Network information visualization device, network information visualization method, network information visualization program, and network information visualization system
The network information visualization device addresses the lack of comprehensive network monitoring in VPN networks by associating fine-grained flow information with topology and geographic data, improving network reliability through detailed visualization.
Patent Information
- Application Number
- JP2023578287
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-02-03
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2042-02-03
AI Technical Summary
Existing network monitoring technologies for VPN networks lack visualization of essential information such as topology, network device configuration, and location, making it difficult to effectively operate and maintain these networks.
A network information visualization device that acquires and associates fine-grained flow information with other network information, including topology, device configuration, and geographic data to generate comprehensive visualization information.
Enhances network reliability by providing detailed visualization of traffic time series, communication paths, geographic trends, and ground exchanges, enabling better network operation and maintenance.
Smart Images

Figure 0007794218000001 
Figure 0007794218000002 
Figure 0007794218000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a network information visualization device, a network information visualization method, a network information visualization program, and a network information visualization system. Regarding. [Background technology]
[0002] In recent years, technologies such as MPLS (Multi-Protocol Label Switching), VPN (Virtual Private Network), and L2TP (Layer 2 Tunneling Protocol) VPN have been provided as a means of realizing VPNs on carrier networks. As this virtualization advances, networks are becoming more complex. As a result, network monitoring is becoming increasingly important for proper network operation.
[0003] Network monitoring uses various traffic acquisition technologies such as SNMP (Simple Network Management Protocol) and IPFIX (Internet Protocol Flow Information Export). By using each acquisition technology, various types of visualized traffic information can be obtained for networks that use VPN technology. For example, by using SNMP as a traffic acquisition technology, IF (Interface) statistical information can be obtained. Also, by using IPFIX as a traffic acquisition technology, MPLS label statistical information and Inner5-tuple statistical information can be obtained.
[0004] Additionally, a format conversion device has been proposed that acquires a header sample containing the outer header of an encapsulated packet and the inner header of the encapsulated packet, converts the format by excluding the outer header, and saves the correspondence information between the inner and outer headers. By using this format conversion device on header samples acquired using IPFIX, it is possible to obtain fine-grained flow information for networks using VPNs. Fine-grained flow information includes information such as the MPLS label of the destination PE (Provider Edge) router, the ID (Identifier) of the output interface, and the ID of the input interface. Hereinafter, a network using VPNs will be referred to as a VPN network. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Patent Publication No. 2021-90161 Summary of the Invention [Problem to be solved by the invention]
[0006] However, while fine-grained flows obtained within a VPN network contain statistical information about VPN communications, they do not contain information such as topology information, network device configuration and operation information, or location information for network devices. Therefore, even if fine-grained flow information obtained within a VPN network is used alone, it is difficult to visualize various information that would be useful for the operation of the VPN network. Examples of information that would be useful for the operation of a VPN network include time-series traffic information for each VPN, path information, geographic usage trend information, and information on ground exchanges.
[0007] The present invention has been made in view of the above, and has an object to improve the reliability of a network by visualizing useful information in network monitoring. [Means for solving the problem]
[0008] In order to solve the above-mentioned problems and achieve the object, an information acquisition unit acquires network information related to a predetermined VPN network, the network information including at least flow information having statistical information related to communications in the predetermined VPN network. An association unit associates the flow information with other network information included in the network information to generate associated flow information. A visualization unit performs the following on the basis of the associated flow information: traffic visualization information that displays side-by-side information that visualizes traffic time series related to a predetermined communication interface based on the statistical information and information that visualizes traffic time series related to multiple VPNs with different network layers; Visualization information is generated that associates the flow information with the other network information. [Effects of the Invention]
[0009] According to the present invention, useful information in network monitoring can be visualized to improve the reliability of the network. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a block diagram of a network information visualization device. [Figure 2] FIG. 2 is a diagram showing a flow of generating visualization information according to the embodiment. [Figure 3] FIG. 3 is a diagram showing information acquisition methods and the granularity of traffic that can be visualized. [Figure 4] FIG. 4 is a diagram for explaining data linking. [Figure 5] FIG. 5 is a flowchart of the network information visualization process performed by the network information visualization device according to the embodiment. [Figure 6] FIG. 6 is a diagram for explaining the traffic visualization process. [Figure 7] FIG. 7 is a diagram for explaining the path visualization process. [Figure 8] FIG. 8 is a diagram for explaining the geographic visualization process. [Figure 9] FIG. 9 is a diagram for explaining the ground exchange visualization process. [Figure 10]FIG. 10 is a flowchart of a specific example of the network information visualization process performed by the network information visualization device according to the embodiment. [Figure 11] FIG. 11 is a diagram illustrating an example of a computer that executes a network information visualization program. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, an embodiment of a network information visualization device, a network information visualization method, a network information visualization program, and a network information visualization system disclosed in the present application will be described in detail with reference to the drawings. Note that the network information visualization device, the network information visualization method, the network information visualization program, and the network information visualization system disclosed in the present application are not limited to the following embodiment.
[0012] [Configuration of network information visualization system] The configuration of a network information visualization device will be described using Figure 1. Figure 1 is a block diagram of the network information visualization device. The network information visualization device 1 is an information processing device such as a server. The network information visualization device 1 associates fine-grained flow information obtained from a network that realizes a VPN with various other information, and visualizes it so that users can easily understand the state of the network. As shown in Figure 1, the network information visualization device 1 is connected to a VPN network 2.
[0013] Here, a flow refers to the flow of signals transmitted through a line. A fine-grained flow is a group of information that stores high-density statistical information related to communications, such as MPLS label statistical information and Inner5-tuple statistical information. High density corresponds to the fine granularity of the information. For example, a fine-grained flow may contain information about flows with fine granularity in the time direction. This fine-grained flow is an example of "flow information."
[0014] [VPN network] 2 is a diagram showing a flow of generating visualization information according to the embodiment. As shown in FIG. 2, the VPN network 2 includes a physical network 21, an underlay network 22, and VPNs 23 to 25 which are overlay networks.
[0015] The physical network 21 is a physical network configured by network devices such as routers and switches and network lines connecting them. In the physical network 21, no logical settings have been made to the network switches or the like.
[0016] The underlay network 22 is a physical network in which multiple logical paths are formed to connect bases and devices on the physical network 21. The underlay network 22 is formed by performing various logical settings on network devices such as routers in the physical network 21, such as restrictions on connection destinations and connection methods, such as signal receiving sources and sending destinations.
[0017] The overlay network is a virtual logical network built on the underlay network 22. VPN 23 is an L3 (Layer 3) VPN. VPN 23 is distinguished and used, for example, by VRF (Virtual Routing and Forwarding) using a router. VPN 24 is an L2VPN realized by EVPN (Ethernet VPN). VPN 24 is distinguished and used by EVI (EVPN Instance). VPN 25 is an L2VPN realized by L2TPv2. VPN 25 is formed between PPP (Point to Point Protocol) termination IFs. MPLS / SR-MPLS VPNs using MPLS, SR (Source Routing)-MPLS, etc. include L3VPNs such as VPN 23 and L2VPNs realized by EVPN such as VPN 24. Furthermore, L2TP VPNs using L2TPv2 (Version 2) include L2VPNs such as VPN 25.
[0018] Fig. 3 shows the information acquisition method and the traffic granularity that can be visualized. For each of VPNs 23 and 24 using MPLS or SR-MPLS, and VPN 25 using L2TPv2, packets in the formats shown in Fig. 3 are sent and received.
[0019] When SNMP is used as the traffic acquisition technology, IF statistical information can be obtained for both VPN23 and 24, which are MPLS / SR-MPLS VPNs, and VPN25, which is an L2TPv2 VPN. When IPFIX is used as the traffic acquisition technology, MPLS label statistical information and inner 5-tuple statistical information can be obtained for VPN23, which is an L3 (Layer 3) VPN among MPLS / SR-MPLS VPNs. MPLS label statistical information can be obtained for VPN24, which is an L2VPN realized by EVPN among MPLS / SR-MPLS VPNs. Outer 5-tuple statistical information can be obtained for VPN25, which is an L2VPN using L2TPv2 (Version 2).
[0020] In addition, for VPNs 23 and 24 using MPLS or SR-MPLS, and VPN 25 using L2TPv2, statistical information on outer headers and statistical information on inner headers can be obtained from header samples acquired using IPFIX.Furthermore, fine-grained flows can be obtained by combining header samples acquired using IPFIX with format conversion.
[0021] [Configuration of network information visualization device] 1, the network information visualization device 1 will be described. As shown in FIG. 1, the network information visualization device 1 includes an information acquisition unit 11, a linking unit 12, a data storage unit 13, and a visualization unit .
[0022] The information acquisition unit 11 acquires network information related to the VPN network 2. The information acquisition unit 11 includes a fine-grained flow acquisition unit 111, a topology acquisition unit 112, an MP-BGP (Multiprotocol-Border Gateway Protocol) information acquisition unit 113, a device information acquisition unit 114, and a geographic information acquisition unit 115.
[0023] The fine-grained flow acquisition unit 111 acquires header samples from the VPN network 2 using IPFIX for each of the VPNs 23 to 25. Furthermore, the fine-grained flow acquisition unit 111 performs format conversion on the acquired header samples by excluding the outer header. Furthermore, the fine-grained flow acquisition unit 111 stores correspondence information between the inner header and the outer header. Then, the fine-grained flow acquisition unit 111 acquires the fine-grained flow 211 shown in FIG. 2, which includes statistical information on MPLS labels and statistical information on Inner5-tuples, for each of the VPNs 23 to 25.
[0024] The fine-grained flow 211 includes, for example, a destination PE MPLS label, a VPN MPLS label, an Inner Ether, an Inner IP, an Outer IP, a Tunnel ID, a Session ID, a sampling rate, and statistical values. The destination PE MPLS label is the MPLS label of the destination PE router. The VPN MPLS label is the MPLS label of each of the VPNs 23 to 25. The Inner Ether is information about the internal network. The Inner IP is information about the IP used in the internal network. The Outer IP is information about the IP used in the external network. The Tunnel ID is identification information for the virtual tunnel used in each of the VPNs 23 to 25. The Session ID is identification information for the session established in each of the VPNs 23 to 25. The statistical values include traffic statistical information such as statistical information on the inner header and outer header, statistical information on the MPLS label, and statistical information on the Inner 5-tuple.
[0025] That is, the fine-grained flow 211 includes statistical information regarding communications in a specified VPN network, identification information regarding a plurality of network devices arranged in the specified VPN network, VPN communication setting information regarding the transmission and reception of signals in a VPN existing in the VPN network, and VPN communication setting information regarding the transmission and reception of signals in a VPN existing in the specified VPN network.
[0026] The fine-grained flow acquisition unit 111 outputs the fine-grained flow 211 for each of the VPNs 23 to 25 to the linking unit 12.
[0027] The topology acquisition unit 112 acquires information on the topology 212 shown in FIG. 2 of the underlay network 22 from the VPN network 2. The topology 212 includes topology information including the connection relationships of each network device, as well as the IDs of the output destination IFs, the IDs of the input destination IDs, and the router IDs of each router. In other words, the topology 212 includes identification information on the network devices and topology information that indicates the connection relationships of the network devices. The topology acquisition unit 112 outputs the acquired information on the topology 212 to the linking unit 12.
[0028] The MP-BGP information acquisition unit 113 acquires MP-BGP information 213 shown in FIG. 2, which includes network routing information such as VRF routing information related to VPN 23, from the VPN network 2. The MP-BGP information 213 includes a destination PE MPLS label, a VPN MPLS label, an Inner Ether, and an Inner IP. The MP-BGP information 213 also includes a PPP termination IF, a Tunnel ID, and a Session ID. In other words, the MP-BGP information 213 can be said to be VPN information including VPN communication setting information related to sending and receiving signals in VPNs 23 to 25 present in the VPN network 2, and VPN identification information for identifying the VPNs 23 to 25. Then, the MP-BGP information acquisition unit 113 outputs the acquired MP-BGP information 213 to the linking unit 12.
[0029] The device information acquisition unit 114 acquires device information 214 shown in FIG. 2, which includes device setting information and operating status information of each network device included in the physical network 21, from the VPN network 2. The device information 214 includes VPN information including setting information such as the configuration of each of the VPNs 23 to 25, an RD value, and information on the PPP termination IF. That is, the device information 214 includes VPN identification information, device setting information of the network devices, and operating status information. The device information acquisition unit 114 then outputs the acquired device information 214 to the linking unit 12.
[0030] The geographic information acquisition unit 115 acquires, from the VPN network 2, geographic information 215 shown in FIG. 2 , which includes location information for each network device included in the physical network 21. The geographic information 215 includes latitude and longitude information indicating the latitude and longitude of each network device, and topology information. In other words, the geographic information 215 includes topology information and location information for the network devices. The geographic information acquisition unit 115 then outputs the acquired geographic information 215 to the linking unit 12.
[0031] As described above, the information acquiring unit 11 acquires network information related to a predetermined VPN network, including at least flow information having statistical information related to communications in the predetermined VPN network. The information acquiring unit 11 also acquires flow information including identification information related to multiple network devices arranged in the VPN network, and topology information including identification information related to the network devices and topology information indicating the connection relationships between the network devices. The information acquiring unit 11 also acquires geographic information including topology information and location information of the network devices. The information acquiring unit 11 also acquires flow information including VPN communication setting information related to signal transmission and reception in a VPN existing in the predetermined VPN network, VPN information including the VPN communication setting information and VPN identification information for identifying the VPN, and device information including the VPN identification information and device setting information and operating status information of the network devices.
[0032] The tying unit 12 receives an input of a fine-grained flow 211 from the fine-grained flow acquisition unit 111. The tying unit 12 also receives an input of information on a topology 212 from the topology acquisition unit 112. The tying unit 12 also receives an input of MP-BGP information 213 from the MP-BGP information acquisition unit 113. The tying unit 12 also receives an input of device information 214 from the device information acquisition unit 114. The tying unit 12 also receives an input of geographic information 215 from the geographic information acquisition unit 115.
[0033] Next, the linking unit 12 links each piece of data between the MPLS / SR-MPLS VPNs VPNs 23 and 24 and the L2TP VPN VPN 25. Fig. 4 is a diagram for explaining data linking.
[0034] The linking unit 12 executes the following process for VPNs 23 and 24, which are MPLS / SR-MPLS VPNs. The linking unit 12 associates the fine-grained flow 211 with the topology 212, for example, by the output IF ID, the input IF ID, and the router ID. The linking unit 12 also associates the fine-grained flow 211 with the MP-BGP information 213, for example, by the destination PE MPS label, the VPN MPLS label, the Inner Ether, and the Inner IP.
[0035] Next, the linking unit 12 links the RD value that associates the MP-BGP information 213 with the device information 214 with the destination PE MPLS label and the VPN MPLS label. As a result, the linking unit 12 links the fine-grained flow 211 with the device setting information and operation status information of each network device included in the device information 214 via the MP-BGP information 213.
[0036] The linking unit 12 also links the output IF ID, the input IF ID, and the router ID to topology information that associates the topology 212 with the geographic information 215. As a result, the linking unit 12 links the fine-grained flow 211 with the latitude and longitude information of each network device included in the geographic information 215 via the topology 212.
[0037] On the other hand, the linking unit 12 executes the following process for the VPN 25, which is an L2TP VPN. The linking unit 12 associates the fine-grained flow 211 with the topology 212, for example, using the output IF ID, input IF ID, and router ID. Then, the linking unit 12 associates the output IF ID, input IF ID, and router ID with topology information that associates the topology 212 with the geographic information 215. In this way, the linking unit 12 associates the fine-grained flow 211 with the latitude and longitude information of each network device included in the geographic information 215 via the topology 212.
[0038] Furthermore, the linking unit 12 links, for example, the Outer IP, Tunnel ID, and Session ID included in the fine-grained flow 211 with the information on the PPP termination IF included in the device information 214. As a result, the linking unit 12 links the fine-grained flow 211 with the information on the device settings and the information on the operating status of each network device included in the device information 214 via the MP-BGP information 213.
[0039] Through the above processing, the linking unit 12 generates a linked fine-grained flow 300 by linking the topology 212, MP-BGP information 213, device information 214, and geographic information 215 to the fine-grained flow 211. The linked fine-grained flow 300 is an example of a "linked flow." The linking unit 12 then stores the generated linked fine-grained flow 300 in the data storage unit 13.
[0040] As described above, the linking unit 12 links the flow information with other network information included in the network information to generate linked flow information. The linking unit 12 also links the identification information related to the network device with the topology information. The linking unit 12 also links the topology information with the location information. The linking unit 12 also links the VPN communication setting information with the VPN identification information.
[0041] Continuing the explanation, returning to Fig. 1, the data storage unit 13 acquires the linked fine-grained flows 300 from the linking unit 12. Then, the data storage unit 13 collectively stores the acquired linked fine-grained flows 300 as the data lake 130 shown in Figs.
[0042] The visualization unit 14 uses the linked fine-grained flows 300 stored in the data storage unit 13 to generate visualization information that associates the fine-grained flows with other network information and provides the information to the user. The visualization unit 14 generates visualization information that visualizes traffic time series, communication paths, geographical usage trends, and terrestrial exchanges for each VPN. The visualization unit 14 then generates a visualization screen or the like that displays the generated visualization information and provides the information to the user. Here, in addition to the information listed above, the visualization unit 14 may also visualize other information that is useful for operating the VPN network 2.
[0043] As described above, the visualization unit 14 generates visualization information that associates flow information with other network information based on the associated flow information. The visualization unit 14 also generates traffic visualization information that visualizes a traffic time series related to a specific VPN or a specific communication interface at a specific time based on statistical information. The visualization unit 14 also generates path visualization information that visualizes a path taken by a specific communication at a specific time based on identification information, topology information, and statistical information related to network devices. The visualization unit 14 also generates geographic visualization information that visualizes the geographical distribution of a specific communication at a specific time based on identification information, location information, and statistical information related to network devices. The visualization unit 14 also generates ground traffic visualization information that visualizes ground traffic between specific network devices at a specific time based on statistical information and device information.
[0044] The entire process of generating visualization information will now be described with reference to Fig. 2. The information acquisition unit 11 acquires a fine-grained flow 211, a topology 212, MP-BGP information 213, device information 214, and geographic information 215 from the VPN network 2. Next, the linking unit 12 links the fine-grained flow 211 with the topology 212, MP-BGP information 213, device information 214, and geographic information 215 to generate a linked fine-grained flow 300. Thereafter, the linking unit 12 stores the linked fine-grained flow 300 in the data storage unit 13 to form a data lake 130. The visualization unit 14 uses the linked fine-grained flow 300 to generate traffic visualization information 221 that visualizes the traffic time series for each VPN, path visualization information 222 that visualizes the communication paths, geographic visualization information 223 that visualizes the geographical usage trends, and ground interaction visualization information 224 that visualizes ground interactions, and provides these to the user.
[0045] [Network Information Visualization Processing] 5 is a flowchart of the network information visualization process by the network information visualization device according to the embodiment. Next, the flow of the network information visualization process by the network information visualization device 1 according to the embodiment will be described with reference to FIG.
[0046] The fine-grained flow acquisition unit 111 acquires a header sample from the VPN network 2 using IPFIX. Then, the fine-grained flow acquisition unit 111 performs format conversion on the header sample to acquire fine-grained flows 211 related to the VPNs 23 to 25 (step S1). Thereafter, the fine-grained flow acquisition unit 111 outputs the acquired fine-grained flows 211 to the linking unit 12.
[0047] The topology acquisition unit 112 acquires the topology 212 of the physical network 21 and the underlay network 22 from the VPN network 2 (step S2). After that, the topology acquisition unit 112 outputs the information of the topology 212 to the linking unit 12.
[0048] The MP-BGP information acquisition unit 113 acquires the MP-BGP information 213 from the VPN network 2 (step S3). Thereafter, the MP-BGP information acquisition unit 113 outputs the MP-BGP information 213 to the linking unit 12.
[0049] The device information acquisition unit 114 acquires device information 214 including information on device settings and operating status of the network devices from the VPN network 2 (step S4). Thereafter, the device information acquisition unit 114 outputs the device information 214 to the linking unit 12.
[0050] The geographic information acquisition unit 115 acquires the geographic information 215 including the latitude and longitude information of the network device from the VPN network 2 (step S5). Thereafter, the geographic information acquisition unit 115 outputs the geographic information 215 to the linking unit 12.
[0051] The linking unit 12 links the fine-grained flow 211 with the topology 212, MP-BGP information 213, device information 214, and geographic information 215 for each of the MPLS / SR-MPLS VPNs VPNs 23 and 24 and the L2TP VPN VPN VPN 25 (step S6).
[0052] Next, the linking unit 12 stores the linked fine-grained flow 300 generated by the linking in the data storage unit 13 to generate the data lake 130 (step S7).
[0053] The visualization unit 14 generates the traffic visualization information 221, the path visualization information 222, the geography visualization information 223, and the ground exchange visualization information 224 by using the linked fine-grained flow 300. Then, the visualization unit 14 provides the traffic visualization information 221, the path visualization information 222, the geography visualization information 223, and the ground exchange visualization information 224 to the user (step S8).
[0054] [An example of the process for generating visualization information] For example, the visualization unit 14 can generate and provide the traffic visualization information 221, path visualization information 222, geographic visualization information 223, and ground traffic visualization information 224 in the following manner. As illustrated in FIG. 1 , the visualization unit 14 can include a traffic visualization unit 141, a path visualization unit 142, a geographic visualization unit 143, and a ground traffic visualization unit 144.
[0055] FIG. 6 is a diagram for explaining the traffic visualization process. The operation of the traffic visualization unit 141 will be described with reference to FIG. 6. The traffic visualization unit 141 filters the associated fine-grained flows 300 included in the data lake 130 at a predetermined time and with a predetermined field value, and acquires the filtered associated fine-grained flows 300. The field value is, for example, a value indicating one of VPNs 23 to 25 or a value indicating a specific interface. The traffic visualization unit 141 can use values specified by the operator as the predetermined time and the predetermined field value. The traffic visualization unit 141 then collects statistical values included in the filtered associated fine-grained flows 300 and plots a time series graph.
[0056] For example, the traffic visualization unit 141 generates a traffic visualization screen 301 shown in FIG. 6 and displays it on a monitor or the like to provide the user with the traffic visualization information 221. The traffic visualization screen 301 includes, for example, a graph 311 representing the traffic time series of VPN 23 and a graph 312 representing the traffic time series of interfaces. Both graphs 311 and 312 represent time on the horizontal axis and bandwidth on the vertical axis. The graph 311 allows the user to understand the change in traffic of VPN 23 over time. The graph 312 also allows the user to understand the change in traffic of interface #A over time and the change in traffic of VPNs 23 to 25 at that time. In this way, the traffic visualization unit 141 can visualize the traffic time series at a certain time of communication specified by the filter conditions.
[0057] FIG. 7 is a diagram illustrating the path visualization process. The operation of the path visualization unit 142 will be described with reference to FIG. 7. The path visualization unit 142 filters the associated fine-grained flows 300 included in the data lake 130 at a predetermined time and with predetermined field values to acquire the filtered associated fine-grained flows 300. The field values are, for example, values indicating specific communications. The path visualization unit 142 can use values specified by the operator as the predetermined time and the predetermined field values. The path visualization unit 142 then collects the router IDs, output IF IDs, and input IF IDs included in the filtered associated fine-grained flows 300, maps them to topology information, and renders them.
[0058] For example, the path visualization unit 142 generates a path visualization screen 302 shown in Fig. 7 and displays it on a monitor or the like to provide the path visualization information 222 to the user. The path visualization screen 302, for example, as shown in Fig. 7, shows routers and links connecting each router, and also shows the transit paths on the links. The path visualization screen 302 allows the user to understand how network devices are connected and which routes the transit paths take. In this way, the path visualization unit 142 can visualize the traffic time series at a certain time of the communication specified by the filter conditions.
[0059] FIG. 8 is a diagram illustrating the geographic visualization process. The operation of the geographic visualization unit 143 will be described with reference to FIG. 8. The geographic visualization unit 143 filters the associated fine-grained flows 300 included in the data lake 130 based on a predetermined time and a predetermined field value, and acquires the filtered associated fine-grained flows 300. The field value is, for example, a value indicating a specific communication. The geographic visualization unit 143 can use values specified by an operator as the predetermined time and the predetermined field value. The geographic visualization unit 143 then collects latitude and longitude information included in the filtered associated fine-grained flows 300 and draws a map showing the distribution of communications.
[0060] For example, the geography visualization unit 143 generates a geography visualization screen 303 shown in Fig. 8 and displays it on a monitor or the like to provide the geography visualization information 223 to the user. The geography visualization screen 303 can show the communication volume in each region by showing the distribution of communication on a map, for example, as shown in Fig. 8. The geography visualization screen 303 allows the user to understand how much communication is occurring in which region. In this way, the geography visualization unit 143 can visualize the communication volume at a certain time of the communication specified by the filter condition as a distribution.
[0061] FIG. 9 is a diagram illustrating the ground traffic visualization process. The operation of the ground traffic visualization unit 144 will be described with reference to FIG. 9. The ground traffic visualization unit 144 filters the associated fine-grained flows 300 included in the data lake 130 based on a predetermined time and a predetermined field value to acquire the filtered associated fine-grained flows 300. The field value is, for example, a value indicating a specific network device. The ground traffic visualization unit 144 can use values specified by an operator as the predetermined time and the predetermined field value. The ground traffic visualization unit 144 then collects the destination PE MPLS label, as well as the IP addresses and MAC addresses of the signal source and destination, included in the filtered associated fine-grained flows 300, to generate and display ground traffic information.
[0062] For example, the ground traffic visualization unit 144 generates a ground traffic visualization screen 304 shown in FIG. 9 and displays it on a monitor or the like, thereby providing the ground traffic visualization information 224 to the user. The ground traffic visualization screen 304 includes, for example, a graph 341 representing ground traffic between specific PE routers and a graph 342 representing ground traffic between specific CE routers. The graphs 341 and 342 allow the user to understand whether ground traffic exists between specific routers and the traffic volume due to that ground traffic. In this way, the ground traffic visualization unit 144 can visualize the presence or absence of ground traffic and the traffic volume at a certain time between routers specified by the filter conditions.
[0063] [Example of network information visualization processing] 10 is a flowchart of a specific example of network information visualization processing by the network information visualization device 1 according to the embodiment. Next, the flow of the specific example of network information visualization processing by the network information visualization device 1 according to the embodiment will be described with reference to FIG.
[0064] The fine-grained flow acquisition unit 111 acquires a header sample from the VPN network 2 using IPFIX. Then, the fine-grained flow acquisition unit 111 acquires fine-grained flows 211 related to the VPNs 23 to 25 by performing format conversion on the header sample (step S11). Thereafter, the fine-grained flow acquisition unit 111 outputs the acquired fine-grained flows 211 to the linking unit 12.
[0065] The topology acquisition unit 112 acquires the topology 212 of the physical network 21 and the underlay network 22 from the VPN network 2 (step S12). After that, the topology acquisition unit 112 outputs the information of the topology 212 to the linking unit 12.
[0066] The MP-BGP information acquisition unit 113 acquires the MP-BGP information 213 from the VPN network 2 (step S13). Thereafter, the MP-BGP information acquisition unit 113 outputs the MP-BGP information 213 to the linking unit 12.
[0067] The device information acquisition unit 114 acquires device information 214 including information on device settings and operating status of the network devices from the VPN network 2 (step S14). Thereafter, the device information acquisition unit 114 outputs the device information 214 to the linking unit 12.
[0068] The geographic information acquisition unit 115 acquires the geographic information 215 including the latitude and longitude information of the network device from the VPN network 2 (step S15). Thereafter, the geographic information acquisition unit 115 outputs the geographic information 215 to the linking unit 12.
[0069] The linking unit 12 links the fine-grained flow 211 with the topology 212, MP-BGP information 213, device information 214, and geographic information 215 for each of the MPLS / SR-MPLS VPNs VPNs 23 and 24 and the L2TP VPN VPN VPN 25 (step S16).
[0070] Next, the linking unit 12 stores the linked fine-grained flow 300 generated by the linking in the data storage unit 13 to generate the data lake 130 (step S17).
[0071] The traffic visualization unit 141 filters the associated fine-grained flows 300 at a predetermined time and in a predetermined field. Then, the traffic visualization unit 141 collects and plots statistical information included in the filtered associated fine-grained flows 300, and provides the traffic visualization information 221 to the user (step S18).
[0072] The path visualization unit 142 filters the associated fine-grained flow 300 at a predetermined time and in a predetermined field. Then, the path visualization unit 142 collects the router IDs, input IF IDs, and output IF IDs included in the filtered associated fine-grained flow 300, maps them to topology information, and draws them, thereby providing the path visualization information 222 to the user (step S19).
[0073] The geography visualization unit 143 filters the linked fine-grained flows 300 at a predetermined time and in a predetermined field. Then, the geography visualization unit 143 collects latitude and longitude information included in the filtered linked fine-grained flows 300 and draws a map showing the distribution of communications, thereby providing the geography visualization information 223 to the user (step S20).
[0074] The ground traffic visualization unit 144 filters the associated fine-grained flow 300 at a predetermined time and in a predetermined field. Then, the ground traffic visualization unit 144 collects the destination PE MPLS label, the IP addresses and MAC addresses of the destination and source of the packet, which are included in the filtered associated fine-grained flow 300, to generate and render ground traffic information, thereby providing the ground traffic visualization information 224 to the user (step S21).
[0075] [Effects of network information visualization device] As described above, the network information visualization device 1 generates the linked fine-grained flow 300 by linking the topology 212, MP-BGP information 213, device information 214, and geographic information 215 to the fine-grained flow 211 acquired from the VPN network 2. Thereafter, the network information visualization device 1 uses the linked fine-grained flow 300 to generate the traffic visualization information 221, path visualization information 222, geographic visualization information 223, and ground exchange visualization information 224, and provides them to the user.
[0076] For example, the presence or absence of a DDoS attack can be detected by visualizing the traffic time series using the traffic visualization information 221. Furthermore, for example, the presence or absence of an OTT communication abnormality can be confirmed by visualizing the traffic time series using the traffic visualization information 221, and it can be shown that the cause is not on the VPN network 2 side.
[0077] In addition, the path visualization information 222 makes it possible to compare paths before and after a user complaint, for example, and quickly narrow down the routers to be checked for abnormalities. Furthermore, the path visualization information 222 makes it possible to count VPN communications that pass through a failed device, for example, when a router or link fails, and quickly identify affected VPNs.
[0078] Furthermore, by visualizing the geographic distribution of communications using the geographic visualization information 223, it is possible to attract MEC data centers based on the geographic distribution of APL usage, for example. Furthermore, by visualizing the geographic distribution of communications using the geographic visualization information 223, it is possible to grasp communications in an area during a disaster, for example.
[0079] Furthermore, the ground exchange visualization information 224 makes it easy to confirm where to add a new link when performing provisioning, for example.
[0080] In this way, the network information visualization device 1 according to this embodiment can visualize and provide to users various information that is useful for the operation of the VPN network 2. Furthermore, users can operate the network using the information provided by the network information visualization device 1, thereby improving the reliability of the network.
[0081] [System configuration, etc.] Furthermore, the components of each device shown in the figure are conceptual functional units and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown, and all or part of the devices can be functionally or physically distributed or integrated in any unit depending on various loads, usage conditions, etc. Furthermore, all or any part of the processing functions performed by each device can be realized by a CPU (Central Processing Unit) and a program analyzed and executed by the CPU, or can be realized as hardware using wired logic.
[0082] Furthermore, among the processes described in this embodiment, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using a known method.In addition, the information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed as desired unless otherwise specified.
[0083] [program] In one embodiment, the network information visualization device 1 can be implemented by installing a network information visualization program that executes the above information processing as package software or online software on a desired computer. For example, by having an information processing device execute the above network information visualization program, the information processing device can function as the network information visualization device 1. The information processing device referred to here includes desktop and notebook personal computers. In addition, the information processing device also includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handy-phone Systems), as well as slate terminals such as PDAs (Personal Digital Assistants).
[0084] The network information visualization device 1 can also be implemented as an information providing server device that provides services related to the above-mentioned network information visualization processing to a client terminal device used by a user. For example, the information providing server device is implemented as a server device that receives time and field values as input and outputs a network information visualization image corresponding to the time and field values. In this case, the information providing server device may be implemented as a web server or as a cloud that provides services related to the above-mentioned network information visualization processing through outsourcing.
[0085] 11 is a diagram showing an example of a computer that executes a network information visualization program. The computer 1000 includes, for example, a memory 1010 and a CPU 1020. The computer 1000 also includes a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.
[0086] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM (Random Access Memory) 1012. The ROM 1011 stores a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1090. The disk drive interface 1040 is connected to a disk drive 1100. A removable storage medium such as a magnetic disk or optical disk is inserted into the disk drive 1100. The serial port interface 1050 is connected to a mouse 1110 and a keyboard 1120, for example. The video adapter 1060 is connected to a display 1130, for example.
[0087] The hard disk drive 1090 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. That is, a classification program that defines each process of the network information visualization device 1, which has functions equivalent to those of the network information visualization device 1, is implemented as a program module 1093 in which computer-executable code is written. The program module 1093 is stored, for example, in the hard disk drive 1090. For example, a program module 1093 for executing processes similar to those of the functional configuration of the network information visualization device 1 is stored in the hard disk drive 1090. Note that the hard disk drive 1090 may be replaced by an SSD (Solid State Drive).
[0088] Furthermore, setting data used in the processing of the above-described embodiment is stored as program data 1094, for example, in the memory 1010 or the hard disk drive 1090. Then, the CPU 1020 reads the program module 1093 or the program data 1094 stored in the memory 1010 or the hard disk drive 1090 into the RAM 1012 as necessary, and executes the processing of the above-described embodiment.
[0089] The program module 1093 and program data 1094 are not limited to being stored in the hard disk drive 1090, but may also be stored in, for example, a removable storage medium and read by the CPU 1020 via the disk drive 1100 or the like. Alternatively, the program module 1093 and program data 1094 may be stored in another computer connected via a network (such as a local area network (LAN) or a wide area network (WAN)). The program module 1093 and program data 1094 may then be read by the CPU 1020 from the other computer via the network interface 1070. [Explanation of symbols]
[0090] 1. Network information visualization device 2 VPN network 11 Information acquisition department 12 Stringing section 13 Data storage unit 14 Visualization part 111 Fine-grained flow acquisition unit 112 Topology Acquisition Unit 113 MP-BGP information acquisition section 114 Device information acquisition unit 115 Geographic Information Acquisition Department 141 Traffic Visualization Unit 142 Path Visualization Unit 143 Geographic Visualization Department 144 Ground Interchange Visualization Department
Claims
1. an information acquisition unit that acquires network information related to a predetermined Virtual Private Network (VPN), the network information including at least flow information having statistical information related to communications in the VPN; a linking unit that links the flow information with other network information included in the network information to generate linked flow information; a visualization unit that generates, based on the associated flow information, visualization information that associates the flow information with the other network information, including traffic visualization information that displays side by side information that visualizes traffic time series related to a predetermined communication interface based on the statistical information and information that visualizes traffic time series related to a plurality of VPNs having different network layers; and A network information visualization device comprising:
2. 2. The network information visualization device according to claim 1, wherein the visualization unit generates traffic visualization information, which is visualization information that visualizes a traffic time series related to a specified VPN or a specified communication interface at a specified time, based on the statistical information.
3. the information acquisition unit acquires the flow information including identification information on a plurality of network devices arranged in the predetermined VPN network, and a topology including the identification information on the network devices and topology information representing a connection relationship between the network devices; The linking unit links the identification information related to the network device with the topology information, 3. The network information visualization device according to claim 1, wherein the visualization unit generates path visualization information, which is visualization information that visualizes a path taken by a specified communication at a specified time, based on the identification information, the topology information, and the statistical information regarding the network devices.
4. the information acquisition unit acquires geographic information including the topology information and location information of the network devices; The linking unit links the topology information with the location information, 4. The network information visualization device according to claim 3, wherein the visualization unit generates geographic visualization information, which is visualization information that visualizes the geographical distribution of a specified communication at a specified time, based on the identification information, the location information, and the statistical information regarding the network devices.
5. the information acquisition unit acquires the flow information including VPN communication setting information related to transmission and reception of signals in a VPN present in the predetermined VPN network, VPN information including the VPN communication setting information and VPN identification information for identifying the VPN, and device information including the VPN identification information, device setting information and operating status information of the network device, The linking unit links the VPN communication setting information with the VPN identification information, The network information visualization device described in claim 3, characterized in that the visualization unit generates ground traffic visualization information, which is the visualization information that visualizes ground traffic between specified network devices at a specified time, based on the statistical information and the device information.
6. an information acquisition step of acquiring network information related to the predetermined VPN network, the network information including at least flow information having statistical information related to communications in the predetermined VPN network; a linking step of linking the flow information with other network information included in the network information to generate linked flow information; a visualization step of generating, based on the linked flow information, visualization information that associates the flow information with the other network information, the visualization information including traffic visualization information that displays side by side information that visualizes traffic time series related to a predetermined communication interface based on the statistical information and information that visualizes traffic time series related to a plurality of VPNs with different network layers; A network information visualization method comprising:
7. an information acquisition step of acquiring network information related to the predetermined VPN network, the network information including at least flow information having statistical information related to communications in the predetermined VPN network; a linking step of linking the flow information with other network information included in the network information to generate linked flow information; a visualization step of generating, based on the linked flow information, visualization information that associates the flow information with the other network information, the visualization information including traffic visualization information that displays side by side information that visualizes traffic time series related to a predetermined communication interface based on the statistical information and information that visualizes traffic time series related to a plurality of VPNs with different network layers; A network information visualization program characterized by causing a computer to execute the above.
8. A network information visualization system having a network information visualization device that visualizes a predetermined VPN network and network information in the predetermined VPN network, The network information visualization device includes: an information acquisition unit that acquires network information related to the predetermined VPN network, the network information including at least flow information having statistical information related to communications in the predetermined VPN network; a linking unit that links the flow information with other network information included in the network information to generate linked flow information; and a visualization unit that generates visualization information that associates the flow information with the other network information, based on the linked flow information, including traffic visualization information that displays side by side information that visualizes a traffic time series related to a predetermined communication interface based on the statistical information and information that visualizes a traffic time series related to a plurality of VPNs with different network layers. A network information visualization system characterized by:
Citation Information
Patent Citations
System and method for traffic analysis
JP2017098907A
Format conversion device, method, and program
JP2021090161A
Context-aware network and situation management for crypto-partitioned networks
US20170310638A1
Flow information collecting device
WO2009118827A1