Method, device, electronic device and medium for determining a network topology map
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2023-11-30
- Publication Date
- 2026-06-02
AI Technical Summary
The existing network topology graph generation tool generates charts based on device connection information, lacks partition display, and is chaotic and difficult to understand.
By obtaining the IP address and connection relationship of the asset device, using image recognition or natural language processing technology to obtain information representing the partitioning method, partitioning the asset device, and determining the network topology diagram based on the partitioning results.
The generated network topology map contains partition information, enriches the display content, improves readability and management efficiency.
Smart Images

Figure CN122139346A_ABST
Abstract
Description
Method, device, electronic device and medium for determining network topology Technical Field
[0001] The present invention relates to the technical field of network topology, and in particular to a method, device, electronic device and medium for determining a network topology graph. Background Art
[0002] Network topology refers to the physical layout of various devices interconnected by transmission media. Currently, many automatic network topology generation tools create a graphical representation of the network structure (called a network topology diagram) based on the connection information of the network's asset devices (for example, the IP addresses of the asset devices or the communication behavior between the asset devices).
[0003] However, network topology diagrams based on the connection information of network devices can only show the connection relationships between asset devices, which has the disadvantage of being limited in content. For example, these network topology diagrams do not display partitions, making the layout confusing and difficult to understand.
[0004] Summary of the Invention
[0005] The embodiments of the present invention provide a method, device, electronic device and medium for determining a network topology graph.
[0006] A method for determining a network topology graph, the method comprising:
[0007] Determine the IP addresses of asset devices in the network and the connection relationships between the asset devices;
[0008] Acquire first information, where the first information represents a partitioning method for partitioning the asset devices based on IP addresses of the asset devices and / or connection relationships between the asset devices;
[0009] Partitioning the asset device based on the first information;
[0010] Based on the partitioning result, a network topology map of the network is determined.
[0011] Therefore, by partitioning the asset devices using the first information representing the partitioning method, a network topology can be determined based on the partitioning results. The network topology includes partitions determined based on IP addresses and / or connection relationships, which not only enriches the display content and facilitates users to understand the partition attributes of the asset devices, but also rationalizes the layout of the topology map and improves readability.
[0012] In one embodiment, the first information is a first partition instruction;
[0013] The acquiring of the first information includes:
[0014] Acquire an image representing the partitioning method in a combination of graphics and characters;
[0015] performing optical character recognition (OCR) on the image to identify the combined pattern;
[0016] Determining the partitioning mode based on the combination mode;
[0017] A first partitioning instruction including the partitioning mode is generated.
[0018] Therefore, by performing OCR on the image, the partitioning operation of the network topology map can be quickly achieved, reducing the difficulty of user operation.
[0019] In one embodiment, the first information is a second partition instruction;
[0020] The acquiring of the first information includes:
[0021] Obtaining natural language text describing the partitioning method;
[0022] performing natural language processing on the natural language text to determine the partitioning method;
[0023] A second partitioning instruction including the partitioning mode is generated.
[0024] Therefore, the partitioning operation of the network topology diagram can be quickly implemented through natural language text, reducing the difficulty of user operation.
[0025] In one embodiment, obtaining a natural language text describing the partitioning method includes:
[0026] Obtaining an audio file describing the partitioning method;
[0027] Speech recognition is performed on the audio file to obtain the natural language text.
[0028] Therefore, by performing speech recognition on audio files, the interaction mode is enriched and the interaction efficiency is improved.
[0029] In one embodiment, the combination mode includes:
[0030] A partition represented by a predetermined graphic;
[0031] an IP address range represented by a first character string in the graph that conforms to an IP address format;
[0032] a partition name represented by a second character string in the graph;
[0033] The determining of the partitioning mode based on the combination mode includes:
[0034] The asset devices in the IP address range are determined to belong to the partition named by the partition name.
[0035] Therefore, the combination pattern can include graphics, and can also include IP address ranges and partition names represented by character strings, thereby achieving a partitioning effect based on IP address ranges and enriching the selectivity of partitioning.
[0036] In one embodiment, the combination mode includes:
[0037] A partition represented by a predetermined graphic;
[0038] an IP address range represented by a first character string in the graph that conforms to an IP address format;
[0039] an IP address of the switch represented by a second character string in the graph that conforms to an IP address format;
[0040] a partition name represented by a third character string in the image;
[0041] The determining of the partitioning mode based on the combination mode includes:
[0042] The asset devices in the IP address range and connected to the switch IP address are determined to belong to the partition named by the partition name.
[0043] Therefore, the combination mode can include graphics, and can also include IP address ranges, switch IP addresses and partition names represented by strings, thereby achieving a partitioning effect based on the IP address range and the understanding status with the switch, enriching the partitioning options.
[0044] A device for determining a network topology graph, the device comprising:
[0045] A first determining module is used to determine the IP addresses of asset devices in the network and the connection relationships between the asset devices;
[0046] An acquisition module, configured to acquire first information, where the first information represents a partitioning method for partitioning the asset devices based on IP addresses of the asset devices and / or connection relationships between the asset devices;
[0047] A partitioning module, configured to partition the asset device based on the first information;
[0048] The second determining module is configured to determine a network topology graph of the network based on a result of the partitioning.
[0049] Therefore, by partitioning the asset devices using the first information representing the partitioning method, a network topology can be determined based on the partitioning results. The network topology includes partitions determined based on IP addresses and / or connection relationships, which not only enriches the display content and facilitates users to understand the partition attributes of the asset devices, but also rationalizes the layout of the topology map and improves readability.
[0050] In one embodiment, the first information is a first partition instruction;
[0051] The acquisition module is used to acquire an image that represents the partition method in a combination pattern of graphics and characters; perform OCR on the image to identify the combination pattern; determine the partition method based on the combination pattern; and generate a first partition instruction containing the partition method.
[0052] Therefore, by performing OCR on the image, the partitioning operation of the network topology map can be quickly achieved, reducing the difficulty of user operation.
[0053] In one embodiment, the first information is a second partition instruction;
[0054] The acquisition module is used to acquire a natural language text describing the partitioning method; perform natural language processing on the natural language text to determine the partitioning method; and generate a second partitioning instruction containing the partitioning method.
[0055] Therefore, the partitioning operation of the network topology diagram can be quickly implemented through natural language text, reducing the difficulty of user operation.
[0056] In one embodiment, the combination mode includes:
[0057] A partition represented by a predetermined graphic;
[0058] an IP address range represented by a first character string in the graph that conforms to an IP address format;
[0059] a partition name represented by a second character string in the graph;
[0060] The acquisition module is used to determine the asset devices in the IP address range as belonging to the partition named as the partition name.
[0061] Therefore, the combination pattern can include graphics, and can also include IP address ranges and partition names represented by character strings, thereby achieving a partitioning effect based on IP address ranges and enriching the selectivity of partitioning.
[0062] In one embodiment, the combination mode includes:
[0063] A partition represented by a predetermined graphic;
[0064] an IP address range represented by a first character string in the graph that conforms to an IP address format;
[0065] an IP address of the switch represented by a second character string in the graph that conforms to an IP address format;
[0066] a partition name represented by a third character string in the image;
[0067] The acquisition module is configured to determine the asset devices in the IP address range that are connected to the switch IP address as belonging to the partition named with the partition name.
[0068] Therefore, the combination mode can include graphics, and can also include IP address ranges, switch IP addresses and partition names represented by strings, thereby achieving a partitioning effect based on the IP address range and the understanding status with the switch, enriching the partitioning options.
[0069] An electronic device, comprising:
[0070] processor;
[0071] a memory for storing executable instructions of the processor;
[0072] The processor is configured to read the executable instructions from the memory and execute the executable instructions to implement the method for determining a network topology map as described in any one of the above items.
[0073] A computer-readable storage medium stores computer instructions thereon, wherein when the computer instructions are executed by a processor, the method for determining a network topology diagram as described in any one of the above items is implemented.
[0074] A computer program product comprises a computer program, wherein when the computer program is executed by a processor, the method for determining a network topology map as described in any one of the above items is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, so that those skilled in the art will understand the above and other features and advantages of the present invention more clearly. In the accompanying drawings:
[0076] FIG1 is an exemplary flow chart of a method for determining a network topology graph according to an embodiment of the present invention.
[0077] FIG. 2 is an exemplary schematic diagram of an image representing a partitioning method according to an embodiment of the present invention.
[0078] FIG3 is an exemplary schematic diagram of a network topology diagram according to an embodiment of the present invention.
[0079] FIG4 is an exemplary schematic diagram of determining a network topology diagram based on artificial intelligence (AI) according to an embodiment of the present invention.
[0080] FIG5 is an exemplary structural diagram of an apparatus for determining a network topology according to an embodiment of the present invention.
[0081] FIG6 is an exemplary structural diagram of an electronic device according to an embodiment of the present invention.
[0082] The accompanying drawings are numerals as follows: DETAILED DESCRIPTION
[0083] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is further described in detail with reference to the following examples.
[0084] For the sake of brevity and intuitiveness in description, the solution of the present invention is explained below by describing several representative implementations. A large number of details in the implementations are only used to help understand the solution of the present invention. However, it is obvious that the technical solution of the present invention may not be limited to these details when implemented. In order to avoid unnecessarily obscuring the solution of the present invention, some implementations are not described in detail, but only a framework is given. Hereinafter, "including" means "including but not limited to", and "according to..." means "at least according to..., but not limited to only according to...". Due to the language habits of Chinese, when the number of a component is not specifically specified below, it means that the component can be one or more, or can be understood as at least one.
[0085] Current network topology automatic generation tools typically focus more on the network connections and communication behaviors between network assets (which can be called asset devices) rather than the physical layout of the assets. Therefore, the generated network topology often lacks sufficient information to identify the physical location of specific assets. For example, current network topology diagrams struggle to reflect the various nuances and logic involved in actual network design and layout by network administrators. As a result, these automatically generated network topology diagrams can appear confusing and difficult to read, and they often struggle to present network assets in a manner consistent with administrator-defined zones (e.g., demilitarized zones (DMZs), production zones, etc.).
[0086] The above disclosure details the technical defects in the prior art, the causes of these defects, and the analytical process for overcoming them. In reality, the understanding of these technical defects is not common knowledge in the field, but rather a novel discovery made by the applicant during their research. Furthermore, the tracing of the causes of these defects and the analytical process for overcoming them are the result of gradual analysis conducted by the applicant during their actual research and are not common knowledge in the field.
[0087] In fact, in many scenarios, enhancing automatically generated network topology maps is an important research and development topic. In the embodiments of the present invention, a network topology map with partitioning effects is generated based on an information-based partitioning method. Partitioning can be performed according to the partitioning method predefined by the administrator. The partitioning can centrally reflect the geographical location (IP location) and connection relationship of assets, thereby significantly improving the efficiency and effectiveness of network management.
[0088] The embodiments of the present invention propose a technical solution for determining a network topology map, which can be implemented as a software module (such as an application (APP), applet or plug-in, etc.), firmware module, component module or hardware module deployed on a network management device.
[0089] For example, when the embodiment of the present invention is implemented as a software module, the software module can be integrated into current network topology automatic discovery tools (such as NetBrain, Nmap or Topology-Scanner, etc.) to form a network topology map integrated management tool suitable for installation at a network management device. When the embodiment of the present invention is implemented as a hardware module, the hardware module can be integrated into a host, router, switch or firewall device in the network to form a hardware device with network topology map management capabilities.
[0090] Figure 1 is an exemplary flow chart of a method for determining a network topology according to an embodiment of the present invention. The method flow in Figure 1 can be implemented in a network management device. The network management device can include any node with computing capabilities in the network or a network management center connected to the network. For example, the network management device can be implemented as a host, router, switch, or firewall device in the network.
[0091] As shown in FIG1 , the method includes:
[0092] Step 101: Determine the IP addresses of asset devices in the network and the connection relationships between the asset devices.
[0093] Here, asset devices are devices in the network for which the network topology is to be determined. For example, asset devices may include hosts, network devices (routers, switches, etc.), and security devices (firewalls, etc.).
[0094] Automatic network topology discovery can be performed to determine the IP addresses of asset devices in the network and the connection relationships between asset devices. Preferably, the asset device type can be further determined, etc. For example, specific methods for automatic network topology discovery may include: (1) a network topology discovery method based on the Simple Network Management Protocol (SNMP); (2) a network topology discovery method based on a general protocol; (3) a network topology discovery method based on a routing protocol, etc.
[0095] Specifically, network topology automatic discovery can be implemented as follows:
[0096] (1) Topology discovery at the network layer: Specific steps may include: obtaining a list of existing subnets through the default gateway router, then traversing all active devices in the specified subnet through Internet Control Message Protocol (ICMP) or Address Resolution Protocol (ARP) information in the router, and searching for the device's community name in the community name database. If found, the basic information of the device is obtained using the SNMP protocol, and the device type (router, switch, firewall, UPS, etc.) is determined. Based on this, detailed information of the corresponding device is obtained. If the device's community name is not found, the device is assumed to be a host.
[0097] (2) Link layer topology discovery: For switches and routers, the principle of link layer topology discovery is to determine the connection relationship of each switch based on the switch's Neighbor Discovery Protocol (CDP) neighbor table, the port's interface index (ifIndex), the port correspondence table, and the self-learning table. The specific steps include: obtaining the ARP table information of all routers, and for hosts, obtaining ARP information by sending ARP (Send ARP) or NetBIOS; obtaining the CDP neighbor table, the port's interface index, the port correspondence table, and the self-learning table of all switches; and determining the interconnection relationship of the switches. If a port on a switch learns the router's Media Access Control (MAC) address, this port is considered an uplink port. If only one port on the switch has a self-learning table entry, this port is also considered an uplink port. If a switch's uplink port is not connected to other switches, this switch is the root switch. For each switch, if a port on it conflicts with multiple ports on other roots, the connection relationship is corrected using CDP information.
[0098] (3) Topology discovery at the routing layer: The principle of topology discovery at the routing layer is to trace all device nodes. Based on the returned routing path, the routing topology relationship of the related devices can be obtained. The specific steps include: first, find the root node. If there is no root node, generate one; then call Trace Route for each non-router device and delete the tree nodes with device ID 0 and no child nodes. Change the device type to a router if it is a host but has child nodes. For the problem of multi-access routers, you can check whether the routers' Open Science Identity (OSID) is consistent to determine whether they belong to the same router.
[0099] The above exemplary description is a typical example of determining the IP addresses of asset devices in the network and the connection relationships between asset devices based on automatic discovery of network topology. Those skilled in the art will appreciate that this description is merely exemplary and is not intended to limit the scope of protection of the embodiments of the present invention.
[0100] Step 102: Obtain first information, where the first information represents a partitioning method for partitioning asset devices based on IP addresses of asset devices and / or connection relationships between asset devices.
[0101] In the first information, a partitioning method for partitioning the asset devices based on the IP addresses of the asset devices and / or the connection relationships between the asset devices is indicated.
[0102] Specifically, the partitioning mode indicated by the first information includes at least one of the following:
[0103] (1): Partition all asset devices based on their IP addresses;
[0104] (2): Partition all assets and devices based on the connection relationship between each asset and device;
[0105] (3): Partition all asset devices based on their IP addresses and the connection relationships between them.
[0106] In one embodiment, the first information is a first partitioning instruction for instructing to perform partitioning processing on the asset equipment discovered in step 101; obtaining the first information in step 102 includes: obtaining an image that represents the partitioning method in a combination pattern of graphics and characters; performing optical character recognition (OCR) on the image to identify the combination pattern; determining the partitioning method based on the combination pattern; and generating a first partitioning instruction including the partitioning method.
[0107] In one embodiment, a specific method of acquiring an image representing the partitioning method may include:
[0108] Method (1): The user draws a sketch on paper that represents the partitioning method. The sketch contains a combination of graphics and characters. For example, the user draws a rectangle on paper and writes "work area" and "192.168.1.0 / " in the rectangle. Among them: the rectangle represents the partition; "work area" is the name of the partition represented by the rectangle; "192.168.1.0 / " is the IP address rule that all asset devices in the partition represented by the rectangle must comply with. Then, the user uses a handheld device to take a photo of the hand-drawn sketch on the paper to obtain an image representing the partitioning method. The user can send the image to the network management device that executes the process shown in Figure 1 through the mobile communication method of the handheld device. The network management device then performs OCR on the image to determine the partitioning method.
[0109] In method (1), based on the sketch drawn by the user, the partitioning method can be automatically identified and the first partitioning instruction can be automatically generated, thus laying the foundation for subsequent automatic partitioning.
[0110] Method (2): The user draws a sketch representing the partitioning method on a smart device equipped with an electronic drawing tool. The sketch contains a combination of graphics and characters. For example, the user draws a rectangle on the electronic screen and writes "server area" and "192.168.1.0 / " in the rectangle. Among them: the rectangle represents the partition; "server area" is the name of the partition represented by the rectangle; "192.168.1.0 / " is the IP address rule that all asset devices in the partition represented by the rectangle must comply with. Then, the user can use a handheld device to take a photo of the sketch on the electronic screen (or save the sketch as a file in the smart device) to obtain an image representing the partitioning method. The user can send the image to the network management device that executes the process shown in Figure 1 through the mobile communication capability of the handheld device or the smart device. The network management device then performs OCR on the image to determine the partitioning method.
[0111] In method (2), based on the sketch drawn by the user on the electronic screen, the partitioning method can be automatically identified and the first partitioning instruction can be automatically generated, thereby laying the foundation for subsequent automatic partitioning.
[0112] In one embodiment, the first information is a second partitioning instruction for instructing to perform partitioning processing on the asset equipment discovered in step 101; obtaining the first information in step 102 includes: obtaining a natural language text describing the partitioning method; performing natural language processing (NLP) on the natural language text to determine the partitioning method; and generating a second partitioning instruction including the partitioning method. For example, an artificial intelligence model can be used to perform NLP on the natural language text to determine the partitioning method. Specifically, the artificial intelligence model can be implemented as a BERT model. BERT is driven by a powerful neural network architecture, namely Transformers. This architecture includes a mechanism called self-attention, which allows the BERT model to weigh the importance of each word based on its context (previous and next context). This contextual awareness gives the BERT model the ability to generate contextualized word embeddings, which are representations generated taking into account their meaning in a sentence.
[0113] Therefore, the partitioning operation of the network topology diagram can be quickly implemented through natural language text, reducing the difficulty of user operation.
[0114] In one embodiment, obtaining the natural language text describing the partitioning method includes: obtaining an audio file describing the partitioning method; and performing speech recognition on the audio file to obtain the natural language text.
[0115] It can be seen that natural language processing can also be performed on natural language text to identify the partitioning method and automatically generate the second partitioning instruction. Among them, by performing voice recognition on audio files, the interaction method is enriched and the interaction efficiency is improved.
[0116] Step 103: Partition the asset device based on the first information.
[0117] For example, the asset device is partitioned by executing the first partition instruction or the second partition instruction.
[0118] In one embodiment, the combination pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a partition name represented by a second string in the graphic; based on the combination pattern, determining the partition method includes: determining the asset devices in the IP address range as belonging to the partition named as the partition name.
[0119] Therefore, the combination pattern can include graphics, as well as IP address ranges and partition names represented by strings, achieving a partitioning effect based on IP address ranges and enriching the partitioning options.
[0120] In one embodiment, the combination pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a switch IP address represented by a second string in the graphic that conforms to the IP address format; and a partition name represented by a third string in the image; based on the combination pattern, determining the partitioning method includes: determining an asset device in the IP address range that is connected to the switch IP address as belonging to a partition named as the partition name.
[0121] Therefore, the combination mode includes graphics, as well as IP address ranges, switch IP addresses, and partition names represented by strings, achieving a partitioning effect based on IP address ranges and the understanding status with the switch, enriching the selectivity of partitioning.
[0122] Step 104: Based on the partitioning result, determine the network topology map of the network.
[0123] Here, all asset devices are partitioned using the partitioning result in step 103, thereby determining a network topology diagram of the network. Preferably, the network topology diagram can be displayed in various types of graphical interfaces.
[0124] FIG. 2 is an exemplary schematic diagram of an image representing a partitioning method according to an embodiment of the present invention.
[0125] In FIG2 , an image (e.g., a hand-drawn image on paper or an image drawn on an electronic screen) includes three regions represented by graphical rectangles, namely a first region 10, a second region 13, and a third region 14. The image also includes a fourth region 19 represented by a graphical cloud.
[0126] The graphical rectangle of the first partition 10 contains two character strings drawn by hand or using a drawing tool. These two character strings are: the name of the first partition 11 (for example, the specific character string is "work area") and the IP address range of the first partition 12 (for example, the specific character string is "192.168.1.0 / ").
[0127] The graphical rectangle of the second zone 13 contains two character strings drawn by hand or using a drawing tool. These two character strings are: the name of the second zone 14 (for example, the specific character string is "server zone") and the IP address range of the second zone 15 (for example, the specific character string is "10.0.0.0 / ").
[0128] The graphical rectangle of the third zone 17 contains two character strings drawn by hand or using a drawing tool. These two character strings are: the name of the third zone 17 (for example, the specific character string is "DMZ Zone") and the IP address range 15 of the third zone (for example, the specific character string is "172.16.0.0 / ").
[0129] The graphical cloud shape of the fourth partition 19 includes a character string drawn by hand or using a drawing tool, which is the name 20 of the fourth partition (for example, the specific character string is "Internet").
[0130] Pre-defined combination patterns include: representing a partition as a rectangle or cloud; representing an IP address range as the first string within the rectangle or cloud that conforms to the IP address format; and representing the partition name as a string within the rectangle or cloud that does not conform to the IP address format. This combination pattern also includes: if the cloud does not contain an IP address range, all assets that do not fall within any of the IP address ranges within the rectangle are assigned to the partition corresponding to the cloud. By parsing the string that conforms to the IP address format, the IP address range can be determined.
[0131] In one embodiment, a user can hand-draw the image shown above on paper. The user can then use a camera in a handheld device (e.g., a smartphone, laptop, or PDA, etc.) to capture the image and send the image (e.g., via mobile communication) to the network management device executing the process shown in FIG1 . In another embodiment, the user can directly capture the image by invoking the camera in the network management device executing the process shown in FIG1 .
[0132] The network management device executing the process shown in FIG1 performs OCR on the image to identify the predetermined graphic (rectangle or cloud) and the character string in the graphic, thereby identifying the combination pattern. Based on the analytical relationship between the combination pattern and the partitioning method, the partitioning method can be determined to include:
[0133] (1) The first partition named "Work Zone" contains all asset devices with IP addresses belonging to 192.168.1.0 / , that is, the IP address range is: 192.168.1.0 ~ 192.168.1.255.
[0134] (2) The second partition named "Server Zone" includes all asset devices with IP addresses belonging to 10.0.0.0 / , that is, the IP address range is: 10.0.0.0 ~ 10.0.0.255.
[0135] (3) The third zone named “DMZ Zone” includes all assets with IP addresses belonging to 172.16.0.0 / , that is, the IP address range is: 172.16.0.0 ~ 172.16.0.255.
[0136] (4) The fourth partition, named "Internet", includes all assets with IP addresses that are not 192.168.1.0, 10.0.0.0 / , and 172.16.0.0 / .
[0137] Then, the network management device that executes the process shown in Figure 1 generates a first partitioning instruction to apply the above-mentioned partitioning method to all asset devices, and then, based on the execution of the first partitioning instruction, performs partitioning on all asset devices discovered by the network topology automatic tool to generate a network topology map containing the partitioning results.
[0138] FIG3 is an exemplary schematic diagram of a network topology diagram according to an embodiment of the present invention.
[0139] As can be seen in Figure 3: all assets with an IP address of 192.168.1.0 / are assigned to the first partition 10; all assets with an IP address of 10.0.0.0 / are assigned to the second partition 13; all assets with an IP address of 172.16.0.0 / are assigned to the third partition 16; and all assets not assigned to the first, second, and third partitions 10, 13, or 16 are assigned to the fourth partition 19. Preferably, the name of the first partition 10, "Work Zone," can be displayed near the first partition 10; the name of the second partition 13, "Server Zone," can be displayed near the second partition 13; the name of the third partition 13, "DMZ Zone," can be displayed near the third partition 16; and the name of the fourth partition 19, "Internet," can be displayed near the fourth partition 19.
[0140] The above describes in detail a typical process of realizing a network topology map with a partitioning effect according to an embodiment of the present invention based on an image and OCR processing of the image.
[0141] FIG4 is an exemplary schematic diagram of determining a network topology diagram based on artificial intelligence (AI) according to an embodiment of the present invention.
[0142] In FIG4 , the user 30 describes the partitioning method in natural language by voice.
[0143] For example, the user describes the following content in voice: "The first partition named "Work Zone" contains assets and devices with IP addresses in the range of 168.1.0 to 192.168.1.255; the second partition named "Server Zone" contains assets and devices with IP addresses in the range of 10.0.0.0 to 10.0.0.255; the third partition named "DMZ Zone" contains assets and devices with IP addresses in the range of 172.16.0.0 to 172.16.0.255; the fourth partition named "Internet" contains all assets and devices with IP addresses that do not belong to 192.168.1.0, 10.0.0.0 / , and 172.16.0.0 / ."
[0144] An audio stream emitted by a user 30 is recorded to obtain an audio file. A speech recognition process 31 is performed on the audio file to obtain a text file describing the partitioning method in natural language. For example, the speech recognition process 31 can be performed by a pattern matching method. Among them: the speech recognition process 31 can include: a rule-based speech recognition model to recognize speech using manually written rules and patterns; (2) a statistics-based speech recognition model, such as a hidden Markov model (HMM) and a deep belief network (DBN), etc.; (3) a deep learning-based speech recognition model, such as using deep learning algorithms such as a deep neural network (DNN) and a recurrent neural network (RNN) to recognize speech.
[0145] Next, the text file identified by the speech recognition process 31 is input into the Bert model 33 to perform natural language processing on the text file. The Bert model 33 outputs a natural language understanding result represented by an OPCODE (operation code). The output of the Bert model 33 can be further used by a drawing tool so that the drawing tool generates an electronic sketch 34 that conforms to the natural language understanding result based on the operation code. Then, the electronic sketch 34 is displayed in the user interface 35. The user can modify the electronic sketch 34, correct the electronic sketch 34 based on the modification, and correct the operation code output by the Bert model 33 based on the modification. Then, based on the operation code output by the corrected Bert model 33, a partitioning process 36 is performed.
[0146] FIG5 is an exemplary structural diagram of an apparatus for determining a network topology according to an embodiment of the present invention. Apparatus 500 can be integrated into a network management device. For example, the network management device can be implemented as a host, router, switch, or firewall device in the network for which the network topology is to be determined, or can be implemented as a network management center connected to the network.
[0147] As shown in FIG5 , the apparatus 500 for determining a network topology diagram includes:
[0148] The first determination module 501 is used to determine the IP address of the asset device in the network and the connection relationship between the asset devices; the acquisition module 502 is used to obtain first information, and the first information represents a partitioning method for partitioning the asset devices based on the IP address of the asset device and / or the connection relationship between the asset devices; the partitioning module 503 is used to partition the asset devices based on the first information; the second determination module 504 is used to determine the network topology diagram of the network based on the partitioning result.
[0149] In one embodiment, the first information is a first partition instruction; the acquisition module 502 is used to acquire an image that represents a partition method in a combination pattern of graphics and characters, wherein the image represents a partition method in a combination pattern of graphics and characters; perform OCR on the image to identify the combination pattern; determine the partition method based on the combination pattern; and generate a first partition instruction including the partition method.
[0150] In one embodiment, the first information is a second partitioning instruction; the acquisition module 502 is used to obtain natural language text describing the partitioning method; perform NLP on the natural language text to determine the partitioning method; and generate a second partitioning instruction including the partitioning method.
[0151] In one embodiment, the combination pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a partition name represented by a second string in the graphic; and an acquisition module 502 for determining that asset devices in the IP address range belong to a partition named as the partition name.
[0152] In one embodiment, the combination pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a switch IP address represented by a second string in the graphic that conforms to the IP address format; a partition name represented by a third string in the image; and an acquisition module 502 for determining an asset device in the IP address range that is connected to the switch IP address as belonging to a partition named as the partition name.
[0153] The embodiment of the present invention also proposes an electronic device with a processor-memory architecture. Figure 6 is a structural diagram of an electronic device according to an embodiment of the present invention. As shown in Figure 6, the electronic device 600 includes a processor 601, a memory 602, and a computer program stored on the memory 602 and executable on the processor 601. When the computer program is executed by the processor 601, it implements any of the above methods for determining a network topology diagram. Among them, the memory 602 can be specifically implemented as a variety of storage media such as an electrically erasable programmable read-only memory (EEPROM), a flash memory (Flash memory), and a programmable read-only memory (PROM). The processor 601 can be implemented to include one or more central processing units or one or more field programmable gate arrays, wherein the field programmable gate array integrates one or more central processing unit cores. Specifically, the central processing unit or the central processing unit core can be implemented as a CPU, an MCU, or a DSP, and so on.
[0154] It should be noted that not all steps and modules in the above processes and structure diagrams are required, and certain steps or modules can be omitted based on actual needs. The execution order of the steps is not fixed and can be adjusted as needed. The division of the modules is merely for the convenience of describing the functional division adopted. In actual implementation, a module can be implemented by multiple modules, and the functions of multiple modules can be implemented by the same module. These modules can be located in the same device or in different devices.
[0155] The hardware modules in each embodiment can be implemented mechanically or electronically. For example, a hardware module may include a specially designed permanent circuit or logic device (such as a dedicated processor, such as an FPGA or ASIC) for performing a specific operation. The hardware module may also include a programmable logic device or circuit (such as a general-purpose processor or other programmable processor) temporarily configured by software to perform a specific operation. As for whether to implement the hardware module mechanically, or using a dedicated permanent circuit, or using a temporarily configured circuit (such as configured by software), it can be decided based on cost and time considerations.
[0156] The above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A method for determining a network topology diagram, characterized in that, the method includes: determining (101) the IP addresses of the asset devices in the network and the connection relationships between the asset devices; acquiring (102) first information, where the first information characterizes a partitioning method for partitioning the asset devices based on the IP addresses of the asset devices and / or the connection relationships between the asset devices; partitioning (103) the asset devices based on the first information; determining (104) the network topology diagram of the network based on the result of the partitioning.
2. The method according to claim 1, characterized in that, the first information is a first partitioning instruction; the acquiring (102) of the first information includes: acquiring an image representing the partitioning method in a combined pattern of graphics and characters; performing optical character recognition on the image to recognize the combined pattern; determining the partitioning method based on the combined pattern; generating a first partitioning instruction including the partitioning method.
3. The method according to claim 1, characterized in that, the first information is a second partitioning instruction; the acquiring (102) of the first information includes: acquiring a natural language text describing the partitioning method; performing natural language processing on the natural language text to determine the partitioning method; generating a second partitioning instruction including the partitioning method.
4. The method according to claim 3, characterized in that, the acquiring of the natural language text describing the partitioning method includes: acquiring an audio file describing the partitioning method; performing speech recognition on the audio file to obtain the natural language text.
5. The method according to claim 2, characterized in that, the combined pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a partition name represented by a second string in the graphic; the determining of the partitioning method based on the combined pattern includes: determining the asset devices within the IP address range as belonging to the partition named the partition name.
6. The method according to claim 2, characterized in that, the combined pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a switch IP address represented by a second string in the graphic that conforms to the IP address format; a partition name represented by a third string in the image; the determining of the partitioning method based on the combined pattern includes: determining the asset devices within the IP address range that are connected to the switch IP address as belonging to the partition named the partition name.
7. A device for determining a network topology diagram, characterized in that, the device includes: a first determining module (501) for determining the IP addresses of the asset devices in the network and the connection relationships between the asset devices; An acquisition module (502) for acquiring first information, where the first information characterizes a partitioning method for partitioning the asset devices based on the IP addresses of the asset devices and / or the connection relationships between the asset devices; A partitioning module (503) for partitioning the asset devices based on the first information; A second determination module (504) for determining a network topology diagram of the network based on the result of the partitioning.
8. The apparatus according to claim 7, wherein, the first information is a first partitioning instruction; the acquisition module (502) for acquiring an image representing the partitioning method in a combined pattern of graphics and characters; performing optical character recognition on the image to recognize the combined pattern; determining the partitioning method based on the combined pattern; generating a first partitioning instruction including the partitioning method.
9. The apparatus according to claim 7, wherein, the first information is a second partitioning instruction; the acquisition module (502) for acquiring a natural language text describing the partitioning method; performing natural language processing on the natural language text to determine the partitioning method; generating a second partitioning instruction including the partitioning method.
10. The apparatus according to claim 8, wherein, the combined pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a partition name represented by a second string in the graphic; the acquisition module (502) for determining the asset devices within the IP address range as belonging to the partition named the partition name.
11. The apparatus according to claim 8, wherein, the combined pattern includes: a partition represented by a predetermined graphic; an IP address range represented by a first string in the graphic that conforms to the IP address format; a switch IP address represented by a second string in the graphic that conforms to the IP address format; a partition name represented by a third string in the image; the acquisition module (502) for determining the asset devices within the IP address range that are connected to the switch IP address as belonging to the partition named the partition name.
12. An electronic device, wherein, comprising: a processor (601); a memory (602) for storing executable instructions of the processor (601); the processor (601) for reading the executable instructions from the memory (602) and executing the executable instructions to implement the method for determining a network topology diagram according to any one of claims 1-6.
13. A computer-readable storage medium having computer instructions stored thereon, wherein, the computer instructions, when executed by a processor, implement the method for determining a network topology diagram according to any one of claims 1-6.
14. A computer program product, wherein, comprising a computer program, and the computer program, when executed by a processor, implements the method for determining a network topology diagram according to any one of claims 1-6.