Network connectivity detection method and system, electronic equipment and storage medium
By using a distributed network connectivity detection system, agents generate and report detection results, and the monitoring platform identifies and alerts to abnormal detection results. This solves the problems of high resource consumption and insufficient real-time detection in large and complex network environments, and achieves efficient link quality monitoring and anomaly early warning.
Patent Information
- Application Number
- CN202511001562.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-10-31
AI Technical Summary
Existing network connectivity detection tools consume high resources and are difficult to scale in large and complex network environments. They cannot achieve second-level monitoring and cannot monitor service and port status, resulting in insufficient real-time detection.
A distributed network connectivity detection system is adopted, in which an agent generates detection tasks on the device and reports the results to the monitoring platform. The monitoring platform determines the abnormal detection results and triggers alarms based on the detection results and device configuration information, thereby reducing the storage and functional requirements of the agent.
It enables efficient link quality detection in large and complex network environments, reduces resource consumption and functional limitations of distributed nodes, and improves the accuracy of anomaly detection and operational efficiency.
Smart Images

Figure CN120880942A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technology, and in particular to a network connectivity detection method, system, electronic device, and storage medium. Background Technology
[0002] Network connectivity detection is a key technology for ensuring the stable operation of network services. It enables the assessment of network quality and the detection of anomalies by monitoring the status of network devices and links.
[0003] In existing technologies, network connectivity probing primarily employs the following methods: Ping probing tools based on the Internet Control Message Protocol (ICMP) determine target host reachability, calculate network latency, and packet loss rate by sending ICMP Echo Request messages and waiting for responses. Fping, an enhanced version of Ping, supports one-to-many batch Ping probing, allowing adjustment of probing accuracy and frequency through parameters and output of results, making it suitable for larger network environments. Smartping, on the other hand, is an open-source, multi-functional network quality monitoring tool that emphasizes continuous network performance monitoring and visual analysis. It supports multi-protocol hybrid probing and multi-point deployment, enabling continuous many-to-many probing.
[0004] However, in existing technologies, Ping and Fping only support basic ICMP probing and cannot monitor service and port status. They are also difficult to extend and are only suitable for small network environments with low monitoring requirements. Their real-time probing is also insufficient, with a default probing time accuracy of minutes. Although Smartping has better functionality, the tool deployment consumes more server resources, and the cost of multi-point deployment is high. Moreover, it is still essentially a ping tool and cannot support second-level monitoring scenarios. Summary of the Invention
[0005] This application provides a network connectivity detection method, system, electronic device, and storage medium to reduce deployment resource consumption and achieve efficient network connectivity detection in large and complex network environments.
[0006] In a first aspect, embodiments of this application provide a network connectivity detection method, applied to a network connectivity detection system. The network connectivity detection system includes a monitoring platform and various agent programs, each agent corresponding one-to-one with a device in the network environment. The method includes: Each Agent in each Agent generates a corresponding probe task based on the configuration information of its corresponding device, performs network connectivity probe according to the corresponding probe task, obtains the corresponding probe results, and reports the corresponding probe results to the monitoring platform. The monitoring platform receives the detection results reported by each Agent and, based on the obtained detection results, the online status of each Agent, and the configuration information of each device, determines the abnormal detection results and triggers corresponding alarms.
[0007] In one optional embodiment, before each Agent generates its corresponding probe task based on the configuration information of its corresponding device, the method further includes: Each Agent in each Agent collects the configuration information of its corresponding device according to the collection period.
[0008] In an optional embodiment, the method further includes: Each Agent reports the configuration information of its corresponding device to the monitoring platform; The monitoring platform receives the configuration information of the corresponding device sent by each Agent and displays the obtained configuration information in a visual format.
[0009] In an optional embodiment, the method further includes: The monitoring platform generates result curves based on the detection results of each Agent and then visualizes these result curves.
[0010] In one optional embodiment, based on the obtained detection results, the online status of each Agent, and the configuration information of each device, anomaly detection results are determined, and corresponding alarms are triggered, including: When the detection result of the first agent indicates that the first detection link between the first device and the second device is damaged, and there is a second detection link between the first device and the second device, the abnormal detection result is determined to be that the detection link of the first agent has changed, and a level 3 alarm is triggered. Here, the first agent is any one of the agents, and the first device is the device corresponding to the first agent. When the detection results of the IP addresses related to the first device are all characterized as abnormal, and the online status of the first agent is offline, the first device is determined to be abnormal. Based on the redundant backup information of the first device, the abnormal detection result is determined and the corresponding alarm is triggered. When the detection results for the IP address related to the first device are all normal, and the online status of the first agent is offline, the abnormal detection result is determined to be that the first agent is offline, and a level 3 alarm is triggered.
[0011] In one optional embodiment, based on the redundancy backup information of the first device, the anomaly detection result is determined, and a corresponding alarm is triggered, including: When the first device has a redundant backup device, the anomaly detection result is determined to be that the first device is abnormal and the service is not affected, and a level 2 alarm is triggered; When there is no redundant backup device for the first device, the anomaly detection result is determined to be that the first device is abnormal and the service is damaged, and a level 1 alarm is triggered.
[0012] In one alternative embodiment, after determining that the first device is malfunctioning, the method further includes: The monitoring platform sends a blocking command to the second agent, which is the agent among all agents that needs to probe the IP address related to the first device; The second agent receives the blocking instruction and stops probing the IP addresses associated with the first device.
[0013] Secondly, this application also provides a network connectivity detection system, including: a monitoring platform and various agent programs, each agent corresponding to a device in the network environment; Each Agent is responsible for generating a corresponding probe task based on the configuration information of its corresponding device, performing network connectivity probe according to the corresponding probe task, obtaining the corresponding probe results, and reporting the corresponding probe results to the monitoring platform. Each Agent corresponds one-to-one with each device in the network environment. The monitoring platform is used to receive the detection results reported by each Agent, and based on the obtained detection results, the online status of each Agent and the configuration information of each device, to determine the abnormal detection results and trigger corresponding alarms.
[0014] In one optional embodiment, each Agent is further configured to collect configuration information of its corresponding device according to the collection period.
[0015] In one optional embodiment, each Agent is further configured to report the configuration information of its corresponding device to the monitoring platform; the monitoring platform is further configured to receive the configuration information of the corresponding device sent by each Agent and to visualize the obtained configuration information.
[0016] In one optional embodiment, the monitoring platform is further configured to generate a result curve based on the detection results corresponding to each Agent, and to visualize the result curve.
[0017] In an optional embodiment, the monitoring platform is further configured to: determine that the probe link of the first agent has changed when the probe result of the first agent indicates that the first probe link between the first device and the second device is damaged, and a second probe link exists between the first device and the second device; and trigger a level 3 alarm. Here, the first agent is any one of the agents, and the first device is the device corresponding to the first agent. When the probe results for the IP addresses related to the first device are all abnormal, and the online status of the first agent is offline, the platform determines that the first device is abnormal, and based on the redundant backup information of the first device, determines the abnormal detection result and triggers a corresponding alarm. When the probe results for the IP addresses related to the first device are all normal, and the online status of the first agent is offline, the platform determines that the abnormal detection result is that the first agent is offline and triggers a level 3 alarm.
[0018] In one optional embodiment, the monitoring platform is further configured to determine that the first device is abnormal and the service is not affected when the first device has a redundant backup device, and trigger a level two alarm; and to determine that the first device is abnormal and the service is affected when the first device does not have a redundant backup device, and trigger a level one alarm.
[0019] In one optional embodiment, the monitoring platform is further configured to send a blocking instruction to a second agent, which is the agent among the agents that needs to probe the IP address related to the first device; the second agent is configured to receive the blocking instruction and stop probing the IP address related to the first device.
[0020] Thirdly, embodiments of this application also provide an electronic device, including: Processor; and Stored program memory, The program includes instructions that, when executed by the processor, cause the processor to perform the network connectivity detection method as described in the first aspect.
[0021] Fourthly, embodiments of this application also provide a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the network connectivity detection method as described in the first aspect.
[0022] Fifthly, this application provides a computer program product that, when invoked by a computer, causes the computer to perform the network connectivity detection method steps as described in the first aspect.
[0023] The beneficial effects of this application are as follows: In the network connectivity detection method provided in this application embodiment, each Agent generates a corresponding detection task based on the configuration information of its corresponding device, performs network connectivity detection according to the corresponding detection task, obtains the corresponding detection results, and reports the corresponding detection results to the monitoring platform. Then, the monitoring platform receives the detection results reported by each Agent, and determines the anomaly detection results and triggers corresponding alarms based on the obtained detection results, the online status of each Agent, and the configuration information of each device. In this way, based on the distributed principle, by deploying simplified Agents to the devices that need to be monitored, the Agents only need to provide detection task generation, detection task execution, and detection result reporting, without the need for additional data storage. The monitoring platform then records the detection results and determines the anomaly detection results, which greatly reduces the workload of the Agents and significantly reduces the resource consumption and functional limitations of distributed node deployment. This achieves efficient detection of link quality in large and complex network environments, while significantly improving overall compatibility and scalability. In addition, based on the obtained detection results, the online status of each Agent, and the configuration information of each device, the abnormal detection results are determined and accurate warnings are issued. This significantly improves the efficiency of operation and maintenance personnel in discovering and locating problems, meeting the monitoring, anomaly detection, and location needs of various complex and large-scale network business environments.
[0024] Furthermore, other features and advantages of this application will be set forth in the following description and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described herein are used to provide a further understanding of this application, constitute a part of this application, and do not constitute an improper limitation of this application. In the accompanying drawings: Figure 1 This is a schematic diagram illustrating an optional application scenario applicable to the embodiments of this application; Figure 2 A schematic diagram illustrating the implementation process of a network connectivity detection method provided in this application embodiment; Figure 3 A schematic diagram of a network environment provided for an embodiment of this application; Figure 4 This is a schematic diagram illustrating another implementation of a network connectivity detection method provided in this application. Figure 5A schematic diagram of a network connectivity detection system provided in this application embodiment; Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0026] Embodiments of this application will now be described in more detail with reference to the accompanying drawings. While some embodiments of this application are shown in the drawings, it should be understood that this application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this application. It should be understood that the drawings and embodiments of this application are for illustrative purposes only and are not intended to limit the scope of protection of this application.
[0027] It should be understood that the steps described in the method embodiments of this application may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this application is not limited in this respect.
[0028] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc., mentioned in this application are used only to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.
[0029] It should be noted that the terms "a" and "a plurality of" used in this application are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0030] The names of the messages or information exchanged between multiple devices in the embodiments of this application are for illustrative purposes only and are not intended to limit the scope of these messages or information.
[0031] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.
[0032] (1) IP address: IP address is a unified address format provided by the IP protocol. It assigns a logical address to each host or server on the Internet and is a communication condition between hosts and servers, such as 1.1.1.1, 2.2.2.2, etc. The IP protocol is a protocol designed for communication between interconnected computer networks. In the Internet, it is a set of rules that enables all computer networks connected to the Internet to communicate with each other. It stipulates the rules that computers should follow when communicating on the Internet, so that all kinds of computers can communicate with each other on the Internet.
[0033] (2) MAC address: It is a unique identifier of a network device, which is specified by the device at the factory and cannot be modified. It is used to accurately locate the device in a certain area. It consists of 12 hexadecimal digits, such as 00:1A:2B:3C:4D:5E.
[0034] (3) Routing: is the activity of transmitting information from the source address to the destination address through an interconnected network, which determines the "path" of the data packet.
[0035] (4) Routing table: records the information of each router in the network and the links they are connected to.
[0036] (5) Security policy: It is a set of rules used to control who can and cannot enter the data packet. The policy settings are generally different for different devices.
[0037] (6) Address translation: During communication, the source IP or destination IP address is translated to hide the real IP information.
[0038] (7) Router: A network device used to distinguish different network and service boundary areas.
[0039] (8) Firewall: A network device used to restrict network policies and boundaries.
[0040] (9) Switch: A basic network device that only supports data aggregation within a region.
[0041] (10) Network connectivity detection: Usually, the source node of the probe performs a simulated access to the target node to be probed in some way, and the link quality between the nodes and the status of the target node are located by the access result information. The simulated access methods include ping probe, fping probe and smartping probe.
[0042] (11) Probe: usually refers to fixed software or hardware for detection purposes, which is a tool used to automatically perform data collection, processing, reporting and other actions in accordance with certain rules.
[0043] (12) Program Agent: This is usually a software program, such as a Windows executable program (.exe). It also supports automatic detection or rule acquisition, makes task decisions based on the rules, executes tasks, and outputs the results. Unlike detection, Agent usually needs to be deployed inside the system and run for a long time.
[0044] (13) Application Programming Interface (API): The API is the rules and tools that allow different systems to "talk".
[0045] (14) Distributed: refers to a system architecture in which multiple nodes work together through a network to complete a task. Its core idea is to distribute computing, storage, communication and other resources to different nodes, and achieve high availability, scalability and fault tolerance through cooperation. Unlike traditional independent deployment, the nodes of a distributed system are usually geographically or functionally dispersed, but appear as a unified whole to the outside world. It can effectively reduce resource consumption and operation and maintenance difficulty.
[0046] Based on the above explanations of terms and related terminology, the design concept of the embodiments of this application will be briefly introduced below: Network connectivity detection is a key technology for ensuring the stable operation of network services. It enables the assessment of network quality and the detection of anomalies by monitoring the status of network devices and links.
[0047] In existing technologies, network connectivity probing mainly employs the following methods: ICMP-based Ping probes, which send ICMP Echo Request messages to hosts and wait for responses to determine target host reachability, calculate network latency, and packet loss rate. Fping, an enhanced version of Ping, supports one-to-many batch Ping probes, allowing adjustment of probe accuracy and number of probes via parameters and output of results. It is suitable for larger network environments and improves probe efficiency. Smartping, on the other hand, is an open-source, multi-functional network quality monitoring tool. Compared to Ping and Fping probes, it focuses more on continuous network performance monitoring and visual analysis, supports multi-protocol hybrid probes and multi-point deployment, enables continuous many-to-many probes, and generates dashboards through a web page, making the probe results more intuitive.
[0048] However, in the existing technology, Ping and Fping only support basic ICMP probes, cannot monitor service and port status, and are difficult to expand. They are only suitable for small network environments with low monitoring requirements. Their probe real-time performance is also insufficient, with the default probe time accuracy at the minute level (i.e., one probe result is taken every minute).
[0049] While Smartping offers superior functionality, it suffers from the following drawbacks: Deploying the tool consumes significant server resources, leading to substantial costs for multi-site deployments; it remains essentially a ping tool and cannot support second-level monitoring scenarios; its configuration and web page setup require a learning curve, making it challenging for first-time users; when monitoring a massive number of nodes over extended periods, lower monitoring accuracy results in larger data volumes, necessitating storage support; and it requires manual configuration of probe tasks and cannot adaptively adjust to dynamically changing network environments.
[0050] In view of this, this application provides a network connectivity detection method applied to a network connectivity detection system. The network connectivity detection system includes a monitoring platform and various agent programs. Each agent corresponds one-to-one with each device in the network environment. Each agent generates a corresponding detection task based on the configuration information of its corresponding device, performs network connectivity detection according to the corresponding detection task, obtains the corresponding detection results, and reports the corresponding detection results to the monitoring platform. Then, the monitoring platform receives the detection results reported by each agent, and determines the abnormal detection results and triggers corresponding alarms based on the obtained detection results, the online status of each agent, and the configuration information of each device.
[0051] By employing the above approach, based on distributed principles, simplified agents are deployed to the devices requiring monitoring. The agents only need to generate, execute, and report detection results, eliminating the need for additional data storage. The monitoring platform then records the detection results and identifies anomalies. This significantly reduces the workload of the agents and minimizes resource consumption and functional limitations associated with distributed node deployments. This enables efficient detection of link quality in large and complex network environments, while also significantly improving overall compatibility and scalability. Furthermore, by analyzing the obtained detection results, the online status of each agent, and the configuration information of each device, anomaly detection results are identified and precise alerts are issued. This significantly improves the efficiency of problem discovery and localization for operations and maintenance personnel, meeting the monitoring, anomaly detection, and localization needs of various complex and large-scale network business environments.
[0052] In particular, the preferred embodiments of this application will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments of this application and the features in the embodiments can be combined with each other without conflict.
[0053] See Figure 1As shown, it is a schematic diagram of an optional application scenario applicable to the embodiments of this application. The application scenario may include: terminal device 101, monitoring platform 102 and each Agent 103. The monitoring platform 102 and each Agent 103 constitute a network connectivity detection system. Each Agent 103 corresponds one-to-one with each device. The devices include network devices (such as firewalls, switches and routers) and system devices (such as personal computers (PCs), physical servers, virtual servers, etc.).
[0054] This application embodiment does not impose any limitation on the number of communication devices involved in the above system architecture. For example, the above system architecture may include more terminal devices 101.
[0055] For example, terminal device 101 may include, but is not limited to: mobile phone, tablet computer, laptop computer, handheld computer, mobile internet device (MID), wearable device, virtual reality (VR) device, augmented reality (AR) device, wireless terminal device in industrial control, wireless terminal device in autonomous driving, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, or wireless terminal device in smart home, etc.
[0056] In addition, a related client can be installed on the terminal device 101. The client can be software, such as an application (APP), browser, short video software, etc., or a webpage, mini-program, etc. It should be noted that the terminal device 101 in this embodiment can be the terminal of the operation and maintenance personnel.
[0057] Each Agent 103 generates a corresponding probe task based on the configuration information of its corresponding device, performs network connectivity probe according to the corresponding probe task, obtains the corresponding probe results, and reports the corresponding probe results to the monitoring platform 102; each Agent 103 is also used to collect the configuration information of its corresponding device according to the collection cycle; each Agent 103 is also used to report the configuration information of its corresponding device to the monitoring platform. The monitoring platform 102 is used to receive the detection results reported by each Agent 103, and based on the obtained detection results, the online status of each Agent 103 and the configuration information of each device, determine the abnormal detection results and trigger corresponding alarms; the monitoring platform 102 is also used to issue monitoring rules (such as collection rules and detection rules); the monitoring platform 102 is also used to receive the configuration information of the corresponding device sent by each Agent 103 and visualize the obtained configuration information; the monitoring platform 102 is also used to generate result curves based on the detection results corresponding to each Agent 103 and visualize the result curves.
[0058] Terminal device 101 receives alarms, notifications and visual displays sent by monitoring platform 102.
[0059] The network connectivity detection method provided by the exemplary embodiments of this application will be described below in conjunction with the above application scenarios and with reference to the accompanying drawings. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.
[0060] See Figure 2 The diagram shown illustrates the implementation flow of a network connectivity detection method provided in this application. Taking a network connectivity detection system as an example, the specific implementation flow of this method is as follows: S20: Each Agent in each Agent generates a corresponding probe task based on the configuration information of its corresponding device, performs network connectivity probe according to the corresponding probe task, obtains the corresponding probe results, and reports the corresponding probe results to the monitoring platform.
[0061] Network connectivity detection includes device detection and link detection. Device detection monitors devices to determine if they are abnormal, while link detection monitors the quality of the path between the source device and the target device. Configuration information includes, but is not limited to, routing, security policies, and address translation.
[0062] In this embodiment of the application, each device is deployed with its own corresponding Agent according to the type and number of devices in the actual network environment. The monitoring platform issues monitoring rules to each Agent. Each Agent generates a corresponding probe task based on the configuration information of its corresponding device, and performs the probe task to detect network connectivity according to the probe rules, obtains the corresponding probe results, and reports the corresponding probe results to the monitoring platform.
[0063] The detection rules include, but are not limited to, collection rules and detection rules. Collection rules include, but are not limited to, collection period. Detection rules include, but are not limited to, detection period. Detection rules can be dynamically adapted and adjusted according to the actual network environment and needs.
[0064] Optionally, in this embodiment of the application, before each Agent generates a corresponding probe task based on the configuration information of its corresponding device, each Agent collects the configuration information of its corresponding device and performs the following operations: SA1: Each Agent in each Agent collects the configuration information of its corresponding device according to the collection period.
[0065] The collection period for each Agent can be the same or different. This embodiment does not impose any restrictions on this. In addition, configuration information that does not change on the device (such as hardware information) only needs to be collected once, while configuration information that changes on the device (such as port status) is collected periodically according to the collection period.
[0066] In this embodiment, the agent corresponding to the firewall collects the firewall's configuration information, which includes: hardware information, port status, IP address, routing table, MAC address, security policy, network session, and address translation information; the agent corresponding to the router collects the router's configuration information, which includes: hardware information, port status, IP address, MAC address, routing table, network session, and address translation information; and the agent corresponding to the switch collects the switch's configuration information, which includes: hardware information, port status, MAC address, and network session.
[0067] In this way, each Agent collects the device's configuration information based on the set collection rules, and then generates a probe task based on the collection results. The probe task can be generated automatically without manual configuration.
[0068] Furthermore, in this embodiment of the application, after each Agent collects the configuration information of its corresponding device, it also performs the following operations: SA2: Each Agent reports the configuration information of its corresponding device to the monitoring platform.
[0069] SA3: The monitoring platform receives the configuration information of the corresponding device sent by each Agent and displays the obtained configuration information in a visual format.
[0070] In this embodiment of the application, the monitoring platform selects target information from the configuration information of a device for visualization display. The target information includes, but is not limited to: device name, serial number, provider, device model, port type, port status, IP address, MAC address, routing table, address mapping table, and security policy.
[0071] In this way, maintenance personnel no longer need to query device configuration information one by one through command lines; they can quickly obtain various key data directly through a visual interface, reducing operational steps and time costs. It also avoids the problem of large amounts of data being continuously and permanently stored on the Agent, increasing storage pressure.
[0072] For example, see Figure 3 The diagram illustrates a network environment provided in this embodiment. When probing network connectivity in this environment, after deploying Agents on each device, each Agent collects the configuration information of its corresponding device and then generates a corresponding probe task based on that configuration information. Assuming all routers and firewalls in the network environment can connect to all IP addresses, the probe tasks for each Agent are as follows: Agent corresponding to switch 1 probes 2.2.2.1, 2.2.2.10, and 2.2.2.20; Agent corresponding to switch 2 probes 2.2.2.1. The Agent corresponding to Switch 3 probes 3.3.3.1, 3.3.3.2, 3.3.3.10, and 3.3.3.20; the Agent corresponding to Switch 4 probes 3.3.3.1, 3.3.3.2, 3.3.3.10, and 3.3.3.20; the Agent corresponding to Router 1 probes all IP addresses except 1.1.1.2 and 2.2.2.1; the Agent corresponding to Router 2 probes all IP addresses except 1.1.1.3 and 3.3.3.1; the Agent corresponding to Router 3 probes all IP addresses except 1.1.1.2 and 2.2.2.1; the Agent corresponding to the Firewall probes all IP addresses except 1.1.1.1.
[0073] S21: The monitoring platform receives the detection results reported by each Agent, and based on the obtained detection results, the online status of each Agent and the configuration information of each device, determines the abnormal detection results and triggers the corresponding alarms.
[0074] The online status of each Agent includes both online and offline.
[0075] In this way, the Agent returns the detection results to the monitoring platform in each detection cycle. The monitoring platform records and processes the detection results, determines the abnormal detection results, greatly reduces the resource consumption and functional limitations of distributed node deployment, and provides timely alerts to further help operation and maintenance personnel to handle the situation. This supports the monitoring and early warning needs of complex network scenarios and greatly reduces the monitoring configuration and operation and maintenance costs.
[0076] In addition, it is worth noting that in this embodiment of the application, the monitoring platform determines the topological relationship between each device based on the configuration information of each device. Based on the topological relationship between each device, it can obtain whether there is a redundant link between two devices, as well as the redundant backup information of each device.
[0077] Optionally, in this embodiment, based on the obtained detection results, the online status of each Agent, and the configuration information of each device, the abnormal detection results are determined, and corresponding alarms are triggered, including but not limited to the following three situations: Scenario 1: When the detection result of the first agent indicates that the first detection link between the first device and the second device is damaged, and there is a second detection link between the first device and the second device, the abnormal detection result is determined to be that the detection link of the first agent has changed, and a level 3 alarm is triggered.
[0078] Here, the first agent is any one of the agents, the first device is the device corresponding to the first agent, the second device is different from the first device, and the link damage includes reasons such as port down and cable damage.
[0079] Additionally, it is worth noting that in this embodiment, alarms are classified into three levels according to their urgency: Level 1 alarm, Level 2 alarm, and Level 3 high-level alarm. Level 1 alarm represents an alarm of the urgency level, Level 2 alarm represents an alarm of the warning level, and Level 3 alarm represents an alarm of the general level.
[0080] For example, such as Figure 3 As shown, when Agent 1 probes Router 1's 2.2.2.1 link, it can directly use the interconnection link. If the 2.2.2.1 link between Switch 1 and Router 1 is damaged, Agent 1 will switch the probe link to the 2.2.2.1 link between Switch 1, Switch 2, and Router 1. At this time, the abnormal detection result is determined to be a change in the probe link of the first Agent, and a level 3 alarm is triggered to notify the operation and maintenance personnel to handle the anomaly.
[0081] Scenario 2: When the detection results of the IP addresses related to the first device are all characterized as abnormal, and the online status of the first agent is offline, the first device is determined to be abnormal. Based on the redundant backup information of the first device, the abnormal detection result is determined and the corresponding alarm is triggered.
[0082] Among them, the detection results of the IP address related to the first device are all characterized as abnormal, which means that the detection results of each Agent that needs to detect the first device are all characterized as abnormal.
[0083] In this embodiment of the application, when the monitoring platform determines the online status of the first agent, if the first agent does not respond within a preset waiting period (e.g., does not report configuration information or detection results), then the online status of the first agent is determined to be offline.
[0084] For example, such as Figure 3 As shown, assuming the first device is router 2, the agents that need to probe the first device are those probing addresses 1.1.1.3 and 3.3.3.1. These agents include: the agent corresponding to router 1, the agent corresponding to router 3, the agent corresponding to the firewall, the agent corresponding to switch 3, and the agent corresponding to switch 4. The monitoring platform will integrate the abnormal IP probing information of these agents. If the probing results of addresses 1.1.1.3 and 3.3.3.1 are both abnormal, and the agent corresponding to router 2 is offline, then router 2 is determined to be abnormal. Then, based on the redundant backup information of the first device, the abnormal detection result is determined, and the corresponding alarm is triggered.
[0085] Optionally, in this embodiment of the application, based on the redundant backup information of the first device, the anomaly detection result is determined, and the corresponding alarm is triggered, specifically by performing the following operations: SB1: Determine if the first device has a redundant backup device. If yes, execute SB2; otherwise, execute SB3.
[0086] SB2: Determine that the anomaly detection result indicates that the first device is faulty and the service is unaffected, and trigger a level 2 alarm.
[0087] In this embodiment of the application, when the first device has a redundant backup device, the anomaly detection result is determined to be that the first device is abnormal and the service is not affected, and a level 2 alarm is triggered.
[0088] For example, such as Figure 3As shown, assuming the first device is router 2, router 2 and router 3 can mutually support access to the link of router 1. Router 2 has a redundant backup device router 3. After it is determined that router 2 is abnormal, the abnormality detection result is determined to be that router 2 is abnormal and the service is not affected, and a level 2 alarm is triggered to notify the operation and maintenance personnel to carry out abnormality repair.
[0089] SB3: If the anomaly detection result indicates that the first device is malfunctioning and services are impaired, a Level 1 alarm is triggered.
[0090] In this embodiment of the application, when the first device does not have a redundant backup device, the anomaly detection result is determined to be that the first device is abnormal and the service is damaged, and a level one alarm is triggered.
[0091] For example, such as Figure 3 As shown, assuming the first device is router 1, and router 1 does not have a redundant backup device, once it is determined that router 1 is abnormal, the anomaly detection result is determined to be that router 1 is abnormal and the service is damaged, and a level 1 alarm is triggered to notify the operation and maintenance personnel to carry out anomaly repair.
[0092] In this way, both equipment and business processes are taken into account, enabling accurate alarms.
[0093] Furthermore, in this embodiment of the application, after the monitoring platform determines that the first device is abnormal, the monitoring platform sends a blocking instruction to the second agent, and then the second agent receives the blocking instruction and stops probing the IP address related to the first device.
[0094] Among them, the second agent is the agent that needs to probe the IP address related to the first device.
[0095] For example, such as Figure 3 As shown, assuming the first device is router 2, after the monitoring platform determines that router 2 is abnormal, it sends a blocking command to the agent corresponding to router 1, the agent corresponding to router 3, the agent corresponding to the firewall, the agent corresponding to switch 3, and the agent corresponding to switch 4. The agents corresponding to router 1, router 3, firewall, switch 3, and switch 4 receive the blocking command and stop probing the addresses 1.1.1.3 and 3.3.3.1.
[0096] This avoids wasting resources.
[0097] Scenario 3: When the detection results for the IP address related to the first device are all normal, and the online status of the first agent is offline, the abnormal detection result is determined to be that the first agent is offline, and a level 3 alarm is triggered.
[0098] For example, such as Figure 3 As shown, assuming the first device is router 2, if the detection results of addresses 1.1.1.3 and 3.3.3.1 are both normal, and the Agent corresponding to router 2 is offline, then the anomaly detection result is that the first Agent is offline, triggering a level 3 alarm and notifying the operation and maintenance personnel to handle and repair it.
[0099] Additionally, it is worth noting that in this embodiment, the anomaly detection results also include detection anomalies and service anomalies caused by configuration changes such as network security policies and address translation, and this embodiment does not impose any restrictions on these.
[0100] Furthermore, in this embodiment of the application, after the monitoring platform receives the detection results reported by each Agent, it also generates a result curve based on the detection results corresponding to each Agent, and then visualizes the result curve.
[0101] For example, taking the link quality from IP address 1 to IP address 2 as an example, a latency curve and a packet loss rate curve for this link are generated, and the latency curve and packet loss rate curve are visualized.
[0102] In this way, the Agent returns the detection results to the monitoring platform at each detection cycle, and the monitoring platform visualizes the collected data, which reduces the resource consumption and functional limitations of distributed node deployment, while optimizing the data display.
[0103] Furthermore, in this embodiment of the application, after determining the anomaly detection result and triggering the corresponding alarm, other platforms can automatically handle the anomaly through the API interface of the monitoring platform.
[0104] For example, if the monitoring platform triggers an alarm, it can output the data to other platforms through the API interface, and the other platforms can perform exception handling operations (such as business loss prevention operations).
[0105] See Figure 4 The diagram shown is another flowchart illustrating network connectivity detection in this application embodiment. The specific process is as follows: S40: Begin.
[0106] S41: The monitoring platform distributes the configured detection rules to each Agent.
[0107] S42: The monitoring platform determines whether the Agent is online. If not, it executes S43; if so, it executes S44.
[0108] S43: The monitoring platform determines that the detection rule delivery failed and checks the Agent status and detection rules.
[0109] S44: The Agent collects the configuration information of its corresponding device according to the detection rules and generates its corresponding detection task.
[0110] S45: The agent continuously performs probes and reports the probe results and the configuration information of its corresponding devices to the monitoring platform.
[0111] S46: The monitoring platform performs data aggregation, visualization processing, and display.
[0112] S47: The monitoring platform determines whether there is an anomaly in the detection results. If so, it executes S48; otherwise, it executes S44.
[0113] The anomalies detected included link anomalies and device anomalies.
[0114] S48: Based on the obtained detection results, the online status of each Agent, and the configuration information of each device, determine the abnormal detection results and trigger the corresponding alarms.
[0115] Furthermore, based on the same technical concept, embodiments of this application provide a network connectivity detection system, which is used to implement the above-described method flow of embodiments of this application. For example, see [link to relevant documentation]. Figure 5 As shown, the network connectivity detection system 500 may include: a monitoring platform 501 and various agent programs 502, each agent corresponding one-to-one with a device in the network environment, wherein: Each Agent502 in each Agent is used to generate a corresponding probe task based on the configuration information of its corresponding device, and to perform network connectivity probe according to the corresponding probe task, obtain the corresponding probe results, and report the corresponding probe results to the monitoring platform. Each Agent corresponds one-to-one with each device in the network environment. The monitoring platform 501 is used to receive the detection results reported by each Agent, and based on the obtained detection results, the online status of each Agent and the configuration information of each device, to determine the abnormal detection results and trigger corresponding alarms.
[0116] In an optional embodiment, each Agent 502 is further configured to collect configuration information of its corresponding device according to the collection period.
[0117] In an optional embodiment, each Agent 502 is further configured to report the configuration information of its corresponding device to the monitoring platform; the monitoring platform 501 is further configured to receive the configuration information of the corresponding device sent by each Agent and to visualize the obtained configuration information.
[0118] In an optional embodiment, the monitoring platform 501 is further configured to generate a result curve based on the detection results corresponding to each Agent, and to visualize the result curve.
[0119] In an optional embodiment, the monitoring platform 501 is further configured to: determine that the detection link of the first agent has changed when the detection result of the first agent indicates that the first detection link between the first device and the second device is damaged, and a second detection link exists between the first device and the second device; and trigger a level 3 alarm when the detection result of the first agent indicates that the first detection link between the first device and the second device is damaged, and a second detection link exists between the first device and the second device; determine that the first device is abnormal when the detection results for the IP addresses related to the first device are all abnormal, and the online status of the first agent is offline; determine the abnormal detection result based on the redundant backup information of the first device; and trigger a corresponding alarm when the detection results for the IP addresses related to the first device are all normal, and the online status of the first agent is offline; and determine that the abnormal detection result is that the first agent is offline, and trigger a level 3 alarm.
[0120] In an optional embodiment, the monitoring platform 501 is further configured to determine that the first device is abnormal and the service is not damaged when the first device has a redundant backup device, and trigger a level two alarm; and to determine that the first device is abnormal and the service is damaged when the first device does not have a redundant backup device, and trigger a level one alarm.
[0121] In an optional embodiment, the monitoring platform 501 is further configured to send a blocking instruction to a second agent, which is the agent among the agents that needs to probe the IP address related to the first device; the second agent 502 is configured to receive the blocking instruction and stop probing the IP address related to the first device.
[0122] Based on the description of the method and apparatus embodiments above, an exemplary embodiment of the present invention also provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program executable by the at least one processor, which, when executed by the at least one processor, causes the electronic device to perform the method according to an embodiment of the present invention.
[0123] This application also provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of this application.
[0124] This application also provides a computer program product, including a computer program, wherein the computer program, when executed by a computer's processor, is used to cause the computer to perform a method according to an embodiment of this application.
[0125] See Figure 6 The diagram illustrates a structural block diagram of an electronic device 600 that can serve as a server or client in this application, serving as an example of hardware devices applicable to various aspects of this application. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the application described and / or claimed herein.
[0126] like Figure 6 As shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. The RAM 603 may also store various programs and data required for the operation of the device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0127] Multiple components in electronic device 600 are connected to I / O interface 605, including: input unit 606, output unit 607, storage unit 608, and communication unit 609. Input unit 606 can be any type of device capable of inputting information to electronic device 600. Input unit 606 can receive input digital or character information and generate key signal inputs related to user settings and / or function control of electronic device. Output unit 607 can be any type of device capable of presenting information and may include, but is not limited to, a display, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 608 may include, but is not limited to, disks and optical discs. Communication unit 609 allows electronic device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, modems, network cards, infrared communication devices, wireless communication transceivers and / or chipsets, such as Bluetooth devices, WiFi devices, worldwide interoperability for microwave access (WiMax) devices, cellular communication devices, and / or the like.
[0128] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above. For example, in some embodiments, the network connectivity detection method described above can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 600 via ROM 602 and / or communication unit 609. In some embodiments, the computing unit 601 can be configured to perform the network connectivity detection method described above by any other suitable means (e.g., by means of firmware).
[0129] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0130] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, erasable programmable read-only memory (EPROM) or flash memory, optical fibers, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0131] As used in this application, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, device, and / or apparatus (e.g., disk, optical disk, memory, programmable logic device, PLD) used to provide machine instructions and / or data to a programmable processor, including machine-readable media that receive machine instructions as machine-readable signals. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.
[0132] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0133] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0134] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other.
[0135] Furthermore, it should be understood that the above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of the invention. Therefore, any equivalent variations made in accordance with the claims of this invention are still within the scope of this application.
Claims
1. A method for detecting network connectivity, characterized in that, The method is applied to a network connectivity detection system, which includes a monitoring platform and various agent programs, each agent corresponding one-to-one with a device in the network environment. Each Agent in the Agent class generates a corresponding probe task based on the configuration information of its corresponding device, performs network connectivity probe according to the corresponding probe task, obtains the corresponding probe results, and reports the corresponding probe results to the monitoring platform. The monitoring platform receives the detection results reported by each Agent, and determines the anomaly detection results and triggers corresponding alarms based on the obtained detection results, the online status of each Agent, and the configuration information of each device.
2. The method as described in claim 1, characterized in that, Before generating the corresponding probe task based on the configuration information of its corresponding device, each Agent in the above categories also includes: Each Agent in the Agent series collects the configuration information of its corresponding device according to the collection period.
3. The method as described in claim 2, characterized in that, The method further includes: Each Agent reports the configuration information of its corresponding device to the monitoring platform; The monitoring platform receives the configuration information of the corresponding device sent by each Agent and displays the obtained configuration information in a visual format.
4. The method as described in claim 1, characterized in that, The method further includes: The monitoring platform generates a result curve based on the detection results corresponding to each Agent, and then visualizes the result curve.
5. The method according to any one of claims 1-4, characterized in that, Based on the obtained detection results, the online status of each Agent, and the configuration information of each device, the abnormal detection results are determined, and corresponding alarms are triggered, including: When the detection result of the first agent indicates that the first detection link between the first device and the second device is damaged, and there is a second detection link between the first device and the second device, the abnormal detection result is determined to be that the detection link of the first agent has changed, and a level 3 alarm is triggered. Here, the first agent is any one of the agents, and the first device is the device corresponding to the first agent. When the detection results for the IP addresses related to the first device are all characterized as abnormal, and the online status of the first Agent is offline, the first device is determined to be abnormal, and based on the redundant backup information of the first device, the abnormal detection result is determined and the corresponding alarm is triggered. When the detection results for the IP addresses related to the first device are all normal, and the online status of the first Agent is offline, the abnormal detection result is determined to be that the first Agent is offline, and a level 3 alarm is triggered.
6. The method as described in claim 5, characterized in that, The process of determining the anomaly detection result and triggering the corresponding alarm based on the redundant backup information of the first device includes: When the first device has a redundant backup device, the anomaly detection result is determined to be that the first device is abnormal and the service is not affected, and a level 2 alarm is triggered. When the first device does not have a redundant backup device, the anomaly detection result is determined to be that the first device is abnormal and the service is damaged, and a level 1 alarm is triggered.
7. The method as described in claim 5, characterized in that, After determining that the first device is malfunctioning, the process further includes: The monitoring platform sends a blocking command to the second agent, which is the agent among the agents that needs to probe the IP address related to the first device; The second Agent receives the blocking instruction and stops probing the IP addresses associated with the first device.
8. A network connectivity detection system, characterized in that, include: The monitoring platform and various agent programs, each agent corresponding one-to-one with a device in the network environment; Each Agent is used to generate a corresponding probe task based on the configuration information of its corresponding device, perform network connectivity probe according to the corresponding probe task, obtain the corresponding probe result, and report the corresponding probe result to the monitoring platform. Each Agent corresponds one-to-one with each device in the network environment. The monitoring platform is used to receive the detection results reported by each Agent, and based on the obtained detection results, the online status of each Agent and the configuration information of each device, determine the abnormal detection results and trigger corresponding alarms.
9. An electronic device, comprising: processor; as well as Stored program memory, The program includes instructions that, when executed by the processor, cause the processor to perform the method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-7.
Citation Information
Cited By
Client-free private cloud full-link monitoring method and system
CN122120122A