Identification device
A system calculates network routes using influence scores to identify devices causing communication network abnormalities, addressing the challenge of alarm-dependent identification by analyzing route overlaps.
Patent Information
- Application Number
- JP2024080678
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-17
- Publication Date
- 2025-11-28
AI Technical Summary
Existing technologies struggle to identify the device causing an abnormality in a communication network without relying on alarms, making it difficult to pinpoint the source of issues affecting service evaluation indices like KPIs.
A system that calculates routes through a network using scores indicating the degree of influence on service evaluation indices for relay devices and ports, identifying the cause of impact by analyzing the overlap of these routes.
Enables the identification of devices causing network abnormalities without relying on alarms, accurately pinpointing the source of issues based on route overlap analysis.
Smart Images

Figure 2025174363000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an identification device, an identification method, and a program. [Background technology]
[0002] 2. Description of the Related Art Techniques are known that are used to identify a device that is the cause of an abnormality or failure that has occurred in a network.
[0003] A related technique is disclosed in Patent Document 1. Patent Document 1 describes a network monitoring device that extracts candidates for network devices (network apparatuses) that are the root cause of a network failure. For example, the network monitoring device includes a monitoring unit, an impact score calculation unit, and a candidate display unit. According to Patent Document 1, the monitoring unit acquires an alarm indicating the occurrence of a failure from the monitored network. Furthermore, when an alarm is acquired from any of the network devices, the impact score calculation unit assigns points indicating the degree of causation to the network devices that can be identified based on the configuration management information. Then, the candidate display unit extracts candidates for network devices that could be the root cause based on the total value of the assigned points, and displays information identifying the extracted network devices. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-195321 Summary of the Invention [Problem to be solved by the invention]
[0005] When an abnormality occurs in a service evaluation index such as a KPI (Key Performance Indicator), it may be desirable to identify the device that has an impact on the evaluation index. However, the technology described in Patent Document 1 requires that an alarm be acquired from a network device. Therefore, when using the technology described in Patent Document 1, it is difficult to identify the device that is causing the abnormality without the assumption of receiving an alarm. Thus, there has been a problem in that it may be difficult to identify the device that is causing the abnormality in a communication network.
[0006] Therefore, one object of the present invention is to provide an identification device, an identification method, and a program that can solve the above-mentioned problems. [Means for solving the problem]
[0007] In order to achieve this object, a specific device according to one embodiment of the present disclosure comprises: a route calculation unit that calculates a route through which each communication will pass in the network using a score indicating the degree of influence on the service evaluation index for each relay device or each port of the relay device that constitutes a network through which multiple communications are performed; an identification unit that identifies the relay device or a port of the relay device that is the cause of an effect on the evaluation index according to the overlapping state of the paths calculated by the path calculation unit, and outputs the identification result; have The structure is as follows.
[0008] Furthermore, a specifying method according to another aspect of the present disclosure includes: The information processing device calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. The structure is as follows.
[0009] Furthermore, a program according to another aspect of the present disclosure includes: In the information processing device, calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. It is a program for realizing the processing. [Effects of the Invention]
[0010] According to the above-described configurations, it is possible to identify the device causing the abnormality in the communication network. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 illustrates an example of the configuration of a specific system. [Figure 2] FIG. 2 is a block diagram illustrating an example of the configuration of a specific device. [Figure 3] FIG. 10 is a diagram illustrating an example of score calculation. [Figure 4] FIG. 10 is a diagram for explaining an example of calculating a route. [Figure 5] FIG. 10 is a diagram for explaining an example of calculating a route. [Figure 6] FIG. 10 is a diagram illustrating an example of calculating a route score. [Figure 7] FIG. 10 is a diagram for explaining an example of specifying a device. [Figure 8] 10 is a flowchart illustrating an example of the operation of the identifying device. [Figure 9]FIG. 10 is a block diagram showing another example of the configuration of the specific device. [Figure 10] FIG. 10 is a diagram illustrating an example of a hardware configuration of a specific device according to a second embodiment of the present disclosure. [Figure 11] FIG. 2 is a block diagram illustrating an example of the configuration of a specific device. [Figure 12] 10 is a flowchart illustrating an example of the operation of the identifying device. DETAILED DESCRIPTION OF THE INVENTION
[0012] [First embodiment] An example configuration of the identification system 100 in the present disclosure will be described with reference to FIGS. 1 to 9. FIG. 1 is a diagram illustrating an example configuration of the identification system 100. FIG. 2 is a block diagram illustrating an example configuration of the identification device 300. FIG. 3 is a diagram illustrating an example calculation of a score. FIGS. 4 and 5 are diagrams illustrating an example calculation of a route. FIG. 6 is a diagram illustrating an example calculation of a route score. FIG. 7 is a diagram illustrating an example identification of a device. FIG. 8 is a flowchart illustrating an example operation of the identification device 300. FIG. 9 is a block diagram illustrating another example configuration of the identification device 300. Note that in the present disclosure, the drawings may be associated with one or more embodiments.
[0013] In a first embodiment of the present disclosure, a description is given of an identification system 100 that identifies a device that is causing an adverse effect or other influence on a key performance indicator (KPI), which is an evaluation index of a service, in a communication network. As will be described later, the identification system 100 calculates the path through which each communication passes using a score indicating the degree of influence on the KPI for each relay device 220 or each port of the relay device 220 that constitutes a network through which multiple communications are performed. Then, the identification system 100 identifies the relay device 220 or the port of the relay device 220 that is causing the influence on the KPI according to the degree of overlap of the calculated paths. For example, the identification system 100 can identify the relay device 220 or the port of the relay device 220 that is causing the influence on the KPI by identifying the relay device 220 or the port of the relay device 220 that is common to the multiple calculated paths.
[0014] Furthermore, the identification system 100 can calculate a path score, which is a score for the calculated path, using the score for each relay device 220 or each port of the relay device 220. For example, the identification system 100 may calculate a path score by adding up the scores corresponding to the relay devices 220 or ports present on the path. The identification system 100 can also extract paths that satisfy a predetermined condition from the calculated paths according to the path score. For example, the identification system 100 extracts paths whose path scores are higher than a predetermined value when the paths are sorted in order of path score. Then, the identification system 100 identifies the relay device 220 or the port of the relay device 220 that is causing an impact on the KPI according to the degree of overlap of the extracted paths. In this way, the identification system 100 may extract paths that satisfy a predetermined condition from the calculated paths, and then identify the relay device 220 or the port of the relay device 220 that is causing an impact on the KPI.
[0015] The identification system 100 can be configured to calculate the above-mentioned score using KPIs and statistical information that can be acquired according to the relay process performed by the relay device 220 when relaying communications. For example, the identification system 100 calculates the score using a model that has been machine-learned in advance. The identification system 100 may calculate the score according to the KPIs and statistical information by using a correlation coefficient between the KPIs and statistical information, Granger causality, causal inference, etc.
[0016] The identifying system 100 may use the traffic volume per given time in the server device or gateway providing the service as a KPI, which is an evaluation index of the service. The identifying system 100 may use values other than the above examples that can be used to evaluate the service provided via the network as an evaluation index of the service. For example, the identifying system 100 may use the transmission and reception volume of the server providing the service or the number of requests processed as an evaluation index of the service.
[0017] Furthermore, the identifying system 100 can use traffic information for each port at a predetermined time level, such as every minute, as statistical information. For example, the identifying system 100 may use the transmission volume or the transmission / reception volume for each port per minute as statistical information. Note that the identifying system 100 may use values other than those exemplified above that correspond to the relay process performed by the relay device 220 when relaying communications as statistical information. For example, the identifying system 100 may use connection route information such as the number of routes per port, the number of new routes, the number of deleted routes, and the number of changed routes, as well as statistical information for each control protocol such as BGP (Border Gateway Protocol), as the statistical information. The identifying system 100 may use a combination of at least some of the information exemplified above.
[0018] FIG. 1 shows an example configuration of an identification system 100. Referring to FIG. 1, the identification system 100 includes a network 200 that communicates when providing a service, and an identification device 300 that identifies a relay device 220 or the like that is causing an impact on a KPI in the network 200. For example, in the example shown in FIG. 1, the network 200 and the identification device 300 can be connected so as to be able to communicate with each other. Note that in the example shown in FIG. 1, the identification device 300 exists outside the network 200. However, at least some of the functions of the identification device 300, which will be described later, may exist inside the network 200.
[0019] The network 200 includes end devices 210 such as a communication source device and a communication destination device, and relay devices 220 such as a switch device that relays communications between the end devices 210. As shown in Fig. 1, the end devices 210 and the relay devices 220 can be connected to each other so that they can communicate with each other. Note that configuration information indicating the configuration of the network 200, such as which devices are connected to each other in the network 200, may be managed by a management device that manages the network 200. The management device may be located inside or outside the network 200.
[0020] The end device 210 is an information processing device that communicates with a communication source device, a communication destination device, etc. when providing a service, etc. The end device 210 may include a server device that provides a service, etc.
[0021] The relay device 220 (relay devices 220-1, 220-2, .... When no distinction is made, they will be referred to as relay device 220) is a switch device or the like that performs relay processing to relay communications between end devices 210. The relay device 220 can also acquire statistical information according to the relay processing. For example, the relay device 220 acquires traffic information for each port at a predetermined time level, such as the transmission volume per port per minute, as statistical information. The relay device 220 may acquire, as statistical information, connection path information or statistical information according to a control protocol, together with or instead of the traffic information. The relay device 220 can also transmit the acquired statistical information to the identifying device 300. The relay device 220 may transmit the statistical information to the identifying device 300 at any timing, such as at a predetermined interval.
[0022] The identifying device 300 is an information processing device that identifies devices that are causing an impact on KPIs by using information periodically collected from the network 200. Referring to Fig. 2, the identifying device 300 has, as main components, for example, an operation input unit 310, a screen display unit 320, a communication interface unit 330, a storage unit 340, and a calculation processing unit 350.
[0023] 2 illustrates an example in which the functions of identifying device 300 are realized using one information processing device. However, at least some of the functions of identifying device 300 may be realized using multiple information processing devices, for example, on the cloud. For example, identifying device 300 may be composed of an information processing device that calculates a score and an information processing device that calculates a route and identifies relay device 220, etc. Furthermore, identifying device 300 may not include some of the components exemplified above, such as not having operation input unit 310 or screen display unit 320, or may have a component other than those exemplified above.
[0024] The operation input unit 310 is made up of operation input devices such as a keyboard, a mouse, etc. The operation input unit 310 detects the operation of the operator who operates the specific device 300 and outputs the detected operation to the calculation processing unit 350.
[0025] The screen display unit 320 is composed of a screen display device such as a liquid crystal display, an organic EL (electro-luminescence) display, etc. The screen display unit 320 can display various information stored in the storage unit 340 on the screen in response to instructions from the arithmetic processing unit 350.
[0026] The communication interface unit 330 is composed of a data communication circuit, etc. The communication interface unit 330 performs data communication with external devices such as the management device, end device 210, and relay device 220 connected via a communication line.
[0027] The storage unit 340 is a storage device such as a hard disk or memory. The storage unit 340 stores processing information and programs 346 required for various processes in the arithmetic processing unit 350. The programs 346 are read into the arithmetic processing unit 350 and executed to realize various processing units. The programs 346 are read in advance from an external device or recording medium via a data input / output function such as the communication interface unit 330, and are stored in the storage unit 340. Main information stored in the storage unit 340 includes, for example, NW (network) configuration information 341, KPI information 342, NW statistical information 343, score information 344, and route score information 345.
[0028] The NW configuration information 341 includes information indicating the configuration of the network 200. For example, the NW configuration information 341 may include information indicating the connection relationships of the end devices 210 and the relay devices 220, such as which devices are connected to which devices in the network 200. The NW configuration information 341 may also include connection path information such as the number of paths for each port in the relay device 220, the number of new paths, the number of deleted paths, and the number of changed paths. The NW configuration information 341 can be updated when the NW configuration information acquisition unit 351 acquires information from a management device or the like.
[0029] The KPI information 342 includes information indicating evaluation indicators of a service, such as the amount of traffic per predetermined time. The KPI information 342 can be updated in response to the KPI information acquisition unit 352 acquiring information indicating KPIs from a server device or a management device that provides the service.
[0030] The NW statistical information 343 includes statistical information such as the transmission amount per port per minute. The NW statistical information 343 can be updated in response to the statistical information acquisition unit 353 acquiring statistical information from the relay device 220 or the like.
[0031] The score information 344 includes a score indicating the degree of influence on the KPI. For example, the score information 344 may include a score for each relay device 220 or for each port of the relay device 220. The score information 344 may be updated in response to the score calculation unit 354 calculating the score, etc.
[0032] The route score information 345 includes a route score, which is a score for a route. For example, the route score information 345 may associate information for identifying a route with the route score. The route score information 345 can be updated in response to the route score calculation unit 356 calculating the route score according to the score for each relay device 220 or for each port of the relay device 220.
[0033] The arithmetic processing unit 350 has an arithmetic device such as a CPU (Central Processing Unit) and its peripheral circuits. The arithmetic processing unit 350 reads and executes a program 346 from the storage unit 340, thereby realizing various processing functions by causing the above hardware and the program 346 to work together. Major processing units realized by the arithmetic processing unit 350 include, for example, a NW configuration information acquisition unit 351, a KPI information acquisition unit 352, a statistical information acquisition unit 353, a score calculation unit 354, a path calculation unit 355, a path score calculation unit 356, an identification unit 357, and an output unit 358.
[0034] In addition, the arithmetic processing unit 350 may have a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an MPU (Micro Processing Unit), an FPU (Floating point number Processing Unit), a PPU (Physics Processing Unit), a TPU (Tensor Processing Unit), a quantum processor, a microcontroller, or a combination of these, instead of the above-mentioned CPU.
[0035] The NW configuration information acquisition unit 351 acquires information indicating the configuration of the network 200, such as information indicating connection relationships, from a management device that manages connection relationships in the network 200. The NW configuration information acquisition unit 351 also stores the acquired information in the storage unit 340 as NW configuration information 341.
[0036] The KPI information acquisition unit 352 acquires information indicating KPIs, which are evaluation indicators of services, from a server device or management device that provides the service. For example, the KPI information acquisition unit 352 acquires the amount of traffic per predetermined time at a server or gateway as information indicating the KPI. The KPI information acquisition unit 352 may acquire the number of processes of a network service instead of or in addition to the above information. The KPI information acquisition unit 352 also stores the acquired information in the storage unit 340 as KPI information 342.
[0037] The statistical information acquiring unit 353 acquires statistical information from the relay device 220 or the like. For example, the statistical information acquiring unit 353 acquires traffic information such as the transmission volume per port per minute. The statistical information acquiring unit 353 may acquire connection path information, statistical information for each control protocol, or the like instead of or together with the above information. In addition, the statistical information acquiring unit 353 stores the acquired information in the storage unit 340 as NW statistical information 343.
[0038] 3, the score calculation unit 354 calculates a score indicating the degree of influence on the KPI for each port of the relay device 220, using the KPI acquired by the KPI information acquisition unit 352 and the statistical information acquired by the statistical information acquisition unit 353. The score calculation unit 354 may calculate the score by inputting the KPI and statistical information into a model that has been trained in advance. In addition, the score calculation unit 354 can store the calculated score in the storage unit 340 as score information 344.
[0039] For example, the score calculation unit 354 can calculate a score according to the input KPIs and statistical information by using a causal graph or the like trained using previously acquired KPIs, statistical information, etc. As an example, the score calculation unit 354 uses time-series KPIs and time-series statistical information to train in advance a model such as a causal graph showing the relationship between the time-series KPIs and the time-series statistical information. The score calculation unit 354 can calculate a score indicating the degree of influence on the KPIs by inputting KPIs, statistical information, etc. into the trained model described above.
[0040] For example, as described above, the score calculation unit 354 calculates the score using the KPI and statistical information. In this case, the score calculation unit 354 can calculate the score using a correlation coefficient between the KPI and the statistical information, Granger causality, causal inference, or the like.
[0041] The path calculation unit 355 uses the score calculated by the score calculation unit 354 to calculate a path through which communication will pass among devices in a connected relationship, such as the relay device 220. The path calculation unit 355 may calculate a path corresponding to each communication performed in the network 200.
[0042] For example, the path calculation unit 355 can calculate a path by using the inverse of the score calculated by the score calculation unit 354 to calculate the shortest path from the end device 210, which is the endpoint of the network. As an example, the path calculation unit 355 may calculate a path using a method such as Dijkstra's algorithm after checking the connection relationship according to the NW configuration information 341. For example, the path calculation unit 355 may calculate the weight of the link connecting each relay device 220 using the score calculated by the score calculation unit 354. As shown in FIG. 4, the path calculation unit 355 may calculate the link weight by adding or multiplying the inverse of the scores of a pair of ports at both ends of the link. For example, in the example shown in FIG. 4, the path calculation unit 355 can calculate the weight of the link between relay device 220-1 and relay device 220-2 according to the inverse of the scores of each port of relay device 220-1 and relay device 220-2. Furthermore, the path calculation unit 355 applies Dijkstra's algorithm using the calculated link weight. As a result, the route calculation unit 355 calculates the shortest route calculated from the end device 210 such as the communication source device as the route, as shown in FIG.
[0043] For example, as described above, the path calculation unit 355 calculates a path corresponding to each communication by applying the Dijkstra algorithm or the like using the score calculated by the score calculation unit 354. The path calculation unit 355 may calculate a path using a shortest path calculation method other than the Dijkstra algorithm.
[0044] The route score calculation unit 356 uses the score calculated by the score calculation unit 354 to calculate a route score, which is a score for the route calculated by the route calculation unit 355. Furthermore, the route score calculation unit 356 can store the calculated route score in the storage unit 340 as route score information 345.
[0045] For example, the route score calculation unit 356 calculates the route score by adding up the scores of each port present on the route. For example, in the case of Fig. 6, route 1 passes through a port with a score of 0.218, a port with a score of 0.444, a port with a score of 0.311, and a port with a score of 0.021. Therefore, in the case of Fig. 6, the route score calculation unit 356 calculates the route score of route 1 as 0.218 + 0.444 + 0.311 + 0.021 = 0.994. The route score calculation unit 356 can perform the route score calculation process as exemplified above for each route calculated by the route calculation unit 355.
[0046] The identifying unit 357 identifies the relay device 220 or port that is the cause of the influence on the KPI, depending on the degree of overlap of the paths calculated by the path calculation unit 355.
[0047] 7, the identification unit 357 identifies the relay device 220 and port that are the cause of an effect on the KPI by identifying the relay device 220 and port that are common to the multiple paths calculated by the path calculation unit 355. For example, in the case of FIG. 7, the relay device 220 shaded with diagonal lines is common to paths 1 and 2. Therefore, the identification unit 357 identifies the relay device 220 that is common to each path as the relay device 220 that is the cause of an effect on the KPI.
[0048] Furthermore, the identification unit 357 may extract routes that satisfy predetermined conditions according to the route scores from among the routes calculated by the route calculation unit 355, and use the extracted routes to identify relay devices 220 that cause an impact on the KPI. For example, the identification unit 357 sorts the routes in order of route score and extracts routes with route scores higher than a predetermined value. The identification unit 357 then identifies relay devices 220 and ports that are common to the extracted routes. This allows the identification unit 357 to identify relay devices 220 and ports that cause an impact on the KPI according to the identification results.
[0049] Note that if there is no relay device 220 or port common to multiple routes, there is a possibility that the relay device 220 on the route is not the cause of affecting the KPI. Therefore, if there is no relay device 220 or port common to multiple routes, the identification unit 357 may be configured to identify that the cause cannot be identified on the route passing through the relay device 220 or the like. Furthermore, the identification unit 357 may be configured to determine whether or not to extract a route according to a predetermined condition such as the number of routes. For example, the identification unit 357 may be configured to extract a route using a route score when, for example, the number of routes calculated by the route calculation unit 355 exceeds a predetermined threshold.
[0050] The output unit 358 outputs the results of identification by the identification unit 357. For example, the output unit 358 outputs information indicating the relay device 220 or port identified by the identification unit 357. The output unit 358 may display the information indicating the relay device 220 or port identified by the identification unit 357 on the screen display unit 320, or may transmit the information to an external device via the communication interface unit 330.
[0051] Furthermore, the output unit 358 may output various information used in the identification, in addition to the result of the identification by the identification unit 357. For example, the output unit 358 may output at least a part of information indicating the calculated route as exemplified in Fig. 5, information according to the route score as exemplified in Fig. 6, information indicating the relay device 220 identified on the network 200, etc. as exemplified in Fig. 7. In addition to the various information described above, the output unit 358 may output the calculated score, route score, information indicating the calculated route, the extracted route, etc.
[0052] The above is an example of the configuration of the identifying device 300. Note that the identifying device 300 may be configured to calculate the score not in units of ports but in units of relay devices 220. Next, an example of the operation of the identifying device 300 will be described with reference to FIG.
[0053] FIG. 8 is a flowchart showing an example of the operation of the identifying device 300. Referring to FIG. 8, various pieces of information are acquired using each acquisition unit (step S101). For example, the NW configuration information acquisition unit 351 acquires information indicating the configuration of the network 200, such as information indicating connection relationships, from a management device that manages connection relationships in the network 200. The KPI information acquisition unit 352 acquires information indicating KPIs, which are evaluation indicators of services, from a server device that provides a service or a management device. The statistical information acquisition unit 353 acquires statistical information from the relay device 220, etc. Each acquisition unit may acquire information at any timing, such as acquiring various pieces of information at predetermined intervals.
[0054] The score calculation unit 354 uses the KPI acquired by the KPI information acquisition unit 352 and the statistical information acquired by the statistical information acquisition unit 353 to calculate a score indicating the degree of influence on the KPI for each port of the relay device 220 (step S102). The score calculation unit 354 may calculate the score by inputting the KPI and statistical information into a model that has been trained in advance.
[0055] The route calculation unit 355 uses the score calculated by the score calculation unit 354 to calculate a route through which communication will pass among devices in a connection relationship such as the relay device 220 (step S103).
[0056] The route score calculation unit 356 uses the score calculated by the score calculation unit 354 to calculate a route score, which is the score for the route calculated by the route calculation unit 355 (step S104). For example, the route score calculation unit 356 calculates the route score by adding up the scores of each port present on the route.
[0057] The identifying unit 357 extracts routes that satisfy a predetermined condition according to the route score from among the routes calculated by the route calculation unit 355. Then, the identifying unit 357 identifies relay devices 220 and ports that cause an impact on the KPI according to the degree of overlap of the extracted routes (step S105).
[0058] The output unit 358 outputs the results of the identification by the identification unit 357 (step S106). For example, the output unit 358 outputs information indicating the relay device 220 or the port identified by the identification unit 357. The output unit 358 may display the information indicating the relay device 220 or the port identified by the identification unit 357 on the screen display unit 320, or may transmit the information to an external device via the communication interface unit 330.
[0059] The above is an example of the operation of the identifying device 300.
[0060] As described above, the identifying device 300 includes a path calculation unit 355 and an identification unit 357. With this configuration, the identification unit 357 can identify the relay device 220 or port that is causing an impact on the KPI, based on the degree of overlap of the paths calculated by the path calculation unit 355. As a result, when an abnormality occurs in the KPI, the relay device 220 or port that is causing an impact on the KPI can be identified without receiving an alarm from the relay device 220 or the like. Furthermore, in a network such as the network 200, an abnormality occurring in one relay device 220 spreads to other relay devices 220 on the path. As a result, simply comparing the scores of each relay device 220 can make it difficult to discern differences between the devices, and the cause of the impact may be hidden. In contrast, in the present disclosure, identification is performed based on the degree of overlap of the paths. Therefore, even in the above-described cases, the relay device 220 or port that is causing an impact on the KPI can be appropriately identified.
[0061] The identifying device 300 also includes a route score calculation unit 356. With this configuration, the identifying unit 357 can identify the relay device 220 or port that is causing an impact on the KPI, depending on the degree of overlap of the routes extracted according to the route scores calculated by the route score calculation unit 356. For example, it is assumed that the impact of the relay device 220 that is causing an impact on the KPI also exists on other relay devices 220 or ports that exist on the route. Therefore, by performing identification according to the degree of overlap of the routes extracted according to the route scores as described above, it is possible to more appropriately identify the relay device 220 or the like that is causing an impact on the KPI.
[0062] The configuration of the identifying device 300 is not limited to the example shown in Fig. 2. For example, Fig. 9 shows another example configuration of the identifying device 300. Referring to Fig. 9, the arithmetic processing unit 350 can implement a detection unit 359 in addition to the configuration shown in Fig. 2 by reading and executing the program 346.
[0063] The detection unit 359 detects an abnormality using the KPI acquired by the KPI information acquisition unit 352. For example, the detection unit 359 compares the KPI with a predetermined threshold. Then, the detection unit 359 detects an abnormality based on the result of the comparison. For example, the detection unit 359 may detect an abnormality when the KPI is equal to or less than the threshold.
[0064] If the identifying device 300 has the detecting unit 359, at least a part of the processing performed by the identifying device 300 to identify the relay device 220 or the like that may be causing an impact on the KPI may be configured to be performed in response to the detection result by the detecting unit 359. For example, the identifying unit 357 may be configured to identify the relay device 220 or the port in response to the detection of an abnormality by the detecting unit 359. In addition, the score calculation processing by the score calculating unit 354, the route calculation processing by the route calculating unit 355, the route score calculation processing by the route score calculating unit 356, and the like may also be configured to be performed in response to the detection of an abnormality by the detecting unit 359.
[0065] [Second embodiment] Next, a second embodiment of the present disclosure will be described with reference to Fig. 10 to Fig. 12. Fig. 10 is a diagram illustrating an example of the hardware configuration of the identifying device 400. Fig. 11 is a block diagram illustrating an example of the configuration of the identifying device 400. Fig. 12 is a flowchart illustrating an example of the operation of the identifying device 400.
[0066] In the second embodiment of the present disclosure, an identification device 400, which is a modified example of the identification device 300, will be described. For example, the identification device 400 is an information processing device that identifies relay devices or ports that cause an impact on KPIs according to the degree of overlap of calculated routes. FIG. 10 shows an example of the hardware configuration of the identification device 400. Referring to FIG. 10, the identification device 400 has the following hardware configuration, as an example. ·CPU(Central Processing Unit)401(Arithmetic unit) ROM (Read Only Memory) 402 (storage device) RAM (Random Access Memory) 403 (storage device) Programs 404 loaded into RAM 403 A storage device 405 for storing the program group 404 A drive device 406 that reads and writes data from a recording medium 410 outside the information processing device A communication interface 407 for connecting to a communication network 411 outside the information processing device Input / output interface 408 for inputting and outputting data Bus 409 connecting each component
[0067] 11 by the CPU 401 acquiring and executing the program group 404. The program group 404 is stored in advance in the storage device 405 or the ROM 402, for example, and is loaded into the RAM 403 or the like by the CPU 401 for execution as needed. The program group 404 may be supplied to the CPU 401 via the communication network 411, or may be stored in advance in the recording medium 410, and the drive device 406 may read out the program and supply it to the CPU 401.
[0068] 10 shows an example of the hardware configuration of the identifying device 400. The hardware configuration of the identifying device 400 is not limited to the above-described case. For example, the identifying device 400 may be configured with only a part of the above-described configuration, such as not including the drive device 406. Furthermore, the CPU 401 may be a GPU or the like exemplified in the first embodiment.
[0069] The path calculation unit 421 calculates a path through which each communication takes place in the network, using a score indicating the degree of influence on the service evaluation index for each relay device or each port of a relay device that constitutes a network performing multiple communications. The path calculation unit 421 may calculate a path using a score calculated in advance in its own device, or may calculate a path using a score obtained from an external device, etc.
[0070] The identification unit 422 identifies a relay device or a port of a relay device that is the cause of an effect on the evaluation index, and outputs the identification result, according to the degree of overlap of the paths calculated by the path calculation unit 421. For example, the identification unit 422 may perform the above identification by identifying a relay device or a port that is common to multiple paths.
[0071] The above is an example of the configuration of identifying device 400. Next, an example of the operation of identifying device 400 will be described with reference to FIG.
[0072] Fig. 12 is a flowchart showing an example of the operation of the identifying device 400. Referring to Fig. 12, the path calculation unit 421 calculates the path through which each communication in the network passes, using a score indicating the degree of influence on the evaluation index of the service for each relay device or each port of the relay device that constitutes the network performing multiple communications (step S201).
[0073] The identifying unit 422 identifies the relay device or the port of the relay device that is the cause of the influence on the evaluation index according to the degree of overlap of the paths calculated by the path calculation unit 421, and outputs the identification result (step S202).
[0074] The above is an example of the operation of the identifying device 400.
[0075] As described above, the identifying device 400 includes a path calculation unit 421 and an identification unit 422. With this configuration, the identification unit 422 can identify the relay device or the port of the relay device that is the cause of affecting the evaluation index, and output the identification result, depending on the degree of overlap of the paths calculated by the path calculation unit 421. As a result, when an abnormality occurs in the evaluation index, it is possible to appropriately identify the relay device or the port of the relay device that is the cause of affecting the evaluation index.
[0076] The above-described identifying device 400 can be realized by installing a predetermined program in an information processing device such as the identifying device 400. Specifically, a program according to another aspect of the present invention is a program for causing an information processing device such as the identifying device 400 to perform a process of calculating the routes taken by each communication in the network using a score indicating the degree of influence on the evaluation index of a service for each relay device or port of the relay device that constitutes a network performing multiple communications, and identifying the relay device or port of the relay device that is the cause of the influence on the evaluation index according to the degree of overlap of the calculated routes, and outputting the identification result.
[0077] In addition, the identification method executed by an information processing device such as the above-mentioned identification device 400 is a method in which the information processing device calculates the route that each communication takes in the network using a score indicating the degree of impact on the service evaluation index for each relay device or port of the relay device that makes up the network conducting multiple communications, and identifies the relay device or port of the relay device that is the cause of the impact on the evaluation index depending on the degree of overlap of the calculated routes, and outputs the identification result.
[0078] Even if the invention is a program having the above-mentioned configuration, or a computer-readable recording medium having the program recorded thereon, or a determination method, it can achieve the same functions and effects as the above-mentioned determination device 400, and therefore can achieve the above-mentioned object of the present disclosure.
[0079] <Additional Notes> A part or all of the above-described embodiments can be described as follows: The following provides an overview of specific devices and the like in the present invention. However, the present invention is not limited to the following configurations.
[0080] (Appendix 1) a route calculation unit that calculates a route through which each communication will pass in the network using a score indicating the degree of influence on the service evaluation index for each relay device or each port of the relay device that constitutes a network through which multiple communications are performed; an identification unit that identifies the relay device or a port of the relay device that is the cause of an effect on the evaluation index according to the overlapping state of the paths calculated by the path calculation unit, and outputs the identification result; have Specific equipment. (Appendix 2) a route score calculation unit that calculates a route score, which is a score for the route calculated by the route calculation unit, using the score for each of the relay devices or each of the ports of the relay devices; The identification unit identifies the relay device or the port of the relay device that is the cause of an effect on the evaluation index, according to an overlapping state of the paths extracted from the paths calculated by the path calculation unit according to the path scores calculated by the path score calculation unit. Specific device as described in Appendix 1. (Appendix 3) The identifying unit identifies the relay device or the port of the relay device that is the cause of an effect on the evaluation index by identifying the relay device or the port of the relay device that is common to a plurality of paths calculated by the path calculation unit. 1. A specific device as described in Appendix 1 or Appendix 2. (Appendix 4) an index acquisition unit that acquires the evaluation index; a statistical information acquisition unit that acquires statistical information according to a relay process performed by the relay device when relaying communication; a score calculation unit that calculates a score by calculating a degree of influence for each relay device or each port using the evaluation index acquired by the index acquisition unit and the statistical information acquired by the statistical information acquisition unit; and and The route calculation unit calculates a route through which communication will be routed in the network using the score calculated by the score calculation unit. 1. The specific device according to any one of Supplementary Note 1 to Supplementary Note 3. (Appendix 5) The route calculation unit calculates a route along which communication will pass in the network by calculating a shortest route using an inverse of the score calculated for each relay device or for each port in the relay device. 1. A specific device according to any one of claims 1 to 4. (Appendix 6) The score calculation unit calculates a score by inputting the evaluation index acquired by the index acquisition unit and the statistical information acquired by the statistical information acquisition unit into a trained model according to the relationship between the evaluation index in time series and the statistical information in time series. Specific devices as described in Appendix 4. (Appendix 7) The route score calculation unit calculates a route score by adding up the scores on the route calculated by the route calculation unit, using the score calculated for each relay device or for each port in the relay device. Specific devices as described in Appendix 2. (Appendix 8) a detection unit that detects an abnormality according to the evaluation index; The identifying unit identifies the relay device or the port of the relay device that is causing the abnormality in response to the detection of the abnormality by the detecting unit, and outputs the identification result. 1. The specific device of any one of Supplementary Notes 1 to 7. (Appendix 9) The information processing device calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. Specific method. (Appendix 10) In the information processing device, calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. A program to realize the processing.
[0081] Note that some or all of the configurations described in Supplementary Notes 2 to 8 that are dependent on the specific device described in Supplementary Note 1 may also be dependent in a similar dependent relationship on the specific method described in Supplementary Note 9 and the program described in Supplementary Note 10. Furthermore, not limited to Supplementary Notes 9 and 10, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems within the scope of the above-mentioned embodiments.
[0082] The programs described in the above embodiments and appendices can be stored in various types of non-transitory computer-readable media and supplied to a computer. Non-transitory computer-readable media include various types of tangible storage media. Examples of non-transitory computer-readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, and semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (Random Access Memory)). The programs may also be supplied to a computer by various types of transitory computer-readable media. Examples of transitory computer-readable media include electrical signals, optical signals, and electromagnetic waves. The transitory computer-readable media can supply the programs to a computer via wired communication paths such as electric wires and optical fibers, or via wireless communication paths.
[0083] Although the present invention has been described above with reference to the above-mentioned embodiments, the present invention is not limited to the above-mentioned embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Explanation of symbols]
[0084] 100 Specific Systems 200 Network 210 End Device 220 Relay Device 300 Specific equipment 310 Operation input section 320 Screen display section 330 Communication Interface Unit 340 Storage section 341 Network Configuration Information 342 KPI information 343 NW statistics information 344 Score Information 345 Route Score Information 346 Programs 350 Processing Unit 351 NW configuration information acquisition unit 352 KPI information acquisition department 353 Statistical information acquisition section 354 Score Calculation Unit 355 Route calculation unit 356 Route score calculation unit 357 Specific part 358 Output Section 359 Detector 400 Specific equipment 401 CPU 402 ROM 403 RAM 404 Programs 405 Storage device 406 Drive Unit 407 Communication Interface 408 Input / Output Interface 409 Bus 410 Recording Media 411 Communication Network 421 Route calculation unit 422 Specific part
Claims
1. a route calculation unit that calculates a route through which each communication in a network passes, using a score indicating the degree of influence on a service evaluation index for each relay device or each port of the relay device that constitutes a network through which multiple communications are performed; an identification unit that identifies the relay device or a port of the relay device that is the cause of an effect on the evaluation index according to the overlapping state of the paths calculated by the path calculation unit, and outputs the identification result; have Specific equipment.
2. a route score calculation unit that calculates a route score, which is a score for the route calculated by the route calculation unit, using a score for each of the relay devices or each of the ports of the relay devices; The identification unit identifies the relay device or the port of the relay device that is the cause of an effect on the evaluation index, according to an overlapping state of the paths extracted from the paths calculated by the path calculation unit according to the path scores calculated by the path score calculation unit. The identification device according to claim 1 .
3. The identifying unit identifies the relay device or the port of the relay device that is the cause of an effect on the evaluation index by identifying the relay device or the port of the relay device that is common to a plurality of paths calculated by the path calculation unit. The identification device according to claim 1 .
4. an index acquisition unit that acquires the evaluation index; a statistical information acquisition unit that acquires statistical information according to a relay process performed by the relay device when relaying communication; a score calculation unit that calculates a score by calculating a degree of influence for each relay device or each port using the evaluation index acquired by the index acquisition unit and the statistical information acquired by the statistical information acquisition unit; and and The route calculation unit calculates a route through which communication will be routed in the network using the score calculated by the score calculation unit. The identification device according to claim 1 .
5. The route calculation unit calculates a route along which communication will pass in the network by calculating a shortest route using an inverse of the score calculated for each relay device or for each port in the relay device. The identification device according to claim 1 .
6. The score calculation unit calculates a score by inputting the evaluation index acquired by the index acquisition unit and the statistical information acquired by the statistical information acquisition unit into a trained model according to the relationship between the evaluation index in time series and the statistical information in time series. The identification device according to claim 4 .
7. The route score calculation unit calculates a route score by adding up the scores on the route calculated by the route calculation unit, using the score calculated for each relay device or for each port in the relay device. The identification device according to claim 2 .
8. a detection unit that detects an abnormality according to the evaluation index; The identifying unit identifies the relay device or the port of the relay device that is causing the abnormality in response to the detection of the abnormality by the detecting unit, and outputs the identification result. The identification device according to claim 1 .
9. The information processing device calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. Specific method.
10. In the information processing device, calculating a route through which each communication is routed in the network using a score indicating the degree of influence on the service evaluation index for each relay device constituting the network through which multiple communications are performed, or for each port of the relay device; According to the degree of overlap of the calculated routes, the relay device or the port of the relay device that is the cause of the influence on the evaluation index is identified, and the identification result is output. A program to realize the processing.
Citation Information
Patent Citations
Network monitoring device, network monitoring method and program
JP2016195321A