An IPv6 interface level topology detection method based on Monte Carlo tree search
Patent Information
- Application Number
- CN202511533136.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-24
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2045-10-24
AI Technical Summary
但是现有的基于探测反馈的方法的探测粒度只到路由前缀,忽略了路由前缀内部活跃拓扑分布的不均匀性,导致探测效率仍然较低
第一、真实世界实验表明,在24小时内,使用分布在全球各地的10台探测服务器,限制发包速率为每秒5000个探测包,总计发包数量40亿的条件下,TopoHunter能够探测得到1.43亿个路由器接口、2.43亿条拓扑边,结果覆盖72.83%的AS和43.36%的路由前缀,探测效率是现有最先进方法的3.38倍,AS覆盖率和路由前缀覆盖率分别比现有最先进方法提高了11.71%和9.86%。
Smart Images

Figure CN121567586B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of communication technology, specifically relating to an IPv6 interface-level topology detection method based on Monte Carlo tree search. Background Technology
[0002] With IANA completing the allocation of the last IPv4 address in 2011, IPv6 has rapidly gained popularity globally and has become a crucial pillar for the development of the next-generation Internet. As of 2025, the number of IPv6 routing prefixes announced by the BGP system has exceeded 290,000, a significant increase from approximately 5,000 in 2011. This trend demonstrates that IPv6 has become a core component of Internet infrastructure, an inevitable path for Internet evolution and upgrades, a driving force for network architecture innovation, and a key support for building digital infrastructure.
[0003] Internet topology refers to the network entities and their connections within the network layers of the Internet. Based on the abstraction level of network entities, from highest to lowest, there are AS level, PoP level, router level, and interface level. Aggregating interface-level topology yields the upper-layer topology; that is, interface-level topology forms the data foundation for upper-layer topology. IPv6 interface-level topology probing involves deploying probing servers to collect probing data, thereby obtaining the IPv6 interface-level topology. IPv6 interface-level topology probing is a crucial step in modern Internet architecture research, possessing significant value in network measurement, performance optimization, and security protection. First, constructing the global IPv6 Internet topology structure provides data support for network planning and research. Second, accurately identifying router interfaces helps discover potential security vulnerabilities and assess network exposure surfaces, thereby strengthening the protection of critical infrastructure. Furthermore, topology data can be used to optimize content distribution, improve IP geolocation accuracy, support fault diagnosis, and protocol design.
[0004] In IPv4 networks, Traceroute can easily cover all addresses, enabling rapid acquisition of global IPv4 interface-level topology. However, the vast address space, sparse and uneven distribution of active topologies, and strict ICMPv6 response rate limiting mechanisms of IPv6 pose significant challenges to global IPv6 interface-level topology probing. Using brute-force scanning methods could take tens of thousands of years to complete. Therefore, numerous studies have focused on exploring more efficient methods to optimize the IPv6 interface-level topology probing process. However, existing research suffers from low probing efficiency and limited coverage; thus, there is an urgent need for an efficient and wide-coverage IPv6 interface-level topology probing method.
[0005] Existing technologies related to IPv6 interface-level topology probing are mainly divided into two parts: IPv6 interface-level topology probing tools and IPv6 topology probing target selection strategies.
[0006] Existing IPv6 topology probing tools suffer from low probing efficiency due to redundant probes. When performing traceroute on different destination addresses within the same routing prefix, most of the front-end paths are identical, with only a small portion of the back-end paths differing. Existing IPv6 topology probing tools cannot accurately predict the TTL values at which traceroute paths fork between different destination addresses, leading to redundant probing of the same topology and consequently, low probing efficiency. Therefore, there is an urgent need for a new, high-concurrency, low-redundancy IPv6 interface-level topology probing tool.
[0007] Existing IPv6 topology probe target selection strategies can be mainly divided into two categories: one is the uniform sampling-based strategy, which generates probe targets by uniformly sampling route prefixes or a list of known active addresses; the other is the probe feedback-based strategy, which dynamically adjusts the direction of probe targets through probe feedback, allocating more probe target addresses to route prefixes that discover more router interfaces and edges. Existing research shows that the probe feedback-based method performs better in terms of probe efficiency and result coverage. However, existing probe feedback-based methods only probe at the route prefix level, ignoring the uneven distribution of active topology within the route prefix, resulting in still relatively low probe efficiency. Therefore, there is an urgent need for a new IPv6 interface-level topology probe target selection strategy that can achieve efficient and wide-coverage probes. Summary of the Invention
[0008] The present invention aims to at least partially solve one of the technical problems in the related art.
[0009] Therefore, the first objective of this invention is to propose an IPv6 interface-level topology detection method based on Monte Carlo tree search.
[0010] The second objective of this invention is to propose an IPv6 interface-level topology detection device based on Monte Carlo tree search.
[0011] To achieve the above objectives, a first aspect of the present invention proposes an IPv6 interface-level topology detection method based on Monte Carlo tree search, comprising: S1, construct the target prefix detection value forest, establish a multi-level value tree structure with the BGP routing prefix as the root node, and store the detection value estimate and detection count of each sub-prefix space; S2, based on the hierarchical structure of the value forest and the exploration rate parameter, adopts a top-down recursive probability allocation strategy to generate detection targets. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas. S3 generates specific probe addresses based on the prefix granularity of the probe target, prioritizes active addresses in the hit list, and generates random addresses within the target prefix range when the hit list is exhausted, following the rule of retaining only one address per / 64 subnet. S4 executes the detection task and updates the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection. S5 uses Kafka message queues and Redis caching to enable real-time communication between the central processing server and multiple probe servers, with probe results stored and synchronized through a MySQL distributed database.
[0012] In one embodiment of the present invention, S1 includes: S11, establish the sub-prefix hierarchy with 4-bit intervals, where the leaf nodes use a default prefix length of / 52; S12 stores the probe value estimate and probe count attribute for each node and reduces distribution bias through multi-data source integration.
[0013] In one embodiment of the present invention, S2 includes: S21, Set the exploration rate parameter to a range of 0.001-0.05, with a default value of 0.01; S22, when a parent node is identified as a high-value region, the target allocation probability of all its child nodes is recursively enhanced by a weight of 80% of the parent node's value.
[0014] In one embodiment of the present invention, S3 includes: S31 uses the / 64 minimum subnet partitioning standard based on RFC4291 for address generation; S32 performs a hash algorithm on the randomly generated addresses to ensure uniform address distribution within the subnet.
[0015] In one embodiment of the present invention, S4 includes: S41, the interface weight in the topology gain calculation formula is set to an adjustable range of 10-20; S42 uses the exponential relationship between the dynamic decay factor β and the prefix length to update the node valuation, where the value of β ranges from 0.8 to 0.95.
[0016] To achieve the above objectives, a second aspect of the present invention provides an IPv6 interface-level topology detection device based on Monte Carlo tree search, comprising: The value forest building module is used to build a multi-level value tree structure with BGP routing prefixes as the root node, and to store the probe value estimate and probe count of each sub-prefix space; The recursive probability allocation module is used to generate detection targets based on the hierarchical structure of the value forest and the exploration rate parameter, using a top-down recursive probability allocation strategy. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas. The probe address generation module is used to generate specific probe addresses based on the prefix granularity of the probe target. It prioritizes active addresses in the hit list. When the addresses in the hit list are exhausted, it generates random addresses within the target prefix range and follows the rule of retaining only one address per / 64 subnet. The detection execution and update module is used to execute detection tasks and update the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection. The communication and storage module is used to enable real-time communication between the central processing server and multiple probe servers through Kafka message queues and Redis caching, while the probe results are stored and synchronized through a MySQL distributed database.
[0017] The beneficial effects of the technical solution of this invention are as follows: First, real-world experiments show that, within 24 hours, using 10 probe servers distributed globally, limiting the packet sending rate to 5,000 probe packets per second, and a total of 4 billion packets sent, TopoHunter was able to detect 143 million router interfaces and 243 million topology edges, resulting in coverage of 72.83% of ASs and 43.36% of routing prefixes. The detection efficiency is 3.38 times that of the current state-of-the-art methods, and the AS coverage and routing prefix coverage are improved by 11.71% and 9.86% respectively compared to the current state-of-the-art methods.
[0018] Secondly, the detection results of this invention bring additional benefits beyond topology discovery: the system detected routing loops in 9.20% of the paths, involving 19.62 million interfaces and 7,919 ASs, providing key data for network security analysis; the addresses discovered by TopoHunter are highly complementary to active address detection, and experiments show that it can provide 29 million additional addresses as a seed list for algorithms such as 6Tree; 48.76% of the interfaces only responded to traceroute instead of ping, revealing the blind spots of traditional active address detection and providing a new perspective for network device configuration research.
[0019] Third, efficient and wide-coverage IPv6 interface-level topology detection provides data support for upper-layer router-level, PoP-level, and AS-level topologies, thereby providing a foundation for important upper-layer applications such as network planning and design, security risk assessment, critical infrastructure protection, content distribution optimization, and IPv6 geolocation.
[0020] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description
[0021] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein: Figure 1 This is a flowchart of an IPv6 interface-level topology detection method based on Monte Carlo tree search according to an embodiment of the present invention; Figure 2 This is a flowchart of the TopoHunter workflow according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a target prefix detection value forest according to an embodiment of the present invention; Figure 4 This is a flowchart of the core algorithm for target allocation according to an embodiment of the present invention; Figure 5 This is a flowchart of the value forest update algorithm according to an embodiment of the present invention; Figure 6 This is a structural diagram of an IPv6 interface-level topology detection device based on Monte Carlo tree search according to an embodiment of the present invention. Detailed Implementation
[0022] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.
[0023] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0024] The following describes, with reference to the accompanying drawings, an IPv6 interface-level topology detection method based on Monte Carlo tree search according to an embodiment of the present invention.
[0025] Example 1 Figure 1 This is a flowchart of an IPv6 interface-level topology detection method based on Monte Carlo tree search according to an embodiment of the present invention, such as... Figure 1 As shown, it includes: S1. Construct a target prefix probe value forest, using the BGP routing prefix as the root node to establish a multi-level value tree structure, storing the probe value estimate and probe count of each sub-prefix space.
[0026] Specifically, constructing a target prefix detection value forest is one of the core steps in the TopoHunter system to achieve efficient and wide-coverage IPv6 interface-level topology detection. This step establishes a multi-level value tree structure with the BGP routing prefix as the root node, estimates the detection value and records the number of detections for each sub-prefix space (length ≤ 48), thereby providing data support for subsequent detection target generation.
[0027] In some implementations, the forest consists of multiple value trees, each with its root node corresponding to a BGP routing prefix. The tree hierarchy increases in 4-bit increments according to prefix length, with leaf nodes defaulting to the / 52 prefix. Each node stores two key attributes: a probing value estimate and probing times. The probing value estimate measures the richness of potential topological information within the prefix space, while the probing times assess the frequency of probes in that area, preventing over-probing or under-probing.
[0028] Specifically, the update of the probe value estimate depends on the calculation of the topological gain. The number of probes is implemented using an incrementing counter; after each probe target is generated, the probe count of the corresponding prefix node is incremented by 1. Furthermore, a decay factor is introduced during the value update process. The calculation method is as follows ,in The prefix length is used to ensure that updates of longer prefixes have a smaller impact, thus avoiding overfitting.
[0029] In practical applications, this forest structure supports the system in dynamically adjusting target distribution during each round of exploration, prioritizing the exploration of high-value areas while retaining basic exploration of low-value or unexplored areas. For example, when exploration servers are deployed in multiple geographical locations globally, the central processing server generates exploration targets based on the value forest, ensuring rational resource allocation and improving exploration efficiency and coverage.
[0030] The technical advantage of this step lies in its ability to accurately identify high-value sub-prefixes through fine-grained modeling and dynamic feedback mechanisms, reducing redundant detection and improving topology discovery efficiency. Experiments show that this method outperforms existing technologies in both detection efficiency and coverage, laying a solid foundation for subsequent path tracing and topology construction.
[0031] Furthermore, S1 includes: S11 establishes a sub-prefix hierarchy with increments of 4 bits, where leaf nodes use a default prefix length of / 52.
[0032] Specifically, a sub-prefix hierarchy is established with increments of 4 bits, where leaf nodes default to a / 52 prefix length. This is one of the core implementation methods of the Target Prefix Probing Value Forest structure design in this invention. This step aims to improve the accuracy of identifying active topological regions in the IPv6 address space through fine-grained prefix partitioning, thereby optimizing the allocation efficiency of probe resources.
[0033] In some implementations, this step employs a top-down prefix partitioning strategy, using the BGP routing prefix as the root node and recursively generating sub-prefixes downwards. The prefix length at each level increases by 4 bits, for example, from / 32, / 36, / 40, / 44, / 48 up to / 52. This partitioning method conforms to the typical structure of IPv6 address allocation (such as / 48 as the smallest subnet allocation unit recommended in RFC4291), while also balancing probe granularity with computational complexity. Leaf nodes default to a / 52 prefix length because this length still provides sufficient coverage in the IPv6 address space and effectively captures differences in topology distribution within subnets, avoiding resource waste caused by overly fine granularity.
[0034] Specifically, each node in this hierarchical structure stores two key attributes: Probing Value and Probed Times. The Probing Value quantifies the potential topological information density within the sub-prefix space, while the Probed Times assess the probing frequency of the region. In each round of probing, the system allocates targets based on the node's Probing Value and the exploration rate parameter α (default 0.01), ensuring that existing probing information is utilized while retaining the ability to explore unknown regions. Furthermore, this structure supports dynamic updates; the probing gain is weighted and updated using a decay factor β (related to the prefix length) to reflect the decreasing trend of probing rewards as the topology becomes more complete.
[0035] In practical applications, this sub-prefix hierarchy is widely used in the multi-round probing loop of the TopoHunter system. The central processing server generates probe targets for each round based on this structure, and the probe server performs Traceroute probing based on the target prefix length. Through this structure, the system can identify high-value subnets and prioritize the allocation of probe resources, while avoiding over-probing of low-value or alias prefixes, thereby improving overall probe efficiency and coverage.
[0036] The technical value of this step lies in the fact that, through fine-grained prefix modeling, the system can more accurately assess the detection potential of different subnets and achieve adaptive resource allocation. Compared to existing methods that only use / 48 as the detection unit, this invention further improves the resolution and flexibility of detection by dividing the system into / 52 leaf nodes, laying a solid foundation for subsequent intelligent target generation and feedback updates.
[0037] S12 stores the probe value estimate and probe count attribute for each node and reduces distribution bias through multi-data source integration.
[0038] Specifically, storing the probe value estimate and probe count attribute for each node, and reducing distribution bias through multi-data source integration, is one of the key mechanisms for achieving efficient topology probing in the TopoHunter system. At the technical implementation level, this step employs a hierarchical data structure—the Target Prefix Probing Value Forest—where each node represents an IPv6 sub-prefix space (prefix length increases in 4-bit increments, with leaf nodes having a default maximum length of / 52) and maintains two core attributes: the probe value estimate and the probe count. The probe value estimate quantifies the potential information content of the prefix space in topology discovery, while the probe count records the number of times the prefix has been probed, used to assess its exploration level.
[0039] Specifically, the update of the probe value estimate depends on the calculation of the topological gain. The number of probes increases by 1 with each probe mission. Furthermore, a decay factor is introduced into the system. (Hyperparameter) is used to decay historical estimates when updating probe values to reflect the diminishing marginal returns of topological information. Longer prefixes (such as / 48) have smaller decay factors because they cover a wider range, and a single probe has a limited impact on the overall estimate.
[0040] In practical applications, this step is suitable for the target selection and resource allocation phases of global IPv6 topology probing missions. By storing and updating probing value and probing counts, the system can dynamically adjust its probing strategy across multiple rounds of probing, prioritizing the probing of high-value areas while retaining basic probing of low-value or unprobing areas, thus achieving a balance between efficiency and coverage in large-scale probing missions. Integration of multiple data sources (such as multiple active address hit lists) further enhances the system's adaptability to real-world topology distributions, reducing distribution bias caused by a single data source.
[0041] This step significantly improves the utilization rate of probe resources through fine-grained value assessment and dynamic feedback mechanisms. Experiments show that TopoHunter, under the same probe scale, improves probe efficiency by 3.38 times compared to existing methods, and increases AS coverage and route prefix coverage by 11.71% and 9.86%, respectively. This mechanism not only enhances the system's adaptability to the IPv6 address space but also provides a high-quality data foundation for subsequent topology discovery, route loop detection, and network device configuration analysis.
[0042] S2, based on the hierarchical structure of the value forest and the exploration rate parameter, uses a top-down recursive probability allocation strategy to generate detection targets. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas.
[0043] Specifically, this step, based on the hierarchical structure of the value forest and the exploration rate parameter α, employs a top-down recursive probability allocation strategy to generate detection targets. Its core lies in achieving a dynamic balance between "utilization" and "exploration," thereby concentrating resources in high-value areas while retaining basic detection capabilities for unknown areas. This strategy intelligently allocates the detection probability of child nodes through a probability formula.
[0044] In some implementations, this step begins with the root node of the value forest (BGP route prefix) and recursively traverses downwards to the leaf nodes (such as the / 52 prefix). For each non-leaf node, the system calculates the probe probability of each child node based on its probe value and quantity, and allocates probe resources proportionally according to the probability. This recursive process ensures a reasonable distribution of probe resources across different levels, avoiding the problem of coarse-grained allocation based solely on route prefixes in traditional methods.
[0045] Specifically, exploration rate This is a key control parameter, and its value directly affects the system's ability to explore unknown areas. Smaller values... A value (such as 0.01) means the system is more inclined to utilize existing valuable information, while a larger value... This value encourages further exploration. Furthermore, the number of targets detected... The number of targets allocated per round is fixed, usually set according to the concurrency capacity of the probe server, for example, 1000 probe targets are allocated per round.
[0046] This step is applicable to large-scale IPv6 topology probing tasks, especially in distributed probing systems with limited resources that need to balance efficiency and coverage. Through recursive probability allocation, TopoHunter can continuously optimize target selection in multiple rounds of probing, prioritizing the probing of high-value areas while avoiding getting trapped in local optima, thus improving overall probing efficiency and coverage.
[0047] This step demonstrates significant technical effectiveness, effectively addressing the low detection efficiency caused by the large IPv6 address space and uneven topology distribution through fine-grained value assessment and dynamic resource allocation mechanisms. Experiments show that this strategy can significantly increase the number of interfaces and edges discovered by the probe server within 24 hours, while reducing the proportion of redundant probes, providing high-quality data support for subsequent topology construction and network analysis.
[0048] Furthermore, S2 includes: S21, set the exploration rate parameter α to a range of 0.001-0.05, with a default value of 0.01.
[0049] Specifically, in this invention, the exploration rate parameter α is a key control parameter in the target generation module, used to achieve a dynamic balance between "utilizing existing detection value" and "exploring unknown address space". The value range of this parameter is set from 0.001 to 0.05, with a default value of 0.01. This setting is based on a comprehensive consideration of the IPv6 address space distribution characteristics and detection efficiency.
[0050] In some implementations, the α value is embedded in the recursive allocation algorithm of the target prefix detection value forest, specifically reflected in the target allocation probability calculation formula of each node's sub-prefix. The introduction of α ensures that even in regions with high detection value, the system can still retain a certain proportion of exploration opportunities, thereby avoiding getting trapped in local optima and improving the overall detection coverage.
[0051] Specifically, the value of α directly affects the exploration-to-utilization ratio of the system. When α = 0.01, in each round of target allocation, approximately 99% of the system's detection resources are used for utilizing high-value areas, while only 1% is used for exploring unknown areas. This ratio has been experimentally verified to achieve an optimal trade-off between detection efficiency and coverage in large-scale IPv6 topology detection. If the α value is too low (e.g., 0.001), the system will over-rely on historical detection results, leading to the omission of low-value areas; if the α value is too high (e.g., 0.05), it will introduce too much randomness, reducing detection efficiency.
[0052] In practical applications, the α setting is suitable for TopoHunter's multi-round probing process, especially in the early and middle stages of probing. During system startup, the α value can be appropriately increased (e.g., 0.02) to accelerate coverage of unknown areas; while after probing enters a stable period, the α value can be gradually decreased (e.g., 0.005) to improve the probing depth of known high-value areas. This dynamic adjustment mechanism allows the system to adapt flexibly to different network environments and probing targets. For example, in situations where probing resources are limited or the network topology distribution is highly uneven, a reasonable α setting can significantly improve probing performance.
[0053] The appropriate range and default value of α enable TopoHunter to achieve a balance between high efficiency and wide coverage in large-scale IPv6 topology probing. Experiments show that when α=0.01, the system can obtain 143 million interfaces and 243 million edges using 10 probe servers within 24 hours, improving probing efficiency by 3.38 times compared to existing methods. This parameter setting not only improves the utilization of probe resources but also enhances the system's ability to discover sparse and active topology regions, providing a high-quality data foundation for subsequent topology aggregation and network analysis.
[0054] S22, when a parent node is identified as a high-value region, the target allocation probability of all its child nodes is recursively enhanced by a weight of 80% of the parent node's value.
[0055] Specifically, when a parent node is identified as a high-value region, the target allocation probability of all its child nodes is recursively enhanced by a weight of 80% of the parent node's value. This step is one of the core mechanisms of the target generation module in the TopoHunter system, which aims to achieve efficient and adaptive probing of the IPv6 address space.
[0056] In some implementations, this step is based on the hierarchical structure of the Target Prefix Probing Value Forest, employing a top-down recursive enhancement strategy. When a parent node (such as the / 32 or / 48 prefix) is determined to be a high-value node in the feedback update module (i.e., its probing value is significantly higher than the average), the system recursively traverses all its child nodes, incorporating 80% of the parent node's value into the child node's target allocation probability calculation. This mechanism guides probing resources towards the subspace of that region by superimposing the high-value signal of the parent node into the probing value evaluation of the child nodes, thereby achieving a "center-to-periphery expansion" probing strategy.
[0057] Specifically, the weighting coefficient for recursive enhancement is set to 0.8. This parameter has been experimentally verified to effectively increase the detection density in high-value areas while maintaining exploration diversity. Furthermore, the system uses an exploration rate parameter when allocating targets. (Default 0.01) is used to balance exploitation and exploration, ensuring that potential high-value sub-regions are not ignored while recursively enhancing the region.
[0058] In practical deployments, this step is applicable to TopoHunter's multi-round probing loops, especially in the early stages of probing or when the network topology is highly uneven. For example, when the / 32 prefix of a large ISP is detected to have a rich topology, the system will automatically increase the probing probability of all its sub-prefixes such as / 48 and / 52, thereby quickly expanding the coverage of the ISP's network and improving the efficiency of interface and edge discovery.
[0059] This step significantly improves the efficiency of probe resource allocation, enabling the system to prioritize probing high-value subspaces, thereby achieving higher topology discovery gains with limited probe resources. Experiments show that this mechanism makes TopoHunter 3.38 times more efficient than existing methods within 24 hours, while also improving AS and routing prefix coverage. The recursive enhancement strategy also enhances the system's responsiveness to topology hotspots, helping to discover critical infrastructure nodes and providing high-quality data support for network security analysis and network performance optimization.
[0060] S3 generates specific probe addresses based on the prefix granularity of the probe target, prioritizes active addresses in the hit list, and generates random addresses within the target prefix range when the hit list is exhausted, following the rule of retaining only one address per / 64 subnet.
[0061] Specifically, in the TopoHunter system, generating specific probe addresses based on the prefix granularity of the probe target is one of the key steps in achieving efficient topology probing. The core of this step lies in maximizing probe efficiency and reducing redundant probes through a fine-grained address selection strategy. Specifically, the system first selects active addresses from the hit list as probe targets based on the target prefixes allocated in the TargetPrefix Probing Value Forest. The hit list typically consists of publicly available IPv6 active address datasets (such as CAIDA, RIPE Atlas, etc.), where only one address is reserved for each / 48 subnet to avoid repeated probes within the same subnet, thereby saving resources and improving the diversity of path tracing.
[0062] In some implementations, once all active addresses in the hit list have been used, the system enters the random address generation phase. At this point, probe addresses are randomly generated within the target prefix range, but adhere to the minimum / 64 subnet length standard recommended in IPv6 subnet best practices (RFC4291). To avoid path redundancy caused by generating multiple probe addresses within the same / 64 subnet, the system adopts the rule of "only one address per / 64 subnet." That is, when generating random addresses, the target prefix is first divided into several / 64 subnets, and then an address is randomly selected from each subnet as the probe target. This strategy effectively reduces the number of probe packets while ensuring representative coverage of the subnet space.
[0063] Furthermore, the parameter settings for this step include the number of targets N to be detected, the exploration rate α (default 0.01), and the address generation granularity (e.g., / 48, / 64). The exploration rate α controls the proportion of unknown areas explored during target allocation, ensuring that the system can explore potentially active areas while utilizing existing high-value areas, thereby improving overall coverage. In addition, the address generation strategy works closely with the TTL prediction mechanism of the DY6 detection tool to provide a more accurate detection starting point for subsequent path tracing, significantly improving topology discovery efficiency.
[0064] This step in the system performs a dual function of allocating probe resources and generating targets, serving as a core bridge connecting value forest modeling and actual probe execution. By prioritizing active addresses and controlling the number of addresses within a subnet, the system can achieve efficient and wide-coverage probes of the IPv6 address space with limited probe resources, providing a high-quality data foundation for subsequent topology construction and analysis.
[0065] Furthermore, S3 includes: S31 uses the / 64 minimum subnet partitioning standard based on RFC4291 for address generation.
[0066] Specifically, the step of "generating addresses using the / 64 minimum subnetting standard based on RFC4291" is a key step in the TopoHunter system's target generation module to achieve efficient detection resource allocation and topology coverage. Its technical implementation is based on a hierarchical structure and subnetting specification of the IPv6 address space, aiming to reduce redundant detection and improve detection efficiency and result quality.
[0067] In some implementations, this step first divides the IPv6 address space into / 64 subnets according to the RFC4291 standard. Based on best practices for IPv6 subnetting, / 64 is the recommended minimum subnet length, typically used for address allocation within a single LAN segment. When generating probe addresses, TopoHunter ensures that at most one probe target address is generated within each / 64 subnet, thus avoiding repeated probes within the same subnet and reducing path redundancy. In practice, the system preprocesses the active addresses in the hit list; if an address belongs to a certain / 64 subnet, only one address from that subnet is retained as a probe target, and the remaining addresses are filtered out.
[0068] Specifically, this step involves prefix length ( / 64), address reservation policy (only one address is reserved per subnet), and granular control of probe resource allocation. By limiting the number of probes to one per / 64 subnet, the system significantly reduces the number of probe packets and network load while ensuring probe coverage. Furthermore, this strategy complements the TTL prediction mechanism of the DY6 probe tool, further improving probe efficiency.
[0069] In practical applications, this step is suitable for large-scale IPv6 topology probing tasks, especially in resource-constrained distributed probing environments. By adhering to the / 64 subnetting standard, the system can efficiently generate probing targets in IPv6 networks globally, enabling finer-grained probing resource allocation, particularly when dealing with uneven topology distribution within routing prefixes.
[0070] The technical advantage of this step lies in reducing redundant probing and improving probing efficiency through standardized subnetting, while ensuring the integrity of topology coverage. Experiments show that this strategy helps the system discover more unique router interfaces and topology edges with limited probing resources, providing a high-quality data foundation for subsequent topology aggregation and analysis.
[0071] S32 performs a hash algorithm on the randomly generated addresses to ensure uniform address distribution within the subnet.
[0072] Specifically, in some implementations, performing a hash algorithm on randomly generated addresses to ensure the uniformity of address distribution within the subnet is one of the key technical means in the target generation module of the TopoHunter system. The core purpose of this step is to maximize the detection coverage under the premise of limited detection resources and avoid detection blind spots or repeated detections caused by uneven address distribution.
[0073] When generating probe addresses, the system first randomly selects several / 64 subnets within the target subnet (e.g., / 48 or / 52), and then generates a target address within each / 64 subnet. To ensure a uniform distribution of addresses within the subnets, the system uses a hash algorithm (e.g., SHA-256) to process the random seed, generating a pseudo-random IPv6 address suffix. This seed is typically composed of a timestamp, probe round number, server ID, etc., to ensure that addresses generated by different probe servers in different rounds have good randomness and unpredictability. Furthermore, the system concatenates the generated address suffix with the prefix of the target subnet to form a complete IPv6 address for Traceroute probing.
[0074] Specifically, the system generates only one probe address per / 64 subnet by default, conforming to the minimum IPv6 subnet length standard recommended in RFC4291. Meanwhile, to avoid excessive concentration of probe addresses within the subnet, the system uses a hash function to evenly distribute address suffixes across the subnet's address space. For example, if the subnet is 2001:db8:1234:: / 64, the suffixes generated by the system using the hash algorithm will cover the address range from 0000:0000:0000:0000:0000:0000:0000:0001 to ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff, ensuring good spatial distribution of probe addresses within the subnet.
[0075] In practical applications, this step is widely used in the multi-round probing process of the TopoHunter system, especially in the initial probing phase and in unknown area probing triggered by the exploration rate mechanism. Through a uniformly distributed address generation strategy, the system can effectively identify active interfaces and potential routing paths in a large-scale IPv6 address space, which is particularly suitable for network environments with sparse address distribution and limited ICMPv6 response.
[0076] The technical advantage of this step lies in significantly improving the coverage and efficiency of the probe. Addresses generated using a hash algorithm avoid local clustering, making the probe results more representative and reducing invalid probes caused by uneven address distribution. In experiments, this strategy, in conjunction with a probe-feedback-based resource allocation mechanism, enabled TopoHunter to discover more unique router interfaces and topology edges with the same probe resources, thus providing a solid foundation for building high-precision IPv6 interface-level topologies.
[0077] S4 executes the detection task and updates the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection.
[0078] Specifically, during the execution of probe tasks and the updating of the value forest, the system achieves refined evaluation and continuous optimization of the probe value of each node through alias prefix filtering, topology gain calculation, and dynamic adjustment of the value decay factor β. This step is the core of the feedback update module in the TopoHunter system, directly determining the subsequent allocation strategy of probe resources and the overall probe efficiency.
[0079] First, during the alias prefix filtering phase, the system identifies multiple interface addresses that may belong to the same logical device by comparing the probe results with a known list of alias prefixes in real time. Alias prefixes typically manifest as network devices returning Echo Reply responses to all addresses within the same subnet, which is common in IPv6 networks. To avoid repeatedly probing the same device, the system merges interfaces under the same alias prefix into a single logical node and reduces the probe frequency for that area in subsequent probes. Furthermore, the system employs a random suffix strategy when generating probe targets to reduce the probability of false positives. If an Echo Reply is detected in the probe response, the system further pings multiple addresses under that / 64 address to confirm the existence of an alias prefix, thereby dynamically updating the alias list.
[0080] Secondly, topology gain calculation is crucial for evaluating the contribution of the probe mission. Topology gain is determined by the quantity and quality of newly discovered interfaces and edges, with the interface weight w set to 10 by default to reflect its higher value relative to edges. The contribution of an edge is attenuated based on the number of anonymous hops in its path, specifically 2^n (where n is the number of anonymous hops), to reflect the uncertainty of its topology information. All newly added topology elements must be globally compared with the historical discovery results of the probe server to ensure that gain calculation is performed only on undiscovered topology information, thereby avoiding redundant probes across servers.
[0081] Finally, the value forest update relies on the dynamic adjustment of the value decay factor β. β, as a hyperparameter, controls the decay rate of node probe value, typically ranging from 0.9 to 0.99. Longer prefixes (such as / 48 or / 52) have relatively smaller decay factors due to their larger coverage, reflecting the limited impact of a single probe result on the value assessment of that level. During the update process, the system traverses the path downwards from the root node, incrementing the probe count for all sub-prefix nodes containing the target address, and updating the node's probe value estimate by weighting the current topology gain according to the decay factor. This mechanism ensures that the value forest can dynamically adapt to the evolution of the topology and continuously optimize the allocation of probe resources.
[0082] In summary, this step, through a multi-dimensional feedback mechanism, enables dynamic modeling and updating of the detection value, providing crucial support for the efficiency and wide coverage of the TopoHunter system in IPv6 interface-level topology detection.
[0083] Furthermore, S4 includes: S41, the interface weight w in the topology gain calculation formula is set to an adjustable range of 10-20.
[0084] Specifically, in this invention, interface weight The parameter is adjustable from 10 to 20 and is one of the key hyperparameters in the topology gain calculation formula. Its function is to quantify the relative value of interface discovery relative to edge discovery. This parameter directly affects the allocation strategy of detection resources and the optimization effect of detection efficiency.
[0085] Interface weight Embedded in the topology gain calculation formula, it is used to weight the newly added topology information brought by each probe mission. Specifically, interface discovery usually means the identification of a new router, while edge discovery represents the connection between two visible hops in a path. Because interface discovery has higher topological significance, it is given a higher weight in the gain calculation. In some implementations, this weight... It can be dynamically adjusted according to the detection phase, network environment, or activity level of the detection target to adapt to the resource allocation needs under different detection scenarios.
[0086] Interface weight The value range is set to 10 to 20, based on statistical analysis of the topological information density of interfaces and edges in IPv6 networks. Experiments show that when... When set to 10, the system achieves an initial balance between interface discovery and edge discovery; while when When the value is increased to 20, the system is more inclined to prioritize detecting areas that may contain new interfaces, thereby quickly building the topology framework in the early detection phase. This parameter setting needs to be adjusted in conjunction with the activity level of the detection target, the distribution density of the detection servers, and the coverage of the current detection round to achieve optimal detection benefits.
[0087] Interface weight The settings directly affect the resource allocation strategy of the detection system in different network regions. For example, in the early stages of detection, if the active interface density in the target area is low, appropriately increasing... The system can be incentivized to prioritize the detection of potential interfaces, accelerating the construction of the topology; however, in the later stages of detection, when most interfaces have been discovered, the detection rate decreases. This can guide the system to focus more on edge discovery, thereby improving topological connectivity. Furthermore, this parameter can be configured differently based on the geographical location of the probe server to adapt to variations in network structure across different regions.
[0088] Interface weight Proper configuration can significantly improve the resource utilization efficiency and topology discovery quality of the detection system. By assigning higher gain weights to interfaces, the system can prioritize the identification of key network nodes, thereby improving the integrity and representativeness of the topology. Experimental data shows that when... When set to 15, the system detected a peak number of interfaces within 24 hours while maintaining high edge discovery efficiency, verifying the rationality and effectiveness of this parameter setting. This step, as a core component of the feedback update mechanism, provides crucial decision-making support for subsequent target generation and resource allocation, and is a vital technical foundation for achieving efficient and wide-coverage IPv6 interface-level topology detection.
[0089] S42 uses the exponential relationship between the dynamic decay factor β and the prefix length to update the node valuation, where the value of β ranges from 0.8 to 0.95.
[0090] Specifically, in the feedback update module, the node valuation update is performed using the exponential relationship between the dynamic decay factor β and the prefix length, which is one of the core mechanisms for achieving adaptive optimization of the value forest. The technical implementation of this step is based on the backpropagation idea of Monte Carlo Tree Search (MCTS). By introducing a decay factor related to the prefix length, the detection results are updated with weights, thereby more accurately reflecting the detection potential of prefix spaces of different granularities.
[0091] In some implementations, the decay factor β is set to a range of 0.8 to 0.95. This parameter controls the weight of historical probes in the current valuation update. Specifically, the value of β decreases as the prefix length increases; that is, the longer the prefix (the finer the granularity), the less influence historical values have on its valuation update. This exponential decay relationship can be expressed as: βL Where L is the difference between the current prefix length and the root node (BGP route prefix) length. For example, if the root node is / 32 and the current node is / 48, then L=16, and the attenuation factor is β. 16 This design conforms to the law of diminishing marginal returns in topology exploration, meaning that in finer-grained prefixes, the contribution of a single exploration to the overall value assessment is limited, and therefore its impact on valuation should be reduced.
[0092] Furthermore, during the value forest update process, the system first locates the path of the probe target in the value tree based on the routing prefix to which the probe belongs. Then, starting from the root node, it updates the probe values of all nodes on the path layer by layer downwards. The probe count of each node increments by 1, and the probe value is calculated according to the formula: V = β L × V old + G new V old For the historical valuation of nodes, G new This represents the topology gain for the current exploration mission. Through this mechanism, the system can dynamically adjust the value assessment of different prefix levels, avoiding valuation biases caused by locally high gains, thereby improving the global rationality of exploration resource allocation.
[0093] This step has significant technical value in IPv6 interface-level topology probing. On the one hand, it effectively suppresses the overshoot problem of fine-grained prefix estimation through an exponential decay mechanism, preventing the system from getting trapped in excessive probing of local high-value regions. On the other hand, by combining topology gain calculation with alias prefix filtering, it ensures the accuracy and efficiency of estimation updates. In large-scale distributed probing scenarios, this method significantly improves the convergence speed and coverage of the probing system, providing reliable data support for subsequent target generation and resource allocation.
[0094] S5 uses Kafka message queues and Redis caching to enable real-time communication between the central processing server and multiple probe servers, with probe results stored and synchronized through a MySQL distributed database.
[0095] Specifically, this invention utilizes Kafka message queues and Redis caching to achieve real-time communication between the central processing server and multiple probe servers, a key technological aspect of the efficient collaborative probe mechanism within the TopoHunter system. In some implementations, the central processing server is responsible for generating probe target addresses and distributing these targets to each probe server via Kafka message queues. Kafka, as a high-throughput, low-latency distributed messaging system, supports a multi-producer-consumer model, ensuring real-time and reliable transmission of target addresses. Specifically, the central server encapsulates probe tasks into JSON-formatted messages and publishes them to a specific Kafka topic. The probe servers, acting as consumers, subscribe to this topic, retrieve tasks on demand, and execute Traceroute probes.
[0096] After executing the probe task, the probe server sends the probe results (including path jumps, response types, interface information, etc.) back to the central processing server in real time. To improve communication efficiency and response speed, the system uses Redis caching as an intermediate storage layer to temporarily store probe results and perform fast aggregation processing. Redis supports high-concurrency read and write operations, and its in-memory database characteristics allow data insertion and query latency to be controlled within milliseconds. In the specific implementation, the probe results are written to a Redis hash structure in key-value pair format, where the key is the probe target address and the value is the serialized data of the probe path. The central server subscribes to Redis's Keyspace Notifications mechanism to monitor the update events of the probe results in real time, thereby achieving dynamic awareness of the probe progress.
[0097] Specifically, the number of Kafka partitions is configured based on the number of probe servers to achieve load balancing and parallel processing. Message compression uses the LZ4 algorithm to reduce network transmission overhead. Redis's caching strategy employs a TTL (Time To Live) mechanism, setting a reasonable expiration time (e.g., 300 seconds) to prevent cached data from growing indefinitely. Furthermore, the system uses Redis Lua scripts to implement atomic updates, ensuring data consistency during concurrent writes from multiple probe servers.
[0098] This step acts as a bridge in the entire technical solution, ensuring efficient distribution of probing tasks and real-time feedback of results, and supporting the dynamic resource allocation mechanism based on Monte Carlo tree search. Through the collaborative work of Kafka and Redis, the system achieves low-latency, high-throughput communication between the probing server and the central server, providing a data foundation for subsequent topology gain calculation and value forest updates, thereby significantly improving probing efficiency and coverage.
[0099] The IPv6 probe resource allocation optimization method based on Monte Carlo tree search in this invention introduces Kafka message queues and Redis caching mechanisms to achieve efficient real-time communication between the central processing server and multiple probe servers. Combined with a MySQL distributed database for storing and synchronizing probe results, it further improves the system scalability and concurrent processing capability of IPv6 interface-level topology probes, ensuring data consistency and response timeliness under large-scale probe tasks.
[0100] Example 2 The following describes in detail, with reference to the accompanying drawings, an IPv6 interface-level topology detection method based on Monte Carlo tree search according to an embodiment of the present invention.
[0101] This invention proposes an innovative IPv6 topology probing method called TopoHunter. Its core lies in a Monte Carlo tree search-based algorithm that addresses the problems of uneven resource allocation and coarse feedback granularity in existing technologies through a fine-grained dynamic feedback mechanism. This method achieves efficient and wide-coverage probing of IPv6 topologies by establishing a target prefix probing value forest, designing an intelligent target generation algorithm, optimizing the probing tool DY6, and implementing multi-dimensional feedback updates.
[0102] S10, System Overview and Core Innovations: TopoHunter is an IPv6 topology probing system based on a multi-round feedback loop. Its core innovation lies in the introduction of a Target Prefix Probing Value Forest structure, which, based on a Monte Carlo tree search algorithm, enables fine-grained value assessment and dynamic resource allocation of the IPv6 address space. Figure 2 As shown, the system comprises four key modules: Value Forest Building Module: Establishes a multi-level value tree structure with BGP route prefixes as the root node, and stores the probe value estimate of each sub-prefix space (length ≤ 48) (corresponding to the Monte Carlo tree creation process).
[0103] Target generation module: Allocates detection targets based on the probability distribution of value forest, balancing exploration and utilization (corresponding to the selection process of Monte Carlo tree search).
[0104] Optimize the detection module: Use the DY6 tool for intelligent TTL prediction and redundant detection elimination (replacing the simulation process of Monte Carlo tree search with actual detection).
[0105] Feedback update module: Dynamically updates the value forest through topology gain calculation and alias filtering (corresponding to the backpropagation process of Monte Carlo tree search).
[0106] S20. Fine-grained modeling of value forest for target prefix detection: Existing feedback-based target selection methods only use the entire BGP prefix as the feedback unit, failing to capture the non-uniformity of topological distribution within the prefix. To address the challenge posed by topological non-uniformity, this invention designs a core data structure called Target Prefix Probing Value Forest, as follows: Figure 3 As shown, this forest consists of multiple value trees, with the root node of each tree corresponding to a BGP-advertised routing prefix. Nodes in the trees represent sub-prefix spaces of different granularities (prefix lengths increase in 4-bit increments, with leaf nodes having a default maximum length of 52 bits) and store two key attributes: the estimated probing value of the prefix space and the number of times it has been probed. This hierarchical modeling allows the system to learn and memorize the topological potential of different address spaces in a fine-grained manner.
[0107] S30. Target generation algorithm combining exploration and utilization: In the initial probe rounds, we probed the ::1 address under each routing prefix and one address within each / 48 subnet of the hit list. These addresses are called warm-up targets. This is because in the early stages of system startup, due to the lack of historical probe results, it is impossible to effectively estimate the probe value of the target prefix space. At this time, randomly generating target addresses is inefficient, while using addresses from the hit list (confirmed to be active addresses) and ::1 addresses (usually used as the ingress router interface of the routing prefix) is more targeted and can quickly obtain basic topology information. The reason for choosing / 48 is that / 48 is the most common routing prefix length in IPv6, with only a very few prefixes longer than / 48. Therefore, sampling at the / 48 granularity can balance coverage and efficiency.
[0108] Initial probing relying on the hit list may introduce distribution bias (e.g., some areas have dense addresses while others are sparse), but the system minimizes this impact through the following design: 1) Exploration rate mechanism: In subsequent rounds, areas not covered by the hit list are actively probed using a probability formula; 2) Dynamic adjustment of the feedback module: As probing progresses, the feedback module identifies high-value areas based on newly discovered topology gains and prioritizes resource allocation; 3) Integration of multiple data sources: By integrating multiple hit lists (such as publicly available active address datasets), the true distribution of the Internet can be more accurately reflected, reducing the bias from a single source.
[0109] After the initial round, the system generates a fixed number (denoted as N) of probe targets per round based on the target prefix probe value forest. This process consists of two steps: 1) Target allocation: The N targets are allocated according to the prefix hierarchy in the value forest. Some targets are allocated to higher-level prefixes (such as BGP routing prefixes), and then recursively allocated down to sub-prefixes, ensuring that resources are tilted towards high-value areas while also exploring unknown areas; 2) Specific address generation: For each allocated target prefix, active addresses in the hit list under that prefix are selected first; if the hit list is exhausted, random addresses are generated, and only one address is reserved for each / 64 subnet (following IPv6 subnet best practices).
[0110] Figure 4 Algorithm 1 illustrates the core process of target allocation in a value forest. This algorithm employs a top-down recursive allocation strategy, intelligently distributing a fixed number of probe targets to different levels of the value tree. When a node is a leaf node (without children), all targets are directly allocated to that node; for non-leaf nodes, allocation is based on the value assessment of their child nodes, ensuring that resources are tilted towards high-potential areas while maintaining the ability to explore unknown areas.
[0111] The core probability calculation formula in the allocation process is as follows:
[0112] This formula achieves a balance between "utilization" and "exploration" through the exploration rate parameter α: the left-hand side (1-α) × (child node value / total child node value) reflects the "utilization" strategy, allocating more resources to areas with high exploration value; the right-hand side α / total number of child nodes reflects the "exploration" strategy, ensuring that each child node receives a basic exploration opportunity. When α=0, it relies entirely on historical value (pure utilization); when α=1, it allocates resources completely randomly (pure exploration). By adjusting the α value (default 0.01), the system can achieve an optimal balance between discovering high-value areas and exploring new areas.
[0113] The hierarchical structure of the value tree naturally supports a "center-to-periphery" detection strategy. When a parent node is identified as a high-value region, the probability of all its child nodes obtaining the target increases accordingly. This prompts the system to prioritize detecting the address space surrounding high-value regions, which aligns perfectly with the design principles. The recursive allocation process continues until a leaf node (such as a specific / 52 prefix) is reached, at which point the target quantity is fully allocated to that node.
[0114] After allocating the target number, the system generates specific probe addresses for each target prefix: first, active addresses under that prefix are selected from the hit list. Since active addresses are more likely to match routing table entries of the target network, using such addresses helps achieve deep probing of the prefix space. When the hit list addresses are exhausted, random addresses are generated within that prefix range to ensure the integrity of probe coverage. The hit list is preprocessed, reserving only one address per / 64 subnet. This is based on the / 64 minimum subnet length standard recommended by RFC4291, while avoiding redundant probing within the same subnet (because addresses within the same subnet usually correspond to the same topology path).
[0115] S40, Design and implementation of the optimized detection tool DY6: After identifying the detection targets, the TopoHunter system initiates path tracing from the detection server to these targets. However, in large-scale internet topology discovery tasks, the detection efficiency of existing advanced tools is not ideal. Therefore, we optimized the underlying topology discovery tools and launched the DY6 detection tool. DY6 significantly improves detection efficiency by optimizing the TTL selection strategy and making full use of existing detection results.
[0116] DY6 follows the core idea of DoubleTree, determining the split TTL and alternately sending forward and backward probe packets until the corresponding stopping condition is met. However, unlike DoubleTree, DY6 globally randomizes the probe order for all targets while ensuring that individual target probe packets are sent in TTL order. The advantage of this method is that it effectively circumvents the strict ICMP rate limits of IPv6 in large-scale topology probes. The key to this strategy is accurately determining the optimal split TTL for each target and setting reasonable stopping conditions.
[0117] The optimal segmented TTL should be set to the number of hops required to reach the target, as this minimizes the number of probes. DoubleTree selects the same segmented TTL for all targets, which is clearly not optimal because path lengths to different targets can vary significantly. In contrast, DY6 uses historical probe data to predict the optimal segmented TTL for each target, achieving more efficient and accurate probing. Specifically: 1) Preferred strategy: Record the minimum TTL of the BGP route prefix to which the target belongs as the predicted value (applicable in 92.05% of cases). 2) Alternative strategy: For unreachable BGP route prefixes, record the average length of their path trajectory (excluding loops) and round it down as the predicted value (applicable in 7.55% of cases). 3) Fallback strategy: When the above estimates are lacking, select a random value between 6 and 20 based on statistical experience (applicable in 0.40% of cases). In actual probing, the percentages of these three scenarios indicate that DY6 can infer a suitable segmented TTL for the vast majority of target addresses.
[0118] DY6 improves efficiency by using intelligent stop conditions to avoid invalid probes. Forward probe stop conditions: 1) Stop forward probe when a Type 1 (destination unreachable) or 129 (echo reply) response is received. 2) Record the x most recently encountered interface IPs (default x=3) during forward probe for loop detection; stop immediately upon detecting a loop. 3) Stop forward probe when y consecutive anonymous hops (default y=5) are encountered. Backward probe stop conditions: Record interfaces with Type 3 (timeout) responses; stop backward probe when the same interface is encountered.
[0119] S50, Forest update based on target value feedback: The core objective of the feedback process is to provide a more accurate basis for target selection in the next round of exploration by updating the node valuations in the Value Forest, thereby continuously improving the efficiency and coverage of topology discovery. This process includes three key steps: 1) alias prefix filtering; 2) topology gain calculation; and 3) value forest update. Through this closed-loop feedback system, TopoHunter can dynamically adapt to the distribution characteristics of IPv6 topologies, achieving adaptive resource allocation.
[0120] The first step is alias prefix filtering. To avoid resource waste caused by over-probing alias prefixes, this system adopts a strict alias prefix filtering strategy. An alias prefix refers to an address range where network devices will respond to all probe requests for addresses under that prefix. Without filtering, the system will overestimate the topological value of the area due to repeated discovery of the same device, causing the probe direction to get stuck in a local optimum. The specific implementation plan is as follows: 1) We aggregate the publicly available alias prefix list and filter the probe results in real time, merging multiple interfaces under the same alias prefix into a single logical node. 2) All generated target addresses use random suffixes, and when calculating the topology gain, interfaces with the same target address and edges containing the target address are excluded to minimize interference from unknown alias prefixes. 3) If the topology probe of a target with a random suffix receives an EchoReply response, the target is likely in an alias prefix. We ping 16 random addresses under / 64 where it is located. If we can get an Echo Reply response from all of them, it means that / 64 is in an alias prefix. Then we use the same method to gradually increase the size of the prefix to obtain the prefix length of the alias prefix, and add it to the alias prefix list for detection.
[0121] The second step is topology gain calculation. Topology gain quantifies the new topological information brought about by a single detection mission, and its calculation comprehensively considers the quantity and quality of newly discovered interfaces and edges. The specific calculation formula is as follows:
[0122] Here, an edge is defined as a connection between two visible hops in the path trajectory. For edges containing anonymous hops, their contribution decays by 2^n (where n is the number of anonymous hops), because anonymous hops reduce the topological information value of the edge. The interface weight w is used as a hyperparameter (default 10) to reflect the higher value of interface discovery compared to edge discovery. When calculating newly added topological elements, a global comparison is performed with the existing discovery results of all probe servers. This means that when a certain topological information has already been discovered by other probe servers, the repeated discovery by the current probe server will not generate gain, thus effectively avoiding redundant probing among probe servers.
[0123] The third step is value forest update. We update the value forest using each detected target and the topology gain it provides. Figure 5Algorithm 2 illustrates the pseudocode for this process. First, the routing prefix to which the target belongs is located (line 2), and the corresponding value tree is updated (line 3). In the value tree, we start from the root node (line 6) and traverse downwards to find the node corresponding to the sub-prefix containing the target. If the node does not exist, it is created (line 9), and all nodes on the path are updated (line 8). All nodes to be updated correspond to prefixes of different lengths within the target routing prefix. The probe count of each node is incremented by 1 (line 13), and the probe value is first multiplied by a decay factor and then added to the current topology gain (line 15). The node probe value represents the prediction of the future topology gain of that prefix. As the topology becomes more complete, the gains of subsequent probes will decrease. Therefore, during the update, the probe value must first be multiplied by a decay factor. This factor is calculated based on the decay rate β and the prefix length (line 14), where β is a hyperparameter. Longer prefixes correspond to smaller decay factors because we assume that the result of a single probe has a smaller impact on the evaluation of large prefixes.
[0124] S60, Detection System Deployment Method TopoHunter supports single-probe or multi-probe deployment. The probing platform consists of a central processing server and multiple probe servers. The central processing server is responsible for generating the target addresses for each round of probing, saving the probing results, and updating the target prefix probing value forest. We maintain an independent target prefix probing value forest for the probing process of each probe server. The probe servers are responsible for probing and alias prefix detection. The central processing server and probe servers communicate using Kafka and Redis, and they use MySQL to store the probing results.
[0125] Example 3 To achieve the above embodiments, such as Figure 6 As shown, this embodiment also provides an IPv6 interface-level topology detection device 10 based on Monte Carlo tree search. The device 10 includes a value forest construction module 100, a recursive probability allocation module 200, a detection address generation module 300, a detection execution and update module 400, and a communication and storage module 500.
[0126] The value forest building module 100 is used to build a multi-level value tree structure with BGP routing prefixes as the root node, and to store the probe value estimate and probe count of each sub-prefix space. The recursive probability allocation module 200 is used to generate detection targets based on the hierarchical structure of the value forest and the exploration rate parameter, using a top-down recursive probability allocation strategy. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas. The probe address generation module 300 is used to generate specific probe addresses based on the prefix granularity of the probe target, prioritize the selection of active addresses in the hit list, and generate random addresses within the target prefix range when the hit list is exhausted, following the rule of retaining only one address per / 64 subnet. The detection execution and update module 400 is used to execute detection tasks and update the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection. The communication and storage module 500 is used to enable real-time communication between the central processing server and multiple probe servers through Kafka message queues and Redis caches, where probe results are stored and synchronized through a MySQL distributed database.
[0127] Furthermore, the aforementioned value forest building module 100 is also used for: Subprefix levels are established with 4-bit intervals, and leaf nodes use a default prefix length of / 52. Store probe value estimates and probe count attributes for each node, and reduce distribution bias through multi-data source integration.
[0128] Furthermore, the aforementioned recursive probability allocation module 200 is also used for: The exploration rate parameter is set to a value range of 0.001-0.05, with a default value of 0.01. When a parent node is identified as a high-value region, the target assignment probability of all its child nodes is recursively augmented with a weight of 80% of the parent node's value.
[0129] Furthermore, the aforementioned probe address generation module 300 is also used for: Address generation is performed using the / 64 minimum subnetting standard based on RFC4291; A hash algorithm is applied to the randomly generated addresses to ensure uniform address distribution within the subnet.
[0130] Furthermore, the aforementioned detection execution and update module 400 is also used for: The interface weight in the topology gain calculation formula is set to an adjustable range of 10-20; The node valuation is updated using the exponential relationship between the dynamic decay factor β and the prefix length, where the value of β ranges from 0.8 to 0.95.
[0131] This invention discloses an IPv6 interface-level topology detection device based on Monte Carlo tree search. By employing a fine-grained resource allocation strategy based on Monte Carlo tree search, it achieves intelligent detection of high-value areas and basic coverage of low-value areas, effectively solving the problems of uneven resource allocation and excessively coarse feedback granularity in traditional methods.
[0132] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0133] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
Claims
1. A method for IPv6 interface-level topology detection based on Monte Carlo tree search, characterized in that, include: S1, construct the target prefix detection value forest, establish a multi-level value tree structure with the BGP routing prefix as the root node, and store the detection value estimate and detection count of each sub-prefix space; S2, based on the hierarchical structure and exploration rate parameter of the value forest, adopts a top-down recursive probability allocation strategy to generate detection targets. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas. S3 generates specific probe addresses based on the prefix granularity of the probe target, prioritizes active addresses in the hit list, and generates random addresses within the target prefix range when the hit list is exhausted, following the rule of retaining only one address per / 64 subnet. S4 executes the detection task and updates the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection. S5 uses Kafka message queues and Redis caching to enable real-time communication between the central processing server and multiple probe servers, with probe results stored and synchronized through a MySQL distributed database.
2. The method as described in claim 1, characterized in that, S1 includes: S11, establish the sub-prefix hierarchy with 4-bit intervals, where the leaf nodes use a default prefix length of / 52; S12 stores the probe value estimate and probe count attribute for each node and reduces distribution bias through multi-data source integration.
3. The method as described in claim 1, characterized in that, The S2 includes: S21, Set the exploration rate parameter to a range of 0.001-0.05, with a default value of 0.01; S22, when a parent node is identified as a high-value region, the target allocation probability of all its child nodes is recursively enhanced by a weight of 80% of the parent node's value.
4. The method as described in claim 1, characterized in that, The S3 further includes: S31 uses the / 64 minimum subnet partitioning standard based on RFC4291 for address generation; S32 performs a hash algorithm on the randomly generated addresses to ensure uniform address distribution within the subnet.
5. The method as described in claim 1, characterized in that, The S4 includes: S41, the interface weight in the topology gain calculation formula is set to an adjustable range of 10-20; S42 uses the exponential relationship between the dynamic decay factor β and the prefix length to update the node valuation, where the value of β ranges from 0.8 to 0.
95.
6. An IPv6 interface-level topology detection device based on Monte Carlo tree search, characterized in that, include: The value forest building module is used to build a multi-level value tree structure with BGP routing prefixes as the root node, and to store the probe value estimate and probe count of each sub-prefix space; The recursive probability allocation module is used to generate detection targets based on the hierarchical structure of the value forest and the exploration rate parameter, using a top-down recursive probability allocation strategy. The detection probability of each child node is determined by a preset formula, realizing resource allocation to high-value areas and basic detection of unknown areas. The probe address generation module is used to generate specific probe addresses based on the prefix granularity of the probe target. It prioritizes active addresses in the hit list. When the addresses in the hit list are exhausted, it generates random addresses within the target prefix range and follows the rule of retaining only one address per / 64 subnet. The detection execution and update module is used to execute detection tasks and update the value forest. It dynamically adjusts the detection value estimate of each node through alias prefix filtering, topology gain calculation and value decay factor β. The topology gain integrates the number and quality of newly discovered interfaces and edges, and is globally compared with the historical discovery results of the detection server to avoid redundant detection. The communication and storage module is used to enable real-time communication between the central processing server and multiple probe servers through Kafka message queues and Redis caching, while the probe results are stored and synchronized through a MySQL distributed database.
7. The apparatus as claimed in claim 6, characterized in that, The value forest building module is also used for: Subprefix levels are established with 4-bit intervals, and leaf nodes use a default prefix length of / 52. Store probe value estimates and probe count attributes for each node, and reduce distribution bias through multi-data source integration.
8. The apparatus as claimed in claim 6, characterized in that, The recursive probability allocation module is also used for: The exploration rate parameter is set to a value range of 0.001-0.05, with a default value of 0.
01. When a parent node is identified as a high-value region, the target assignment probability of all its child nodes is recursively augmented with a weight of 80% of the parent node's value.
9. The apparatus as claimed in claim 6, characterized in that, The probe address generation module is also used for: Address generation is performed using the / 64 minimum subnetting standard based on RFC4291; A hash algorithm is applied to the randomly generated addresses to ensure uniform address distribution within the subnet.
10. The apparatus as claimed in claim 6, characterized in that, The detection execution and update module is also used for: The interface weight in the topology gain calculation formula is set to an adjustable range of 10-20; The node valuation is updated using the exponential relationship between the dynamic decay factor β and the prefix length, where the value of β ranges from 0.8 to 0.95.