Flow anomaly localization method and apparatus

By filtering and analyzing packet groups that overlap in shared links and time periods using network management equipment, and combining this with traffic control packet statistics, the problem of locating abnormal flows in complex interactive services has been solved, improving fault location efficiency and service stability.

WO2026002097A9PCT designated stage Publication Date: 2026-02-05HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/103720
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-29
Filing Date
2025-06-26
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively pinpoint the exact location causing abnormal business traffic transmission, especially in complex interactive services where it's difficult to quickly locate the source of the abnormal flow.

Method used

By obtaining the transmission path and time period of the abnormal flow through network management devices, a specified packet group that shares the same link and time period with it is selected. Combined with the statistical information of flow control packets, the location of the abnormality is determined.

Benefits of technology

It enables precise location of abnormal flows, improves fault location efficiency, and ensures the stability of business operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025103720_05022026_PF_FP_ABST
    Figure CN2025103720_05022026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a flow anomaly localization method and apparatus, relating to the technical field of networks. On the basis of a transmission path of an abnormal flow in a network and an abnormal transmission period corresponding to the abnormal flow, one or more specified packet groups are selected from packet groups transmitted over the network other than the abnormal flow; and an anomaly occurrence location of the abnormal flow is determined on the basis of an overlapping link between a transmission path of a specified packet group and the transmission path of the abnormal flow, a transmission period of the specified packet group, and a transmission period of a packet group transmitted by the abnormal flow during the abnormal transmission period. There is at least one overlapping link between the transmission path of the specified packet group and the transmission path of the abnormal flow, and the transmission period of the specified packet group overlaps the abnormal transmission period. By determining transmission time overlapping between a packet group sharing a link with the abnormal flow and the packet group in the abnormal flow during the abnormal transmission period, and in combination with the specific location of the shared link, accurate localization of the anomaly occurrence location of the abnormal flow is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for locating traffic anomaly

[0001] The present application claims priority to the Chinese patent application No. 202410874178.2, filed on June 29, 2024, and entitled "Method and device for locating traffic anomaly", the entire content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present application relates to the field of network technology, and in particular to a method and device for locating traffic anomaly. BACKGROUND

[0003] With the rapid development of network technology, more and more services need to transmit traffic through the network in the running process. Once the service traffic occurs transmission anomaly in the network, it will directly affect the service quality. The premise and key to solve the problem of service traffic transmission anomaly is how to effectively determine the location that causes the service traffic to occur transmission anomaly. SUMMARY

[0004] The present application provides a method and device for locating traffic anomaly.

[0005] In a first aspect, a method for locating traffic anomaly is provided. The method can be applied to a network management device. The method comprises: obtaining, by the network management device, a transmission path of an abnormal flow that occurs transmission anomaly in a network, an abnormal transmission time period corresponding to the abnormal flow, and a transmission time period of each of one or more message groups transmitted by the abnormal flow in the abnormal transmission time period. Each message group is used to complete one data transmission. The network management device screens one or more specified message groups from other message groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission time period. Each specified message group satisfies that there is at least one overlapping link between the transmission path of the specified message group and the transmission path of the abnormal flow, and the transmission time period of the specified message group overlaps with the abnormal transmission time period. The network management device determines the abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified message groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified message groups, and the transmission time period of each of one or more message groups transmitted by the abnormal flow in the abnormal transmission time period.

[0006] The present application determines the abnormal occurrence position of the abnormal flow by judging the transmission time overlap of the message groups sharing the link with the abnormal flow and the message groups in the abnormal flow in the abnormal transmission time period, and combining the specific position of the shared link, to realize the accurate positioning of the congestion point position of the abnormal flow.

[0007] Optionally, the abnormal flow is a remote direct memory access (RDMA) flow. Each packet group in the abnormal flow is used to transmit one message in the RDMA flow.

[0008] Optionally, the one or more specified packet groups include first-type packet groups. Each specified packet group in the first-type packet groups satisfies: a receiving device of the specified packet group is the same as a receiving device of the abnormal flow, an access link connected to the receiving device on a transmission path of the specified packet group is the same as an access link connected to the receiving device on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow includes a first access layer device and a convergence layer device, the first access layer device is connected to the receiving device, and the first access layer device is connected to the convergence layer device through a first interface. Accordingly, the network management device determines the implementation of the abnormal occurrence position of the abnormal flow according to the overlapping links between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified packet groups, and the transmission time period of each of the one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period, including: if the overlapping time length between the transmission time period of each of the packet groups transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each of the specified packet groups in the first-type packet groups satisfies the time overlap requirement, and the statistical information of the flow control packet sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission time period satisfies the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow.

[0009] Optionally, the overlapping time length between the transmission time period of each of the packet groups transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each of the specified packet groups in the first-type packet groups satisfies the time overlap requirement, including: the overlapping time length reaches a time threshold, and / or, an overlapping time length ratio reaches a ratio threshold. For example, the overlapping time length ratio is equal to the overlapping time length / the total transmission time length of each of the packet groups transmitted by the abnormal flow in the abnormal transmission time period.

[0010] Optionally, the flow control message is a priority flow control (PFC) message. The first preset condition that the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period satisfies can include that: the number of PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first number threshold, or the anti-pressure time length corresponding to the PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first time length threshold, or the anti-pressure proportion corresponding to the PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first anti-pressure proportion threshold. The anti-pressure time length refers to a time length for instructing the sending end to stop packet sending.

[0011] In the present application, by judging whether the transmission time of the message group of the receiving device shared by the abnormal flow and the access link connected thereto coincides with the transmission time of the message group in the abnormal flow in the abnormal transmission period and the flow control condition in the network, it is determined whether the receiving device causes the transmission abnormality of the abnormal flow to occur, so as to realize accurate positioning of the abnormal occurrence position of the abnormal flow.

[0012] Optionally, the transmission path of the abnormal flow further includes a second access layer device, the aggregation layer device is connected to the second access layer device through a second interface, and the second access layer device is connected to the sending device of the abnormal flow through a third interface. If the coincidence time length between the transmission time period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission time period of each specified message group in the first type of message group satisfies the time coincidence requirement, and the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period satisfies the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow, which can be alternatively implemented as: if the coincidence time length between the transmission time period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission time period of each message group in the first type of message group satisfies the time coincidence requirement, and the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period satisfies the first preset condition, the statistical information of the flow control messages sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission period satisfies a second preset condition, and the statistical information of the flow control messages sent by the second access layer device to the sending device through the third interface in the abnormal transmission period satisfies a third preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow.

[0013] In the present application, by judging whether there are flow control messages on the reverse link from the access layer device connected to the receiving device, the determination of whether the flow control message sent by the access layer device is for the abnormal flow can be facilitated, thereby improving the accuracy of the determination of the abnormal transmission position of the abnormal flow.

[0014] Optionally, the one or more specified message groups include a second type of message group. Each specified message group in the second type of message group satisfies that the transmission path of the specified message group includes a downlink aggregation link on the transmission path of the abnormal flow, and the transmission period of the specified message group overlaps with the abnormal transmission period. The transmission path of the abnormal flow includes a first access layer device, a second access layer device, and an aggregation layer device, the first access layer device is connected to the receiving device, the first access layer device is connected to the aggregation layer device through a first interface, the aggregation layer device is connected to the second access layer device through a second interface, the second access layer device is connected to the sending device of the abnormal flow, and the downlink aggregation link is a link between the aggregation layer device and the first access layer device. Correspondingly, the implementation manner of determining the abnormal occurrence position of the abnormal flow by the network management device according to the overlapping link between the transmission path of each of the one or more specified message groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified message groups, and the transmission period of each of the one or more message groups transmitted by the abnormal flow in the abnormal transmission period includes: if the overlapping time length between the transmission period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified message group in the second type of message group satisfies the time overlapping requirement, and the statistical information of the flow control message sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission period satisfies the second preset condition and the statistical information of the flow control message sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period does not satisfy the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link.

[0015] In the present application, by judging the transmission time overlap between the message group transmitted on the downlink aggregation link of the abnormal flow and the message group in the abnormal flow and the network congestion condition, it is determined whether the transmission abnormality is caused by the congestion of the downlink aggregation link.

[0016] Optionally, the second access layer device is connected with the sending device of the abnormal flow through a third interface. If the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet groups meets the time overlap requirement, and the statistical information of the flow control packets sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition and the statistical information of the flow control packets sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link. Alternatively, if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet groups meets the time overlap requirement, and the statistical information of the flow control packets sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, the statistical information of the flow control packets sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, and the statistical information of the flow control packets sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link.

[0017] In the present application, by judging whether there is a flow control packet on the reverse link from the aggregation layer device on the transmission path of the abnormal flow, it can be determined whether the flow control packet sent by the aggregation layer device is for the abnormal flow, thereby improving the accuracy of determining the abnormal transmission position of the abnormal flow.

[0018] Optionally, the one or more specified packet groups include a third type of packet group. Each specified packet group in the third type of packet group satisfies that a transmission path of the specified packet group includes an uplink aggregation link on the transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow includes a second access layer device and an aggregation layer device, the aggregation layer device is connected to the second access layer device through a second interface, the second access layer device is connected to a sending device of the abnormal flow through a third interface, and the uplink aggregation link is a link between the second access layer device and the aggregation layer device. Correspondingly, the network management device determines the implementation manner of the abnormal occurrence position of the abnormal flow according to the coincident link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified packet groups, and the transmission time period of each of the one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period, and the implementation manner includes: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group satisfies the time overlap requirement, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period satisfies the third preset condition and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period does not satisfy the second preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link.

[0019] In the present application, whether the transmission abnormality is caused by the congestion of the uplink aggregation link is determined by judging the transmission time overlap between the packet groups transmitted on the uplink aggregation link of the abnormal flow and the packet groups in the abnormal flow, and the network congestion.

[0020] Optionally, the one or more specified packet groups comprise a fourth type of packet group. Each specified packet group in the fourth type of packet group satisfies: a sending device of the specified packet group is the same as a sending device of the abnormal flow, an access link connected to a sending device on a transmission path of the specified packet group is the same as an access link connected to a sending device on a transmission path of the abnormal flow, and a transmission period of the specified packet group overlaps with the abnormal transmission period. The transmission path of the abnormal flow comprises a second access layer device connected to the sending device of the abnormal flow through a third interface. Accordingly, the network management device determines an implementation manner of the abnormal occurrence position of the abnormal flow according to overlapping links between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified packet groups, and the transmission period of each of the one or more packet groups transmitted by the abnormal flow in the abnormal transmission period, which comprises: if the overlapping time length between the transmission period of each packet group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified packet group in the fourth type of packet group satisfies a time overlapping requirement, and statistical information of a flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission period does not satisfy a third preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow comprises the sending device of the abnormal flow.

[0021] In the present application, whether the sending device causes the abnormal flow to have a transmission abnormality is determined by judging the transmission time overlapping condition of the packet group sharing the sending device and the access link connected thereto with the packet group in the abnormal flow in the abnormal transmission period and the link congestion condition, so as to realize accurate positioning of the abnormal occurrence position of the abnormal flow.

[0022] Optionally, the network management device outputs a traffic abnormality positioning result corresponding to the abnormal flow, the traffic abnormality positioning result comprising one or more of the abnormal occurrence position of the abnormal flow, the abnormal transmission period, or evidence. The evidence is used to prove the abnormal occurrence position of the abnormal flow.

[0023] In the present application, by outputting the traffic abnormality positioning result corresponding to the abnormal flow, the operation and maintenance personnel can quickly locate the fault position, so as to take corresponding isolation or recovery measures on the related devices or transmission links in time, improve the fault recovery efficiency, and thus guarantee the stability of the business operation.

[0024] Optionally, the evidence comprises transmission information of a flow identifier corresponding to a specified packet group whose transmission period overlaps with the transmission period of the packet group transmitted by the abnormal flow in the abnormal transmission period, the transmission information comprising one or more of flow transmission throughput, flow completion time, or flow sharing time information in the abnormal transmission period. The flow sharing time information is used to reflect the time overlapping information of the flow to which the specified packet group belongs and the packet group transmitted by the abnormal flow in the abnormal transmission period.

[0025] In a second aspect, a traffic anomaly locating apparatus is provided. The apparatus can be applied to a network management device, and the apparatus comprises a plurality of functional modules which interact to implement the method of the first aspect and its embodiments. The plurality of functional modules can be implemented based on software, hardware or a combination of software and hardware, and the plurality of functional modules can be combined or divided in any manner based on specific implementation.

[0026] For example, the apparatus comprises but is not limited to an obtaining module, a screening module and a determining module. Optionally, the apparatus further comprises an output module.

[0027] The obtaining module is configured to obtain a transmission path of an abnormal flow in which transmission anomaly occurs in the network, an abnormal transmission period corresponding to the abnormal flow, and a transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period, wherein each of the packet groups is used to complete one data transmission.

[0028] The screening module is configured to screen one or more specified packet groups from other packet groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission period, and each of the specified packet groups satisfies that there is at least one overlapping link between the transmission path of the specified packet group and the transmission path of the abnormal flow, and the transmission period of the specified packet group overlaps the abnormal transmission period.

[0029] The determining module is configured to determine an abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified packet groups, and the transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period.

[0030] Optionally, the abnormal flow is an RDMA flow, and each of the packet groups in the abnormal flow is used to transmit one message in the RDMA flow.

[0031] Optionally, the one or more specified packet groups comprise a first type of packet group, each specified packet group in the first type of packet group satisfying: a receiving device of the specified packet group is the same as the receiving device of the abnormal flow, an access link connected to the receiving device on a transmission path of the specified packet group is the same as an access link connected to the receiving device on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a first access layer device connected to the receiving device and a convergence layer device, and the first access layer device is connected to the convergence layer device through a first interface. The determining module is specifically configured to: if the overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the first type of packet group satisfies a time overlap requirement, and statistical information of a flow control packet sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission time period satisfies a first preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the receiving device of the abnormal flow.

[0032] Optionally, the transmission path of the abnormal flow further comprises a second access layer device, the convergence layer device is connected to the second access layer device through a second interface, and the second access layer device is connected to the sending device of the abnormal flow through a third interface. The determining module is specifically configured to: if the overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each packet group in the first type of packet group satisfies the time overlap requirement, and the statistical information of the flow control packet sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission time period satisfies the first preset condition, the statistical information of the flow control packet sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period satisfies a second preset condition, and the statistical information of the flow control packet sent by the second access layer device to the sending device of the abnormal flow through the third interface in the abnormal transmission time period satisfies a third preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the receiving device of the abnormal flow.

[0033] Optionally, the one or more specified packet groups comprise a second type of packet group, each specified packet group in the second type of packet group satisfying: a transmission path of the specified packet group comprises a downstream aggregation link on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a first access layer device, a second access layer device and an aggregation layer device, the first access layer device being connected to the receiving device, the first access layer device being connected to the aggregation layer device through a first interface, the aggregation layer device being connected to the second access layer device through a second interface, the second access layer device being connected to a sending device of the abnormal flow, and the downstream aggregation link being a link between the aggregation layer device and the first access layer device. The determining module is specifically configured to: if an overlap length between a transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and a transmission time period of each specified packet group in the second type of packet group satisfies a time overlap requirement, and statistical information of a flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period satisfies a second preset condition and statistical information of a flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not satisfy a first preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the downstream aggregation link.

[0034] Optionally, the second access layer device is connected to the sending device of the abnormal flow through a third interface. The determining module is specifically configured to: if the overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet group satisfies the time overlap requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period satisfies the second preset condition, the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period satisfies a third preset condition, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not satisfy the first preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the downstream aggregation link.

[0035] Optionally, the one or more specified packet groups comprise a third type of packet group, each specified packet group in the third type of packet group satisfying: a transmission path of the specified packet group comprises an uplink aggregation link on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a second access layer device and an aggregation layer device, the aggregation layer device being connected to the second access layer device through a second interface, the second access layer device being connected to a sending device of the abnormal flow through a third interface, and the uplink aggregation link being a link between the second access layer device and the aggregation layer device. The determining module is specifically configured to: if a time overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group satisfies a time overlap requirement, and statistical information of a flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period satisfies a third preset condition and statistical information of a flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period does not satisfy a second preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the uplink aggregation link.

[0036] Optionally, the one or more specified packet groups comprise a fourth type of packet group, each specified packet group in the fourth type of packet group satisfying: a sending device of the specified packet group is the same as a sending device of the abnormal flow, an access link connected to the sending device on a transmission path of the specified packet group is the same as an access link connected to the sending device on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a second access layer device, and the second access layer device is connected to the sending device of the abnormal flow through a third interface. The determining module is specifically configured to: if a time overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the fourth type of packet group satisfies a time overlap requirement, and statistical information of a flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period does not satisfy a third preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the sending device of the abnormal flow.

[0037] Optionally, the output module is configured to output a flow anomaly positioning result corresponding to the abnormal flow, the flow anomaly positioning result comprising one or more of the abnormal occurrence position of the abnormal flow, the abnormal transmission time period, or evidence used to prove the abnormal occurrence position of the abnormal flow.

[0038] Optionally, the evidence includes transmission information of a flow identifier corresponding to a flow to which the specified packet group belongs, the transmission information including one or more of flow transmission throughput, flow completion time, or flow sharing time information in the abnormal transmission period, the flow sharing time information reflecting time overlap information of the flow to which the specified packet group belongs and the packet group transmitted by the abnormal flow in the abnormal transmission period.

[0039] In a third aspect, a traffic anomaly positioning apparatus is provided, including a processor and a memory.

[0040] The memory is configured to store a computer program including program instructions, and the processor is configured to invoke the computer program to implement the method in the first aspect and each of the implementations thereof.

[0041] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores instructions thereon, and the instructions, when executed by a processor, implement the method in the first aspect and each of the implementations thereof.

[0042] In a fifth aspect, a computer program product is provided, and the computer program product includes a computer program, and the computer program, when executed by a processor, implements the method in the first aspect and each of the implementations thereof.

[0043] In a sixth aspect, a chip is provided. The chip includes a programmable logic circuit and / or program instructions. When the chip is running, the method in the first aspect and each of the implementations thereof is implemented. BRIEF DESCRIPTION OF DRAWINGS

[0044] FIG. 1 is a distributed training task view provided by an embodiment of the present application;

[0045] FIG. 2 is a schematic diagram of an implementation scenario provided by an embodiment of the present application;

[0046] FIG. 3 is a flowchart of a traffic anomaly positioning method provided by an embodiment of the present application;

[0047] FIG. 4 is a schematic diagram of an output interface provided by an embodiment of the present application;

[0048] FIG. 5 is a schematic diagram of another output interface provided by an embodiment of the present application;

[0049] FIG. 6 is a flowchart of a traffic anomaly analysis and positioning method provided by an embodiment of the present application;

[0050] FIG. 7 is a structural schematic diagram of a traffic anomaly positioning apparatus provided by an embodiment of the present application;

[0051] FIG. 8 is a schematic diagram of a hardware structure of a network management device according to an embodiment of the present application. DETAILED DESCRIPTION

[0052] For the purpose, technical solutions and advantages of the present application to be clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.

[0053] In current networks, traffic transmission anomalies often occur due to network environment, human operation or device defects, which directly affect service quality. Since most services (such as distributed training tasks, financial services or banking services, etc.) are sensitive to quality problems, it is necessary to timely detect traffic transmission anomalies and effectively determine the location of traffic transmission anomalies. In this way, after traffic transmission anomalies (such as a decrease in transmission throughput) occur, the anomalies can be located in time, and then corresponding isolation or recovery measures can be taken for related devices or transmission links.

[0054] Current network measurement mainly focuses on network traffic, bandwidth, explicit congestion notification (ECN) and PFC-related statistics. Current network measurement is mostly performed in a flow granularity, for example, a flow can be identified by a two-tuple, a four-tuple or a five-tuple. A network management device can capture a two-tuple, a four-tuple or a five-tuple of a passing packet from a network device to determine the flow to which the packet belongs, and in combination with network devices through which the packet of the flow passes, the flow size, transmission path, link bandwidth, whether congestion occurs and whether the PFC mechanism is enabled, etc. of the flow can be determined. The two-tuple includes a source Internet Protocol (IP) address and a destination IP address. The four-tuple includes a source IP address, a destination IP address, a source port and a destination port. The five-tuple includes a source IP address, a destination IP address, a source port, a destination port and a transport layer protocol.

[0055] However, for some services involving complex interactions, such as a service involving multiple sources and / or multiple destinations, the service corresponds to multiple flows, and the multiple flows have multiple transmission paths in the network. If the service has performance problems, the scattered data collected by the current network measurement method usually cannot effectively determine which flow has transmission anomalies that cause the performance problems of the service, nor can it effectively determine the location of the abnormal flow having transmission anomalies.

[0056] For example, a distributed training task, as a kind of distributed computing task, usually uses thousands of computing cards, and is a typical business involving complex interaction. With the development of artificial intelligence (AI) and big data technology, the computing resources and data resources available to the model are increasing, and the model parameter scale and computing demand are also increasing. Training the model becomes a very intensive and time-consuming task. Distributed training has become a mainstream technology to improve the efficiency of model training. A distributed training task usually involves multiple computing nodes, each of which has a part of data and model parameters, and multiple computing nodes need to interact with each other through a network to train the model together. Currently, there are two basic schemes for distributed parallel training of models, namely data parallelism (DP) and model parallelism (MP). Among them, the model parallelism scheme is divided into two categories according to the model splitting method: pipeline parallelism (PP) and tensor parallelism (TP). Data parallelism evenly distributes a batch of training data to multiple computing nodes, each of which maintains a complete copy of the model. After each training is completed, gradient synchronization communication is required between computing nodes to ensure that the models stored by all computing nodes have exactly the same parameters. Model parallelism splits the model and places it on multiple computing nodes to reduce memory usage during model training. Pipeline parallelism splits the model by layer, and tensor parallelism adopts a complex intra-layer tensor splitting method. Among them, the data parallelism (DP) stage and the pipeline parallelism (PP) stage involve communication between different computing nodes (inter-machine communication), and the tensor parallelism (TP) stage involves communication between different processing units within a single computing node (intra-machine communication). For example, FIG. 1 is a distributed training task view provided by an embodiment of the present application. As shown in FIG. 1, the distributed training task involves four computing nodes, denoted as computing nodes N0-N3. Each computing node Nx (x is any integer in 0-3) includes four graphics processing units (GPUs), denoted as GPU0-GPU3. In the DP stage, each computing node Nx is allocated a part of the training data, and multiple computing nodes communicate with each other through a network for gradient synchronization. In the PP stage, multiple computing nodes exchange model data through a network. In the TP stage, multiple GPUs within a computing node exchange model data through a bus technology, which can be, for example, a peripheral component interconnect express (PCIe) technology or an Nvlink technology.

[0057] In a distributed training task, data interaction between computing nodes usually adopts collective communication for implementation. One distributed training task can include one or more collective communications. Collective communication refers to coordinated communication between multiple processes in a distributed computing environment to complete certain specific tasks. Since one collective communication involves multiple interaction operations between computing nodes, all computing nodes participating in the collective communication must complete the interaction process, otherwise the distributed training task will be slowed down or even stuck.

[0058] Due to the long duration of the distributed training task, training task time degradation, training task interruption and other problems often occur due to various reasons, among which network congestion is one of the main reasons. Therefore, for distributed training tasks or collective communications and other services involving complex communication, it is necessary to quickly determine the abnormal flow and effectively determine the abnormal occurrence position of the abnormal flow.

[0059] The present application provides a technical solution for abnormal positioning of traffic. In the technical solution, a network management device obtains a transmission path of an abnormal flow in a network, an abnormal transmission period corresponding to the abnormal flow, and one or more transmission time periods of each packet group transmitted by the abnormal flow in the abnormal transmission period. Each packet group is used to complete one data transmission. Then the network management device screens one or more specified packet groups from other packet groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission period corresponding to the abnormal flow. Each specified packet group satisfies that there is at least one overlapping link between the transmission path of the specified packet group and the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission period. Finally, the network management device determines the abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified packet groups, and the transmission time period of each of the one or more packet groups transmitted by the abnormal flow in the corresponding abnormal transmission period. The present application determines the abnormal occurrence position of the abnormal flow by judging the transmission time overlap of the packet group sharing the link with the abnormal flow and the packet group in the abnormal flow in the abnormal transmission period, and combining the specific position of the shared link, to realize accurate positioning of the congestion point position of the abnormal flow.

[0060] Optionally, in the present application, a source IP address and a destination IP address are used to identify a flow, and an abnormal flow refers to an IP pair that indicates abnormal communication. A flow usually includes multiple message groups used to complete multiple data transmissions respectively. When the amount of data of a single data transmission is large, the data usually needs to be split and transmitted by multiple messages, and the multiple messages are a message group used to complete the data transmission. RDMA is a message-based transmission protocol. For an RDMA flow, completing a data transmission refers to completing the transmission of a message, and a message is split into multiple messages for transmission, wherein the first message is a first message and the last message is a last message, and a network device can identify a data transmission according to the received first message and last message, that is, a message group can be used to transmit a message. Optionally, the abnormal flow is an RDMA flow, and each message group in the abnormal flow is used to transmit a message in the RDMA flow.

[0061] The technical solutions of the present application are described in detail from the aspects of implementation scenarios, method flows, software devices, hardware devices, and the like.

[0062] The implementation scenarios of the embodiments of the present application are described below by way of example.

[0063] For example, FIG. 2 is a schematic diagram of an implementation scenario provided by an embodiment of the present application. As shown in FIG. 2, the implementation scenario includes a network management device 201, multiple terminal devices 202A-202C (collectively referred to as terminal devices 202), and multiple network devices 203A-203E (collectively referred to as network devices 203) in a communication network. The number of terminal devices and network devices in FIG. 2 is only used as an example for illustrative description, and does not limit the implementation scenario of the embodiments of the present application.

[0064] The network management device 201 can be a server, or a server cluster composed of several servers, or a cloud computing platform, or a network controller. The terminal device 202 can be a physical device such as a host or a server, or a logical device obtained by virtualizing the computing resources of a computer device such as a virtual machine. The network device 203 can be a switch, a router, or a firewall, etc. The network management device 201 and the network device 203 are connected through a wired network or a wireless network. The network management device 201 is used to manage the network devices 203 in the communication network. For example, the network management device 201 can issue a measurement command to the network device 203 to instruct the network device 203 to count the traffic characteristics of one or more flows flowing through itself, and receive and process the measurement results from the network device 203. The multiple terminal devices 202 communicate through one or more network devices 203 in the communication network.

[0065] Optionally, in the implementation scenario shown in FIG. 2 is a distributed training task scenario or a collective communication scenario, the terminal device 202 is a computing node. The computing node can include, but is not limited to, one or more processors of a central processing unit (CPU), a GPU, a tensor processing unit (TPU), or a neural processing unit (NPU), and the computing node can be a server with computing capability.

[0066] The communication network provided by the embodiments of the present application can be a data center network (DCN), a metropolitan area network, a wide area network, a campus network, a virtual local area network (VLAN), or a virtual extensible local area network (VXLAN), etc. The embodiments of the present application do not limit the type of the communication network. Optionally, the communication network provided by the embodiments of the present application supports RDMA, for example, the communication network can be a RDMA over converged Ethernet (RoCE) network or an InfiniBand (IB) network.

[0067] Optionally, the communication network provided by the embodiments of the present application can adopt a two-layer network architecture, such as a two-layer Clos architecture. The communication network includes an aggregation layer and an access layer, and the communication network can also be referred to as a two-layer network. The aggregation layer is a high-speed switching backbone of the communication network, and the access layer is used to access the terminal device to the communication network. The network device located in the access layer can be referred to as an access layer device, and the network device located in the aggregation layer can be referred to as an aggregation layer device. In the embodiments of the present application, the link between the access layer device and the terminal device is referred to as an access link, and the link between the access layer device and the aggregation layer device is referred to as an aggregation link. For example, referring to FIG. 2, the network device 203A and the network device 203B are located in the aggregation layer and are aggregation layer devices. The network device 203C, the network device 203D, and the network device 203E are located in the access layer and are access layer devices. Each terminal device 202 is connected to the network device 203C, the network device 203D, and the network device 203E respectively. The network device 203C, the network device 203D, and the network device 203E are connected to the network device 203A and the network device 203B respectively. The communication network adopting the two-layer network architecture can be a fat tree network, also known as a leaf-spine network, for example. In the leaf-spine network, the aggregation layer device can be a spine switch, and the access layer device can be a top of rack (tor) switch.

[0068] Alternatively, the communication network provided by the embodiments of the present application can also adopt a three-layer network architecture. Under the three-layer network architecture, the communication network includes a core layer, an aggregation layer and an access layer, and the communication network can also be referred to as a three-layer network. The core layer is a high-speed switching backbone of the communication network, the aggregation layer is configured to provide aggregation connection (connecting the access layer and the core layer), and the access layer is configured to access the terminal device to the communication network.

[0069] Optionally, please continue to refer to FIG. 2, the implementation scenario further includes a service platform 204. The service platform 204 can be a server, or a server cluster composed of a plurality of servers, or a cloud computing platform. The service platform 204 is configured to provide a human-computer interaction interface. Optionally, the service platform 204 includes a scheduling module, a tenant management module and an operation and maintenance monitoring module. The scheduling module is configured to allocate computing resources for services. The tenant management module is configured to manage tenant information. The operation and maintenance monitoring module is configured to monitor the quality of services. The service platform 204 is connected with the network management device 201 through a wired network or a wireless network. The service platform 204 can send a service measurement task to the network management device 201, and receive and display a traffic anomaly positioning result sent by the network management device 201. Optionally, the service platform 204 can be an AI service operation and maintenance platform.

[0070] The method flow of the embodiments of the present application is described below.

[0071] For example, FIG. 3 is a flow diagram of a traffic anomaly positioning method 300 provided by the embodiments of the present application. As shown in FIG. 3, the method 300 includes but is not limited to the following steps 301 to 303. Optionally, the method 300 further includes the following step 304. The method 300 can be applied to the network management device 201 in the implementation scenario shown in FIG. 2.

[0072] In step 301, the network management device acquires a transmission path of an abnormal flow in which transmission anomaly occurs in the network, an abnormal transmission period corresponding to the abnormal flow, and a transmission period of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period.

[0073] Each packet group is configured to complete one data transmission. In the embodiments of the present application, the transmission period of one packet group can include a transmission start time and a transmission end time of the packet group, or can include a transmission start time and a transmission length of the packet, or can include a transmission end time and a transmission length of the packet group, or can include a transmission start time, a transmission end time and a transmission length of the packet group.

[0074] Optionally, the transmission path of the abnormal flow comprises a sending device of the abnormal flow, network devices through which the abnormal flow passes in the network, and a receiving device of the abnormal flow. For example, referring to the implementation scenario shown in FIG. 2, the transmission path of an abnormal flow can be represented as: terminal device 202A→network device 203C→network device 203B→network device 203E→terminal device 202C. It should be noted that the transmission path of a flow in the embodiments of the present application can also indicate the ingress interface and the egress interface of the network device through which the flow passes. For example, the transmission path of a flow can be represented as: terminal device 202A→(interface C1 of network device 203C→interface C2 of network device 203C)→(interface B1 of network device 203B→interface B2 of network device 203B)→(interface E1 of network device 203E→interface E2 of network device 203E)→terminal device 202C, indicating that after the flow is sent by the terminal device 202A, it reaches the interface C1 (ingress interface) of the network device 203C, and is then sent by the interface C2 (egress interface) of the network device 203C, reaches the interface B1 (ingress interface) of the network device 203B, and is then sent by the interface B2 (egress interface) of the network device 203B, reaches the interface E1 (ingress interface) of the network device 203E, and is then sent by the interface E2 (egress interface) of the network device 203E, and reaches the terminal device 202C. In order to simplify the description, the transmission path of the flow described in the embodiments of the present application only shows the network devices through which the flow passes, but this does not limit the form of the transmission path.

[0075] In the embodiments of the present application, the abnormal transmission period corresponding to the abnormal flow refers to the period in which the abnormal flow occurs transmission abnormality. The start time of the abnormal transmission period is a certain historical time in the past, and the end time of the abnormal transmission period can be a certain historical time in the past or the current time. For example, in the case where the abnormal flow has ended transmission abnormality, the end time of the abnormal transmission period corresponding to the abnormal flow can be a certain historical time in the past. In the case where the abnormal flow has not ended transmission abnormality, the end time of the abnormal transmission period corresponding to the abnormal flow can be the current time.

[0076] Optionally, one implementation of the above step 301 is that the network management device determines the flow in the network that occurs transmission abnormality, and determines the transmission path of the abnormal flow, the abnormal transmission period corresponding to the abnormal flow, and the transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period.

[0077] The transmission abnormality of a flow described in the embodiments of the present application can refer to the transmission throughput abnormality of the flow. Optionally, the embodiments of the present application provide a scheme for detecting transmission abnormality of a flow in a network, and the implementation process of the scheme comprises the following steps A1 to A2.

[0078] In step A1, the network management device acquires a measurement result sent by a network device in the network, the measurement result comprising traffic characteristics corresponding to a flow identifier of a flow passing through the network device, the flow identifier comprising a device identifier of a sending device of the flow and a device identifier of a receiving device of the flow, the flow comprising a plurality of packet groups, and the traffic characteristics comprising a transmission time period of each of the plurality of packet groups in the flow, and the traffic characteristics being used to determine a transmission indicator of each of the plurality of packet groups in the flow.

[0079] Optionally, the transmission indicator of a packet group comprises a transmission duration and / or a transmission throughput. The network management device can determine the transmission duration of each of the plurality of packet groups in the flow according to the transmission time period of each of the plurality of packet groups in the flow. For example, the transmission of a packet group starts at T1 and ends at T2, and the transmission duration of the packet group is t = T2 - T1.

[0080] Optionally, the traffic characteristics of a flow further comprise a traffic size of each of the plurality of packet groups in the flow. The network management device can determine the transmission throughput of each of the plurality of packet groups in the flow according to the transmission duration and the traffic size of each of the plurality of packet groups in the flow. For example, the transmission duration of a packet group is t and the traffic size of the packet group is G, and the transmission throughput of the packet group is M = G / t, and the unit of the transmission throughput can be bit per second (bps).

[0081] Optionally, the measurement result sent by the network device to the network management device further comprises an interface identifier, the interface identifier being used to indicate an ingress interface and an egress interface of the flow passing through the network device.

[0082] In step A2, the network management device determines whether a transmission anomaly occurs in the flow according to the transmission time sequence of the plurality of packet groups in the flow and the transmission indicator of each of the plurality of packet groups.

[0083] Optionally, the implementation of step A2 is that the network management device groups the transmission indicator of each of the plurality of packet groups in a flow into a time sequence varying with time, and performs anomaly detection on the time sequence by using a time sequence anomaly detection algorithm to determine whether a transmission anomaly occurs in the flow. Further, the time period (including the anomaly start time) when the transmission anomaly occurs in the flow can be determined.

[0084] For example, in the case that the transmission indicators of the packet groups include transmission durations, the network management device groups the transmission durations of the multiple packet groups in a flow according to the transmission time sequence of the multiple packet groups to form a transmission duration time sequence, and performs anomaly detection on the transmission duration time sequence to determine whether the flow has a transmission anomaly. For the start point of the transmission duration time sequence, a duration threshold can be set. If the transmission duration of the packet group at the start point is higher than the duration threshold, it is determined that the flow has a transmission anomaly at the start point. For the intermediate points in the transmission duration time sequence, it can be determined whether there is an ascending mutation of the transmission duration. If there is an ascending mutation of the transmission duration, it is determined that the flow has a transmission anomaly at the mutation.

[0085] For example, in the case that the transmission indicators of the packet groups include transmission durations, the network management device groups the transmission durations of the multiple packet groups in a flow according to the transmission time sequence of the multiple packet groups to form a transmission duration time sequence, and performs anomaly detection on the transmission duration time sequence to determine whether the flow has a transmission anomaly. For the start point of the transmission duration time sequence, a duration threshold can be set. If the transmission duration of the packet group at the start point is higher than the duration threshold, it is determined that the flow has a transmission anomaly at the start point. For the intermediate points in the transmission duration time sequence, it can be determined whether there is an ascending mutation of the transmission duration. If there is an ascending mutation of the transmission duration, it is determined that the flow has a transmission anomaly at the mutation.

[0086] Optionally, before performing the above step A1, the network management device obtains measurement task information of the service, the measurement task information including device identifiers of multiple terminal devices associated with the service, the service including multiple service flows, and the multiple terminal devices including sending devices and receiving devices of the multiple service flows. The network management device sends a measurement command to multiple network devices in the network, the measurement command being used to instruct the network devices receiving the measurement command to count traffic features of one or more flows flowing through the network devices. Accordingly, in the above step A1, the measurement results obtained by the network management device are from the network devices receiving the measurement command. According to the measurement results respectively reported by the multiple network devices in the network, the network management device can determine the transmission path of the abnormal flow.

[0087] The terminal device associated with the service refers to a terminal device that transmits and / or receives one or more service flows of the service. The device identifier of the terminal device can be represented by an IP address of the terminal device. Alternatively, the device identifier of the terminal device can also be represented by an IP address of the terminal device and a port identifier associated with the service on the terminal device. For example, one terminal device is associated with multiple services, and different services use different ports of the terminal device. The IP address and the port identifier are used as the device identifier to distinguish the resources provided by the same terminal device for different services. Alternatively, the terminal device is a virtual resource obtained by virtualizing the computing resources of a computer device. The device identifier of the terminal device can be represented by a virtual resource identifier, for example, an IP address allocated to the virtual resource. The present application does not limit the representation of the device identifier of the terminal device. In the following embodiments, the device identifier of the terminal device is represented by an IP address of the terminal device as an example. Correspondingly, the measurement task information includes the IP addresses of the multiple terminal devices associated with the service. The IP addresses can be source IP addresses of service flows of the service, or can be destination IP addresses of service flows of the service.

[0088] Optionally, the service in the present application is a collective communication or a distributed training task. In the scenario where the service is a collective communication, the multiple terminal devices associated with the service refer to multiple computing nodes participating in the collective communication. The multiple computing nodes belong to one collective communication domain. Correspondingly, the device identifier in the measurement task information is used to limit all computing resources involved in the collective communication. Alternatively, in the scenario where the service is a distributed training task, the terminal device associated with the service refers to a computing node participating in the distributed training task. The device identifier in the measurement task information is used to limit all computing resources involved in the distributed training task. Optionally, one distributed training task usually includes multiple stages of collective communication. The computing resources involved in different stages of collective communication can be the same or different. That is, one distributed training task can correspond to one or more collective communication domains.

[0089] Optionally, if the network management device can explicitly know which network devices or interfaces of network devices the traffic generated by the current service will pass through, the network management device can send measurement commands to only these network devices to collect the traffic characteristics of the flows flowing through the corresponding interfaces of these network devices. If the network management device cannot explicitly know which network devices or interfaces of network devices the traffic generated by the current service will pass through, the network management device can send measurement commands to all network devices in the network respectively to collect the traffic characteristics of the flows flowing through the interfaces of the network devices.

[0090] Optionally, the measurement command can further include a measurement task validity time, such as permanent validity or validity within a period of time. In the case where the measurement command indicates permanent validity, the network device always maintains a working state of counting the traffic characteristics of the flow passing through itself before receiving a measurement end command sent by the network management device. In the case where the measurement command indicates validity within a period of time, the network device only counts the traffic characteristics of the flow passing through itself within the validity period, and after the validity period, the network device automatically stops performing the traffic counting task. Correspondingly, the network device can periodically (or on demand) send a measurement result to the network management device within the measurement task validity period, and the measurement result includes the respective transmission start time, transmission end time and traffic size of the ingress interface and egress interface of one or more flows passing through the network device on the network device and the packet groups transmitted within the current period. For example, flow 1 (IP1→IP2) passing through the network device 1 has an ingress interface of interface 11 and an egress interface of interface 21 on the network device 1, and flow 1 completes transmission of 3 packet groups within the current period, which are packet group 11, packet group 12 and packet group 13. The transmission start time of packet group 11 is T11, the transmission end time is T12, and the traffic size is F1. The transmission start time of packet group 12 is T13, the transmission end time is T14, and the traffic size is F2. The transmission start time of packet group 13 is T15, the transmission end time is T16, and the traffic size is F3. Flow 2 (IP3→IP4) passing through the network device 1 has an ingress interface of interface 12 and an egress interface of interface 22 on the network device 1, and flow 2 completes transmission of 2 packet groups within the current period, which are packet group 21 and packet group 22. The transmission start time of packet group 21 is T21, the transmission end time is T22, and the traffic size is F4. The transmission start time of packet group 22 is T23, the transmission end time is T24, and the traffic size is F5. Then, the network device 1 sends a measurement result to the network management device as shown in Table 1.

[0091] Table 1

[0092] Optionally, after determining the abnormal flow in which transmission anomaly occurs in the network, the network management device can output the flow identifier of the abnormal flow and the abnormal transmission period corresponding to the abnormal flow. For example, in the implementation scenario shown in FIG. 2, it is assumed that the transmission path of an abnormal flow is: terminal device 202A→network device 203C→network device 203B→network device 203E→terminal device 202C. The IP address of the terminal device 202A is IP1, and the IP address of the terminal device 202C is IP2. The flow identifier of the abnormal flow can be represented by the source IP address and the destination IP address, that is, represented as an abnormal IP pair: IP1→IP2. FIG. 4 is a schematic diagram of an output interface provided in an embodiment of the present application. As shown in FIG. 4, the output interface can include the flow identifier (abnormal IP pair) of the abnormal flow, the abnormal transmission period (T13→T16) corresponding to the abnormal flow, and the transmission path (abnormal transmission path) of the abnormal flow.

[0093] In the embodiment of the present application, by outputting the flow identifier of the abnormal flow and the abnormal transmission period corresponding to the abnormal flow, the network management device facilitates the operation and maintenance personnel to timely find the flow in which transmission anomaly occurs in the network and the time period in which transmission anomaly occurs, thereby helping the operation and maintenance personnel to quickly solve the problem.

[0094] Alternatively, another implementation of the above step 301 is that a device other than the network management device determines the flow in which transmission anomaly occurs in the network, and determines the transmission path of the abnormal flow, the abnormal transmission period corresponding to the abnormal flow, and the transmission time period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period. The specific implementation process can refer to the implementation scheme of the network management device. The network management device receives the transmission path of the abnormal flow, the abnormal transmission period corresponding to the abnormal flow, and the transmission time period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period sent by the other device.

[0095] Step 302, the network management device screens one or more specified packet groups from other packet groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission period. Each specified packet group meets that there is at least one overlapping link between the transmission path of the specified packet group and the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission period.

[0096] Optionally, the one or more specified packet groups screened out in step 302 include one or more types of packet groups, and the coincident links between the transmission path of different types of packet groups and the transmission path of the abnormal flow are different. Each type of packet group is respectively used to determine whether a position on the transmission path of the abnormal flow is an abnormal occurrence position (such as a congestion position) of the abnormal flow. For example, taking a network adopting a two-layer network architecture as an example, the one or more specified packet groups screened out in step 302 include one or more of the following four types of packet groups: a first type of packet group, wherein the coincident links between the transmission path of each specified packet group and the transmission path of the abnormal flow include an access link (a downlink access link, i.e., a link from an access layer device to a receiving device) connected to the respective receiving device; a second type of packet group, wherein the coincident links between the transmission path of each specified packet group and the transmission path of the abnormal flow include a downlink aggregation link (i.e., a link from an aggregation layer device to an access layer device connected to the receiving device); a third type of packet group, wherein the coincident links between the transmission path of each specified packet group and the transmission path of the abnormal flow include an uplink aggregation link (i.e., a link from an access layer device connected to a sending device to the aggregation layer device); and a fourth type of packet group, wherein the coincident links between the transmission path of each specified packet group and the transmission path of the abnormal flow include an access link (an uplink access link, i.e., a link from the sending device to the access layer device) connected to the respective sending device.

[0097] For example, referring to the implementation scenario shown in FIG. 2, assuming that the transmission path of the abnormal flow is: terminal device 202A→network device 203C→network device 203B→network device 203E→terminal device 202C, then the specified packet group in the above-mentioned first type of packet group satisfies: the receiving device is the terminal device 202C, and the link from the network device 203E to the terminal device 202C in the transmission path of the abnormal flow is passed through; the specified packet group in the above-mentioned second type of packet group satisfies: the link from the network device 203B to the network device 203E in the transmission path of the abnormal flow is passed through; the specified packet group in the above-mentioned third type of packet group satisfies: the link from the network device 203C to the network device 203B in the transmission path of the abnormal flow is passed through; and the specified packet group in the above-mentioned fourth type of packet group satisfies: the sending device is the terminal device 202A, and the link from the terminal device 202A to the network device 203C in the transmission path of the abnormal flow is passed through.

[0098] In step 303, the network management device determines the abnormal occurrence position of the abnormal flow according to the coincident links between the respective transmission path of the one or more specified packet groups and the transmission path of the abnormal flow, the respective transmission time period of the one or more specified packet groups, and the respective transmission time period of one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period.

[0099] A flow transmission anomaly, such as a transmission throughput anomaly, is mostly caused by network congestion. The root cause of network congestion is that multiple terminal devices send different flows on the same link at the same time, and the link bandwidth cannot meet the optimal throughput performance of these flows. At this time, the network device can reduce the flow transmission rate of the terminal device through the flow control mechanism (such as the PFC mechanism), so as to realize lossless transmission of the network. Based on this principle, the embodiments of the present application determine the transmission time overlap of the message groups sharing the link with the abnormal flow and the message groups in the abnormal flow within the abnormal transmission period, combine the specific location of the shared link, and further combine the flow control message transmitted in the network to determine the abnormal occurrence position of the abnormal flow, so as to realize accurate positioning of the congestion point position of the abnormal flow.

[0100] Optionally, in combination with the example shown in step 302, the network adopting a two-layer network architecture is taken as an example, and the embodiments of the present application provide the following four implementation manners to judge four possible positions causing transmission anomaly of the abnormal flow.

[0101] The first implementation manner is used to judge whether the abnormal transmission position of the abnormal flow includes the receiving device of the abnormal flow. The one or more specified message groups screened in step 302 include the first type of message group. Each specified message group in the first type of message group satisfies that the receiving device of the specified message group is the same as the receiving device of the abnormal flow, the access link connected to the receiving device on the transmission path of the specified message group is the same as the access link connected to the receiving device on the transmission path of the abnormal flow, and the transmission period of the specified message group overlaps with the abnormal transmission period. Wherein, the transmission path of the abnormal flow includes a first access layer device and a convergence layer device, the first access layer device is connected to the receiving device, and the first access layer device is connected to the convergence layer device through a first interface. Correspondingly, the implementation manner of step 303 is that if the overlap time length between the transmission period of each message group transmitted by the abnormal flow within the abnormal transmission period and the transmission period of each specified message group in the first type of message group meets the time overlap requirement, and the statistical information of the flow control message sent by the first access layer device to the convergence layer device through the first interface within the abnormal transmission period meets the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow.

[0102] Optionally, the overlap duration between the transmission period of each packet group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified packet group in the first type of packet groups satisfies a time overlap requirement, including: the overlap duration reaches a duration threshold, and / or, the overlap duration proportion reaches a proportion threshold. The overlap duration proportion is, for example, equal to the overlap duration / the total transmission duration of each packet group transmitted by the abnormal flow in the abnormal transmission period. The overlap duration here can be the total duration of the overlap period between the transmission period of each specified packet group in the first type of packet groups and the transmission period of each packet group transmitted by the abnormal flow in the abnormal transmission period. For example, the abnormal flow transmits 3 packet groups in the abnormal transmission period, the transmission periods of the 3 packet groups are 00:00-00:05, 00:10-00:15 and 00:20-00:25 respectively, and the first type of packet groups includes 2 specified packet groups, the transmission periods of the 2 specified packet groups are 00:02-00:08 and 00:03-00:12 respectively, then the overlap period between the specified packet group with the transmission period of 00:02-00:08 and the 3 packet groups of the abnormal flow is 00:02-00:05, the overlap period between the specified packet group with the transmission period of 00:03-00:12 and the 3 packet groups of the abnormal flow includes 00:03-00:05 and 00:10-00:12, and correspondingly, the overlap period between the transmission period of each of the 2 specified packet groups of the first type of packet groups and the transmission period of each of the 3 packet groups of the abnormal flow includes 00:02-00:05 and 00:10-00:12, and correspondingly, the overlap duration is 5 seconds, and the overlap duration proportion is 5 seconds / 15 seconds=1 / 3 (wherein 15 seconds is the total transmission duration of the 3 packet groups of the abnormal flow).

[0103] Optionally, the flow control message is a PFC message. Alternatively, in an IB network, the flow control message can also be a credit message. Embodiments of the present application take the flow control message as a PFC message as an example. When the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period meets the first preset condition, the statistical information can include that: the number of PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first number threshold, or the anti-pressure time length corresponding to the PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first time length threshold, or the anti-pressure ratio corresponding to the PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period reaches a first anti-pressure ratio threshold. The anti-pressure ratio corresponding to the PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period can be equal to the ratio of the number of PFC messages sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period to the number of data messages received by the first access layer device from the aggregation layer device through the first interface in the abnormal transmission period. The anti-pressure time length refers to the time length for indicating the sending end to stop packet sending.

[0104] In this implementation, by judging whether the transmission time of the message groups of the receiving device shared by the abnormal flow and the access link connected thereto and the message groups in the abnormal flow coincide in the abnormal transmission period and the flow control condition in the network, it is determined whether the abnormal flow occurs transmission abnormality due to the receiving device, so as to realize accurate positioning of the abnormal occurrence position of the abnormal flow. In addition, after determining that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow, it can be inferred based on this implementation that the abnormal root cause is that the receiving device of the abnormal flow simultaneously receives multiple flows sent by one or more sending devices, causing the flow to occur transmission throughput abnormality.

[0105] Optionally, the transmission path of the abnormal flow further comprises a second access layer device, the convergence layer device is connected with the second access layer device through a second interface, and the second access layer device is connected with the sending device of the abnormal flow through a third interface. Alternatively, the implementation of the step 303 is that if the overlap duration between the transmission time period of each packet group of the abnormal flow transmitted in the abnormal transmission time period and the transmission time period of each packet group in the first type of packet group meets the time overlap requirement, and the statistical information of the flow control packet sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission time period meets the first preset condition, the statistical information of the flow control packet sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow comprises the receiving device of the abnormal flow.

[0106] It should be noted that the preset conditions required to be met by the statistical information of the flow control packet set for different network devices can be the same or different, and can be determined according to the function configuration of the network device for the flow control packet. For example, the statistical information of the PFC packet sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, which can comprise that the number of PFC packets sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period reaches a second number threshold, or the pressure time corresponding to the PFC packet sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period reaches a second time threshold, or the pressure ratio corresponding to the PFC packet sent by the convergence layer device to the second access layer device through the second interface in the abnormal transmission time period reaches a second pressure ratio threshold. Assuming that the pressure time corresponding to the PFC packet sent by the first access layer device is greater than the pressure time corresponding to the PFC packet sent by the convergence layer device, the second number threshold can be set to be greater than the first number threshold, the second time threshold can be set to be equal to the first time threshold, and the second pressure ratio threshold can be set to be greater than the first pressure ratio threshold.

[0107] The embodiments of the present application can help to determine whether the flow control packet sent by the access layer device is for the abnormal flow by judging whether there is a flow control packet on the reverse link from the access layer device connected to the receiving device on the transmission path of the abnormal flow, thereby improving the accuracy of determining the abnormal transmission position of the abnormal flow.

[0108] Optionally, after determining the abnormal occurrence position of the abnormal flow including the receiving device of the abnormal flow, the network management device can further generate evidence 1, which can be used to prove that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow. Optionally, the evidence 1 includes transmission information of a flow identifier corresponding to a specified packet group in the first type of packet group, which has a transmission time period overlapping with a transmission time period of the packet group transmitted by the abnormal flow in the abnormal transmission time period. The transmission information includes but is not limited to one or more of the flow transmission throughput, the flow completion time or the flow sharing time information in the abnormal transmission time period. Wherein, the flow sharing time information is used to reflect the time overlapping information of the flow to which the specified packet group belongs and the packet group transmitted by the abnormal flow in the abnormal transmission time period. The flow to which the specified packet group in the first type of packet group belongs, that is, the flow of the access link connected to the receiving device shared by the abnormal flow in the abnormal transmission time period, is called the first type of shared flow in the embodiments of the present application for the convenience of description.

[0109] Optionally, the flow identifier of the first type of shared flow is represented by a source IP address and a destination IP address, i.e., can be represented as a shared IP pair. The flow completion time (FCT) of the first type of shared flow in the abnormal transmission period is determined according to the transmission duration of one or more message groups in the message group set of the first type of shared flow, the transmission of which ends in the abnormal transmission period. Optionally, the flow completion time of a flow in a statistical period is a statistical value of the transmission duration of all message groups in the flow, the transmission of which ends in the statistical period, and the statistical value can be an average value, a median value, a maximum value, or a quantile value. The flow transmission throughput of the first type of shared flow in the abnormal transmission period is determined according to the transmission duration and the traffic size of one or more message groups in the message group set of the first type of shared flow, the transmission of which ends in the abnormal transmission period. The flow sharing time information of the first type of shared flow in the abnormal transmission period can include the overlapping transmission period of the first type of shared flow itself and the abnormal flow. For example, a first type of shared flow transmits 2 message groups in the abnormal transmission period, and the transmission periods of the 2 message groups are 00:02-00:07 and 00:12-00:17, respectively. The abnormal flow transmits 3 message groups in the abnormal transmission period, and the transmission periods of the 3 message groups are 00:00-00:05, 00:10-00:15, and 00:20-00:25, respectively. The flow sharing time information of the first type of shared flow in the abnormal transmission period can include the overlapping transmission period 00:02-00:05 and 00:12-00:15, and the shared duration of 6 seconds. Or in the case of multiple first type of shared flows, the flow sharing time information of the first type of shared flow in the abnormal transmission period can include the overlapping transmission period of each of the first type of shared flow and the abnormal flow, and the completely overlapping transmission period of all the first type of shared flow and the abnormal flow. For another example, another first type of shared flow transmits 1 message group in the abnormal transmission period, and the transmission period of the message group is 00:01-00:06. The flow sharing time information of the first type of shared flow in the abnormal transmission period can include the overlapping transmission period 00:01-00:05, and the shared duration of 4 seconds. In addition, it can also include the completely overlapping transmission period 00:02-00:05 of the 2 first type of shared flows and the abnormal flow, and the completely shared duration of 3 seconds.

[0110] In a second implementation, whether the abnormal transmission position of the abnormal flow includes the downstream aggregation link of the abnormal flow is determined. The one or more specified message groups filtered in step 302 include a second type of message group. Each specified message group in the second type of message group satisfies that a transmission path of the specified message group includes a downstream aggregation link on the transmission path of the abnormal flow, and a transmission period of the specified message group overlaps with the abnormal transmission period. The transmission path of the abnormal flow includes a first access layer device, a second access layer device, and an aggregation layer device. The first access layer device is connected to the receiving device. The first access layer device is connected to the aggregation layer device through a first interface. The aggregation layer device is connected to the second access layer device through a second interface. The second access layer device is connected to the sending device of the abnormal flow. The downstream aggregation link is a link between the aggregation layer device and the first access layer device. Accordingly, the implementation of step 303 is that if the overlap duration between the transmission period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified message group in the second type of message group satisfies the time overlap requirement, and the statistical information of the flow control message sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission period satisfies the second preset condition and the statistical information of the flow control message sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission period does not satisfy the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the downstream aggregation link.

[0111] The related explanation of the overlap duration between the transmission period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified message group in the second type of message group satisfying the time overlap requirement can be referred to the related explanation of the overlap duration between the transmission period of each message group transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each specified message group in the first type of message group satisfying the time overlap requirement in the first implementation. The embodiments of the present application will not be repeated here.

[0112] Optionally, the flow control message is a PFC message. In a case where the first preset condition comprises that a number of PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period reaches a first number threshold, the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not satisfy the first preset condition can comprise that the number of PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not reach the first number threshold. In a case where the first preset condition comprises that a pressure duration corresponding to the PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period reaches a first duration threshold, the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not satisfy the first preset condition can comprise that the pressure duration corresponding to the PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not reach the first duration threshold. In a case where the first preset condition comprises that a pressure ratio corresponding to the PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period reaches a first pressure ratio threshold, the statistical information of the flow control messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not satisfy the first preset condition can comprise that the pressure ratio corresponding to the PFC messages sent by the first access layer device to the aggregation layer device via the first interface in the abnormal transmission period does not reach the first pressure ratio threshold. The determination manner of whether the statistical information of the flow control message satisfies the preset condition can refer to the related content in the first implementation manner, which will not be described here again.

[0113] In this implementation manner, by judging whether the transmission time of the message group sharing the downlink aggregation link with the abnormal flow and the message group in the abnormal flow in the abnormal transmission period coincides and the flow control condition in the network, it is determined whether the abnormal flow occurs transmission abnormality due to the downlink aggregation link, so as to realize accurate positioning of the abnormal occurrence position of the abnormal flow. In addition, after determining that the abnormal occurrence position of the abnormal flow comprises the downlink aggregation link of the abnormal flow, it can be inferred that the abnormal root cause is that the flow occurs transmission throughput abnormality due to the congestion of the downlink aggregation link of the abnormal flow.

[0114] Optionally, the second access layer device is connected with the sending device of the abnormal flow through a third interface. Alternatively, the implementation of the step 303 is as follows: if the overlap duration between the transmission period of each packet group transmitted by the abnormal flow during the abnormal transmission period and the transmission period of each specified packet group in the second type of packet group meets the time overlap requirement, the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface during the abnormal transmission period meets the second preset condition, the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface during the abnormal transmission period meets the third preset condition, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface during the abnormal transmission period does not meet the first preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link.

[0115] By judging whether there is a flow control packet on the reverse link from the aggregation layer device on the transmission path of the abnormal flow, the embodiment of the present application can help determine whether the flow control packet sent by the aggregation layer device is for the abnormal flow, thereby improving the accuracy of determining the abnormal transmission position of the abnormal flow.

[0116] Optionally, after determining that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link of the abnormal flow, the network management device can further generate evidence 2, which can be used to prove that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link of the abnormal flow. Optionally, the evidence 2 includes the transmission information corresponding to the flow identifier of the flow to which the specified packet group belongs, the transmission period of which overlaps with the transmission period of the packet group transmitted by the abnormal flow during the abnormal transmission period. For ease of description, the flow that shares the downlink aggregation link with the abnormal flow during the abnormal transmission period is referred to as the second type of shared flow in the embodiment of the present application. The explanation of the transmission information corresponding to the flow identifier of the second type of shared flow can refer to the related explanation of the transmission information corresponding to the flow identifier of the first type of shared flow in the first implementation mode, which will not be described herein again.

[0117] In the third implementation, whether the abnormal transmission position of the abnormal flow includes the uplink aggregation link of the abnormal flow is determined. The one or more specified packet groups filtered in the step 302 include a third type of packet group. Each specified packet group in the third type of packet group satisfies that the transmission path of the specified packet group includes the uplink aggregation link on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow includes the second access layer device and the aggregation layer device, the aggregation layer device is connected to the second access layer device through the second interface, the second access layer device is connected to the sending device of the abnormal flow through the third interface, and the uplink aggregation link is a link between the second access layer device and the aggregation layer device. Accordingly, the implementation of the step 303 is as follows: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group satisfies the time overlap requirement, the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period satisfies the third preset condition, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period does not satisfy the second preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link.

[0118] The related explanation of the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group satisfying the time overlap requirement can be referred to the related explanation of the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the first type of packet group satisfying the time overlap requirement in the first implementation. The determination of whether the statistical information of the flow control packet satisfies the preset condition can be referred to the related content in the first implementation and the second implementation, which will not be described herein again.

[0119] In this implementation, whether the abnormal flow occurs transmission abnormality due to the uplink aggregation link is determined by judging the transmission time overlap of the packet group sharing the uplink aggregation link with the packet group in the abnormal flow in the abnormal transmission time period and the flow control in the network, so as to accurately locate the abnormal occurrence position of the abnormal flow. In addition, after it is determined that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link of the abnormal flow, it can be inferred that the abnormal root cause is that the uplink aggregation link of the abnormal flow is congested to cause the transmission throughput abnormality of the flow.

[0120] Optionally, after determining that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link of the abnormal flow, the network management device can further generate evidence 3, which can be used to prove that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link of the abnormal flow. Optionally, the evidence 3 includes transmission information of a flow identifier corresponding to a specified packet group in the third type of packet group, which has a transmission time period overlapping with the transmission time period of the packet group transmitted by the abnormal flow in the abnormal transmission time period. For ease of description, the flow that shares the uplink aggregation link with the abnormal flow in the abnormal transmission time period is referred to as a third type of shared flow in the embodiments of the present application. The explanation of the transmission information of the flow identifier corresponding to the third type of shared flow can refer to the related explanation of the transmission information of the flow identifier corresponding to the first type of shared flow in the first implementation mode, which will not be described herein again.

[0121] In the fourth implementation mode, whether the abnormal transmission position of the abnormal flow includes the sending device of the abnormal flow is determined. The one or more specified packet groups screened in the step 302 include a fourth type of packet group. Each specified packet group in the fourth type of packet group satisfies that the sending device of the specified packet group is the same as the sending device of the abnormal flow, the access link connected to the sending device on the transmission path of the specified packet group is the same as the access link connected to the sending device on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow includes a second access layer device connected to the sending device of the abnormal flow through a third interface. Accordingly, the implementation mode of the step 303 is that if the overlapping time length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the fourth type of packet group satisfies the time overlapping requirement, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period does not satisfy the third preset condition, the network management device determines that the abnormal occurrence position of the abnormal flow includes the sending device of the abnormal flow.

[0122] The related explanation of the overlapping time length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the fourth type of packet group satisfying the time overlapping requirement can refer to the related explanation of the overlapping time length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the first type of packet group satisfying the time overlapping requirement in the first implementation mode. The determination mode of whether the statistical information of the flow control packet satisfies the preset condition can refer to the related content in the first implementation mode and the second implementation mode, which will not be described herein again.

[0123] In this implementation, whether the sending device causes the transmission anomaly of the abnormal flow is determined by judging whether the transmission time of the packet group shared with the abnormal flow by the sending device and the access link connected thereto coincides with the transmission time of the packet group in the abnormal flow within the abnormal transmission period and the link congestion, so as to accurately locate the abnormal position of the abnormal flow. In addition, after determining that the abnormal position of the abnormal flow includes the sending device of the abnormal flow, it can be inferred that the abnormal root cause is that the sending device of the abnormal flow simultaneously sends multiple flows to one or more receiving devices, causing the transmission throughput anomaly of the flow.

[0124] Optionally, after determining that the abnormal position of the abnormal flow includes the sending device of the abnormal flow, the network management device can further generate evidence 4, which can be used to prove that the abnormal position of the abnormal flow includes the sending device of the abnormal flow. Optionally, the evidence 4 includes the transmission information corresponding to the flow identifier of the specified packet group of the fourth type of packet group, which coincides with the transmission time of the packet group of the abnormal flow within the abnormal transmission period. In order to facilitate the description, the flow connected to the access link of the sending device shared by the abnormal flow within the abnormal transmission period is referred to as the fourth type of shared flow in the embodiment of the present application. The explanation of the transmission information corresponding to the flow identifier of the fourth type of shared flow can be referred to the above-mentioned related explanation of the transmission information corresponding to the flow identifier of the first type of shared flow, which will not be described herein again.

[0125] It is worth noting that the implementation sequence of the above-mentioned four implementations is not limited in the embodiment of the present application. For example, in one implementation, the network device sequentially executes the above-mentioned first implementation to the fourth implementation. Specifically, the network management device first judges whether the abnormal transmission position of the abnormal flow includes the receiving device of the abnormal flow (corresponding to the first implementation), and then further judges whether the abnormal transmission position of the abnormal flow includes the downlink aggregation link of the abnormal flow (corresponding to the second implementation) after determining that the abnormal transmission position of the abnormal flow does not include the receiving device of the abnormal flow, otherwise the judgment process is stopped. Further, the abnormal transmission position of the abnormal flow is judged whether it includes the uplink aggregation link of the abnormal flow (corresponding to the third implementation) after determining that the abnormal transmission position of the abnormal flow does not include the downlink aggregation link of the abnormal flow, otherwise the judgment process is stopped. Further, the abnormal transmission position of the abnormal flow is judged whether it includes the sending device of the abnormal flow (corresponding to the fourth implementation) after determining that the abnormal transmission position of the abnormal flow does not include the uplink aggregation link of the abnormal flow. In this way, unnecessary judgment can be reduced, thereby saving processing resources. For another example, in another implementation, the network device simultaneously executes the above-mentioned first implementation to the fourth implementation, that is, the positions possibly causing the transmission anomaly of the abnormal flow are judged in parallel, so as to improve the judgment efficiency.

[0126] In step 304, the network management device outputs a traffic anomaly positioning result corresponding to the abnormal flow, the traffic anomaly positioning result including one or more of an abnormal occurrence position of the abnormal flow, an abnormal transmission time period, or evidence proving the abnormal occurrence position of the abnormal flow.

[0127] Optionally, the evidence includes transmission information corresponding to a flow identifier of a specified packet group, the transmission information including one or more of a flow transmission throughput, a flow completion time, or flow sharing time information of the abnormal flow in the abnormal transmission time period. The flow sharing time information reflects time overlap information of the specified packet group belonging to the flow and the packet group transmitted by the abnormal flow in the abnormal transmission time period. For example, in a case where the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow, the evidence includes the evidence 1 described above. In a case where the abnormal occurrence position of the abnormal flow includes the downlink aggregation link of the abnormal flow, the evidence includes the evidence 2 described above. In a case where the abnormal occurrence position of the abnormal flow includes the uplink aggregation link of the abnormal flow, the evidence includes the evidence 3 described above. In a case where the abnormal occurrence position of the abnormal flow includes the sending device of the abnormal flow, the evidence includes the evidence 4 described above.

[0128] For example, in the implementation scenario shown in FIG. 2, it is assumed that the transmission path of an abnormal flow is: terminal device 202A→network device 203C→network device 203B→network device 203E→terminal device 202C. The abnormal occurrence position of the abnormal flow includes the terminal device 202A. There is one shared flow that shares the link from the terminal device 202A to the network device 203C with the abnormal flow in the abnormal transmission time period, the sending device of the shared flow being the terminal device 202A and the receiving device being the terminal device 202B. The IP address of the terminal device 202A is IP1, the IP address of the terminal device 202C is IP2, and the IP address of the terminal device 202B is IP3. The abnormal flow can be represented as an abnormal IP pair: IP1→IP2, and the shared flow can be represented as a shared IP pair: IP1→IP3. FIG. 5 is another output interface provided by an embodiment of the present application. As shown in FIG. 5, the output interface can include the flow identifier of the abnormal flow (abnormal IP pair), the abnormal occurrence position of the abnormal flow (terminal device 202A), the abnormal transmission time period corresponding to the abnormal flow (T13→T16), the flow identifier of the shared flow (shared IP pair), the flow transmission throughput of the shared flow in the abnormal transmission time period (M1), the flow completion time of the shared flow in the abnormal transmission time period (FCT1), and the overlap transmission time period of the shared flow and the abnormal flow (T13→T14).

[0129] In the embodiments of the present application, the network management device outputs the traffic anomaly positioning result corresponding to the abnormal flow, so as to facilitate the operation and maintenance personnel to quickly locate the fault position, thereby being able to take corresponding isolation or recovery measures on the related device or transmission link in time, improve the fault recovery efficiency, and thus guarantee the stability of business operation. In addition, since the shared flow may be affected by the abnormal flow to cause transmission anomaly, by outputting the identifier of the shared flow, the transmission period of the shared flow can be changed in advance to prevent transmission anomaly.

[0130] Optionally, the network management device can perform abnormal analysis and positioning on the service traffic at the triggering of the service platform. For example, FIG. 6 is a flowchart of a traffic anomaly analysis and positioning method provided by an embodiment of the present application. As shown in FIG. 6, the method 600 includes but is not limited to the following steps 601 to 611.

[0131] Step 601, the service platform sends a service measurement task to the network management device, the service measurement task including measurement task information of the service, the measurement task information including device identifiers of a plurality of terminal devices associated with the service.

[0132] The service includes a plurality of service flows, and the plurality of terminal devices include sending devices and receiving devices of the plurality of service flows. The interpretation of the measurement task information can refer to the related content in the above step 301, which will not be described here again by the embodiments of the present application.

[0133] Optionally, taking the distributed training task as an example, the measurement task information can include task identifier, computing resource information occupied by the task, and measurement task valid time. The task identifier is a unique identifier for distinguishing the distributed training task, for example, a universally unique identifier (UUID). The computing resource information occupied by the task includes IP addresses of the computing nodes involved in the task.

[0134] Step 602, the network management device sends a measurement command to a plurality of network devices in the network, the measurement command being used to instruct the network devices receiving the measurement command to count traffic features of one or more flows flowing through the network devices.

[0135] Optionally, the measurement command is used to instruct the required traffic features to be counted. The traffic features can include transmission period and traffic size of each packet group in the flow, and the traffic features can also include interface identifiers used to indicate the ingress interface and the egress interface of the flow on the network device, etc.

[0136] Step 603, the network device counts the traffic features of one or more flows flowing through itself according to the measurement command.

[0137] In step 604, the network device sends the measurement result to the network management device, where the measurement result includes the traffic characteristics corresponding to the flow identifiers of one or more flows flowing through the network device.

[0138] The implementation process of this step 604 can refer to the above step A1, and the embodiments of the present application will not be described here.

[0139] In step 605, the network management device determines whether transmission abnormity occurs in a flow according to the transmission time sequence of a plurality of message groups in the flow and the transmission indexes of the plurality of message groups.

[0140] The implementation process of this step 605 can refer to the above step A2, and the embodiments of the present application will not be described here.

[0141] In step 606, the network management device sends the flow identifier of the abnormal flow in the service and the abnormal transmission period corresponding to the abnormal flow to the service platform.

[0142] In step 607, the service platform outputs the flow identifier of the abnormal flow in the service and the abnormal transmission period corresponding to the abnormal flow.

[0143] Optionally, the service platform displays the flow identifier of the abnormal flow in the service and the abnormal transmission period corresponding to the abnormal flow, or the service platform sends the flow identifier of the abnormal flow in the service and the abnormal transmission period corresponding to the abnormal flow to the connected display device for display, so as to facilitate the operation and maintenance personnel to timely locate the service flow with transmission abnormity in the network and the specific period in which the transmission abnormity occurs, thereby helping the operation and maintenance personnel to quickly solve the problem.

[0144] In step 608, the network management device screens one or more specified message groups from other message groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission period corresponding to the abnormal flow.

[0145] Each specified message group satisfies that there is at least one overlapping link between the transmission path of the specified message group and the transmission path of the abnormal flow, and the transmission period of the specified message group overlaps with the abnormal transmission period. The implementation process of this step 608 can refer to the above step 302, and the embodiments of the present application will not be described here.

[0146] In step 609, the network management device determines the abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified message groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified message groups, and the transmission period of each of one or more message groups transmitted by the abnormal flow in the abnormal transmission period.

[0147] The implementation process of this step 609 can refer to the above step 303, and the embodiments of this application will not be repeated here.

[0148] In step 610, the network management device sends the traffic anomaly positioning result corresponding to the abnormal flow to the service platform, the traffic anomaly positioning result including one or more of the abnormal occurrence position of the abnormal flow, the abnormal transmission period, or the evidence.

[0149] The evidence is used to prove the abnormal occurrence position of the abnormal flow. The implementation process of this step 610 can refer to the above step 304, and the embodiments of this application will not be repeated here.

[0150] In step 611, the service platform outputs the traffic anomaly positioning result.

[0151] Optionally, the service platform displays the traffic anomaly positioning result, or the service platform sends the traffic anomaly positioning result to a connected display device for display, so as to facilitate the operation and maintenance personnel to quickly locate the fault position, so as to be able to take corresponding isolation or recovery measures on the related equipment or transmission link in time, improve the fault recovery efficiency, and thus guarantee the stability of the service operation.

[0152] The steps of the traffic anomaly positioning method provided by the embodiments of this application can be adjusted in proper order, and the steps can be increased or decreased according to the situation. Any skilled person in the art can easily think of the changed method within the technical range disclosed by the present application, which should be covered within the protection scope of the present application.

[0153] The virtual device of the embodiments of this application is illustrated below.

[0154] For example, FIG. 7 is a structural schematic diagram of a traffic anomaly positioning device provided by an embodiment of the present application. The device can be applied to a network management device. As shown in FIG. 7, the traffic anomaly positioning device 700 includes but is not limited to an acquisition module 701, a screening module 702, and a determination module 703. Optionally, the traffic anomaly positioning device 700 further includes an output module 704.

[0155] The obtaining module 701 is configured to obtain a transmission path of an abnormal flow in which a transmission exception occurs in the network, an abnormal transmission time period corresponding to the abnormal flow, and a transmission time period of each of one or more message groups transmitted by the abnormal flow in the abnormal transmission time period, where each of the message groups is used to complete one data transmission. The screening module 702 is configured to screen one or more specified message groups from other message groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission time period, where each of the specified message groups satisfies that there is at least one overlapping link between the transmission path of the specified message group and the transmission path of the abnormal flow, and the transmission time period of the specified message group overlaps the abnormal transmission time period. The determining module 703 is configured to determine an abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified message groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified message groups, and the transmission time period of each of the one or more message groups transmitted by the abnormal flow in the abnormal transmission time period.

[0156] Optionally, the abnormal flow is an RDMA flow, and each of the message groups in the abnormal flow is used to transmit one message in the RDMA flow.

[0157] Optionally, the one or more specified message groups include first-type message groups, each of the specified message groups in the first-type message groups satisfies that a receiving device of the specified message group is the same as a receiving device of the abnormal flow, an access link connected to the receiving device on the transmission path of the specified message group is the same as an access link connected to the receiving device on the transmission path of the abnormal flow, and the transmission time period of the specified message group overlaps the abnormal transmission time period. The transmission path of the abnormal flow includes a first access layer device and a convergence layer device, the first access layer device is connected to the receiving device, and the first access layer device is connected to the convergence layer device through a first interface. The determining module 703 is specifically configured to determine that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow if the overlapping time length between the transmission time period of each of the message groups transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each of the specified message groups in the first-type message groups satisfies a time overlapping requirement, and statistical information of a flow control message sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission time period satisfies a first preset condition.

[0158] Optionally, the transmission path of the abnormal flow further comprises a second access layer device, the aggregation layer device is connected with the second access layer device through a second interface, and the second access layer device is connected with the sending device of the abnormal flow through a third interface. The determining module 703 is specifically configured to: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each packet group in the first type of packet group meets the time overlap requirement, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period meets the first preset condition, the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the receiving device of the abnormal flow.

[0159] Optionally, the one or more specified packet groups comprise a second type of packet group, and each specified packet group in the second type of packet group meets: the transmission path of the specified packet group comprises a downlink aggregation link on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a first access layer device, a second access layer device and an aggregation layer device, the first access layer device is connected with the receiving device, the first access layer device is connected with the aggregation layer device through a first interface, the aggregation layer device is connected with the second access layer device through a second interface, the second access layer device is connected with the sending device of the abnormal flow, and the downlink aggregation link is a link between the aggregation layer device and the first access layer device. The determining module 703 is specifically configured to: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet group meets the time overlap requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the downlink aggregation link.

[0160] Optionally, the second access layer device is connected with a sending device of the abnormal flow through a third interface. The determining module 703 is specifically configured to: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet group meets the time overlap requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, determining that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link.

[0161] Optionally, the one or more specified packet groups include a third type of packet group, each specified packet group in the third type of packet group meets: the transmission path of the specified packet group includes the uplink aggregation link on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow includes the second access layer device and the aggregation layer device, the aggregation layer device is connected with the second access layer device through a second interface, the second access layer device is connected with a sending device of the abnormal flow through a third interface, and the uplink aggregation link is a link between the second access layer device and the aggregation layer device. The determining module 703 is specifically configured to: if the overlap duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group meets the time overlap requirement, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period does not meet the second preset condition, determining that the abnormal occurrence position of the abnormal flow includes the uplink aggregation link.

[0162] Optionally, the one or more specified packet groups comprise a fourth type of packet group, each specified packet group in the fourth type of packet group satisfying: a sending device of the specified packet group is the same as a sending device of the abnormal flow, an access link connected to a sending device on a transmission path of the specified packet group is the same as an access link connected to a sending device on a transmission path of the abnormal flow, and a transmission time period of the specified packet group overlaps with the abnormal transmission time period. The transmission path of the abnormal flow comprises a second access layer device connected to the sending device of the abnormal flow through a third interface. The determining module 703 is specifically configured to: if the overlap length between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the fourth type of packet group satisfies the time overlap requirement, and statistical information of a flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period does not satisfy the third preset condition, determine that the abnormal occurrence position of the abnormal flow comprises the sending device of the abnormal flow.

[0163] Optionally, the output module 704 is configured to output a flow anomaly positioning result corresponding to the abnormal flow, the flow anomaly positioning result comprising one or more of the abnormal occurrence position of the abnormal flow, the abnormal transmission time period, or evidence used to prove the abnormal occurrence position of the abnormal flow.

[0164] Optionally, the evidence comprises transmission information of a flow corresponding to a flow identifier of a specified packet group, the specified packet group being a packet group whose transmission time period overlaps with the transmission time period of the packet group transmitted by the abnormal flow in the abnormal transmission time period, the transmission information comprising one or more of flow transmission throughput, flow completion time, or flow sharing time information in the abnormal transmission time period, the flow sharing time information being used to reflect time overlap information of the flow corresponding to the specified packet group and the packet group transmitted by the abnormal flow in the abnormal transmission time period.

[0165] As to the apparatus in the above-described embodiments, the specific manners in which various modules perform operations have been described in details in the embodiments of the method, and will not be described in details here.

[0166] The basic hardware structure of the network management device in the embodiments of the present application is described below.

[0167] For example, FIG. 8 is a schematic diagram of a hardware structure of a network management device provided in an embodiment of the present application. As shown in FIG. 8, the network management device 800 comprises a processor 801 and a memory 802, and the memory 801 and the memory 802 are connected through a bus 803. FIG. 8 illustrates the processor 801 and the memory 802 as being independent of each other. Optionally, the processor 801 and the memory 802 are integrated together. Optionally, in combination with FIG. 2, the network management device 800 in FIG. 8 can be the network management device 201 shown in FIG. 2.

[0168] The memory 802 is used to store computer programs, including an operating system and program codes. The memory 802 is various types of storage media, such as a read-only memory (ROM), a random access memory (RAM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), a flash memory, an optical memory, a register, an optical disc storage, a magnetic disc storage, or other magnetic storage devices.

[0169] The processor 801 is a general-purpose processor or a special-purpose processor. The processor 801 can be a single-core processor or a multi-core processor. The processor 801 includes at least one circuit to perform the actions of the network management device in the above method provided by the embodiments of the present application.

[0170] Optionally, the network management device 800 further includes a network interface 804 connected to the processor 801 and the memory 802 through the bus 803. The network interface 804 enables the network management device 800 to communicate with other devices, such as enabling the network management device 800 to communicate with a network device or a service platform.

[0171] Optionally, the network management device 800 further includes an input / output (I / O) interface 805 connected to the processor 801 and the memory 802 through the bus 803. The processor 801 can receive input commands or data through the I / O interface 805. The I / O interface 805 is used for the network management device 800 to connect to input devices, such as a keyboard and a mouse.

[0172] Optionally, the network management device 800 further includes a display 806 connected to the processor 801 and the memory 802 through the bus 803. The display 806 can be used to display intermediate results and / or final results generated by the processor 801 in the above method, such as displaying a traffic anomaly positioning result corresponding to an abnormal flow. In a possible implementation, the display 806 is a touch display screen to provide a human-computer interaction interface.

[0173] The bus 803 is any type of communication bus, for example, a system bus, for interconnecting internal components of the network management device 800. The above-mentioned components within the network management device 800 are interconnected by the bus 803, for example. Alternatively, the above-mentioned components within the network management device 800 are communicatively connected to each other by means other than the bus 803, for example, the above-mentioned components within the network management device 800 are interconnected by means of logical interfaces within the network management device 800.

[0174] The above-mentioned components can be respectively arranged on separate chips, or at least partially or entirely arranged on the same chip. Whether to arrange the components on separate chips or integrate the components on one or more chips depends on the product design requirement. The embodiments of the present application do not limit the specific implementation form of the above-mentioned components.

[0175] The network management device 800 shown in FIG. 8 is merely exemplary, and in the implementation process, the network management device 800 includes other components, which are not listed one by one herein. The network management device 800 shown in FIG. 8 can implement the traffic anomaly positioning by executing all or part of the steps of the method provided in the above-mentioned embodiments.

[0176] The embodiments of the present application also provide a traffic anomaly positioning system, including a network management device and a plurality of network devices. The network management device is configured to perform the actions performed by the network management device in the above-mentioned method embodiments. The network device is configured to perform the actions performed by the network device in the above-mentioned method embodiments.

[0177] Optionally, the system further includes a service platform, and the service platform is configured to perform the actions performed by the service platform in the above-mentioned method embodiments.

[0178] The embodiments of the present application also provide a computer readable storage medium, and the computer readable storage medium stores instructions. When the instructions are executed by a processor, the actions performed by the network management device in the above-mentioned method embodiments are implemented.

[0179] The embodiments of the present application also provide a computer program product, including a computer program. When the computer program is executed by a processor, the actions performed by the network management device in the above-mentioned method embodiments are implemented.

[0180] The embodiments of the present application also provide a chip, and the chip includes a programmable logic circuit and / or program instructions. When the chip is running, the actions performed by the network management device in the above-mentioned method embodiments are implemented.

[0181] In the above embodiments, all or part of the steps can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the steps can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be magnetic media (such as floppy disk, hard disk, magnetic tape), optical media (such as digital versatile disc (DVD)), or semiconductor media (such as solid state disk (SSD)) and the like.

[0182] Those of ordinary skill in the art understand that all or part of the steps of the above embodiments can be completed by hardware, or by programs instructing related hardware, and the programs can be stored in a computer readable storage medium, which can be a read only memory, a magnetic disk or an optical disk.

[0183] In the embodiments of the present application, the terms "first", "second" and "third" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance.

[0184] In the present application, the term "and / or" is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects have an "or" relationship.

[0185] It should be noted that the information (including but not limited to user equipment information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0186] The above only describes optional embodiments of the present application and is not intended to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the concept and principle of the present application shall be included in the protection scope of the present application.

Claims

A flow anomaly positioning method, characterized in that, The method comprises: obtaining a transmission path of an abnormal flow in which transmission abnormity occurs in a network, an abnormal transmission period corresponding to the abnormal flow, and a transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period, wherein each of the packet groups is used to complete one data transmission; screening one or more specified packet groups from other packet groups transmitted in the network except the abnormal flow according to the transmission path of the abnormal flow and the abnormal transmission period, each of the specified packet groups satisfying that there is at least one overlapping link between the transmission path of the specified packet group and the transmission path of the abnormal flow, and the transmission period of the specified packet group overlaps the abnormal transmission period; determining an abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified packet groups, and the transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period. The method of claim 1, wherein The abnormal flow is a remote direct memory access (RDMA) flow, and each of the packet groups in the abnormal flow is used to transmit one message in the RDMA flow. The method according to claim 1 or 2, characterized in that The one or more specified packet groups comprise first-type packet groups, each of the specified packet groups in the first-type packet groups satisfying that a receiving device of the specified packet group is the same as a receiving device of the abnormal flow, an access link connected to the receiving device on the transmission path of the specified packet group is the same as an access link connected to the receiving device on the transmission path of the abnormal flow, and the transmission period of the specified packet group overlaps the abnormal transmission period; The transmission path of the abnormal flow comprises a first access layer device and a convergence layer device, the first access layer device is connected to the receiving device, and the first access layer device is connected to the convergence layer device through a first interface; The determination of the abnormal occurrence position of the abnormal flow according to the overlapping link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission period of each of the one or more specified packet groups, and the transmission period of each of one or more packet groups transmitted by the abnormal flow in the abnormal transmission period comprises: if the overlapping time length between the transmission period of each of the packet groups transmitted by the abnormal flow in the abnormal transmission period and the transmission period of each of the specified packet groups in the first-type packet groups satisfies a time overlapping requirement, and statistical information of a flow control packet sent by the first access layer device to the convergence layer device through the first interface in the abnormal transmission period satisfies a first preset condition, the abnormal occurrence position of the abnormal flow is determined to comprise the receiving device of the abnormal flow. The method according to claim 3, characterized in that The transmission path of the abnormal flow further comprises a second access layer device, the convergence layer device is connected to the second access layer device through a second interface, and the second access layer device is connected to a sending device of the abnormal flow through a third interface; If the time overlap requirement is met between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the first type of packet group, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period meets the first preset condition, it is determined that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow, comprising: If the time overlap requirement is met between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each packet group in the first type of packet group, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period meets the first preset condition, the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition, it is determined that the abnormal occurrence position of the abnormal flow includes the receiving device of the abnormal flow. The method according to any one of claims 1 to 4, characterized in that The one or more specified packet groups include a second type of packet group, and each specified packet group in the second type of packet group meets: the transmission path of the specified packet group includes the downlink aggregation link on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period; The transmission path of the abnormal flow includes a first access layer device, a second access layer device and an aggregation layer device, the first access layer device is connected with the receiving device, the first access layer device is connected with the aggregation layer device through a first interface, the aggregation layer device is connected with the second access layer device through a second interface, the second access layer device is connected with the sending device of the abnormal flow, and the downlink aggregation link is the link between the aggregation layer device and the first access layer device; The abnormal occurrence position of the abnormal flow is determined according to the overlap link between the transmission path of each of the one or more specified packet groups and the transmission path of the abnormal flow, the transmission time period of each of the one or more specified packet groups, and the transmission time period of each of the one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period, comprising: If the time length of coincidence between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet groups meets the time coincidence requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, it is determined that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link. The method according to claim 5, characterized in that The second access layer device is connected with a sending device of the abnormal flow through a third interface; If the time length of coincidence between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet groups meets the time coincidence requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, it is determined that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link, including: If the time length of coincidence between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the second type of packet groups meets the time coincidence requirement, and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period meets the second preset condition, the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets a third preset condition, and the statistical information of the flow control packet sent by the first access layer device to the aggregation layer device through the first interface in the abnormal transmission time period does not meet the first preset condition, it is determined that the abnormal occurrence position of the abnormal flow includes the downlink aggregation link. The method according to any one of claims 1 to 6, characterized in that The one or more specified packet groups include a third type of packet groups, and each specified packet group in the third type of packet groups meets that the transmission path of the specified packet group includes an uplink aggregation link on the transmission path of the abnormal flow, and the transmission time period of the specified packet group coincides with the abnormal transmission time period; The transmission path of the abnormal flow includes a second access layer device and an aggregation layer device, the aggregation layer device is connected with the second access layer device through a second interface, the second access layer device is connected with a sending device of the abnormal flow through a third interface, and the uplink aggregation link is a link between the second access layer device and the aggregation layer device; The transmission path of the abnormal flow includes a second access layer device and an aggregation layer device, the aggregation layer device is connected with the second access layer device through a second interface, the second access layer device is connected with a sending device of the abnormal flow through a third interface, and the uplink aggregation link is a link between the second access layer device and the aggregation layer device; The abnormality occurrence position of the abnormal flow is determined according to coincidence links between respective transmission paths of the one or more specified packet groups and the transmission path of the abnormal flow, respective transmission time periods of the one or more specified packet groups, and respective transmission time periods of one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period, and the method comprises the following steps of: If the coincidence duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the third type of packet group meets the time coincidence requirement, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period meets the third preset condition and the statistical information of the flow control packet sent by the aggregation layer device to the second access layer device through the second interface in the abnormal transmission time period does not meet the second preset condition, it is determined that the abnormality occurrence position of the abnormal flow comprises the uplink aggregation link. The method according to any one of claims 1 to 7, characterized in that The one or more specified packet groups comprise a fourth type of packet group, and each specified packet group in the fourth type of packet group meets the following conditions: the sending device of the specified packet group is the same as the sending device of the abnormal flow, the access link connected to the sending device on the transmission path of the specified packet group is the same as the access link connected to the sending device on the transmission path of the abnormal flow, and the transmission time period of the specified packet group overlaps with the abnormal transmission time period; The transmission path of the abnormal flow comprises a second access layer device, and the second access layer device is connected to the sending device of the abnormal flow through a third interface; The abnormality occurrence position of the abnormal flow is determined according to coincidence links between respective transmission paths of the one or more specified packet groups and the transmission path of the abnormal flow, respective transmission time periods of the one or more specified packet groups, and respective transmission time periods of one or more packet groups transmitted by the abnormal flow in the abnormal transmission time period, and the method comprises the following steps of: If the coincidence duration between the transmission time period of each packet group transmitted by the abnormal flow in the abnormal transmission time period and the transmission time period of each specified packet group in the fourth type of packet group meets the time coincidence requirement, and the statistical information of the flow control packet sent by the second access layer device to the sending device through the third interface in the abnormal transmission time period does not meet the third preset condition, it is determined that the abnormality occurrence position of the abnormal flow comprises the sending device of the abnormal flow. The method according to any one of claims 1 to 8, characterized in that The method further comprises the following steps of: Outputting a flow abnormality positioning result corresponding to the abnormal flow, wherein the flow abnormality positioning result comprises one or more of the abnormality occurrence position of the abnormal flow, the abnormal transmission time period, or evidence used to prove the abnormality occurrence position of the abnormal flow. The method of claim 9, wherein The evidence includes transmission information corresponding to a flow identification of a flow to which the specified packet group belongs, the transmission information including one or more of flow transmission throughput, flow completion time, or flow sharing time information within the abnormal transmission period, the flow sharing time information reflecting time overlap information of the flow to which the specified packet group belongs and the packet group transmitted by the abnormal flow within the abnormal transmission period. A flow anomaly locating device, characterized by The apparatus comprises a plurality of functional modules that interact to implement the method of any of claims 1 to 10. A flow anomaly locating device, characterized by Comprising: a processor and a memory; the memory, configured to store a computer program, the computer program comprising program instructions; the processor, configured to invoke the computer program to implement the method of any of claims 1 to 10. A computer-readable storage medium, characterized by, The computer readable storage medium has stored thereon instructions which, when executed by a processor, implement the method of any of claims 1 to 10. A computer program product, characterized in that A computer program which, when executed by a processor, implements the method of any of claims 1 to 10.