A routing anomaly analysis method based on a routing source

CN122764800APending Publication Date: 2026-09-15SHENZHEN FORWARD IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611028480.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-10
Publication Date
2026-09-15

AI Technical Summary

Technical Problem

[0003]通常在网络运维系统中通过一些网络经验值和网络运维海量日志来分析网络故障,此类分析网络故障的方法不仅复杂,还会消耗大量网络资源(比如分析海量的网络日志),却有可能找不到网络故障的根源

Benefits of technology

(1)本发明简化了网络日志记录,只需要记录路由源变化的网络日志,避免在不同设备上重复判断和上报日志,大量减少了网络变化日志的记录。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122764800A_ABST
    Figure CN122764800A_ABST
Patent Text Reader

Abstract

The application discloses a routing source-based routing exception analysis method, which comprises the following steps: firstly, identifying routing sources of all routings in a network according to whole-network routing information; secondly, classifying and managing the routing sources, and reporting routing source migration logs when the routing sources change; and finally, analyzing various routing exception events in combination with network deployment conditions and principles of various routing exceptions. The application directly locates positions of routing exceptions based on routing source analysis, avoids repeated judgment and log reporting on devices, and is convenient for operation and maintenance personnel to timely handle network faults and quickly recover the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network operation and maintenance technology, specifically involving the design of a routing anomaly analysis method based on routing source. Background Technology

[0002] With the continuous expansion of network scale and the popularization of cloud computing applications, network topologies are becoming increasingly complex. When network failures occur, traditional troubleshooting methods (such as manual experience-based judgment and single-point detection) are no longer sufficient to meet the needs of rapid network response. Adopting automated operation and maintenance tools can not only quickly reflect the network's operational status but also promptly locate network faults.

[0003] Network fault analysis in network operations and maintenance systems typically relies on network experience and massive amounts of network logs. This method is complex, resource-intensive (e.g., analyzing vast amounts of logs), and may not pinpoint the root cause. In contrast, route anomaly analysis, based on route entries, generates multiple events and duplicate reports (making it difficult to accurately locate the root cause). Route source analysis, however, can pinpoint the problem to its source. By analyzing route sources (such as AS numbers or IP address prefixes), the initiator or propagation path of the abnormal route can be quickly identified, accurately locating the root cause (e.g., whether the route anomaly stems from configuration errors, malicious attacks, or protocol failures), thus significantly improving operational efficiency. Summary of the Invention

[0004] The purpose of this invention is to propose a routing anomaly analysis method based on routing source, which can accurately identify the routing advertisement source, filter out routing anomalies caused by non-source routes, directly locate the location of the routing anomaly, and avoid repeated judgment and reporting on different devices.

[0005] The technical solution of this invention is: a routing anomaly analysis method based on routing source, comprising the following steps: S1. Identify the routing source of all routes in the network based on the network-wide routing information.

[0006] S2. Classify and manage routing sources, and report routing source migration logs when routing sources change.

[0007] S3. Monitor changes in routing source information, and analyze various routing anomaly events by combining network deployment information and the principles of various routing anomalies.

[0008] Further, step S1 includes the following sub-steps: S11. For the routing protocol in the network where the next hop of route N is 0, determine whether it is a single routing protocol. If yes, proceed to step S12; otherwise, proceed to step S13.

[0009] S12. Use the single routing protocol route source determination process to determine whether a directly connected route source can be found in the single routing protocol. If so, use the directly connected route source as the actual route source of the single routing protocol. Otherwise, proceed to step S13.

[0010] S13. In the redistribution route source of route N, find the routing protocol X whose next hop is not 0, and use the single routing protocol route source determination process to determine whether a directly connected route source can be found in the routing protocol X. If so, the directly connected route source is taken as the actual route source of route N; otherwise, the redistribution route source is taken as the actual route source of route N.

[0011] Furthermore, the single routing protocol route source determination process includes the OSPF protocol route source determination process, the IS-IS protocol route source determination process, and the BGP protocol route source determination process.

[0012] Furthermore, the OSPF protocol route source determination process is as follows: For intra-area routes, the actual advertiser of the route is obtained through OSPF's Router-LSA or Network-LSA as the directly connected route source; for inter-area routes and external routes, if the directly connected route source cannot be found, the search continues to find the actual route source based on the redistributed route source.

[0013] Furthermore, the IS-IS protocol route source determination process is as follows: In narrow metric mode, the advertised route source is distinguished from the redistributed route source based on the flag in the TLV; in wide metric mode, the route is matched with the IP address for network segment to distinguish between the directly connected route source and the redistributed route source.

[0014] Furthermore, the BGP protocol route source determination process is as follows: for routes whose next-hop address is its own IP, if a directly connected route source cannot be found, the search continues to find the actual route source by redistributing the route source.

[0015] Furthermore, the specific method for reporting the routing source migration log when the routing source changes in step S2 is as follows: In response to the detection that the routing source has been deleted, a deletion timer is started.

[0016] If the deleted route source comes back online within the time set by the deletion timer, the deletion timer is canceled.

[0017] In response to a new routing source coming online during the deletion timer's execution, immediately report the routing source migration log.

[0018] Each time a timer expires, check if any deleted timers have expired. If at least one deleted timer has expired, report the routing source migration log.

[0019] Furthermore, step S3 analyzes and identifies various routing anomaly events, including: Based on the legitimacy of the route source location information, we can analyze illegal route advertising and route prefix hijacking.

[0020] Based on the comparison of multi-protocol routing sources, the analysis revealed an anomaly in route redistribution.

[0021] Based on the existence of multiple sources for the same route, route conflicts are identified through analysis.

[0022] Based on the relationships between route sources that have an inclusion relationship, route leakage can be analyzed.

[0023] Route reachability analysis is performed with the route source as the destination, and route reachability-related anomalies are identified.

[0024] Based on the frequency of changes in the routing source, an anomaly in the routing advertising frequency was identified.

[0025] The beneficial effects of this invention are: (1) This invention simplifies network log recording. It only needs to record network logs of changes in routing sources, avoiding repeated judgment and reporting of logs on different devices, and greatly reducing the recording of network change logs.

[0026] (2) The present invention can quickly locate the root cause of network anomalies. There are many kinds of common network faults, such as routing oscillation, routing conflict, routing black hole, routing loop, routing redistribution anomaly, etc. These network faults only reflect network problems from different perspectives. Multiple network faults often occur at the same time in complex networks. It is only because the root cause of these network faults is the same that the present invention analyzes network anomalies from the perspective of routing source, which is more direct and effective.

[0027] (3) This invention is more valuable in cross-autonomous region network fault diagnosis, ignoring network anomalies caused by intermediate network propagation and directly addressing the root cause of network problems.

[0028] (4) This invention directly locates the root cause of network problems, making it easy for maintenance personnel to quickly identify the source of network problems. For example, such network problems may be caused by configuration errors, malicious attacks, unstable network interfaces, etc., which makes it easier for maintenance personnel to deal with network faults in a timely manner and quickly restore the network. Attached Figure Description

[0029] Figure 1 The diagram shows a flowchart of a routing anomaly analysis method based on routing source provided by an embodiment of the present invention.

[0030] Figure 2 The diagram shown is a schematic representation of the original routing source provided in an embodiment of the present invention.

[0031] Figure 3The diagram shown is a schematic diagram of the IS-IS protocol routing source provided in an embodiment of the present invention.

[0032] Figure 4 The diagram shown is a schematic diagram of the BGP routing source provided in an embodiment of the present invention. Detailed Implementation

[0033] Exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be understood that the embodiments shown and described in the drawings are merely exemplary and are intended to illustrate the principles and spirit of the invention, and are not intended to limit the scope of the invention.

[0034] This invention provides a routing anomaly analysis method based on routing source, such as... Figure 1 As shown, it includes the following steps S1~S3: S1. Identify the routing source of all routes in the network based on the network-wide routing information.

[0035] The source router (or simply routing source) is the router that advertises the route. Analyzing changes in the routing source allows for network fault diagnosis, such as identifying network topology changes, diagnosing network link failures, and detecting network security intrusions (in BGP hijacking attacks, attackers send fake route advertisements in an attempt to redirect network traffic to malicious servers). Therefore, finding the routing source and locating changes in it are fundamental conditions for network anomaly analysis (such as routing source migration, routing conflicts, and routing oscillations) in network operations and maintenance systems.

[0036] like Figure 2 As shown, when the complete network packets can be obtained, R4, as an ASBR route, advertises route 100.1.1.0 / 24. Therefore, the route source of route 100.1.1.0 / 24 that can be analyzed in the operation and maintenance system is R4.

[0037] The following two routing source definitions are given in the embodiments of the present invention: Directly connected route source: The publisher of directly connected routes calculated by the routing protocol, and also the actual route source in the network.

[0038] Redistributed route source: A route that is redistributed or cannot be directly identified as a directly connected route in the network (in this embodiment of the invention, such routes are treated as redistributed routes). The route publication source of this type of route is defined as a redistributed route source. This type of route source also needs to be determined in conjunction with the network environment to determine whether it is an actual route source in the network.

[0039] Based on this, step S1 includes the following sub-steps S11 to S13: S11. For the routing protocol in the network where the next hop of route N is 0, determine whether it is a single routing protocol. If yes, proceed to step S12; otherwise, proceed to step S13.

[0040] S12. Use the single routing protocol route source determination process to determine whether a directly connected route source can be found in the single routing protocol. If so, use the directly connected route source as the actual route source of the single routing protocol. Otherwise, proceed to step S13.

[0041] In this embodiment of the invention, the single routing protocol route source determination process includes the OSPF protocol route source determination process, the IS-IS protocol route source determination process, and the BGP protocol route source determination process.

[0042] The OSPF protocol can precisely distinguish between intra-area routes, inter-area routes, and external routes based on its LSAs. For intra-area routes, the actual advertiser of the route is obtained through OSPF's Router-LSA or Network-LSA as the directly connected route source.

[0043] The inter-area routing source is the inter-area route publisher (ABR), which is actually an indirect source, or can be understood as a relay connecting multiple areas. The external routing source is the redistribution border router (ASBR). Therefore, for inter-area routes and external routes, the directly connected routing source cannot be found; the search continues to find the actual routing source based on the redistribution routing source.

[0044] The IS-IS protocol operates in two modes: narrow measure and wide measure. In narrow measure mode, the advertised route source is distinguished from the redistributed route source based on the flag in the TLV. In wide measure mode, there is no flag to distinguish between the two, and the route is matched with the IP address to determine the network segment to distinguish between the directly connected route source and the redistributed route source.

[0045] like Figure 3 As shown, in the IS-IS protocol, R4 is the direct route source for the directly connected route 20.14.0.0 / 24, and R4 is also the redistribution route source for the externally imported route 100.1.1.0 / 24.

[0046] BGP is a pure route transmission protocol, acting as a route carrier. It is generally responsible for the transmission of routing protocols in the network and has no route generation capability. Furthermore, BGP cannot distinguish between redistributed routes and directly connected routes. Therefore, for routes in BGP whose next-hop address is its own IP address, the directly connected route source cannot be found. Instead, it is treated as a redistributed route source, and the search continues to find the actual route source.

[0047] S13. In the redistribution route source of route N, find the routing protocol X whose next hop is not 0, and use the single routing protocol route source determination process to determine whether a directly connected route source can be found in the routing protocol X. If so, the directly connected route source is taken as the actual route source of route N; otherwise, the redistribution route source is taken as the actual route source of route N.

[0048] In this embodiment of the invention, by analyzing the routing sources of various common routing protocols, the original route advertiser can generally be traced back, thereby revealing the actual routing source of each route.

[0049] like Figure 4 As shown, on R41, the route of user subnet 41 is redistributed to BGP via OSPF, and then advertised to other user subnets via BGP. In BGP, the route is found to be a redistributed route. Then, the source of the route is found in the OSPF network. Thus, it can be determined that R41 is the source router of the route of user subnet 41.

[0050] S2. Classify and manage routing sources, and report routing source migration logs when routing sources change.

[0051] During network operation, dynamic changes in routes are commonplace, and accurately grasping these changes is crucial for network maintenance. Therefore, based on the route source, we can focus on changes in source routes, such as route source migration and route AS migration.

[0052] When the routing source changes, the system records detailed log information. These logs are not isolated but can be correlated with routing anomaly logs. Once a routing anomaly occurs in the network, operations and maintenance personnel can accurately pinpoint the root cause of the routing anomaly by thoroughly analyzing the routing source change logs.

[0053] In this embodiment of the invention, routing-related information is first extracted, including key attributes such as route prefix, route advertisement source, route type, and route AS. These attributes act as the identity identifier of the route, providing basic data for subsequent comparative analysis. Next, the extracted routing-related information is comprehensively compared with the previously reported route source information to determine whether there are any differences between all route sources corresponding to the current route and the previously reported route sources. If differences exist, it indicates that a route source migration phenomenon has occurred.

[0054] To ensure timely and accurate reporting of routing source migration logs, and to effectively reduce frequent log reporting caused by routing oscillations, the system has optimized the reporting of routing source migration logs, with the following specific provisions: In response to the detection that a route source has been deleted, a deletion timer is started. This is to provide a buffer time for the recovery or change of the route source, avoiding misjudgments and frequent log reports caused by brief route fluctuations.

[0055] If the deleted route source comes back online within the time set by the deletion timer, the deletion timer is canceled. This indicates that the deletion of the route source may have been a mistake or a temporary anomaly, and not a genuine removal of the route source.

[0056] In response to the emergence of a new routing source during the deletion timer's execution, the routing source migration log should be reported immediately. The emergence of a new routing source may be related to a deleted routing source, or it may indicate a significant change in the network topology. This is important information for network operations personnel, and timely reporting allows them to stay informed about network changes.

[0057] Each time a timer expires, check if any deleted timers have expired. If at least one deleted timer has expired, report the routing source migration log.

[0058] In this embodiment of the invention, route source deletion adopts a centralized reporting method. That is, when reporting route source migration logs, all currently deleted route sources are reported together, regardless of whether their route source deletion timers have expired. This method helps to comprehensively and systematically record route source deletion status, facilitating comprehensive analysis by operations and maintenance personnel.

[0059] S3. Monitor changes in routing source information (number of routing sources, protocol type, network location, frequency of change, etc.), and analyze various routing anomaly events in conjunction with network deployment and the principles of various routing anomalies.

[0060] In this embodiment of the invention, the various routing anomaly events analyzed include: Based on the legitimacy of the route source location information, we can analyze illegal route advertising and route prefix hijacking.

[0061] Based on the comparison of multi-protocol routing sources, the analysis revealed an anomaly in route redistribution.

[0062] Based on the existence of multiple sources for the same route, route conflicts are identified through analysis.

[0063] Based on the relationships between route sources that have an inclusion relationship, route leakage can be analyzed.

[0064] Route reachability analysis is performed with the route source as the destination, and route reachability-related anomalies are identified.

[0065] Based on the frequency of changes in the route source (addition, deletion, update), anomalies in route advertising frequency were identified.

[0066] In this embodiment of the invention, the route anomaly analysis method based on route source has a wide range of applications. It can be used to perform route anomaly analysis for various issues, including changes in route advertising source, changes in route advertising AS, route redistribution, changes in SRv6 Locator, changes in SRv6 SID, route oscillation, route conflicts, route black holes, route loops, route reachability anomalies, VPN route conflicts, and SRv6 Locator conflicts.

[0067] The following example uses routing conflicts to analyze routing anomalies based on the routing source.

[0068] Routing conflicts refer to the occurrence of the same address range in different locations within a network, violating the constraint of network address uniqueness. Because the network fault symptoms exhibited by routing conflicts are very similar to those of link failures and protocol configuration errors—typically including packet loss and intermittent network outages—locating and maintaining routing conflict faults is extremely difficult.

[0069] To address the challenges of locating and detecting routing conflicts during network operations and maintenance, the routing conflict detection function performs a comprehensive analysis of the entire network's routing based on the results of routing source analysis. It is divided into two modules according to the network scenario: intra-domain routing conflicts and inter-domain routing conflicts.

[0070] The inter-domain routing conflict module targets routes advertised across ASs based on BGP. By analyzing routes with the BGP protocol type, it determines if there are multiple route sources based on the BGP protocol in different ASs, indicating that an inter-domain routing conflict has occurred.

[0071] The intra-domain routing conflict module detects all routing conflict behaviors except for inter-domain conflict scenarios. Intra-domain routing conflict detection is based on the results of multi-protocol routing source analysis. If a route has multiple (same or different) route advertisers, it indicates that an intra-domain routing conflict has occurred.

[0072] When a routing conflict is detected in the network, combined with event messages indicating changes in the routing source, the source of the routing failure can be accurately located.

[0073] Those skilled in the art will recognize that the embodiments described herein are intended to help the reader understand the principles of the invention, and should be understood that the scope of protection of the invention is not limited to such specific statements and embodiments. Those skilled in the art can make various other specific modifications and combinations based on the technical teachings disclosed in this invention without departing from the spirit of the invention, and these modifications and combinations are still within the scope of protection of this invention.

Claims

1. A routing anomaly analysis method based on a routing source, characterized by, Includes the following steps: S1. Identify the routing source of all routes in the network based on the network-wide routing information; S2. Classify and manage routing sources, and report routing source migration logs when routing sources change; S3. Monitor changes in routing source information, and analyze various routing anomaly events by combining network deployment information and the principles of various routing anomalies.

2. The routing source-based routing anomaly analysis method according to claim 1, characterized in that, Step S1 includes the following sub-steps: S11. For the routing protocol in the network where the next hop of route N is 0, determine whether it is a single routing protocol. If yes, proceed to step S12; otherwise, proceed to step S13. S12. Use the single routing protocol route source determination process to determine whether a directly connected route source can be found from the single routing protocol. If so, the directly connected route source is taken as the actual route source of the single routing protocol. Otherwise, proceed to step S13. S13. In the redistribution route source of route N, find the routing protocol X whose next hop is not 0, and use the single routing protocol route source determination process to determine whether a directly connected route source can be found in the routing protocol X. If so, the directly connected route source is taken as the actual route source of route N; otherwise, the redistribution route source is taken as the actual route source of route N. 3.The route-source based route anomaly analysis method according to claim 2, characterized in that, The single routing protocol route source determination process includes the OSPF protocol route source determination process, the IS-IS protocol route source determination process, and the BGP protocol route source determination process.

4. The routing source-based routing anomaly analysis method according to claim 3, characterized in that, The OSPF protocol routing source determination process is as follows: For intra-area routes, the actual advertiser of the route is obtained through OSPF's Router-LSA or Network-LSA as the directly connected route source; for inter-area routes and external routes, if the directly connected route source cannot be found, the search continues to find the actual route source by redistributing the route source.

5. The routing source-based routing anomaly analysis method according to claim 3, characterized in that, The IS-IS protocol routing source determination process is as follows: In narrow metric mode, the advertised route source is distinguished from the redistributed route source based on the flags in the TLV; in wide metric mode, the route is matched with the IP address by network segment to distinguish between the directly connected route source and the redistributed route source.

6. The routing source-based routing anomaly analysis method according to claim 3, characterized in that, The BGP protocol routing source determination process is as follows: For routes whose next-hop address is its own IP, if a directly connected route source cannot be found, the search continues to find the actual route source by redistributing the route source. 7.The route-source based route anomaly analysis method according to claim 1, wherein, The specific method for reporting the routing source migration log when the routing source changes in step S2 is as follows: In response to the detection that the routing source has been deleted, a deletion timer is started; If the deleted route source comes back online within the time set by the deletion timer, the deletion timer is canceled. In response to a new routing source coming online during the deletion timer's execution, immediately report the routing source migration log; Each time a timer expires, check if any deleted timers have expired. If at least one deleted timer has expired, report the routing source migration log.

8. The routing anomaly analysis method based on routing source according to claim 1, characterized in that, The various routing anomaly events analyzed in step S3 include: Based on the legitimacy of the route source location information, we can analyze illegal route advertising and route prefix hijacking. Based on the comparison of multi-protocol routing sources, the analysis revealed an anomaly in route redistribution. Based on the existence of multiple sources for the same route, route conflicts are identified. Based on the relationships between route sources that have an inclusion relationship, route leakage can be analyzed. Perform route reachability analysis with the route source as the destination to identify route reachability-related anomalies. Based on the frequency of changes in the routing source, an anomaly in the routing advertising frequency was identified.