the characteristic information of network data collected by multiple detectors; wherein the detectors are deployed in key network nodes of the network link, the network data includes detector identifiers, and the characteristic information includes multiple initial characteristic data and a detector identifier associated with each initial characteristic data.
[0008] Among the plurality of initial feature data, there are anomalous candidate feature data;
[0009] The target feature data that has caused the fault is determined from the candidate feature data by rule matching.
[0010] Based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the key network node, the faulty key network node corresponding to the target feature data is determined.
[0011] According to another aspect of the present invention, a network link fault location device is provided, the device comprising:
[0012] The first determining module is used to determine the feature information of network data collected by multiple detectors; wherein the detectors are deployed in key network nodes of the network link, the network data includes detector identifiers, and the feature information includes multiple initial feature data and detector identifiers associated with each initial feature data.
[0013] The second determining module is used to determine whether there are abnormal candidate feature data among the plurality of initial feature data;
[0014] The third determining module is used to determine the target feature data that has a fault in the candidate feature data through rule matching.
[0015] The fourth determining module is used to determine the faulty critical network node corresponding to the target feature data based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the critical network node.
[0016] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0017] At least one processor; and
[0018] A memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the network link fault location method according to any embodiment of the present invention.
[0020] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, the computer program being configured to cause a processor to execute and implement the network link fault location method according to any embodiment of the present invention.
[0021] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the network link fault location method according to any embodiment of the present invention.
[0022] The technical solution of this invention includes: determining feature information of network data collected by multiple detectors, wherein the detectors are deployed in key network nodes of the network link, the network data includes detector identifiers, and the feature information includes multiple initial feature data and detector identifiers associated with each initial feature data; determining candidate feature data with anomalies among the multiple initial feature data; determining target feature data with a fault among the candidate feature data through rule matching; and determining the faulty key network node corresponding to the target feature data based on the detector identifiers associated with the target feature data and the mapping relationship between the detector identifiers and key network nodes. It has the following technical effects: On the one hand, by collecting network data through detectors deployed in key network nodes of the network link, the faulty key network node corresponding to the target feature data can be located after the faulty target feature data is determined, achieving efficient network link fault location and ensuring high availability and service quality of the network link; on the other hand, by first determining candidate features with anomalies and then determining the faulty target feature data from the candidate features, the accuracy of the determined target feature data is ensured through a secondary screening method, thereby ensuring the accuracy of the determined faulty key network node and further improving the efficiency of network link fault location.
[0023] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 This is a flowchart of a network link fault location method provided in an embodiment of the present invention;
[0026] Figure 2 This is a schematic diagram of a network link provided in an embodiment of the present invention;
[0027] Figure 3 This is a schematic diagram of a user interface provided in an embodiment of the present invention;
[0028] Figure 4 This is a flowchart of another network link fault location method provided in an embodiment of the present invention;
[0029] Figure 5This is a schematic diagram of a faulty network region provided in an embodiment of the present invention;
[0030] Figure 6 This is a schematic diagram of the structure of a network link fault location device provided in an embodiment of the present invention;
[0031] Figure 7 This is a schematic diagram of the structure of an electronic device that implements the network link fault location method of this invention. Detailed Implementation
[0032] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0033] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that comprises a series of steps or units is not necessarily limited to those explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products, or devices. The acquisition, storage, use, and processing of data in the embodiments of this invention comply with relevant national laws and regulations. The information collected in the embodiments of this invention is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant national and regional laws, regulations, and standards, necessary confidentiality measures have been taken, public order and good morals have not been violated, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0034] To facilitate subsequent understanding, the terms involved in this embodiment will be explained below.
[0035] Active probing: A technique for assessing network performance and status by actively sending test packets to network links and analyzing their responses.
[0036] Data analysis: using statistical and algorithmic techniques to process and interpret collected data in order to extract useful information and patterns.
[0037] Network link fault location: The process of determining the specific location or component of a fault in a network link.
[0038] Figure 1 This is a flowchart illustrating a network link fault location method provided in an embodiment of the present invention. This embodiment is applicable to scenarios involving the location of faulty network nodes. The method can be executed by a network link fault location device, which can be implemented in hardware and / or software. This network link fault location device can be configured in an electronic device, such as a computer or server. Figure 1 As shown, the method includes the following steps 101 to 104.
[0039] Step 101: Determine the characteristic information of the network data collected by multiple detectors.
[0040] The detectors are deployed in key network nodes of the network link. Network data includes detector identifiers. Feature information includes multiple initial feature data and a detector identifier associated with each initial feature data.
[0041] The network link in this embodiment includes multiple key network nodes. This network link can be used in the financial sector, the medical sector, or the energy sector. This embodiment does not limit the specific application area of the network link.
[0042] In this embodiment, the detector can be a software module capable of transmitting and receiving data, or a hardware component capable of transmitting and receiving data.
[0043] In this embodiment, the detector is deployed in key network nodes of the network link. Optionally, the key network node in this embodiment can be every network node in the network link. Alternatively, the key network node in this embodiment can be a network node with certain characteristics in the network link, such as a border network node or a gateway node, to ensure that the detector's transmission and reception range can cover the entire network link. For example, the key network node in this embodiment can be an edge gateway, border router, core router, core switch, access gateway, etc.
[0044] Figure 2 This is a schematic diagram of a network link provided by an embodiment of the present invention. For example... Figure 2 As shown, the network link in this embodiment includes multiple network nodes 21. For example, network nodes in this network link that deploy detectors include... Figure 2 As shown.
[0045] The detector in this embodiment can collect network data passively: monitoring and analyzing actual service traffic without injecting additional data packets into the network. Alternatively, it can collect network data actively: injecting additional test data packets into the network and collecting the network data transmitted through the network links using these test data packets.
[0046] In order to achieve fault location, the network data collected by each detector in this embodiment includes the detector's identifier.
[0047] In this embodiment, the feature information of the network data refers to information that can characterize certain properties of the network data. Optionally, the initial feature data in the network data in this embodiment may include: network performance indicators such as latency, packet loss rate, jitter, and time series characteristics. To achieve fault location, the feature information in this embodiment includes the detector identifier associated with the initial feature data.
[0048] Optionally, the feature information in this embodiment may include: (network performance index delay D1, associated detector identifiers N1, N2), (network performance index delay D2, associated detector identifiers N1, N3), ..., (packet loss rate LT1, associated detector identifier N7), (packet loss rate LT2, associated detector identifiers N9, N10).
[0049] In one implementation, the feature information of network data can be determined based on an artificial intelligence model: network data collected by multiple detectors is input into the feature information determination model to obtain the feature information output by the model.
[0050] In another implementation, step 101 includes: preprocessing the network data collected by multiple detectors to obtain preprocessed network data; converting the preprocessed network data into network data in a target format; normalizing the network data in the target format to obtain normalized network data; and determining the feature information of the normalized network data.
[0051] In this embodiment, preprocessing refers to cleaning the network data to remove invalid data and outliers. The network data collected by different detectors in this embodiment may have different formats. To improve the accuracy and efficiency of the determined feature information, the preprocessed network data is converted to a target format. Optionally, the target format in this embodiment can be a key-value pair data format. Normalizing the network data to the target format aims to normalize the network data to the same order of magnitude, avoiding the influence of numerical differences on the determined feature information. In this embodiment, the normalized network data can be input into an artificial intelligence model to obtain the feature information of the network data output by the model.
[0052] This implementation method limits the determination of feature information to preprocessing, format conversion, and normalization of network data, thereby improving the efficiency and accuracy of feature information determination.
[0053] In another implementation, the feature information of the network data can be determined based on the calculation rules of the feature data.
[0054] Step 102: Identify candidate feature data that are anomalous among multiple initial feature data.
[0055] In step 102, the initial feature data is screened to identify candidate feature data that have obvious anomalies, i.e., deviate from the normal pattern.
[0056] The initial feature data in this embodiment can include multiple categories, such as network performance metrics like latency and packet loss rate. For each category of initial feature data, step 102 is executed to determine candidate feature data. This classification process can improve the accuracy and comprehensiveness of the determined candidate feature data, avoiding missed detections.
[0057] In one implementation, multiple initial feature data are output to an artificial intelligence model to obtain candidate feature data output by the model. Further, each type of initial feature data can be input into the artificial intelligence model for that type of feature data to obtain candidate feature data.
[0058] In another implementation, clustering methods can be used to identify candidate feature data that exhibits anomalies. Furthermore, clustering can be performed on each initial feature data group to identify candidate feature data that exhibits anomalies.
[0059] In another implementation, candidate feature data that does not meet the corresponding threshold can be determined based on a threshold.
[0060] Step 103: Determine the target feature data that has caused the fault in the candidate feature data through rule matching.
[0061] In this embodiment, the rule matching method refers to a mechanism for identifying fault data based on predefined conditions or business logic.
[0062] Optionally, the rules in this embodiment include threshold-based rules and pattern-based rules. The threshold-based rules in this embodiment include a series of threshold rules determined based on historical data of network performance indicators and best practices, such as not exceeding a certain threshold, not less than a certain threshold, or falling within a certain threshold range. Pattern-based rules refer to predefined common fault modes and their characteristics. For example, a sudden increase in bandwidth utilization of a link segment may be due to a traffic burst or a configuration error.
[0063] Step 103 includes any one of steps 1031 and 1032.
[0064] Step 1031: Using a threshold-based rule matching method, identify the target feature data in the candidate feature data that does not meet the corresponding threshold, and determine the fault type of the target feature data based on the corresponding threshold.
[0065] In this embodiment, the candidate feature data has a corresponding threshold, which can be determined based on the type or category of the candidate feature data. Alternatively, the threshold can be determined based on the detector identifier associated with the candidate feature data. This is because different locations in the network link have different performance requirements, and the detector identifier associated with the candidate feature data can characterize the location of the candidate feature data, thereby achieving refined fault detection. Both of these methods of determining the threshold can improve the accuracy of the identified target feature data.
[0066] In this embodiment, not meeting the corresponding threshold means: if the threshold rule is not greater than a certain threshold, then not meeting the corresponding threshold means being less than that threshold; if the threshold rule is not less than a certain threshold, then not meeting the corresponding threshold means being greater than that threshold; if the threshold rule is within a certain threshold range, then not meeting the corresponding threshold means being outside that threshold range.
[0067] In this embodiment, the threshold-based rule matching method can also characterize the fault type of the target feature data. For example, the threshold rule is: not lower than the transmission rate A; if it exceeds, it indicates network congestion. If a candidate feature data is less than the transmission rate A, it is determined to be the target feature data that has experienced a fault, and the fault type of the target feature data is network congestion.
[0068] It should be noted that if the candidate feature data all meet the corresponding thresholds through threshold-based rule matching, then the network link is determined to be fault-free.
[0069] Step 1032: Using pattern-based rule matching, determine the target feature data that meets the target fault mode among the candidate feature data, and determine the fault types included in the target fault mode as the fault types of the target feature data.
[0070] The pattern-based rule matching method in this embodiment also includes the fault types corresponding to each pattern. When it is determined that there are target feature data in the candidate feature data that satisfy the target fault pattern, the fault types included in the target fault pattern are further determined as the fault types of the target feature data.
[0071] In practical applications, the target feature data and its corresponding fault type can be determined through either step 1031 or step 1032, based on the instructions of the maintenance personnel. Alternatively, the target feature data and its corresponding fault type can be determined through either step 1031 or step 1032, depending on the type of the target feature data.
[0072] It should be noted that if the candidate feature data does not contain target feature data that meets the predefined fault mode, then the network link is determined to be fault-free.
[0073] Steps 1031 and 1032 above define that the target feature data and the corresponding fault type can be determined by using a threshold-based rule matching method or a pattern-based rule matching method. This achieves efficient and accurate determination of the fault type and improves the precision of the fault location method.
[0074] Step 104: Based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the key network node, determine the faulty key network node corresponding to the target feature data.
[0075] In this embodiment, the mapping relationship between detector identifiers and critical network nodes can be information determined when deploying detectors. After determining the target feature data, the faulty critical network node corresponding to the target feature data can be determined based on the detector identifiers associated with the target feature data and the mapping relationship between detector identifiers and critical network nodes, thereby achieving fault location at the network node level.
[0076] Optionally, the method provided in this embodiment further includes the following steps: displaying network data, feature information, and target feature data through a visual dashboard. In scenarios where the fault type has been determined, the fault type of the target feature data can also be displayed. The visual dashboard in this embodiment can be a time trend chart, bar chart, pie chart, etc. This implementation provides an intuitive view of the fault, simplifies the fault diagnosis process, improves the efficiency of network link fault diagnosis, and thus improves operation and maintenance efficiency.
[0077] Optionally, the method provided in this embodiment further includes the following step: displaying the location of the faulty critical network node in the network topology. This implementation can display the faulty critical network node in the network topology, achieving a more intuitive display method and further simplifying the fault diagnosis process.
[0078] Figure 3 This is a schematic diagram of a user interface provided in an embodiment of the present invention. For example... Figure 3As shown, in the user interface 301, the left area 3011 displays network data, feature information, target feature data, and fault type. The right area 3012 displays the location of the fault-critical network node 3013 in the network topology.
[0079] Furthermore, this embodiment can also generate a fault report, which may include: network data, feature information, target feature data, the critical fault network node corresponding to the target feature data, the collection time of the network data, and the determination time of the critical fault network node. Optionally, the network link fault location method provided in this embodiment can also send a fault report to the terminal corresponding to the pre-configured maintenance personnel.
[0080] Passive detection techniques in related technologies can provide detailed statistical information about Internet Protocol (IP) traffic, such as source / destination IP addresses, port numbers, protocol types, and throughput. However, they cannot pinpoint a specific network node when a fault occurs, making troubleshooting difficult and time-consuming. Furthermore, it is difficult to trace back to historical issues. For faults that have occurred but are no longer ongoing, passive detection lacks effective means to trace their causes and the time of occurrence. Because it relies on real-time traffic data, once the problem disappears, relevant evidence is lost, making post-event analysis and root cause identification difficult. Finally, there is a lack of efficient diagnostic tools. Methods in related technologies mainly rely on network node logs and alarm information, which are often scattered and not intuitive, failing to provide real-time fault detection and location capabilities. In contrast, the network link fault location method provided in this embodiment can achieve network node-level fault location, providing network operation and maintenance managers with a comprehensive and efficient fault location method to ensure high availability and quality of service for network links.
[0081] The network link fault location method provided in this invention includes: determining feature information of network data collected by multiple detectors, wherein the detectors are deployed in key network nodes of the network link, the network data includes detector identifiers, and the feature information includes multiple initial feature data and detector identifiers associated with each initial feature data; determining candidate feature data with anomalies among the multiple initial feature data; determining target feature data with a fault among the candidate feature data through rule matching; and determining the faulty key network node corresponding to the target feature data based on the detector identifiers associated with the target feature data and the mapping relationship between the detector identifiers and key network nodes. This method has the following technical effects: On the one hand, by collecting network data through detectors deployed in key network nodes of the network link, the faulty key network node corresponding to the target feature data can be located after the faulty target feature data is determined, achieving efficient network link fault location and ensuring high availability and service quality of the network link; on the other hand, by first determining candidate features with anomalies and then determining the faulty target feature data from the candidate features, the accuracy of the determined target feature data is ensured through a secondary screening method, thereby ensuring the accuracy of the determined faulty key network node and further improving the efficiency of network link fault location.
[0082] Figure 4 This is a flowchart of another network link fault location method provided in an embodiment of the present invention. This network link fault location method... Figure 1 Based on the illustrated embodiments and various optional implementations, other implementations of the method will be described in detail. For example... Figure 4 As shown, the network link fault location method provided in this embodiment includes the following steps 401 to 412.
[0083] Step 401: Based on the network topology of the network link and the fault monitoring requirements, identify the key network nodes in the network link where detectors need to be deployed.
[0084] In this embodiment, the network topology refers to the way network nodes are interconnected and their physical or logical layout. The fault monitoring requirement in this embodiment indicates at least one of the following: monitoring area and monitoring granularity. The monitoring granularity in this embodiment indicates the level of detail in the monitoring and may include: system-level monitoring, cluster-level monitoring, service-level monitoring, and node-level monitoring.
[0085] Optionally, when the fault monitoring requirement is monitoring area A, the network nodes included in monitoring area A in the network topology of the network link are identified as critical network nodes.
[0086] Optionally, when the fault monitoring requirement is node-level monitoring, all network nodes included in the network topology of the network link are identified as critical network nodes.
[0087] Step 402: Deploy detectors in each critical network node.
[0088] When the detector in this embodiment is a module that can send and receive data, implemented by a software module, the deployment process can be to write program code that implements the corresponding detector function into the software program of the key network node.
[0089] When the detector in this embodiment is a hardware-implemented component capable of sending and receiving data, the deployment process can involve connecting the corresponding detector to the data transmission path of the key network node.
[0090] Step 403: Configure the detector identifier for each detector and establish a mapping relationship between the detector identifier and the key network nodes.
[0091] Detector identifiers are used to uniquely identify detectors. After establishing the mapping relationship between detector identifiers and key network nodes, the key network nodes of the fault can be determined through the detector identifiers during subsequent fault localization, thus enabling precise identification of the specific location of the fault.
[0092] Step 404: Configure the detection request type and detection parameters for each detector.
[0093] To further improve the accuracy and flexibility of monitoring, the detection request type and detection parameters for each detector can be configured in step 404.
[0094] Optionally, the probe request type in this embodiment may include at least one of the following: Internet Control Message Protocol (ICMP) request, Transmission Control Protocol (TCP) request, Hypertext Transfer Protocol (HTTP) request, and custom protocol requests according to specific needs to simulate real business requests.
[0095] The detection parameters in this embodiment are used to characterize parameters such as time interval, time frequency, and detection range during the detection process of the detector.
[0096] Steps 401 to 404 above enable the deployment of detectors in network links based on demand and actual network topology, improving the matching of fault monitoring with actual scenarios. Furthermore, configuring the detectors with detection request types facilitates subsequent detection of specific request types, enhancing the precision of fault localization.
[0097] Step 405: Determine the target probe request type among multiple probe request types.
[0098] In step 405, the target detection request type among multiple detection request types can be determined according to the time slot requirements.
[0099] Step 406: Obtain network data collected by the target detector that supports the target detection request type.
[0100] The target detector collects network data based on a set detection frequency and detection strategy.
[0101] Optionally, when the detection in this embodiment is passive detection, the network data is the network data generated during normal service operation. Target detectors supporting target detection request types collect network data generated during normal service operation.
[0102] Optionally, when the detection in this embodiment is active detection, the target detector supporting the target detection request type can actively inject test data into the network link according to its detection parameters, and collect the network data generated after sending the test data into the network link. This active detection method is highly flexible.
[0103] In this embodiment, active detection or passive detection can be selected according to actual needs.
[0104] Step 407: Determine the characteristic information of the network data collected by multiple target detectors.
[0105] The network data includes detector identifiers, and the feature information includes multiple initial feature data and detector identifiers associated with each initial feature data.
[0106] The difference between step 407 and step 101 is that step 407 can determine the feature information of the network data collected by the target detector that supports the target detection request type, thereby improving the precision of fault location.
[0107] Steps 405 to 407 above enable the detection of specific probe request types, improving the precision of fault localization. Furthermore, the system allows for selection of detection during business operations or based on test data, enhancing flexibility.
[0108] Step 408: Identify candidate feature data that are anomalous among multiple initial feature data.
[0109] Step 409: Determine the target feature data that has a fault in the candidate feature data through rule matching.
[0110] The implementation process and technical principles of steps 408 and 102, and steps 409 and 103 are similar, and will not be repeated here.
[0111] Step 410: For each target feature data, based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the key network nodes, determine the multiple faulty key network nodes corresponding to the target feature data.
[0112] In this embodiment, there are multiple target feature data, and each target feature data is associated with multiple detector identifiers.
[0113] In this embodiment, in scenarios with multiple target feature data, multiple critical network nodes corresponding to each target feature data can be identified. The specific determination process is similar to step 104 and will not be repeated here.
[0114] Step 411: Determine the fault network region composed of faulty key network nodes corresponding to multiple target feature data.
[0115] Step 412: Identify all network nodes in the faulty network region as faulty network nodes.
[0116] Based on step 410, multiple critical fault network nodes can be identified. To avoid missing detections, in step 411, a fault network region composed of critical fault network nodes corresponding to each target feature data can be identified. In step 412, all network nodes in the fault network region are identified as fault network nodes.
[0117] Optionally, in step 411, the largest region composed of the faulty critical network nodes corresponding to multiple target feature data (and the region is bounded by the faulty critical network nodes) can be determined as the faulty network region.
[0118] Optionally, in step 411, connectivity analysis can be used to determine the fault network region composed of faulty key network nodes corresponding to multiple target feature data. For example, a depth-first search algorithm or a breadth-first search algorithm can be used to determine the fault network region.
[0119] The implementation of steps 410 to 412 above, by limiting the determination of multiple critical faulty network nodes, can identify faulty network regions and determine all network nodes in the faulty network regions as faulty network nodes, thereby improving the comprehensiveness of the identified faulty network nodes and avoiding missed detections.
[0120] Figure 5 This is a schematic diagram of a faulty network region provided in an embodiment of the present invention. Figure 5 As shown, the critical network node 51 is... Figure 5 The black-filled network nodes in the diagram. Figure 5 The following example illustrates the concept of three critical network nodes 51. These three critical network nodes 51 constitute a faulty network region 52. All three critical network nodes 51 and network nodes 53 within the faulty network region 52 are defined as faulty network nodes.
[0121] The network link fault location method provided in this embodiment, on the one hand, realizes the deployment of detectors in network links according to demand and actual network topology, improving the matching of fault monitoring with actual scenarios. Furthermore, configuring detection request types for detectors facilitates subsequent detection of specific request types, improving the precision of fault location. On the other hand, enabling detection of specific request types further enhances the precision of fault location. Moreover, it allows for selection of detection during business operation or based on test data, improving flexibility. Furthermore, it can determine faulty network areas based on multiple identified critical faulty network nodes, classifying all network nodes within these areas as faulty network nodes, improving the comprehensiveness of identified faulty network nodes and avoiding missed detections.
[0122] This embodiment also provides a network link fault location system, including: an active detection module, a data analysis module, and a fault location module.
[0123] The active detection module is used to implement the functions of deploying detectors and transmitting and receiving data in the above embodiments. Its main function is to initiate network detection to collect network data and upload it to the data analysis module, and to execute steps 401 to 404.
[0124] The data analysis module is used to analyze the network data uploaded by the detector, and execute steps 101 to 102 above, or steps 405 to 408 above.
[0125] The fault location module is used to locate critical network nodes with faults through rule matching, and is used to execute steps 103 to 104, or to execute steps 409 to 412.
[0126] The network link fault location system provided in this embodiment of the invention can execute the network link fault location method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0127] Figure 6 This is a schematic diagram of a network link fault location device provided in an embodiment of the present invention. The device is installed in an electronic device. Figure 6 As shown, the network link fault location device provided in this embodiment includes the following modules: a first determining module 61, a second determining module 62, a third determining module 63, and a fourth determining module 64.
[0128] The first determining module 61 is used to determine the characteristic information of network data collected by multiple detectors.
[0129] The detectors are deployed in key network nodes of the network link. The network data includes detector identifiers. The feature information includes multiple initial feature data and a detector identifier associated with each initial feature data.
[0130] The second determining module 62 is used to determine whether there are abnormal candidate feature data among the plurality of initial feature data.
[0131] The third determining module 63 is used to determine the target feature data that has a fault in the candidate feature data through rule matching.
[0132] The fourth determining module 64 is used to determine the faulty critical network node corresponding to the target feature data based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the critical network node.
[0133] In one embodiment, the device further includes a fifth determining module, a deployment module, a first configuration module, and a second configuration module.
[0134] The fifth determining module is used to determine, based on the network topology and fault monitoring requirements of the network link, multiple key network nodes in the network link where detectors need to be deployed.
[0135] A deployment module is used to deploy the detector in each of the key network nodes.
[0136] The first configuration module is used to configure the detector identifier of each detector and establish a mapping relationship between the detector identifier and key network nodes.
[0137] The second configuration module is used to configure the detection request type and detection parameters for each of the detectors.
[0138] In one embodiment, the device further includes a sixth determining module and an acquiring module.
[0139] The sixth determination module is used to determine the target detection request type among multiple detection request types.
[0140] The acquisition module is used to acquire network data collected by target detectors that support the target detection request type. The target detectors collect network data based on a set detection frequency and detection strategy. The network data is either generated during normal service operation or generated after sending test data to the network link.
[0141] Correspondingly, the first determining module 61 is specifically used to: determine the feature information of the network data collected by multiple target detectors.
[0142] In one embodiment, the first determining module 61 is specifically used for: preprocessing the network data collected by the plurality of detectors to obtain preprocessed network data; converting the preprocessed network data into network data in a target format; normalizing the network data in the target format to obtain normalized network data; and determining the feature information of the normalized network data.
[0143] In one embodiment, the rules include threshold-based rules and pattern-based rules. The third determining module 63 is specifically configured to: determine target feature data in the candidate feature data that does not meet a corresponding threshold using threshold-based rule matching, and determine the fault type of the target feature data based on the corresponding threshold; determine target feature data in the candidate feature data that meets a target fault pattern using pattern-based rule matching, and determine the fault types included in the target fault pattern as the fault types of the target feature data.
[0144] In one embodiment, the device further includes a display module, configured to: display the network data, the feature information, the target feature data, and the fault type of the target feature data through a visual dashboard; and display the location of the fault-critical network node in the network topology.
[0145] In one embodiment, the number of target feature data is multiple, and each target feature data is associated with multiple detector identifiers. The fourth determining module 64 is specifically configured to: for each target feature data, determine multiple faulty critical network nodes corresponding to the target feature data based on the detector identifiers associated with the target feature data and the mapping relationship between the detector identifiers and critical network nodes; determine a faulty network region composed of the multiple faulty critical network nodes corresponding to the target feature data; and determine all network nodes in the faulty network region as faulty network nodes.
[0146] The network link fault location device provided in this embodiment of the invention can execute the network link fault location method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0147] Figure 7 This is a schematic diagram of the structure of an electronic device implementing the network link fault location method of this invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0148] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0149] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0150] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as network link fault location methods.
[0151] In some embodiments, the network link fault location method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the network link fault location method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the network link fault location method by any other suitable means (e.g., by means of firmware).
[0152] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0153] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0154] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0155] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0156] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0157] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0158] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the network link fault location method provided in any embodiment of this invention.
[0159] In the implementation of a computer program product, computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages as well as conventional procedural programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0160] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0161] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for locating network link faults, characterized in that, The method includes: Determine the characteristic information of network data collected by multiple detectors; wherein the detectors are deployed in key network nodes of the network link, the network data includes detector identifiers, and the characteristic information includes multiple initial characteristic data and a detector identifier associated with each initial characteristic data. Among the plurality of initial feature data, there are anomalous candidate feature data; The target feature data that has caused the fault is determined from the candidate feature data by rule matching. Based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the key network node, the faulty key network node corresponding to the target feature data is determined.
2. The method according to claim 1, characterized in that, The method further includes: Based on the network topology and fault monitoring requirements of the network link, identify the key network nodes in the network link where detectors need to be deployed. The detector is deployed in each of the key network nodes; Configure a detector identifier for each detector and establish a mapping relationship between the detector identifier and key network nodes; Configure the detection request type and detection parameters for each of the detectors.
3. The method according to claim 2, characterized in that, The method further includes: Determine the target probe request type from among multiple probe request types; Obtain network data collected by a target detector that supports the target detection request type; wherein the target detector collects network data based on a set detection frequency and detection strategy, and the network data is network data generated during normal business operation, or network data generated after sending test data to the network link; The determination of the characteristic information of network data collected by multiple detectors includes: Determine the characteristic information of network data collected by multiple target detectors.
4. The method according to claim 1, characterized in that, The determination of the characteristic information of network data collected by multiple detectors includes: The network data collected by the multiple detectors is preprocessed to obtain preprocessed network data. The preprocessed network data is converted into network data in the target format. The network data in the target format is normalized to obtain normalized network data; Determine the feature information of the normalized network data.
5. The method according to any one of claims 1 to 4, characterized in that, The rules include threshold-based rules and pattern-based rules; The target feature data of the fault is determined from the candidate feature data by rule matching, including any one of the following: By using a threshold-based rule matching method, target feature data that does not meet the corresponding threshold in the candidate feature data is identified, and the fault type of the target feature data is determined based on the corresponding threshold. By using a pattern-based rule matching method, target feature data that meets the target fault mode is determined from the candidate feature data, and the fault types included in the target fault mode are determined as the fault types of the target feature data.
6. The method according to claim 5, characterized in that, The method further includes: The network data, the feature information, the target feature data, and the fault type of the target feature data are displayed through a visual dashboard; This displays the location of the critical network node in the network topology.
7. The method according to any one of claims 1 to 4, characterized in that, The number of target feature data is multiple, and each target feature data is associated with multiple detector identifiers; The step of determining the faulty critical network node corresponding to the target feature data based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the critical network node includes: For each target feature data, based on the detector identifier associated with the target feature data and the mapping relationship between the detector identifier and the key network node, multiple faulty key network nodes corresponding to the target feature data are determined. Determine the fault network region composed of multiple fault-critical network nodes corresponding to the target feature data; All network nodes in the faulty network region are identified as faulty network nodes.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the network link fault location method according to any one of claims 1 to 7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that enables a processor to execute the network link fault location method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the network link fault location method as described in any one of claims 1 to 7.