Network routing anomaly detection method, system and device and medium

By transmitting probe packets between network devices and the central controller, and utilizing lightweight path coding for path probing and multi-dimensional anomaly detection, this method solves the problem of detecting network routing anomalies caused by pulsed OSPF attacks, achieving efficient fault diagnosis and recovery, and is suitable for routine monitoring of large-scale production networks.

CN121940176APending Publication Date: 2026-04-28TSINGHUA UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TSINGHUA UNIVERSITY
Filing Date
2026-01-12
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing technologies are insufficient for effectively detecting and tracing network routing anomalies caused by pulsed OSPF attacks. Traditional detection methods have limitations in terms of timeliness and detection dimensions, and in-band telemetry technology is too expensive to deploy in large-scale networks.

Method used

By transmitting probe data packets between network devices and the central controller, lightweight path coding is used for path probing. Combined with device forwarding offset, network segment offset, and loop path detection, a fine comparison between the actual path and the expected path and multi-dimensional anomaly detection are achieved, building a precise source tracing capability from path deviation to the root cause device.

Benefits of technology

It enables refined classification and diagnosis of path anomalies, shortens fault diagnosis and recovery time, reduces data plane and control plane overhead, and is suitable for routine monitoring of large-scale production networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940176A_ABST
    Figure CN121940176A_ABST
Patent Text Reader

Abstract

Provided are a network routing anomaly detection method, system, device and medium, the method comprising: receiving detection result information comprising an actual path code sent by a network device, the actual path code being used for reflecting an actual forwarding path of a detection data packet in a target network; and if the actual path code is different from an expected path code (an expected forwarding path in a normal routing state) of the target detection service flow, respectively carrying out equipment forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path by utilizing a preset routing anomaly detection mechanism to obtain an anomaly detection result, the anomaly detection result comprises the identifier of the network equipment with the path offset, the information of the network segment with the path offset and whether the actual forwarding path comprises the loop path, so that the source tracing can be carried out on the initial network equipment with the anomaly in the target network based on the anomaly detection result. According to the embodiment of the invention, refined classification and diagnosis of path anomalies can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network traffic analysis technology, and more specifically, to a method, system, device, and storage medium for detecting anomalies in network routing. Background Technology

[0002] The Open Shortest Path First (OSPF) protocol, as the core of routing within an autonomous system, directly impacts the correctness and stability of data forwarding across the entire network. With the evolution of network attack techniques, attacks against routing protocols like OSPF have become increasingly sophisticated and covert. For example, pulsed OSPF attacks inject forged Link-State Advertisements (LSAs) serially within millisecond-level time windows, inducing momentary routing anomalies followed by rapid recovery. Their transient nature and stealth make traditional detection mechanisms based on fixed-period polling or random sampling systematically miss these attacks due to insufficient sampling frequency. Such attacks not only expose the inherent timeliness deficiencies of existing detection methods but also highlight the limitations of current routing anomaly detection systems in terms of detection dimensions.

[0003] The relevant technologies typically employ end-to-end path probing techniques, which can obtain the actual forwarding path. However, these techniques usually only assess connectivity or latency, lacking a refined comparison mechanism with the expected path. Furthermore, they do not establish the ability to classify and diagnose path deviations into specific anomaly types, resulting in ambiguous anomaly localization and difficulty in supporting accurate source tracing. Summary of the Invention

[0004] In view of this, this application provides a method, system, device and storage medium for detecting network routing anomalies, in order to at least solve the problems existing in the related technologies.

[0005] Specifically, this application is implemented through the following technical solution: This application provides a method for detecting network routing anomalies, applied to a central controller in a target network. The target network further includes multiple network devices, each connected to the central controller. The method includes: The system receives probe result information sent by a network device. The probe result information is obtained based on path probing of probe data packets in the target probe service flow passing through the network device. The probe result information includes actual path encoding, which reflects the actual forwarding path of the probe data packets in the target network. Obtain the expected path code of the target probe service flow. If the actual path code is different from the expected path code, based on the actual path code, use a preset routing anomaly detection mechanism to perform device forwarding offset detection, network segment offset detection, and loop path detection on the actual forwarding path to obtain anomaly detection results. The expected path encoding is used to characterize the expected forwarding path followed by the target probe service flow under normal routing conditions; the anomaly detection result includes the network device identifier where the path deviation occurred, the network segment information where the path deviation occurred, and whether the actual forwarding path includes a loop path; the anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

[0006] This application provides a method for detecting network routing anomalies, applied to network devices in a target network, wherein the target network further includes a central controller, and the central controller is communicatively connected to the network devices; the method includes: Receive a target detection service flow; the target detection service flow includes multiple detection data packets, and the target detection service flow corresponds to an expected forwarding path; For each probe data packet, the actual path code in the telemetry header information of the probe data packet is updated based on the device identifier of the network device; the actual path code is used to reflect the actual forwarding path of the probe data packet in the target network. Based on the location of the network device in the expected forwarding path and the updated probe data packet, probe result information is generated and sent to the central controller. The central controller is used to perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path based on the probe result information, so as to trace the originating network device in the target network where the anomaly occurred.

[0007] This application also provides a network routing anomaly detection system, including a central controller and multiple network devices connected to the central controller; The network device is used to perform path probing based on probe data packets in the target probe service flow to obtain probe result information, and sends the probe result information to the central controller; the probe result information includes actual path encoding, which reflects the actual forwarding path of the probe data packets in the target network; The central controller is used to receive the detection result information and obtain the expected path code of the target detection service flow. If the actual path code is different from the expected path code, based on the actual path code, a preset routing anomaly detection mechanism is used to perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path to obtain the anomaly detection result. The expected path encoding is used to characterize the expected forwarding path followed by the target probe service flow under normal routing conditions; the anomaly detection result includes the network device identifier where the path deviation occurred, the network segment information where the path deviation occurred, and whether the actual forwarding path includes a loop path; the anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

[0008] This application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the network routing anomaly detection method described in any of the foregoing embodiments.

[0009] This application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the network routing anomaly detection method described in any of the foregoing embodiments.

[0010] This application also provides a computer program product, including a computer program that, when run by a processor, performs the steps of any of the possible network routing anomaly detection methods described above.

[0011] The technical solutions provided by the embodiments of this application may include the following beneficial effects: In this embodiment, fine-grained classification and diagnosis of path anomalies can be achieved. By comparing the actual path code with the expected path code in a fine-grained manner, and performing multi-dimensional anomaly detection (device offset, network segment offset, loop detection) on the discovered deviation path, the abstract "path inconsistency" can be transformed into a specific and operable anomaly type, thereby clarifying whether it is a forwarding error of a single network device, a routing policy conflict in a certain network segment, or a forwarding loop, so as to take targeted measures and greatly shorten the fault diagnosis and recovery time.

[0012] Furthermore, this application establishes a precise tracing capability from path deviation to the root cause device. Compared to related methods that, after detecting path anomalies, can often only locate the node where the anomaly occurred, but struggle to determine the starting point (root cause device), this application, through device forwarding offset detection, can accurately identify the first network device deviating from the expected path; through network segment offset detection, it can define the network segment affected by the abnormal routing; and by combining loop path detection, it can discover loop forwarding points caused by routing calculation errors. These detection results together constitute a complete anomaly impact chain, enabling the system to directly trace the originating network device of the anomaly.

[0013] Furthermore, compared to high-overhead solutions that require full-flow, full-path tracing (such as in-band telemetry) to achieve similar diagnostic accuracy, the detection results in this method are obtained based on the detection of service flows. Lightweight path coding is used for information compression and comparison, significantly reducing data plane overhead and control plane analysis burden while maintaining sensitivity to path deviations and diagnostic depth. This "low-overhead, high-precision" characteristic makes it more suitable for continuous deployment in large-scale production networks, enabling routine and refined monitoring of routing anomalies.

[0014] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description

[0015] Figure 1 This is a schematic diagram illustrating an open shortest path first protocol pulse attack according to an exemplary embodiment of this application; Figure 2 This is a schematic diagram of the architecture of an anomaly detection system for network routing, as illustrated in an exemplary embodiment of this application. Figure 3 This is a flowchart illustrating an exemplary embodiment of a network device-side anomaly detection method for network routing; Figure 4 This is a flowchart illustrating an anomaly detection method for network routing on the central controller side, as shown in an exemplary embodiment of this application; Figure 5 This is a schematic diagram illustrating an equivalent multipath routing according to an exemplary embodiment of this application; Figure 6 This is a diagram illustrating the relationship between packet loss rate and time, provided in an exemplary embodiment of this application. Figure 7 This is a schematic diagram illustrating the impact of service flow filtering on network overhead, as shown in an exemplary embodiment of this application. Figure 8 This is an architectural diagram illustrating an attack scenario according to an exemplary embodiment of this application; Figure 9 This is a schematic diagram illustrating the impact of an attack, as shown in an exemplary embodiment of this application. Figure 10 This is a hardware structure diagram of a computer device illustrated in an exemplary embodiment of this application. Detailed Implementation

[0016] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0017] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0018] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0019] The Open Shortest Path First (OSPF) protocol, as the core of routing within an autonomous system, directly impacts the correctness and stability of data forwarding across the entire network. Attack methods against OSPF are constantly evolving, with pulse OSPF attacks being particularly insidious. This attack serializes and injects forged Link-State Advertisements (LSAs) within an extremely short time (milliseconds), inducing a momentary, imperceptible deflection in network traffic, which then quickly recovers. This circumvents traditional monitoring systems based on fixed-period polling, such as Simple Network Management Protocol (SNMP), or sampling. Such attacks expose a fundamental flaw in the timeliness of existing detection methods: their detection frequency is far lower than the attack frequency, leading to the systematic omission of brief routing anomalies. This type of attack not only exposes the inherent timeliness deficiencies of existing detection methods but also highlights the limitations of current routing anomaly detection systems in terms of detection dimensions.

[0020] Please see Figure 1 This is a schematic diagram illustrating a pulse attack using an open shortest path first protocol, provided as an exemplary embodiment of this application. Figure 1 As shown, the attacker constructs a first forged LSA. The information of this first forged LSA indicates that it is a normal LSA with sequence number N and aging time M. It advertises a subnet 192.168.2.0 / 28 and the advertised router is 1.1.1.1. It sends the first forged LSA to router 1.1.1.1 (victim) through router 2.2.2.2 (attacker). At the same time, the attacker also constructs a second forged LSA. The information of this second forged LSA indicates that it is a normal LSA with sequence number N+1 and aging time 0. It advertises a subnet 192.168.2.0 / 28 and the advertised router is 1.1.1.1. It sends the second forged LSA to another router 3.3.3.3 through router 2.2.2.2.

[0021] After receiving the first forged LSA, router 1.1.1.1 announces a counterattack to the entire network. The counterattack message indicates that the sequence number of the normal LSA is N+1 and the aging time is 0. Here, the time when the counterattack announcement reaches other routers 3.3.3.3 is later than the time when the second forged LSA reaches other routers 3.3.3.3. Other routers 3.3.3.3 modify their local routing table entries based on the earliest reception time and the second forged LSA. Furthermore, before the polling cycle of router 1.1.1.1 is completed, the attacker withdraws the second forged LSA from other routers 3.3.3.3. Other routers 3. ...

[0022] In other words, if the contents of the routing table entries are incorrect within a certain period of the polling cycle, it can lead to network anomalies (such as loops).

[0023] In related technologies, end-to-end path probing is commonly used. This method can obtain the actual forwarding path, but it usually only makes judgments on connectivity or latency. It lacks a fine-grained comparison mechanism with the expected path and has not established the ability to classify and diagnose from path deviation to specific anomaly types. This results in ambiguous anomaly location and makes it difficult to support accurate source tracing.

[0024] Furthermore, the development of inband network telemetry (INT) technology has provided a new way to obtain the actual forwarding path of data packets, enabling the control plane to obtain actual path information that can be compared with the ideal state. However, directly implementing INT-style full path tracing on all service flows across the entire network will result in unbearable bandwidth overhead, data plane processing burden, and control plane analysis pressure. It also lacks scalability for deployment in large-scale networks, makes it difficult to automatically and quickly identify abnormal patterns, and thus fails to locate the root cause.

[0025] Furthermore, to capture transient anomalies such as pulse attacks, near-continuous path state sampling and comparison are required. This typically implies extremely high monitoring frequencies or full-flow monitoring, leading to a surge in network overhead and processing load. While traditional methods based on periodic polling or random sampling control overhead, they come at the cost of sacrificing real-time detection and false negative rates, failing to meet the timeliness requirements of security detection.

[0026] Based on the above research, this disclosure provides a network routing anomaly detection method applied to a central controller in a target network. The target network also includes multiple network devices, each connected to the central controller. The method first receives probe result information sent by the network devices. The probe result information is obtained by path probing of probe data packets in the target probe service flow passing through the network devices. The probe result information includes an actual path code, which reflects the actual forwarding path of the probe data packets in the target network. Then, the expected path code of the target probe service flow is obtained. If the actual path code differs from the expected path code, based on the actual path code, a preset routing anomaly detection mechanism is used to perform device forwarding offset detection, network segment offset detection, and loop path detection on the actual forwarding path to obtain an anomaly detection result. The expected path code characterizes the expected forwarding path followed by the target probe service flow under normal routing conditions. The anomaly detection result includes the network device identifier where the path offset occurred, the network segment information where the path offset occurred, and whether the actual forwarding path includes a loop path. The anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

[0027] In this embodiment, fine-grained classification and diagnosis of path anomalies can be achieved. By comparing the actual path code with the expected path code in a fine-grained manner, and performing multi-dimensional anomaly detection (device offset, network segment offset, loop detection) on the discovered deviation path, the abstract "path inconsistency" can be transformed into a specific and operable anomaly type, thereby clarifying whether it is a forwarding error of a single network device, a routing policy conflict in a certain network segment, or a forwarding loop, so as to take targeted measures and greatly shorten the fault diagnosis and recovery time.

[0028] Furthermore, this application establishes a precise tracing capability from path deviation to the root cause device. Compared to related methods that, after detecting path anomalies, can often only locate the node where the anomaly occurred, but struggle to determine the starting point (root cause device), this application, through device forwarding offset detection, can accurately identify the first network device deviating from the expected path; through network segment offset detection, it can define the network segment affected by the abnormal routing; and by combining loop path detection, it can discover loop forwarding points caused by routing calculation errors. These detection results together constitute a complete anomaly impact chain, enabling the system to directly trace the originating network device of the anomaly.

[0029] Furthermore, compared to high-overhead solutions that require full-flow, full-path tracing (such as in-band telemetry) to achieve similar diagnostic accuracy, the detection results in this method are obtained based on the detection of service flows. Lightweight path coding is used for information compression and comparison, significantly reducing data plane overhead and control plane analysis burden while maintaining sensitivity to path deviations and diagnostic depth. This "low-overhead, high-precision" characteristic makes it more suitable for continuous deployment in large-scale production networks, enabling routine and refined monitoring of routing anomalies.

[0030] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.

[0031] Please see the appendix Figure 2 This is a schematic diagram illustrating the architecture of an anomaly detection system for network routing, as shown in an exemplary embodiment of this application. Figure 2 As shown, the target network 100 includes a central controller 10 and multiple network devices 20 (including network device 20(1), network device 20(2), ..., network device 20(n), where n is a positive integer). The central controller 10 is communicatively connected to the multiple network devices 20 respectively.

[0032] Optionally, the central controller 10 can be a hardware central controller or a software central controller. If it is a software central controller, the central controller can be a server. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud storage, big data and artificial intelligence platforms.

[0033] Any network device 20 can be a switch, router, or other device. In other embodiments, network device 20 can also be a terminal device, such as a mobile phone, tablet computer, or computer. This is not a limitation.

[0034] The following section provides a detailed description of the anomaly detection procedures performed by network device 20 and central controller 10, respectively.

[0035] Please see the appendix Figure 3 This is a flowchart illustrating an anomaly detection method for network routing on the network device side, as shown in an exemplary embodiment of this application. Figure 3 As shown, the network routing anomaly detection method in this embodiment includes the following steps S301~S303: S301: Receive target detection service flow; the target detection service flow includes multiple detection data packets, and the target detection service flow corresponds to an expected forwarding path.

[0036] Here, the target probe traffic received by the network device is one of the probe traffic traffic sets. The probe traffic traffic sets are selected by the central controller from the traffic traffic flowing through the target network. Each probe traffic traffic in the probe traffic traffic traffic sets is used to perform path probing on the target network.

[0037] The expected forwarding path refers to the complete router sequence from the ingress device to the egress device that the target probe traffic follows under normal routing conditions. It is the baseline path for judging whether the actual forwarding behavior is abnormal.

[0038] Specifically, since the target network includes multiple links, to ensure no monitoring blind spots, it is necessary to guarantee that each link is traversed by at least one probing service flow path. The central controller models this requirement as a set coverage optimization problem, the goal of which is to find a subset of service flows that can cover all critical links while minimizing the total path length (i.e., total probing cost) of these selected service flows. By solving this model (e.g., using a greedy heuristic algorithm), the final set of probing service flows is obtained. Therefore, each probing service flow in this set is responsible for continuously sampling specific path segments (i.e., expected forwarding paths) or forwarding behaviors in the target network. All probing service flows work together to form an active monitoring system that achieves full coverage of critical links across the entire network by minimizing cost.

[0039] The process of filtering the detection service flow set will be described in detail later.

[0040] S302: For each probe data packet, based on the device identifier of the network device, update the actual path code in the telemetry header information of the probe data packet; the actual path code is used to reflect the actual forwarding path of the probe data packet in the target network.

[0041] Among them, the device identifier of a network device is the network device's physical address (Media Access Control Address, MAC address).

[0042] It is understandable that when probe data packets in the target detection service flow arrive at the network device sequentially, the actual path encoding in the telemetry header information of the probe data packet is updated based on the device identifier of the network device for each probe data packet.

[0043] The actual path code is a dynamically updated data field (usually located in the IPv6 extension header or a custom telemetry header). The initial value of the actual path code is set at the ingress device. Whenever a probe packet passes through a network device, the unique identifier of that network device (such as the low bits of the MAC address) is accumulated in the code. In this way, the actual path code can completely record the sequence of devices that the probe packet actually passes through (i.e., the actual forwarding path).

[0044] Optionally, the actual path code can be updated using an XOR operation, as shown in formula (1): (1) in, Encode the actual path. c 1 represents the first network device (i.e., the ingress network device) through which the probe data packet passes. c 2 represents the second network device through which the probe data packet passes. c y To detect the last network device (i.e., the egress network device) through which the data packet passes.

[0045] The mathematical properties of formula (1) ensure that the path encoding can record the structural changes of the complete path in a finite number of bits without increasing complexity. Finally, an encoding that can uniquely fingerprint the path is formed. In this process, it is not necessary to record the path length or the specific port.

[0046] In this embodiment, if the network device is the ingress device, telemetry header information, such as Internet Protocol Version 6 (IPv6) flow label or Internet Protocol version 4 (IPv4) alignment extension header, is first embedded in the header of the probe data packet. The telemetry header information includes flow identifier, arrival timestamp of probe data packet, and path encoding field. In this way, the actual path encoding in the path encoding field can be dynamically updated when the probe data packet flows through each network device.

[0047] S303: Based on the location of the network device in the actual forwarding path and the updated probe data packet, generate probe result information and send the probe result information to the central controller; the central controller is used to perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path according to the probe result information, so as to trace the originating network device in the target network where the anomaly occurred.

[0048] In this embodiment, after processing the probe data packet, the network device generates probe result information and sends the probe result information to the central controller, so that the central controller can perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path according to the probe result information, so as to trace the origin of the abnormal network device in the target network.

[0049] It is understandable that network devices can be located at the exit point or a non-exit point in the actual forwarding path, and the processing methods differ for network devices in different locations.

[0050] Specifically, if the network device is not the exit point in the actual forwarding path and the updated probe data packet is not forwarded, the network device will detect a black hole by default. At this time, the network device will copy the updated probe data packet to obtain a copied probe data packet, and generate detection result information based on the copied probe data packet. In this way, the network device can trigger the black hole anomaly detection mechanism at the first time.

[0051] Specifically, when generating probe result information based on the replicated probe data packet, the payload of the replicated probe data packet can be deleted first to obtain a new replicated probe data packet, and alarm information can be added to the header of the new replicated probe data packet to obtain the probe result information.

[0052] The alarm information includes the network device's device identifier, timestamp, ingress port identifier corresponding to the probe data packet, and egress port identifier. The timestamp refers to the time when the black hole event occurred, the ingress port identifier is the ingress port number of the network device receiving the probe data packet, and the egress port identifier is the expected egress port number of the network device forwarding the probe data packet.

[0053] Here, the payload of the copied probe data packet is deleted in order to reduce the size of the data packet and reduce the transmission overhead of the probe detection results.

[0054] In this embodiment, the network device locally judges, constructs and actively reports lightweight detection result information in real time, reducing the delay of anomaly detection and reporting to the millisecond level, which perfectly meets the needs of capturing "pulse attacks". Compared with the "traditional SNMP scheme that relies on the controller to actively poll (15 seconds)" in related technologies, it can improve the real-time performance of black hole detection.

[0055] Furthermore, the detection results generated by this application have a very small size (containing only the necessary header and metadata), but contain high-precision tracing information such as path encoding, device identification, port, and time. This helps reduce overhead and provides high-precision information, solving the problem of large data packets and non-scalable monitoring in INT technology that records the entire path.

[0056] In addition, regarding the above, it should be noted that when network devices send probe result information, they usually adopt a periodic upload method, and for the same probe service flow, the probe result information is only uploaded once within a preset time. That is, the network device will first perform one-sided information aggregation. Specifically, for the same probe service flow, if different probe data packets all have black hole events, then the network device will send the probe result information corresponding to the latest black hole event to the central controller.

[0057] In other implementations, if the location of the network device in the actual forwarding path is an exit location, the telemetry header information is stripped from the header information of the probe data packet sent by the preceding network device, the actual path code is extracted from the telemetry header information, and the probe result information is generated based on the actual path code and the network identifier of each network device corresponding to the actual path code.

[0058] Similarly, in order to generate lightweight probe result information, embodiments of this application extract telemetry header information from the header information of probe data packets, and extract actual path codes and network identifiers of each network device corresponding to the actual path codes from the telemetry header information to generate probe result information.

[0059] Please see the appendix Figure 4 This is a flowchart illustrating an anomaly detection method for network routing on the central controller side, as shown in an exemplary embodiment of this application. Figure 4 As shown, the network routing anomaly detection method in this embodiment includes the following steps S401~S402: S401: Receive probe result information sent by the network device; the probe result information is obtained based on path probing of probe data packets in the target probe service flow flowing through the network device, and the probe result information includes actual path encoding, which is used to reflect the actual forwarding path of the probe data packets in the target network.

[0060] As mentioned above, network devices periodically send detection results to the central controller, which then receives the detection results from the network devices.

[0061] S402: Obtain the expected path code of the target probe service flow. If the actual path code is different from the expected path code, based on the actual path code, use a preset routing anomaly detection mechanism to perform device forwarding offset detection, network segment offset detection, and loop path detection on the actual forwarding path to obtain anomaly detection results. The expected path encoding is used to characterize the expected forwarding path followed by the target probe service flow under normal routing conditions; the anomaly detection result includes the network device identifier where the path deviation occurred, the network segment information where the path deviation occurred, and whether the actual forwarding path includes a loop path; the anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

[0062] After receiving the probe results, the central controller compares the expected path code of the target probe service flow with the actual path code in the probe results. If the actual path code is different from the expected path code, the routing anomaly monitoring mechanism is triggered. Based on the actual path code, the preset routing anomaly detection mechanism is used to perform device forwarding offset detection, network segment offset detection, and loop path detection on the actual forwarding path to conduct in-depth analysis of the differences (origin of the anomaly, scope of impact, and whether a loop route has occurred) and obtain the anomaly detection results.

[0063] In this embodiment, a pre-defined routing anomaly detection mechanism is used to perform multi-angle collaborative detection, which can analyze the same path deviation event from multiple dimensions. Compared with the related technology's "detection of a single reachability loss" scheme, it can accurately distinguish different types of anomalies such as route hijacking, partial tampering, configuration errors and routing loops.

[0064] Furthermore, related technologies typically only indicate "path anomaly" or "packet loss," and the location range is often a segment or the entire network. This technology's multi-angle analysis, especially its difference identification rules, can directly output the identifier of the network device from which the earliest offset occurred. This transforms troubleshooting from a traditional "network-wide" approach to a "targeted" one, directly focusing on suspicious devices. Combined with the impact range output by tamper detection rules, the routing table, policy configuration, or logs of the device can be quickly checked, thereby reducing the Mean Time to Repair (MTTR) from hours to minutes or even seconds.

[0065] Furthermore, through the above multi-faceted analysis, the nature of the anomaly can be quickly understood, and targeted response strategies can be adopted, greatly improving the accuracy and efficiency of emergency response.

[0066] The routing anomaly detection mechanism described above in this application will be described in detail below.

[0067] The routing anomaly detection mechanism in this application includes path offset detection rules, offset network segment detection rules, and loop detection rules.

[0068] The path offset detection rule is used to detect the network device identifier that causes the path offset. Specifically, the path offset detection rule includes the difference point identification rule and the path difference rule. The difference point identification rule is used to detect the device identifier of the starting network device that causes the path offset. The path difference rule is used to detect the device identifier of the network device that passively causes the path offset after the starting network device. The difference point identification rule is shown in formula (2): (2) Where C is the device identifier of the network device from which the path offset occurred. i It refers to the first i One network device, For the first in the expected forwarding path i Device identifier for a network device For the first in the actual forwarding path i Device identifier for a network device.

[0069] The path difference rule is shown in formula (3): (3) Among them, PDR is the device identifier of other network devices that have experienced path offsets and whose device identifier is greater than that of the starting network device.

[0070] Offset network segment detection rules are used to detect network segments whose paths have been tampered with, as shown in formula (4): (4) in, R i This refers to the network segment whose path has been altered.

[0071] The loop detection rule is used to detect whether a routing loop exists in the actual forwarding path. Specifically, when using the loop detection rule to perform loop routing detection based on the actual path code and obtain the routing loop detection result, it can be determined whether the actual forwarding path meets the preset routing loop condition based on the actual path code. If the routing loop condition is met, it is determined that the actual forwarding path includes a loop path, and the routing loop detection result is obtained.

[0072] The routing loop condition refers to the fact that two network devices located at different locations in the actual forwarding path are the same, and the network devices at any two consecutive locations within the path segment between the different locations are different.

[0073] As shown in formula (5): (5) in, j and kThese represent different locations in the actual forwarding path. l for j and k Any position between.

[0074] For routing loop events, the determination is made by detecting whether the encoding exhibits a periodic zeroing pattern formed by XOR cancellation. For example, in the case of router A→B→C→D→B, in the first loop, a⊕b⊕c⊕d⊕b is encoded. After b is cancelled, only a⊕c⊕d remains. If in the second loop the encoding returns to a, but the port source is not A, then it is determined to be a routing loop.

[0075] Furthermore, in networks supporting Equal-Cost Multi-Path Routing (ECMP), a single probe flow may have multiple legitimate forwarding paths. To avoid normal path changes caused by ECMP hashing being falsely reported as anomalies, a set comparison mechanism for the Equal-Cost Multi-Path encoding is first introduced when comparing the actual path encoding with the expected path encoding: For each probe flow, all possible equal-cost paths are determined, and a corresponding path encoding is calculated for each equal-cost path, forming a set of path encodings corresponding to the target probe flow. During consistency comparison, the comparison condition is first relaxed from "whether it is equal to a single expected encoding (i.e., the encoding of the expected forwarding path)" to "whether it matches any encoding in the path encoding set". As long as the actual path encoding is the same as any encoding in the path encoding set, it is determined that the path is consistent and belongs to normal ECMP forwarding behavior; if the actual path encoding is different from all encodings in the path encoding set, it is determined that the actual path encoding is different from the expected path encoding, and then the routing anomaly detection mechanism is triggered to perform root cause analysis.

[0076] like Figure 5 The diagram shown is a schematic representation of an equivalent multipath routing method provided in an exemplary embodiment of this application. Figure 5 As shown, the source network device is coded as 10111, and the destination network device is coded as 00110. There are two equivalent paths between the source and destination network devices. The first path, indicated by the green directed line in the figure, passes through the intermediate network device 10011. Therefore, the expected path code = 10111 XOR 10011 XOR 00110 = 00100. The second path, indicated by the pink directed line in the figure, passes through the intermediate network device 01011. The expected path code = 10111 XOR 01011 XOR 00110 = 11100. Thus, during comparison, if the actual forwarding path is the same as either the expected path code (00100 or 11100), the paths are considered to be consistent; otherwise, they are considered inconsistent.

[0077] In some implementations, after obtaining the anomaly detection results, the anomaly detection results can be structured to generate anomaly diagnosis results.

[0078] The anomaly diagnosis results include at least an anomaly flag, black hole source distance, path deviation identifier, number of network device hops in the path deviation, and the identifier of the first attacked network device. The anomaly flag indicates whether there is an anomaly in the actual forwarding path. For example, an anomaly flag of 1 indicates that there is an anomaly in the network. The black hole source distance indicates the distance between the network device that caused the black hole and the last network device in the event of a black hole event. For example, if the black hole source distance = 0, it means that the network device is the one that caused the black hole. If the black hole source distance = n (n>0), it means that the black hole event occurred on the nth hop downstream of the network device. The path deviation identifier indicates that there is a deviation between the actual forwarding path and the expected forwarding path. For example, a path deviation identifier of 1 means that the actual forwarding path conforms to the expected forwarding path. A path deviation identifier of 0 means that a path deviation has occurred. The number of network device hops in the path deviation indicates the total number of consecutive network devices in which the actual forwarding path deviates from the expected forwarding path. The magnitude of this value reflects the scope of the anomaly and is used to assess the severity of the anomaly. The identifier of the first attacked network device indicates the first network device in which the routing anomaly occurred.

[0079] In other implementations, the anomaly diagnosis results may also include other content, such as anomaly type flags. Specifically, the anomaly type flags may include a black hole flag and / or a loop flag. For the black hole flag, the black hole flag is used to indicate whether a black hole exists in the actual forwarding path. For example, a black hole flag of 1 indicates the presence of a black hole, and a black hole flag of 0 indicates the absence of a black hole. For the loop flag, the loop flag is used to indicate whether a loop is included in the actual forwarding path. For example, if the loop flag is 1, it indicates the presence of a loop, and if the loop flag is 0, it indicates the absence of a loop.

[0080] It should be noted that the content of the above abnormal diagnosis results is only illustrative. Other contents may be included in other embodiments, which are not limited here.

[0081] In this embodiment of the application, by performing structured processing on the anomaly diagnosis results, the complex multi-rule anomaly detection results are transformed into a standardized and structured anomaly diagnosis result. This anomaly diagnosis result can comprehensively characterize the type, severity, location, and scope of the anomaly, thereby improving the observability and recoverability of the network.

[0082] As mentioned above, the probe service flow set is obtained by the central controller through filtering the service flows of the target network. The filtering process is described in detail below, specifically including steps (1) to (3): (1) Obtain the service flow set of the target network; the service flow set includes multiple service flows.

[0083] The service flow set can be the set of all possible end-to-end actual service flows in the target network, determined by the central controller based on the network topology and OSPF routing protocol state of the target network.

[0084] (2) Construct a service flow filtering model; the service flow filtering model includes a path length objective function and constraints. The path length objective function is used to indicate the sum of the total path lengths of the selected service flows. The constraints are used to indicate the forwarding path of the selected service flows covers the target link set. The target link set includes the links between each network device and its corresponding destination address prefix.

[0085] In this embodiment, the business flow selection problem is transformed into an integer linear programming (ILP) model, and a business flow selection model is constructed based on the idea of ​​the integer linear programming model. The business flow selection model includes a path length objective function and constraints.

[0086] The path length objective function is used to indicate minimizing the sum of path lengths of the selected business flows, that is, reflecting the principle of cost minimization, as shown in formula (6): (6) in, For business flow Path length, Select an indicator to characterize the business flow. Whether to be selected as a probe service flow , For a set of business flows, n This represents the total number of business flows in the business flow set.

[0087] The constraints are used to indicate that the forwarding path of the selected service flow covers the target link set, which includes the links between each network device and its corresponding destination address prefix, as shown in formula (7): (7) in, j For the target link set The first in j One link, Link coefficient, used to indicate service flow Does it cover the link? j , n For the target link set The total number of links in the system.

[0088] (3) The set of business flows and the path length of each business flow are used as input parameters of the business flow filtering model, and the greedy heuristic algorithm is used to solve the business flow filtering model to obtain the set of probe flows.

[0089] That is, the set of business flows is used as the input parameter of the business flow screening model, and a greedy heuristic algorithm is used to approximate the solution of the model. Here, the greedy heuristic algorithm can make a locally optimal choice at each step to obtain an approximate solution.

[0090] Specifically, the above solution process may include the following steps (A) to (C): (A) Using the service flow set as the input parameter of the service flow filtering model, if the target link set is not empty, determine the target service flow from the service flow set and determine the coverage ratio of the target service flow; the coverage ratio is the ratio of the path length corresponding to the target service flow to the number of target links, and the number of target links is the number of links contained in the intersection of the links expected to be covered by the target service flow and the target link set.

[0091] (B) The target service flow with the smallest ratio is taken as the probe service flow, and the link corresponding to the service flow with the smallest ratio is removed from the target link set.

[0092] (C) Repeat the above steps until the target link set is empty, and generate the probe flow set based on each probe service flow.

[0093] First, initialize the probe flow set C as an empty set and the total path length W of the selected service flows as 0. Then, take the service flow set as input. If the target link set... If the set is not empty (meaning there are still uncovered links), proceed to the loop process: determine the target service flow from the service flow set (the target service flow can be understood as an unselected candidate service flow), and determine the coverage ratio of the target service flow. The coverage ratio is the ratio of the path length corresponding to the target service flow to the number of target links, where the number of target links is the ratio of the path length corresponding to the target service flow to the number of target links.

[0094] The coverage ratio is given by formula (8): (8) in, This represents the path length of the business flow. For the first i A business flow.

[0095] In other words, using the above formula, the optimal service flow (i.e., the target service flow with the smallest ratio) is determined from the service flows that can cover the current remaining links in the target link set, and the selected target service flow is added to the probe flow set C (C ← C∪). ),Will The path lengths are accumulated into the total path length W, and the target link set is updated simultaneously. (Set of target links) Removed from (covered links), until the target link set. If the set is empty, the loop process ends, and the probe flow set C and the total path length W are obtained.

[0096] In this embodiment, the problem of filtering business flows is transformed into an NP-hard set coverage problem. This application employs a greedy heuristic algorithm for solving this problem, which improves efficiency. Furthermore, the greedy heuristic algorithm has polynomial time complexity, enabling the filtering of ultra-large-scale candidate flow sets within seconds or even milliseconds. This ensures system agility; specifically, if the network topology or routing strategy changes, a new optimal probe flow set can be quickly recalculated and distributed, ensuring the monitoring system always maintains high coverage and high efficiency.

[0097] Please see Figure 6 and Figure 7 , Figure 6 A graph illustrating the relationship between packet loss rate and time is provided as an exemplary embodiment of this application. Figure 7 This is a schematic diagram illustrating the impact of traffic filtering on network overhead, provided as an exemplary embodiment of this application.

[0098] like Figure 6 As shown, the horizontal axis represents time (seconds), and the vertical axis represents the packet loss rate (percentage). Each scatter point in the graph represents the change in the packet loss rate at the corresponding time. During the observation period of 60 seconds, the maximum packet loss rate is 7%. That is, the above method can keep the packet loss rate at a low level, which is beneficial to improving the network response speed.

[0099] Figure 7The horizontal axis represents different networks (including Bell Canada (BC), US (US), VW (VW), Tata (TT), Coggent (CG), and Sprint (SL),) and the vertical axis represents network overhead in hop count. Fewer hops mean fewer network devices the data packet needs to pass through, resulting in a better path, lower latency, and less resource consumption. Yellow bars represent detection overhead without traffic flow filtering, while green bars represent detection overhead with traffic flow filtering. As the caption shows, monitoring all traffic flows would lead to unnecessary overhead for any given network. Through the aforementioned traffic flow filtering, a 74% to 98% reduction in overhead was observed in six typical network environments, while ensuring complete coverage. Network overhead was significantly reduced.

[0100] Please see Figures 8-9 , Figure 8 An architecture diagram of an attack scenario provided as an exemplary embodiment of this application. Figure 9 This is a schematic diagram illustrating the impact of an attack, provided as an exemplary embodiment of this application.

[0101] Figure 8 The diagram illustrates a network architecture for an attack scenario. The network consists of six routers running the OSPF protocol, each with a unique identifier (Router-ID). These routers include the attacker (6.6.6.6), the victim (1.1.1.1), and other routers (2.2.2.2, 3.3.3.3, 4.4.4.4, and 5.5.5.5).

[0102] In this attack, attacker 6.6.6.6 forged an LSA that pretended to originate from victim 1.1.1.1 (an LSA spoofing attack). The forged information included: claiming that victim router 1.1.1.1 had a direct link to 5.5.5.5, and that this link's metric was 10 (i.e., OSPF Link 5.5.5.5metric:10 AD:1.1.1.1). This forged LSA was injected into the network and ultimately received and stored in victim 1.1.1.1's Link State Database (LSDB). This meant the victim router was "tricked" into believing that its local routing table contained a link that did not exist.

[0103] Figure 9The diagram shows the routing anomaly detection results after the attack took effect. The victim 1.1.1.1 and other routers were identified, and it indicates that in a certain routing table entry, the old next hop was 1.1.1.1, but the new next hop became 3.3.3.3. f(1,2,0,0,1) is the anomaly diagnosis result, which indicates that: the first bit being 1 indicates the existence of a routing anomaly, the second bit being 2 indicates that the distance from the last router to the current router is 2, and the last bit being 1 directly confirms the existence of a routing loop.

[0104] Corresponding to the above-described network routing anomaly detection method, this disclosure also provides a computer device, such as... Figure 10 The diagram shown is a structural schematic of a computer device provided in an embodiment of this disclosure. Figure 10 As shown, the computer device 1000 includes a processor 1010, an internal bus 1020, memory 1030, a network interface 1040, and non-volatile memory 1050, and may also include other hardware required for its functions. One or more embodiments of this specification can be implemented in software, for example, the processor 1010 reads the corresponding computer program from the non-volatile memory 1050 into the memory 1030 and then runs it. Of course, besides software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution entity of the following processing flow is not limited to individual logic units, but can also be hardware or logic devices.

[0105] The memory 1030, also known as internal memory, is used to temporarily store the computational data in the processor 1010, as well as the data exchanged with non-volatile memory 1050 such as hard disk. The processor 1010 exchanges data with the non-volatile memory 1050 through the memory 1030.

[0106] In this embodiment, memory 1030 is specifically used to store application code that executes the solution of this application, and its execution is controlled by processor 1010. That is, when the computer device is running, processor 1010 communicates with network interface 1040, memory 1030 and non-volatile memory 1050 through internal bus 1020, so that processor 1010 executes the application code stored in memory 1030 and non-volatile memory 1050, thereby executing the network routing anomaly detection method described in the above method embodiment.

[0107] Processor 1010 may be an integrated circuit chip with signal processing capabilities. The aforementioned processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware microservices. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this invention. The general-purpose processor can be a microprocessor or any conventional processor.

[0108] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the computer device 1000. In other embodiments of this application, the computer device 1000 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0109] This disclosure also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the network routing anomaly detection method described in the above method embodiments. The storage medium can be a volatile or non-volatile computer-readable storage medium.

[0110] This disclosure also provides a computer program product carrying program code. The program code includes instructions that can be used to execute the steps of the network routing anomaly detection method in the above method embodiments. For details, please refer to the above method embodiments, which will not be repeated here.

[0111] The aforementioned computer program product can be implemented through hardware, software, or a combination thereof. In one optional embodiment, the computer program product is specifically embodied in a computer storage medium; in another optional embodiment, the computer program product is specifically embodied in a software product, such as a software development kit (SDK), etc.

[0112] The embodiments of the subject matter and functional operation described in this specification can be implemented in the following ways: digital electronic circuits, tangibly embodied computer software or firmware, computer hardware including the structures disclosed in this specification and their structural equivalents, or combinations thereof. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible, non-transitory program carrier for execution by a data processing apparatus or for controlling the operation of a data processing apparatus. Alternatively or additionally, the program instructions may be encoded on artificially generated propagation signals, such as machine-generated electrical, optical, or electromagnetic signals, which are generated to encode information and transmit it to a suitable receiving device for execution by the data processing apparatus. The computer storage medium may be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or combinations thereof.

[0113] The processing and logic flow described in this specification can be executed by one or more programmable computers that execute one or more computer programs to perform corresponding functions by operating on input data and generating output. The processing and logic flow can also be executed by dedicated logic circuitry—such as FPGAs (Field-Programmable Gate Arrays) or ASICs (Application-Specific Integrated Circuits), and the device can also be implemented as dedicated logic circuitry.

[0114] Computers suitable for executing computer programs include, for example, general-purpose and / or special-purpose microprocessors, or any other type of central processing unit. Typically, the central processing unit receives instructions and data from read-only memory and / or random access memory. Basic computer microservices include a central processing unit for implementing or executing instructions and one or more memory devices for storing instructions and data. Typically, a computer will also include one or more mass storage devices for storing data, such as disks, magneto-optical disks, or optical disks, or the computer will be operatively coupled to such mass storage devices to receive data from or transfer data to them, or both. However, a computer is not required to have such devices. Furthermore, a computer can be embedded in another device, such as a mobile phone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a global positioning system (GPS) receiver, or a portable storage device such as a universal serial bus (USB) flash drive, to name a few.

[0115] Computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media, and memory devices, such as semiconductor memory devices (e.g., EPROM, EEPROM, and flash memory devices), magnetic disks (e.g., internal hard disks or removable disks), magneto-optical disks, and CD-ROM and DVD-ROM disks. Processors and memory may be supplemented by or incorporated into dedicated logic circuitry.

[0116] While this specification contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope of the claims, but rather are primarily intended to describe features of specific embodiments of a particular invention. Certain features described in the various embodiments herein may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in various embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described above and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation thereof.

[0117] Similarly, although the operations are depicted in a specific order in the accompanying drawings, this should not be construed as requiring these operations to be performed in the specific order shown or sequentially, or requiring all illustrated operations to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Furthermore, the separation of various system modules and microservices in the above embodiments should not be construed as requiring such separation in all embodiments, and it should be understood that the described program microservices and systems can generally be integrated together in a single software product or packaged into multiple software products.

[0118] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings are not necessarily shown in a specific order or sequence to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.

[0119] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for detecting anomalies in network routing, characterized in that, A central controller applied in a target network, the target network further comprising multiple network devices respectively connected to the central controller, the method comprising: The system receives probe result information sent by a network device. The probe result information is obtained based on path probing of probe data packets in the target probe service flow passing through the network device. The probe result information includes actual path encoding, which reflects the actual forwarding path of the probe data packets in the target network. Obtain the expected path code of the target probe service flow. If the actual path code is different from the expected path code, based on the actual path code, use a preset routing anomaly detection mechanism to perform device forwarding offset detection, network segment offset detection, and loop path detection on the actual forwarding path to obtain anomaly detection results. The expected path encoding is used to characterize the expected forwarding path followed by the target probe service flow under normal routing conditions; the anomaly detection result includes the network device identifier where the path deviation occurred, the network segment information where the path deviation occurred, and whether the actual forwarding path includes a loop path; the anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

2. The method according to claim 1, characterized in that, The routing anomaly detection mechanism includes path offset detection rules, network segment offset detection rules, and loop detection rules. Based on the actual path encoding, and using the preset routing anomaly detection mechanism, the actual forwarding path is subjected to device forwarding offset detection, network segment offset detection, and loop path detection to obtain anomaly detection results, including: Using the path offset detection rules, based on the actual path code and the expected path code, path offset detection is performed to obtain the network device identifier where the path offset occurred; Using the aforementioned offset network segment detection rules, based on the actual path encoding and the expected path encoding, offset network segment detection is performed to obtain the network segment information where the path offset has occurred. Using the loop detection rules, loop routing detection is performed based on the actual path encoding to obtain a routing loop detection result; the routing loop detection result is used to indicate whether the actual forwarding path includes a loop path; The anomaly detection result is generated based on the network device identifier where the path offset occurred, the network segment information where the path offset occurred, and the routing loop detection result.

3. The method according to claim 2, characterized in that, The step of using the loop detection rules to perform loop routing detection based on the actual path code to obtain the routing loop detection result includes: Based on the actual path encoding, it is determined whether the actual forwarding path meets the preset routing loop condition. If the routing loop condition is met, it is determined that the actual forwarding path includes a loop path, and the routing loop detection result is obtained. The routing loop condition refers to the fact that two network devices located at different positions in the actual forwarding path are the same, and the network devices at any two consecutive positions within the path segment between the different positions are different.

4. The method according to any one of claims 1-3, characterized in that, After obtaining the anomaly detection result, the method further includes: The anomaly detection results are structured to generate anomaly diagnosis results; the anomaly diagnosis results include anomaly flags, black hole source distance, path deviation identifiers, number of network device hops of path deviation, and identifier of the first attacked network device.

5. The method according to claim 1, characterized in that, The target network includes multiple links; before receiving the probe result information sent by the network device, the method further includes: Obtain the service flow set of the target network; the service flow set includes multiple service flows. Construct a service flow filtering model; the service flow filtering model includes a path length objective function and constraints. The path length objective function is used to indicate minimizing the sum of the total path lengths of the selected service flows. The constraints are used to indicate that the forwarding path of the selected service flow covers the target link set. The target link set includes the links between each network device and its corresponding destination address prefix. The set of business flows is used as the input parameter of the business flow filtering model, and the greedy heuristic algorithm is used to solve the business flow filtering model to obtain the set of probe flows.

6. The method according to claim 5, characterized in that, The step of using the set of business flows as input parameters to the business flow filtering model and solving the business flow filtering model using a greedy heuristic algorithm to obtain the probe flow set includes: The service flow set is used as the input parameter of the service flow filtering model; when the target link set is not empty, the target service flow is determined from the service flow set, and the coverage ratio of the target service flow is determined; the coverage ratio is the ratio of the path length corresponding to the target service flow to the number of target links, and the number of target links is the number of links contained in the intersection of the links covered by the target service flow and the target link set; The target service flow with the smallest coverage ratio is selected as the probe service flow, and the link corresponding to the service flow with the smallest ratio is removed from the target link set; Repeat the above steps until the target link set is empty, and generate the probe flow set based on each probe service flow.

7. A method for detecting anomalies in network routing, characterized in that, A network device applied in a target network, the target network further including a central controller, the central controller being communicatively connected to the network device; the method includes: Receive a target detection service flow; the target detection service flow includes multiple detection data packets, and the target detection service flow corresponds to an expected forwarding path; For each probe data packet, the actual path code in the telemetry header information of the probe data packet is updated based on the device identifier of the network device; the actual path code is used to reflect the actual forwarding path of the probe data packet in the target network. Based on the location of the network device in the expected forwarding path and the updated probe data packet, probe result information is generated and sent to the central controller. The central controller is used to perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path based on the probe result information, so as to trace the originating network device in the target network where the anomaly occurred.

8. The method according to claim 7, characterized in that, The location of the network device in the actual forwarding path includes the egress location; the generation of probe result information based on the location of the network device in the expected forwarding path and the updated probe data packet includes: If the network device is not the exit location of the actual forwarding path, and the updated probe data packet is not forwarded, the updated probe data packet is copied to obtain a copied probe data packet, and the probe result information is generated based on the copied probe data packet.

9. The method according to claim 8, characterized in that, The generation of the detection result information based on the replicated detection data packet includes: The payload of the copied probe data packet is deleted to obtain a new copied probe data packet, and alarm information is added to the header of the new copied probe data packet to obtain the probe result information; the alarm information includes the device identifier of the network device, the timestamp, the ingress port identifier and the egress port identifier corresponding to the probe data packet.

10. The method according to claim 7 or 8, characterized in that, The location of the network device in the actual forwarding path includes the egress location; the generation of probe result information based on the location of the network device in the expected forwarding path and the updated probe data packet includes: If the network device is the exit point of the actual forwarding path, the telemetry header information is stripped from the header information of the probe data packet sent by the preceding network device. The actual path code is extracted from the telemetry header information, and the detection result information is generated based on the actual path code and the network identifier of each network device corresponding to the actual path code.

11. An anomaly detection system for network routing, characterized in that, Includes a central controller and multiple network devices connected to the central controller; The network device is used to perform path probing based on probe data packets in the target probe service flow to obtain probe result information, and sends the probe result information to the central controller; the probe result information includes actual path encoding, which reflects the actual forwarding path of the probe data packets in the target network; The central controller is used to receive the detection result information and obtain the expected path code of the target detection service flow. If the actual path code is different from the expected path code, based on the actual path code, a preset routing anomaly detection mechanism is used to perform device forwarding offset detection, network segment offset detection and loop path detection on the actual forwarding path to obtain the anomaly detection result. The expected path encoding is used to characterize the expected forwarding path followed by the target probe service flow under normal routing conditions; the anomaly detection result includes the network device identifier where the path deviation occurred, the network segment information where the path deviation occurred, and whether the actual forwarding path includes a loop path; the anomaly detection result is used to trace the originating network device in the target network where the anomaly occurred.

12. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method as described in any one of claims 1-6 or 7-10.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method as described in any one of claims 1-6 or 7-10.