Remote detection method for opening of OSPF (Open Shortest Path First) authentication function

By generating network and OSPF protocol probe packets, analyzing the network performance data sequence of the target routing device, and using statistical methods to determine the OSPF authentication function status, this technology solves the problems of detection permission dependency and configuration effectiveness in existing technologies, and achieves efficient and accurate remote detection.

CN121907601APending Publication Date: 2026-04-21CHINESE PEOPLES LIBERATION ARMY UNIT 96411
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINESE PEOPLES LIBERATION ARMY UNIT 96411
Filing Date
2026-02-13
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In existing technologies, OSPF authentication relies on remotely logging into the routing device to view the configuration, which presents problems such as difficulty in obtaining permissions and complexity in credential management. Furthermore, it cannot ensure that the configuration takes effect, resulting in a decrease in the efficiency and accuracy of network security authentication.

Method used

By acquiring the interface address data of the target routing device, network probe and OSPF protocol probe packets are generated. The network performance data sequence of the target routing device at different stages is analyzed, and statistical methods are used to determine the status of the OSPF authentication function, including packet loss rate differences and significance analysis, to achieve remote detection without login permissions.

Benefits of technology

It achieves highly accurate and automated verification of OSPF authentication, improves the efficiency of network security authentication, and overcomes the difficulties of traditional methods in detecting permission dependencies and configuration effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907601A_ABST
    Figure CN121907601A_ABST
Patent Text Reader

Abstract

The invention relates to an OSPF authentication function starting remote detection method. The method comprises the following steps: acquiring a detection entry parameter of target routing equipment; generating a network detection data packet based on the detection entry parameter, the interface address data and a preset data packet composition rule, and sending the network detection data packet to obtain a first network performance data sequence; generating OSPF protocol detection data based on the detection entry parameter, the interface address data and a preset detection protocol composition rule, and simultaneously sending the OSPF protocol detection data and a network detection data packet; obtaining a second network performance data sequence; after stopping sending the OSPF protocol detection data, sending a network detection data packet to the target routing equipment to obtain a third network performance data sequence; and obtaining an OSPF authentication function state judgment result based on the network detection data packet, the first network performance data sequence, the second network performance data sequence and the third network performance data sequence. By adopting the method, the accuracy of security authentication can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security, and in particular relates to a method for remote detection of OSPF authentication function. Background Technology

[0002] With the development of information security technology, the Open Shortest Path First (OSPF) protocol has emerged as a core interior gateway protocol and is widely deployed. It achieves dynamic routing through link-state broadcasting and neighbor relationship maintenance. OSPF is a widely used IGP routing protocol. When operating, it first establishes neighbor relationships among directly connected routing devices, then synchronizes link-state information to enter the adjacency relationship, and finally calculates routes based on this link-state information. Establishing an adjacency relationship first requires sending an OSPF-type HELLO packet. Only when the relevant parameters are agreed upon can the neighbor relationship be established, information in the link-state database be synchronized, and the adjacency relationship be finalized. To prevent external attackers from sending malicious link-state data, authentication functions are typically configured to prevent malicious routes from entering or network attacks.

[0003] However, current verification methods typically require remotely logging into the router device to check its configuration to verify if authentication is enabled. This approach presents two problems: First, it requires obtaining the router's remote access password. When conducting third-party security assessments, automated inspections, or batch checks on a large number of devices, difficulties in obtaining permissions and complex credential management often arise, hindering the detection process. Second, configuration alone cannot guarantee effectiveness; the configuration may contain errors, such as not being applied to a specified interface or process abnormalities preventing authentication from taking effect—a "silent failure." These issues cannot be detected simply by checking the configuration, creating security blind spots and reducing the efficiency and accuracy of network security authentication. Summary of the Invention

[0004] Therefore, it is necessary to provide a remote detection method for enabling OSPF authentication, which can improve the efficiency and accuracy of network security authentication, to address the aforementioned technical issues.

[0005] Firstly, this application provides a method for enabling remote detection of OSPF authentication functionality, including:

[0006] Obtain the interface address data of the target routing device; and determine the detection input parameters based on the interface address data;

[0007] Based on the detection entry parameters, interface address data, and preset data packet composition rules, network probe data packets are generated and sent to the target routing device in a first preset number, resulting in a first network performance data sequence. The first network performance data sequence is used to characterize the target routing device's response to the network probe data packets.

[0008] Based on the detection entry parameters, interface address data, and preset detection protocol composition rules, OSPF protocol probe data is generated, and OSPF protocol probe data and a second preset number of network probe data packets are sent to the target routing device simultaneously; a second network performance data sequence is obtained; the second network performance data sequence is used to characterize the target routing device's feedback to the network probe data packets when sending OSPF protocol probe data;

[0009] After stopping the transmission of OSPF probe data to the target routing device, a third preset number of network probe data packets are sent to the target routing device to obtain a third network performance data sequence. The third network performance data sequence is used to characterize the target routing device's response to the network probe data packets after the transmission of OSPF probe data is stopped.

[0010] Based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence, the OSPF authentication function status determination result of the target routing device interface is obtained.

[0011] Furthermore, based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence, the OSPF authentication function status determination result of the target routing device interface is obtained, including:

[0012] The number of packet losses in the first network performance data sequence is identified to obtain the first total number of packet losses; the number of packet losses in the second network performance data sequence is identified to obtain the second total number of packet losses; the number of packet losses in the third network performance data sequence is identified to obtain the third total number of packet losses.

[0013] Based on the first preset quantity, the second preset quantity, the third preset quantity, the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses, the differences in feedback from the target routing device before and after receiving OSPF protocol probe data are analyzed to obtain a significance judgment result; the significance judgment result is used to characterize the degree of difference between the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses.

[0014] Based on the saliency judgment result and the preset authentication judgment rule, the OSPF authentication function status judgment result of the target routing device is obtained.

[0015] Furthermore, based on the first preset quantity, the second preset quantity, the third preset quantity, the first total packet loss, the second total packet loss, and the third total packet loss, the differences in feedback from the target routing device before and after receiving OSPF protocol probe data are analyzed to obtain significance judgment results, including:

[0016] Based on the first total number of packet losses, the second total number of packet losses, the first preset quantity, and the second preset quantity, a first test statistic is obtained, wherein the expression of the first test statistic is:

[0017]

[0018] in, It is the first test statistic. This is the second highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the second preset quantity;

[0019] Based on the first total number of packet losses, the third total number of packet losses, the first preset quantity, and the third preset quantity, a second test statistic is obtained, wherein the expression for the second test statistic is:

[0020]

[0021] in, It is the second test statistic. This is the third highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the third preset quantity;

[0022] The first test statistic is compared with a preset first significance threshold to obtain a first comparison result, and the second test statistic is compared with a preset second significance threshold to obtain a second comparison result;

[0023] Based on the first comparison result and the second comparison result, the significance judgment result is obtained.

[0024] Furthermore, based on the first preset quantity, the second preset quantity, the third preset quantity, the first total packet loss, the second total packet loss, and the third total packet loss, the differences in feedback from the target routing device before and after receiving OSPF protocol probe data are analyzed to obtain significance judgment results, which also include:

[0025] Based on the total number of packet losses in the first, second, and third phases, the total number of packet losses is calculated. The expression for the total number of packet losses is:

[0026]

[0027] in, That is the total number of packets lost. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets;

[0028] Based on the first preset quantity, the second preset quantity, and the third preset quantity, the total number of detection packets is calculated. The expression for the total number of detection packets is:

[0029]

[0030] in, It is the total number of probe packets. It is the first preset quantity. It is the second preset quantity. It is the third preset quantity;

[0031] Based on the first preset quantity, the total number of probe packets, and the total number of lost packets, the first expected number of packet loss is calculated; based on the second preset quantity, the total number of probe packets, and the total number of lost packets, the second expected number of packet loss is calculated; based on the third preset quantity, the total number of probe packets, and the total number of lost packets, the third expected number of packet loss is calculated.

[0032] Based on the expected number of packet losses (first, second, and third), the first preset number, the second preset number, and the third preset number, the chi-square statistic for packet loss is calculated. The expression for the chi-square statistic for packet loss is:

[0033]

[0034] in, This is the packet loss statistics. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets. This is the expected number of packets lost in the first round. This is the second expected number of packet losses. This is the third expected number of packet losses;

[0035] The packet loss chi-square statistic is compared with the preset chi-square threshold to obtain a third comparison result; and the significance judgment result is obtained based on the third comparison result.

[0036] Furthermore, the method also includes:

[0037] Calculate the ratio of the second total number of packet losses to the first total number of packet losses to obtain the first packet loss increase rate; calculate the ratio of the third total number of packet losses to the second total number of packet losses to obtain the second packet loss increase rate.

[0038] Based on the preset first packet loss change probability distribution function, the probability that the first packet loss increase rate reflects the OSPF authentication function being enabled is calculated, thus obtaining the first enabled conditional probability; the probability that the first packet loss increase rate reflects the OSPF authentication function being disabled is calculated, thus obtaining the first disabled conditional probability.

[0039] Based on the preset second packet loss change probability distribution function, the probability that the second packet loss increase rate reflects the OSPF authentication function being enabled is calculated, thus obtaining the second enabled conditional probability; the probability that the second packet loss increase rate reflects the OSPF authentication function being disabled is calculated, thus obtaining the second disabled conditional probability.

[0040] Based on the preset prior probability of OSPF authentication function being enabled, the preset prior probability of OSPF authentication function being disabled, the first enable condition probability, the first disable condition probability, the second enable condition probability, and the second disable condition probability, the posterior probability of OSPF authentication function being enabled is calculated, and the posterior probability is determined as the reliability probability of the OSPF authentication function status determination result.

[0041] Secondly, this application also provides a remote detection device with OSPF authentication enabled, comprising:

[0042] The input parameter confirmation module is used to obtain the interface address data of the target routing device and determine the detection input parameters based on the interface address data.

[0043] The first data generation module is used to generate network probe data packets based on the detection entry parameters, interface address data, and preset data packet composition rules, and send a first preset number of network probe data packets to the target routing device to obtain a first network performance data sequence; the first network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets;

[0044] The second data generation module is used to generate OSPF protocol probe data based on the detection entry parameters, interface address data, and preset detection protocol composition rules, and simultaneously send the OSPF protocol probe data and a second preset number of network probe data packets to the target routing device; to obtain a second network performance data sequence; the second network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets when sending OSPF protocol probe data;

[0045] The third data generation module is used to send a third preset number of network probe data packets to the target routing device after stopping the transmission of OSPF protocol probe data to the target routing device, thereby obtaining a third network performance data sequence. The third network performance data sequence is used to characterize the target routing device's feedback to the network probe data packets after stopping the transmission of OSPF protocol probe data.

[0046] The verification result determination module is used to obtain the OSPF authentication function status determination result of the target routing device interface based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence.

[0047] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement any of the OSPF authentication function enabling remote detection methods described in the first aspect of this application.

[0048] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements any of the OSPF authentication function enabling remote detection methods described in the first aspect of this application.

[0049] The aforementioned method for enabling remote detection of OSPF authentication involves: acquiring the interface address data of the target routing device; determining detection entry parameters based on the interface address data; generating network probe packets based on the detection entry parameters, interface address data, and preset packet composition rules; and sending a first preset number of network probe packets to the target routing device to obtain a first network performance data sequence. This first network performance data sequence characterizes the target routing device's response to the network probe packets. Furthermore, based on the detection entry parameters, interface address data, and preset detection protocol composition rules, OSPF protocol probe data is generated, and simultaneously, OSPF protocol probe data and a second preset number of network probe packets are sent to the target routing device. The system generates a second network performance data sequence. This sequence characterizes the target routing device's response to network probe packets when OSPF probe data is sent. After stopping the transmission of OSPF probe data to the target routing device, a third preset number of network probe packets are sent to the target routing device, resulting in a third network performance data sequence. This sequence characterizes the target routing device's response to network probe packets after the transmission of OSPF probe data is stopped. Based on the first, second, and third preset numbers, the first, second, and third network performance data sequences, the OSPF authentication function status determination result of the target routing device's interface is obtained. This system transforms the configuration check problem of "whether the protocol authentication is effective" into an observable and quantifiable scientific detection problem of "whether network behavior responds as expected to specific stimuli." Without relying on any management permissions or login credentials of the target device, it achieves remote, automated, and highly accurate verification of the actual operating status of the OSPF authentication function. This effectively overcomes the inherent defects of traditional CLI viewing methods, such as permission dependence and the inability to verify the effectiveness of functions, thus improving the efficiency and accuracy of network security authentication. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0051] Figure 1 A flowchart illustrating a method for enabling remote detection of OSPF authentication functionality according to an embodiment of this application;

[0052] Figure 2 A flowchart illustrating a method for enabling remote detection of OSPF authentication functionality according to an embodiment of this application;

[0053] Figure 3 This is a schematic diagram of a remote detection device for enabling OSPF authentication functionality, provided as an embodiment of this application. Detailed Implementation

[0054] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0055] In one embodiment, such as Figure 1 As shown, a method for enabling remote detection with OSPF authentication is provided. This embodiment illustrates the method applied to a detection terminal. It is understood that this method can also be applied to a server, and to a system including both a detection terminal and a server, and is implemented through interaction between the detection terminal and the server. In this embodiment, the method includes the following steps S101-S105, wherein:

[0056] S101, obtain the interface address data of the target routing device; and determine the detection entry parameters based on the interface address data.

[0057] Specifically, the detection terminal acquires the interface address data of the target routing device. Interface address data is information used to uniquely identify a specific interface of the routing device to be detected in the network; its mathematical form can be expressed as... This is typically a 32-bit IPv4 address (e.g., 192.168.1.1). This data comes from the detection task list and is the initial input for this detection. The detection terminal determines the detection entry parameters based on the interface address data. The detection entry parameters are a set of data used to define the origin of all active probe traffic in this detection, including at least the source IP address. Source network interface identifier Specifically, this includes: the detection terminal detecting multiple pre-set, confirmed secure candidate detection sources (such as monitoring hosts in different subnets) to... Send path probe packets (such as ICMPTraceroute messages) with increasing Time-to-Live (TTL) values, collect responses from each path, and analyze the IP addresses of the routing nodes in the responses. Determine the network affiliation (e.g., whether they are on the same IP subnet or within an autonomous system). Then select the network that is closest in network topology. And the routing node address that is most likely to be in the same OSPF broadcast domain as the target interface is used as... and its corresponding physical or logical interface as Together, they constitute the detection input parameters.

[0058] S102, based on the detection entry parameters, interface address data and preset data packet composition rules, generate network probe data packets and send a first preset number of network probe data packets to the target routing device to obtain a first network performance data sequence; the first network performance data sequence is used to characterize the target routing device's feedback to the network probe data packets.

[0059] Specifically, the preset packet composition rules define a standard probe packet format for testing network connectivity and performance, specifying the generation of IP packets with Internet Control Message Protocol (ICMP) Echo Request messages as payloads. The packet composition consists of two parts: an IP datagram header and an ICMP payload. The IP header includes, but is not limited to, version (IPv4), header length, type of service, total length, identifier, flags and fragment offset, time to live (TTL), protocol (value 1 here represents ICMP), header checksum, source IP address field, and destination IP address field. The ICMP payload includes, but is not limited to, ICMP type (value 8 represents Echo Request), code (value 0), checksum, identifier, sequence number, and optional data payload. The preset packet composition rules can be selected and set according to the actual Internet Protocol (IP) packet construction specifications used in practice. The detection terminal generates network probe packets according to the preset packet composition rules, where the source IP address field is determined based on the parameters in the detection input parameters. The destination IP address field is filled in based on the interface address data. Padding. The generated network probe packets can be denoted as... The detection terminal continuously sends a first preset number of network probe packets to the target routing device at preset sending intervals (e.g., every 100 milliseconds). Simultaneously, the detection terminal listens for and records ICMP echo reply messages from the target routing device. For each sent network probe packet, the receiving timestamp corresponding to its sending timestamp is recorded, resulting in a first network performance data sequence. This first network performance data sequence can be denoted as... The sequence is an ordered set, and its mathematical form can be... , This is the first preset quantity, and each data unit can be represented as... , It is the first The packet loss identifier for the first data unit, if the detection terminal receives a packet loss identifier from the target routing device for the first data unit. The response to a network probe packet. Other situations . It is the first The round-trip delay of the first data unit is achieved through the first... The network probe data packet is obtained by subtracting the corresponding sending timestamp from the received timestamp. hour It is infinite. The first preset quantity can be set according to the actual work situation.

[0060] S103, based on the detection entry parameters, interface address data, and preset detection protocol composition rules, generates OSPF protocol probe data, and simultaneously sends OSPF protocol probe data and a second preset number of network probe data packets to the target routing device; obtains a second network performance data sequence; the second network performance data sequence is used to characterize the target routing device's feedback to the network probe data packets when sending OSPF protocol probe data.

[0061] Specifically, the preset detection protocol composition rules are a complete specification defining the OSPFv2 Hello packet structure and padding requirements. The preset rules predefine the fixed portion of the packet and the padding logic for variable parameters: the fixed portion includes OSPF (IP protocol number 89), OSPF packet type Hello (type 1), an authentication type (AuType) field fixed at 0 (indicating null authentication), and an authentication data field fixedly padded with all zero bytes; the variable parameter padding logic stipulates that the source IP address should be set to a pseudo-IP address generated based on the target network information, the destination IP address should be set to the OSPF AllSPFRouters multicast address 224.0.0.5, and the packet body must contain placeholders for configurable fields such as network mask, Hello interval, and router priority. The preset detection protocol composition rules can be configured according to the specific detection technology characteristics of the target routing device in actual operation after the OSPF protocol standard is implemented. The Internet Protocol (IP) packet construction specifications can also be selected and configured. The detection terminal infers the subnet to which the target router belongs based on the interface address data, and calculates an unused address within that subnet (e.g., the last available host address in the subnet where the target router is located) as the pseudo source IP address according to the "pseudo IP address generation logic" in the preset detection protocol composition rules. It then strictly follows the rules to create an OSPF packet: filling the source address field in the IP header with this pseudo source IP address and the destination address field with 224.0.0.5; in the OSPF packet header, setting the AuType field to 0 as defined in the rule and filling the authentication data field with all zeros; and in the Hello packet body, according to... The corresponding subnet mask and default values ​​defined in the rules (such as a 10-second Hello interval) are used to fill in other necessary fields. This generates OSPF protocol probe data, denoted as... After generating OSPF probe data, the detection terminal initiates a concurrent transmission process: Firstly, it continuously sends OSPF probe data to 224.0.0.5 at the same preset transmission interval as in S102 (e.g., every 100 milliseconds). Secondly, the OSPF probe data is sent synchronously to the target routing device at the same interval and format as in S102, with a second preset number of network probe packets. The transmission and reception of all network probe packets are also recorded to obtain a second network performance data sequence, which can be denoted as... .in This is the second preset quantity. Each data unit in the sequence can be represented as... . It is the first The packet loss identifier for the first data unit has the same judgment rule as in S102: if the detection terminal receives a packet loss identifier from the target routing device for the first data unit... The response to a network probe packet, then ;otherwise . It is the first The round-trip delay of the data unit, which is achieved through the first... The timestamp of a network probe data packet is subtracted from its corresponding sending timestamp to calculate the timestamp; when hour, This is recorded as an invalid value or infinity. This sequence reflects the change in the target device's forwarding performance under continuous "interference" from OSPF probe data. The second preset number can be set according to actual operating conditions, and its value can also be the same as the first preset number.

[0062] S104, after stopping sending OSPF protocol probe data to the target routing device, send a third preset number of network probe data packets to the target routing device to obtain a third network performance data sequence; the third network performance data sequence is used to characterize the target routing device's feedback to the network probe data packets after stopping sending OSPF protocol probe data.

[0063] Specifically, after sending the second preset number of network probe data packets and OSPF protocol probe data, the detection terminal sends a third preset number of network probe data packets to the target routing device at the same interval and in the same format as in S102. It also records the sending and receiving of all network probe data packets to obtain a third network performance data sequence, which can be denoted as... .in This is the third preset quantity. Each data unit in the sequence can be represented as... . It is the first The packet loss identifier for the first data unit has the same judgment rule as in S102: if the detection terminal receives a packet loss identifier from the target routing device for the first data unit... The response to a network probe packet, then ;otherwise . It is the first The round-trip delay of the data unit, which is achieved through the first... The timestamp of a network probe data packet is subtracted from its corresponding sending timestamp to calculate the timestamp; when hour, This is recorded as an invalid value or infinity. This sequence is used to evaluate whether the network performance of the target device recovers to the baseline level after the external OSPF protocol stimulus is removed, thereby confirming whether any performance changes observed in S103 are causally related to the transmission of OSPF protocol probe data. The third preset number can be set according to actual work requirements; its number can be the same as the first preset number or the second preset number.

[0064] S105, based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence, obtain the OSPF authentication function status determination result of the target routing device interface.

[0065] Specifically, the detection terminal infers how the target device's OSPF protocol stack processes OSPF probe data by comparing the differences in network behavior reflected in the first, second, and third network performance data sequences, thereby determining the true state of its authentication function. The final OSPF authentication function status determination result characterizes whether authentication is enabled or disabled. This OSPF authentication function status determination result serves as a remote, non-intrusive verification of the effectiveness of the target routing device's security configuration.

[0066] This embodiment provides a remote detection method for enabling OSPF authentication. By using the interface address data of the target routing device, it accurately locates the detection entry point and establishes a network performance baseline, obtaining the detection entry point parameters. It then proactively injects a cleverly constructed, invalidally authenticated OSPF protocol probe packet as an external stimulus. Simultaneously, it closely monitors the forwarding performance changes of the target device towards standard probe traffic in three periods: before, during, and after the stimulus, obtaining a first, second, and third network performance data sequence, respectively. Furthermore, by analyzing the difference patterns in the performance data across these three periods, it infers the internal protocol processing logic of the target device to obtain the OSPF authentication function status determination result. This transforms the configuration check problem of "whether protocol authentication is effective" into an observable and quantifiable scientific detection problem of "whether network behavior responds as expected to a specific stimulus." Without relying on any management permissions or login credentials of the target device, it achieves remote, automated, and highly accurate verification of the actual operating status of the OSPF authentication function. This effectively overcomes the inherent defects of traditional CLI viewing methods, such as permission dependence and the inability to verify function effectiveness, thus improving the efficiency and accuracy of network security authentication.

[0067] In one embodiment, based on a first preset quantity, a second preset quantity, a third preset quantity, a first network performance data sequence, a second network performance data sequence, and a third network performance data sequence, the OSPF authentication function status determination result of the target routing device interface is obtained, including:

[0068] S201, identify the number of packet losses in the first network performance data sequence to obtain the first total number of packet losses; identify the number of packet losses in the second network performance data sequence to obtain the second total number of packet losses; identify the number of packet losses in the third network performance data sequence to obtain the third total number of packet losses.

[0069] Specifically, for the first network performance data sequence, the detection terminal traverses the packet loss identifiers of all data units within it. Statistics of The number of packets lost is the total number of packets lost in the first round, denoted as . Similarly, the detection terminal iterates through all data units in the second network performance data sequence to find the packet loss identifier. Statistics The number of packets lost is used to obtain the second total number of packet losses, denoted as . The detection terminal iterates through all data units in the third network performance data sequence to identify packet loss identifiers. Statistics The number of packets lost is used to obtain the total number of packets lost in the third round, denoted as . .

[0070] S202, based on the first preset quantity, the second preset quantity, the third preset quantity, the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses, analyze the differences in feedback from the target routing device before and after receiving OSPF protocol probe data, and obtain the significance judgment result; the significance judgment result is used to characterize the degree of difference between the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses.

[0071] Specifically, the detection terminal analyzes whether the increase in the total number of second packet losses relative to the total number of first packet losses is statistically significant, and whether the total number of third packet losses recovers relative to the total number of first packet losses, based on the first preset quantity, the second preset quantity, the third preset quantity, the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses. The conclusions obtained are recorded as the significance judgment results. The significance judgment result is a logical value, which can be 0, indicating that there is a significant perturbation in the total number of first, second, and third packet losses; or 1, indicating that there is no significant difference in the total number of first, second, and third packet losses.

[0072] S203, based on the saliency judgment result and the preset authentication judgment rule, obtain the OSPF authentication function status judgment result of the target routing device.

[0073] Specifically, the preset authentication determination rule is a simple logical mapping table. Its basis is as follows: if OSPF authentication is enabled, invalid OSPF probe data will be silently discarded, without affecting the forwarding plane; therefore, the packet loss rate should not differ significantly across the three phases. If OSPF authentication is disabled, OSPF probe data will be processed by the protocol stack, potentially causing brief fluctuations and a significant increase in packet loss rate during the stimulus period, while the packet loss rate returns to the baseline level during the recovery period. Therefore, the preset authentication determination rule can be defined as follows: if the significance judgment result is 1, the OSPF authentication function status determination result is "OSPF authentication function disabled"; if the significance judgment result is 0, the OSPF authentication function status determination result is "OSPF authentication function enabled". The detection terminal queries the preset authentication determination rule based on the obtained significance judgment result to obtain the OSPF authentication function status determination result of the target routing device.

[0074] This embodiment provides a remote detection method for enabling OSPF authentication. By compressing massive amounts of network performance data collected in three detection phases, it obtains the first, second, and third total packet loss counts. Then, it uses statistical hypothesis testing theory to conduct a rigorous significance analysis of the differences between these three indicators, obtaining a significance judgment result. The analysis conclusion is then mapped to a definite state of the authentication function according to explicit logical rules, resulting in the OSPF authentication function status determination result of the target routing device. This transforms the vague concept of "network behavior change" into the calculable and determinate scientific problem of "statistical significance of packet loss rate differences," freeing the entire judgment process from subjective experience and ensuring objectivity, repeatability, and high reliability, thus guaranteeing the accuracy and persuasiveness of the detection conclusions.

[0075] In one embodiment, based on a first preset quantity, a second preset quantity, a third preset quantity, a first total packet loss, a second total packet loss, and a third total packet loss, the differences in feedback from the target routing device before and after receiving OSPF protocol probe data are analyzed to obtain a significance judgment result, including:

[0076] S301, based on the first total number of packet losses, the second total number of packet losses, the first preset quantity, and the second preset quantity, a first test statistic is obtained, wherein the expression of the first test statistic is:

[0077]

[0078] in, It is the first test statistic. This is the second highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the second preset quantity.

[0079] Specifically, the detection terminal calculates the first test statistic using a formula based on the first total number of lost packets, the second total number of lost packets, the first preset quantity, and the second preset quantity. The packet loss rate of the second network performance data sequence can be denoted as: , It is the packet loss rate of the first network performance data sequence, which can be denoted as: Test statistic The molecule represents the difference in packet loss rates between the two sequences, directly reflecting the direction and magnitude of the change in packet loss rate. This is the merging ratio, representing the best estimate of the common packet loss rate assuming the packet loss rates in both stages are the same. In the formula... It is their complementarity probability. Calculate the first test statistic. The larger the calculated value, the less likely the difference between the packet loss rate of the second network performance data sequence and the packet loss rate of the first network performance data sequence is due to accidental factors. (Second total packet loss) and the first total number of packet losses This can be obtained from S201. First preset quantity. The second preset quantity can be obtained from S102. It can be obtained from S103.

[0080] S302, based on the first total number of packet losses, the third total number of packet losses, the first preset quantity, and the third preset quantity, a second test statistic is obtained, wherein the expression of the second test statistic is:

[0081]

[0082] in, It is the second test statistic. This is the third highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the third preset quantity.

[0083] Specifically, the detection terminal calculates the second test statistic using a formula based on the first total number of lost packets, the third total number of lost packets, the first preset quantity, and the third preset quantity. The packet loss rate of the third network performance data sequence can be denoted as: , This is the packet loss rate of the first network performance data sequence. Its principle is the same as S301, but the testing objective is different; a second test statistic is designed. The molecules are The second test statistic focuses solely on whether the packet loss rate of the third network performance data sequence is the same as that of the first network performance data sequence, regardless of the direction of change. The smaller the value, the closer the packet loss rate of the third network performance data sequence is to the packet loss rate of the first network performance data sequence, and the more it supports the "recovered" hypothesis.

[0084] S303, compare the first test statistic with the preset first significance threshold to obtain the first comparison result, and compare the second test statistic with the preset second significance threshold to obtain the second comparison result.

[0085] Specifically, the preset first significance threshold is used to determine Compared to Whether the increase is statistically significant can be denoted as: The preset second significance threshold is used to determine... and Whether the difference between them is not significant can be denoted as The preset first significance threshold and the preset second significance threshold can be key values ​​obtained from the standard normal distribution table based on the desired confidence level (e.g., 95%). For example, for a one-sided test (test... ),exist At horizontal level, For two-sided tests (tests) At the same level, The detection terminal compares the first test statistic with a preset first significance threshold to obtain the first comparison result, which can be denoted as... The second test statistic is compared with the preset second significance threshold to obtain the second comparison result, which can be denoted as... The first comparison result and the second comparison result can both be a binary value; when hour, 0 (i.e., packet loss increases significantly during the stimulus period), other cases =1; when hour, A value of 0 (i.e., no significant difference in packet loss during the recovery period compared to baseline) indicates a different situation. =1;

[0086] S304. Based on the first comparison result and the second comparison result, the significance judgment result is obtained.

[0087] Specifically, the detection terminal performs an OR operation on the first comparison result and the second comparison result to obtain a significance judgment result. When the significance judgment result is 0, it indicates that there is a significant perturbation in the total number of first, second, and third packet losses; when the value is 1, it indicates that there is no significant difference in the total number of first, second, and third packet losses.

[0088] This embodiment provides a remote detection method for enabling OSPF authentication. By constructing and calculating two proportional Z-test statistics, it quantifies the increase in packet loss rate during the stimulus period relative to the baseline period, and the deviation of the packet loss rate during the recovery period relative to the baseline period, respectively. This yields a first test statistic and a second test statistic. A preset statistical threshold is then used to objectively determine the significance of these two quantitative indicators. This transforms the abstract concept of "difference analysis" into precise mathematical calculations and logical comparisons, providing a stable and reproducible means of determining significance and offering a strong statistical evidence chain for determining whether OSPF authentication is enabled.

[0089] In one embodiment, based on a first preset quantity, a second preset quantity, a third preset quantity, a first total packet loss, a second total packet loss, and a third total packet loss, the differences in feedback from the target routing device before and after receiving OSPF protocol probe data are analyzed to obtain a significance judgment result, and the method further includes:

[0090] S401, based on the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses, the total number of packet losses is calculated. The expression for the total number of packet losses is:

[0091]

[0092] in, That is the total number of packets lost. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets.

[0093] Specifically, the detection terminal adds the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses to obtain the total number of packet losses for the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence. Total Packet Losses This represents the total number of observed "failure" events. (First total number of packet losses) Second total number of packets lost and the third total number of packet losses It can be obtained from S201.

[0094] S402, based on the first preset quantity, the second preset quantity, and the third preset quantity, the total number of detection packets is calculated. The expression for the total number of detection packets is:

[0095]

[0096] in, It is the total number of probe packets. It is the first preset quantity. It is the second preset quantity. It is the third preset quantity.

[0097] Specifically, the detection terminal calculates the total number of network probe data packets sent during the three transmission processes using the first preset number, the second preset number, and the third preset number. Total number of probes. This represents the total number of trials. First preset number. This can be obtained from S102. Second preset quantity. This can be obtained from S103. The third preset quantity. It can be obtained from S104.

[0098] S403, based on the first preset quantity, the total number of probe packets, and the total number of lost packets, calculate the first expected number of packet losses; based on the second preset quantity, the total number of probe packets, and the total number of lost packets, calculate the second expected number of packet losses; based on the third preset quantity, the total number of probe packets, and the total number of lost packets, calculate the third expected number of packet losses.

[0099] Specifically, the detection terminal assumes a null hypothesis (i.e., the packet loss rate is the same in all three stages, which is the overall packet loss rate). Under the condition that the network performance data sequence is true, calculate the expected packet loss number when receiving the first network performance data sequence, sending the second network performance data sequence to the expected packet loss number, and sending the third network performance data sequence to the expected packet loss number, respectively. The specific calculation formula is as follows: ; ; .in, This is the expected number of packets lost in the first round. This is the second expected number of packet losses. This is the third expected packet loss number. It is the first preset quantity. It is the second preset quantity. It is the third preset quantity.

[0100] S404, based on the expected number of packet losses (first, second, and third), the first preset number, the second preset number, and the third preset number, the chi-square statistic of packet loss is calculated. The expression for the chi-square statistic of packet loss is:

[0101]

[0102] in, This is the packet loss statistics. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets. This is the expected number of packets lost in the first round. This is the second expected number of packet losses. This is the third expected number of packet losses.

[0103] Specifically, the detection terminal calculates the packet loss chi-square statistic using a formula based on the expected number of packet losses in the first, second, and third stages, as well as the first, second, and third preset quantities. A larger value for the packet loss chi-square statistic indicates a greater deviation of the observed data from the null hypothesis that "the packet loss rate is the same at each stage," meaning a greater difference between the three packet loss rates. The first total number of packet losses... Second total number of packets lost and the third total number of packet losses This can be obtained from S201. The expected number of packets lost in the first instance. Expected number of second packet loss And the third expected number of packet loss It can be obtained from S403.

[0104] S405, compare the packet loss chi-square statistic with the preset chi-square critical value to obtain the third comparison result; and obtain the significance judgment result based on the third comparison result.

[0105] Specifically, the preset chi-square critical value is used to determine whether the overall deviation between the observed frequency and the expected frequency is statistically significant, and can be denoted as: . It can be based on the selected significance level. (e.g., 0.05) and degrees of freedom The values ​​were obtained from the chi-square distribution table. In this test, the degrees of freedom... The detection terminal compares the packet loss chi-square statistic with a preset chi-square threshold to obtain a third comparison result, which can be denoted as... The third comparison result can be a binary value, when... hour, The value is 0 for all cases and 1 for all others. The detection terminal uses the third comparison result as the significance judgment result.

[0106] This embodiment provides a remote detection method for OSPF authentication activation. Through a chi-square goodness-of-fit test, it comprehensively evaluates whether the observed packet loss distribution across the three detection stages matches the expected distribution of a "uniform distribution" (i.e., the same packet loss rate), obtaining a significance judgment result. This method does not pre-assume the direction of change (e.g., which stage has a higher rate), but rather keenly captures any form of distributional non-uniformity. When the chi-square test shows no significant difference, it strongly supports the conclusion that "network behavior remains stable before and after protocol stimulation," thus providing a concise yet rigorous statistical judgment framework for determining whether OSPF authentication is enabled. This complements the Z-test path in Embodiment 3, enhancing the robustness and applicability of this method.

[0107] In one embodiment, the method further includes:

[0108] S501, calculate the ratio of the second total number of packet losses to the first total number of packet losses to obtain the first packet loss increase rate; calculate the ratio of the third total number of packet losses to the second total number of packet losses to obtain the second packet loss increase rate.

[0109] Specifically, the detection terminal calculates the ratio of the second total number of lost packets to the first total number of lost packets to obtain the first packet loss increase rate, which can be denoted as: The ratio of the total number of third packet losses to the total number of second packet losses is calculated to obtain the second packet loss increase rate, which can be denoted as... .

[0110] S502, based on the preset first packet loss change probability distribution function, calculate the probability that the first packet loss increase rate reflects the OSPF authentication function being enabled, and obtain the first enabled conditional probability; calculate the probability that the first packet loss increase rate reflects the OSPF authentication function being disabled, and obtain the first disabled conditional probability.

[0111] Specifically, the preset probability distribution function for the first packet loss change is obtained in advance through analysis of historical experimental data, including the first packet loss increase rate. The probability distributions for OSPF authentication status results of "OSPF authentication enabled" and "OSPF authentication disabled" are denoted as follows: and The preset probability distribution function for the first packet loss change can be obtained statistically from the distribution of the first packet loss increase rate under various states in actual operation. For example, It is a log-normal distribution with a mean of 1 and a very small variance, because theoretically there should be no increase; It is a distribution with a mean greater than 1 and a large variance. The detection terminal uses the current first packet loss increase rate. The specific value is retrieved from the preset first packet loss change probability distribution function. The probability distribution is calculated under the two preset assumptions of "authentication enabled" and "authentication disabled". The conditional probability of the value yields the first open conditional probability and the first close conditional probability. The first open conditional probability can be denoted as... The probability of the first closing condition can be denoted as: .

[0112] S503, based on the preset second packet loss change probability distribution function, calculate the probability that the second packet loss increase rate reflects the OSPF authentication function being enabled, and obtain the second enabled condition probability; calculate the probability that the second packet loss increase rate reflects the OSPF authentication function being disabled, and obtain the second disabled condition probability.

[0113] Specifically, the preset second packet loss change probability distribution function was obtained in advance through analysis of historical experimental data, including the second packet loss increase rate. The probability distributions for OSPF authentication status results of "OSPF authentication enabled" and "OSPF authentication disabled" are denoted as follows: and The preset probability distribution function for the second packet loss variation can be obtained statistically from the distribution of the second packet loss increase rate under various states in actual operation. For example... It is a distribution with a mean less than 1, indicating a decline; It fluctuates around 1. The detection terminal adjusts the rate based on the current first packet loss increase rate. The specific value is retrieved from the preset second packet loss change probability distribution function. The probability distribution is calculated under the two preset assumptions of "authentication enabled" and "authentication disabled". The conditional probability of the value yields the second opening conditional probability and the second closing conditional probability. The second opening conditional probability can be denoted as... The probability of the second closing condition can be denoted as: .

[0114] S504, based on the preset prior probability of OSPF authentication function being enabled, the preset prior probability of OSPF authentication function being disabled, the first enable condition probability, the first disable condition probability, the second enable condition probability and the second disable condition probability, calculate the posterior probability of OSPF authentication function being enabled, and determine the posterior probability as the reliability probability of the OSPF authentication function status determination result.

[0115] Specifically, the preset prior probability of OSPF authentication being enabled. and prior probability of the closed state It is an initial belief based on prior knowledge. and It is a scalar between 0 and 1, and satisfies For example, set it to [condition] when there is no information. The preset prior probabilities for OSPF authentication being enabled and disabled can be set based on prior knowledge gained in practical work. For example, if the target network generally requires OSPF authentication, then the following settings can be configured: A higher value (e.g., 0.8); if there is a complete lack of prior information, then no-information priors can be used, i.e., set to... The detection terminal assumes that the four conditional probabilities calculated by S502 and S503 are combined with the preset prior probabilities of the OSPF authentication function being enabled and disabled, and Bayes' theorem is applied for probability updates. It is assumed that under a given authentication state... and If the observations are independent, then the joint likelihood is the product of their respective conditional probabilities. The formula for calculating the posterior probability of the authentication-enabled state is as follows: The numerator is the product of the prior probability of the open hypothesis and its joint likelihood, and the denominator is the sum of this product under all possible hypotheses (i.e., the marginal probability of evidence). The calculated... This is the posterior probability of the OSPF authentication function being enabled; it is a value between 0 and 1, reflecting the overall packet loss pattern observed so far. Then, the updated probability that the authentication function has actually been enabled is used. The detection terminal uses this posterior probability as the confidence probability of the "OSPF authentication function status determination result" obtained in S203. For example, if the OSPF authentication function status determination result is "OSPF authentication function is enabled" and the posterior probability is 0.92, it means that this determination has a 92% confidence level.

[0116] This embodiment provides a remote detection method for enabling OSPF authentication. Building upon deterministic judgments obtained through statistical hypothesis testing based on the frequentist approach, it further introduces a Bayesian inference framework. This framework quantifies observed packet loss patterns into continuous evidence variables and utilizes likelihood distribution parameters learned from historical data to calculate a posterior belief about the authentication status, expressed in probabilistic form. The core value of this method lies in adding a continuous confidence metric to the binary "yes / no" judgment, enabling a more nuanced expression of the degree of certainty in the detection conclusion. In boundary situations or when background noise exists in the network, this confidence probability can provide administrators with more valuable decision-making reference information than a simple "pass / fail" answer, enhancing the practicality and guiding significance of the detection method in complex real-world network environments.

[0117] To further illustrate the solution of the application embodiment in this embodiment, a specific example is provided below:

[0118] This application provides a method for enabling remote detection of OSPF authentication functionality, referring to... Figure 2 This includes the following steps:

[0119] S01, Parameter preparation stage.

[0120] Specifically, this includes: 1. Identifying the target routing devices, connection ports, and links that need to be detected;

[0121] 2. Collect the OSPF HELLO packet templates for the target routing device;

[0122] 3. Use a route tracing tool to detect the route to the target routing device in order to select and determine a suitable detection entry point;

[0123] 4. Using an IP packet generation tool, modify some specific fields in the HELLO template packet collected in step 2 according to the detection environment.

[0124] S02, Testing Phase.

[0125] Specifically, this includes: 1. Starting with the ping tool, continuously perform connectivity tests on the router under test through the entry point selected in step 3, and collect the relevant test results as dataset 1;

[0126] 2. At the entry point selected in step 3, use the IP packet sending tool to send the modified HELLO packet from step 4 to the determined target routing device;

[0127] 3. While sending packets in step 6, the ping tool is used to continuously perform connectivity tests on the router under test through the entry point selected in step 3, and the relevant test results are collected as dataset 2.

[0128] 4. Stop sending ping packets in step 6;

[0129] 5. Repeat step 5 and collect the relevant test results as dataset 3.

[0130] S03, Judgment Phase.

[0131] Specifically, this includes: 1. If there is no packet loss in dataset 1, packet loss in dataset 2, and no packet loss in dataset 3, then it is determined that the port of the routed device does not have OSPF authentication enabled.

[0132] 2. If there is no packet loss in dataset 1 and no packet loss in dataset 2, then OSPF authentication is considered to be enabled.

[0133] 3. If there is packet loss in dataset 1, the detection will fail, and the packet loss fault needs to be ruled out before continuing the test;

[0134] 4. If the fault cannot be eliminated, collect more data and make probability estimates based on the packet loss rates of dataset 1, dataset 2, and dataset 3.

[0135] In the aforementioned method for enabling remote detection of OSPF authentication, the following steps are taken: First, the interface address data of the target routing device is obtained. Based on the interface address data, detection entry parameters are determined. Then, based on the detection entry parameters, interface address data, and preset data packet composition rules, network probe data packets are generated and sent to the target routing device in a first preset number, resulting in a first network performance data sequence. This first network performance data sequence characterizes the target routing device's response to the network probe data packets. Finally, based on the detection entry parameters, interface address data, and preset detection protocol composition rules, OSPF protocol probe data is generated, and simultaneously, OSPF protocol probe data and a second preset number of network probe data packets are sent to the target routing device. The system generates a second network performance data sequence. This sequence characterizes the target routing device's response to network probe packets when OSPF probe data is sent. After stopping the transmission of OSPF probe data to the target routing device, a third preset number of network probe packets are sent to the target routing device, resulting in a third network performance data sequence. This sequence characterizes the target routing device's response to network probe packets after the transmission of OSPF probe data is stopped. Based on the first, second, and third preset numbers, the first, second, and third network performance data sequences, the OSPF authentication function status determination result of the target routing device's interface is obtained. This system transforms the configuration check problem of "whether the protocol authentication is effective" into an observable and quantifiable scientific detection problem of "whether network behavior responds as expected to specific stimuli." Without relying on any management permissions or login credentials of the target device, it achieves remote, automated, and highly accurate verification of the actual operating status of the OSPF authentication function. This effectively overcomes the inherent defects of traditional CLI viewing methods, such as permission dependence and the inability to verify the effectiveness of functions, thus improving the efficiency and accuracy of network security authentication.

[0136] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0137] Based on the same inventive concept, this application also provides an OSPF authentication function enabling remote detection device for implementing the aforementioned OSPF authentication function enabling remote detection method. The solution provided by this device is similar to the implementation described in the above method. Therefore, the specific limitations of one or more embodiments of the OSPF authentication function enabling remote detection device provided below can be found in the limitations of the OSPF authentication function enabling remote detection method described above, and will not be repeated here.

[0138] In one exemplary embodiment, such as Figure 3 As shown, an OSPF authentication-enabled remote detection device 200 is provided, comprising:

[0139] The input parameter confirmation module 201 is used to obtain the interface address data of the target routing device and determine the detection input parameters based on the interface address data.

[0140] The first data generation module 202 is used to generate network probe data packets based on the detection entry parameters, interface address data and preset data packet composition rules, and send a first preset number of network probe data packets to the target routing device to obtain a first network performance data sequence; the first network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets;

[0141] The second data generation module 203 is used to generate OSPF protocol probe data based on the detection entry parameters, interface address data and preset detection protocol composition rules, and simultaneously send the OSPF protocol probe data and a second preset number of network probe data packets to the target routing device; to obtain a second network performance data sequence; the second network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets when sending OSPF protocol probe data;

[0142] The third data generation module 204 is used to send a third preset number of network probe data packets to the target routing device after stopping the transmission of OSPF protocol probe data to the target routing device, thereby obtaining a third network performance data sequence; the third network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets after stopping the transmission of OSPF protocol probe data.

[0143] The verification result determination module 205 is used to obtain the OSPF authentication function status determination result of the target routing device interface based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence.

[0144] Furthermore, the verification result determination module includes:

[0145] The packet loss calculation unit is used to identify the number of packets lost in the first network performance data sequence to obtain the first total number of packets lost; identify the number of packets lost in the second network performance data sequence to obtain the second total number of packets lost; and identify the number of packets lost in the third network performance data sequence to obtain the third total number of packets lost.

[0146] The significance judgment result calculation unit is used to analyze the differences in feedback from the target routing device before and after receiving OSPF protocol probe data based on the first preset quantity, the second preset quantity, the third preset quantity, the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses, and to obtain the significance judgment result; the significance judgment result is used to characterize the degree of difference between the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses.

[0147] The status determination result determination unit is used to obtain the OSPF authentication function status determination result of the target routing device based on the saliency judgment result and the preset authentication judgment rule.

[0148] Furthermore, the significance judgment result calculation unit is also used for:

[0149] Based on the first total number of packet losses, the second total number of packet losses, the first preset quantity, and the second preset quantity, a first test statistic is obtained, wherein the expression of the first test statistic is:

[0150]

[0151] in, It is the first test statistic. This is the second highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the second preset quantity;

[0152] Based on the first total number of packet losses, the third total number of packet losses, the first preset quantity, and the third preset quantity, a second test statistic is obtained, wherein the expression for the second test statistic is:

[0153]

[0154] in, It is the second test statistic. This is the third highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the third preset quantity;

[0155] The first test statistic is compared with a preset first significance threshold to obtain a first comparison result, and the second test statistic is compared with a preset second significance threshold to obtain a second comparison result;

[0156] Based on the first comparison result and the second comparison result, the significance judgment result is obtained.

[0157] Furthermore, the significance judgment result calculation unit is also used for:

[0158] Based on the total number of packet losses in the first, second, and third phases, the total number of packet losses is calculated. The expression for the total number of packet losses is:

[0159]

[0160] in, That is the total number of packets lost. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets;

[0161] Based on the first preset quantity, the second preset quantity, and the third preset quantity, the total number of detection packets is calculated. The expression for the total number of detection packets is:

[0162]

[0163] in, It is the total number of probe packets. It is the first preset quantity. It is the second preset quantity. It is the third preset quantity;

[0164] Based on the first preset quantity, the total number of probe packets, and the total number of lost packets, the first expected number of packet loss is calculated; based on the second preset quantity, the total number of probe packets, and the total number of lost packets, the second expected number of packet loss is calculated; based on the third preset quantity, the total number of probe packets, and the total number of lost packets, the third expected number of packet loss is calculated.

[0165] Based on the expected number of packet losses (first, second, and third), the first preset number, the second preset number, and the third preset number, the chi-square statistic for packet loss is calculated. The expression for the chi-square statistic for packet loss is:

[0166]

[0167] in, This is the packet loss statistics. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets. This is the expected number of packets lost in the first round. This is the second expected number of packet losses. This is the third expected number of packet losses;

[0168] The packet loss chi-square statistic is compared with the preset chi-square threshold to obtain a third comparison result; and the significance judgment result is obtained based on the third comparison result.

[0169] Furthermore, an OSPF authentication-enabled remote detection device also includes a result confidence calculation module, which is used for:

[0170] Calculate the ratio of the second total number of packet losses to the first total number of packet losses to obtain the first packet loss increase rate; calculate the ratio of the third total number of packet losses to the second total number of packet losses to obtain the second packet loss increase rate.

[0171] Based on the preset first packet loss change probability distribution function, the probability that the first packet loss increase rate reflects the OSPF authentication function being enabled is calculated, thus obtaining the first enabled conditional probability; the probability that the first packet loss increase rate reflects the OSPF authentication function being disabled is calculated, thus obtaining the first disabled conditional probability.

[0172] Based on the preset second packet loss change probability distribution function, the probability that the second packet loss increase rate reflects the OSPF authentication function being enabled is calculated, thus obtaining the second enabled conditional probability; the probability that the second packet loss increase rate reflects the OSPF authentication function being disabled is calculated, thus obtaining the second disabled conditional probability.

[0173] Based on the preset prior probability of OSPF authentication function being enabled, the preset prior probability of OSPF authentication function being disabled, the first enable condition probability, the first disable condition probability, the second enable condition probability, and the second disable condition probability, the posterior probability of OSPF authentication function being enabled is calculated, and the posterior probability is determined as the reliability probability of the OSPF authentication function status determination result.

[0174] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the steps of the OSPF authentication function enabling remote detection method as described above.

[0175] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0176] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The components described as separate parts may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0177] The above-described embodiments are merely illustrative of several implementation methods of the embodiments of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the embodiments of this application, and these modifications and improvements all fall within the protection scope of the embodiments of this application.

Claims

1. A method for enabling remote detection of OSPF authentication functionality, characterized in that, The method includes: Obtain the interface address data of the target routing device; and determine the detection entry parameters based on the interface address data; Based on the detection entry parameters, the interface address data, and the preset data packet composition rules, a network probe data packet is generated, and a first preset number of the network probe data packets are sent to the target routing device to obtain a first network performance data sequence; the first network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packet; Based on the detection entry parameters, the interface address data, and the preset detection protocol composition rules, OSPF protocol probe data is generated, and simultaneously the OSPF protocol probe data and a second preset number of network probe data packets are sent to the target routing device; a second network performance data sequence is obtained; the second network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets when the OSPF protocol probe data is sent; After stopping the transmission of OSPF protocol probe data to the target routing device, a third preset number of network probe data packets are sent to the target routing device to obtain a third network performance data sequence; the third network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets after stopping the transmission of OSPF protocol probe data; Based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence, the OSPF authentication function status determination result of the target routing device interface is obtained.

2. The method according to claim 1, characterized in that, The step of obtaining the OSPF authentication function status determination result of the target routing device interface based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence includes: The number of packet losses in the first network performance data sequence is identified to obtain a first total number of packet losses; the number of packet losses in the second network performance data sequence is identified to obtain a second total number of packet losses; the number of packet losses in the third network performance data sequence is identified to obtain a third total number of packet losses. Based on the first preset quantity, the second preset quantity, the third preset quantity, the first total packet loss, the second total packet loss, and the third total packet loss, the differences in feedback from the target routing device before and after receiving the OSPF protocol probe data are analyzed to obtain a significance judgment result; the significance judgment result is used to characterize the degree of difference between the first total packet loss, the second total packet loss, and the third total packet loss. Based on the saliency judgment result and the preset authentication judgment rule, the OSPF authentication function status judgment result of the target routing device is obtained.

3. The method according to claim 2, characterized in that, The method analyzes the differences in feedback from the target routing device before and after receiving the OSPF protocol probe data based on the first preset quantity, the second preset quantity, the third preset quantity, the first total packet loss, the second total packet loss, and the third total packet loss, to obtain a significance judgment result, including: Based on the first total packet loss, the second total packet loss, the first preset quantity, and the second preset quantity, a first test statistic is obtained, wherein the expression of the first test statistic is: in, It is the first test statistic. This is the second highest total number of lost packets. This is the first total number of lost packets. It is the first preset quantity. It is the second preset quantity; Based on the first total number of packet losses, the third total number of packet losses, the first preset quantity, and the third preset quantity, a second test statistic is obtained, wherein the expression of the second test statistic is: in, It is the second test statistic. This is the third highest total number of packet losses. This is the first total number of lost packets. It is the first preset quantity. It is the third preset quantity; The first test statistic is compared with a preset first significance threshold to obtain a first comparison result, and the second test statistic is compared with a preset second significance threshold to obtain a second comparison result; Based on the first comparison result and the second comparison result, the significance judgment result is obtained.

4. The method according to claim 2, characterized in that, The step of analyzing the differences in feedback from the target routing device before and after receiving the OSPF protocol probe data based on the first preset quantity, the second preset quantity, the third preset quantity, the first total packet loss, the second total packet loss, and the third total packet loss, to obtain a significance judgment result, further includes: Based on the first total number of packet losses, the second total number of packet losses, and the third total number of packet losses, the total number of packet losses is calculated, and the expression for the total number of packet losses is: in, That is the total number of packets lost. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of lost packets; Based on the first preset quantity, the second preset quantity, and the third preset quantity, the total number of detection packets is calculated, and the expression for the total number of detection packets is: in, It is the total number of probe packets. It is the first preset quantity. It is the second preset quantity. It is the third preset quantity; Based on the first preset quantity, the total number of probe packets, and the total number of lost packets, a first expected number of packet losses is calculated; based on the second preset quantity, the total number of probe packets, and the total number of lost packets, a second expected number of packet losses is calculated; based on the third preset quantity, the total number of probe packets, and the total number of lost packets, a third expected number of packet losses is calculated. Based on the first expected number of packet losses, the second expected number of packet losses, the third expected number of packet losses, the first preset number, the second preset number, and the third preset number, a packet loss chi-square statistic is calculated. The expression for the packet loss chi-square statistic is: in, This is the packet loss statistics. This is the first total number of lost packets. This is the second highest total number of lost packets. This is the third highest total number of packet losses. This is the expected number of packets lost in the first round. This is the second expected number of packet losses. This is the expected number of packet losses for the third time. The packet loss chi-square statistic is compared with a preset chi-square threshold to obtain a third comparison result; and the significance judgment result is obtained based on the third comparison result.

5. The method according to claim 2, characterized in that, The method further includes: Calculate the ratio of the second total number of packet losses to the first total number of packet losses to obtain the first packet loss increase rate; calculate the ratio of the third total number of packet losses to the second total number of packet losses to obtain the second packet loss increase rate; Based on the preset first packet loss change probability distribution function, the probability that the first packet loss increase rate reflects the OSPF authentication function being enabled is calculated to obtain the first enabled conditional probability; the probability that the first packet loss increase rate reflects the OSPF authentication function being disabled is calculated to obtain the first disabled conditional probability. Based on the preset second packet loss change probability distribution function, the probability that the second packet loss increase rate reflects the OSPF authentication function being enabled is calculated to obtain the second enabled condition probability; the probability that the second packet loss increase rate reflects the OSPF authentication function being disabled is calculated to obtain the second disabled condition probability. Based on the preset prior probability of OSPF authentication function being enabled, the preset prior probability of OSPF authentication function being disabled, the first enabling condition probability, the first disabling condition probability, the second enabling condition probability, and the second disabling condition probability, the posterior probability of OSPF authentication function being enabled is calculated, and the posterior probability is determined as the reliability probability of the OSPF authentication function status determination result.

6. A remote detection device with OSPF authentication enabled, characterized in that, The device includes: The entry parameter confirmation module is used to obtain the interface address data of the target routing device and determine the detection entry parameters based on the interface address data. The first data generation module is used to generate network probe data packets based on the detection entry parameters, the interface address data, and preset data packet composition rules, and send a first preset number of network probe data packets to the target routing device to obtain a first network performance data sequence; the first network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets; The second data generation module is used to generate OSPF protocol probe data based on the detection entry parameters, the interface address data, and the preset detection protocol composition rules, and simultaneously send the OSPF protocol probe data and a second preset number of network probe data packets to the target routing device; to obtain a second network performance data sequence; the second network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets when the OSPF protocol probe data is sent; The third data generation module is used to send a third preset number of network probe data packets to the target routing device after stopping the transmission of the OSPF protocol probe data to the target routing device, thereby obtaining a third network performance data sequence; the third network performance data sequence is used to characterize the feedback of the target routing device to the network probe data packets after stopping the transmission of the OSPF protocol probe data. The verification result determination module is used to obtain the OSPF authentication function status determination result of the target routing device interface based on the first preset quantity, the second preset quantity, the third preset quantity, the first network performance data sequence, the second network performance data sequence, and the third network performance data sequence.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 5.