Network fault localization method, system, and electronic device
Patent Information
- Application Number
- PCT/CN2026/075322
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-28
- Filing Date
- 2026-01-28
- Publication Date
- 2026-10-01
Smart Images

Figure CN2026075322_01102026_PF_FP_ABST
Abstract
Description
Network fault location methods, systems and electronic devices Technical Field
[0001] This disclosure relates to the fields of cloud computing and fault location, and more specifically, to a network fault location method, system, and electronic device. Background Technology
[0002] With the development of machine learning and big data analytics, network fault location solutions are shifting towards greater intelligence and automation. Unsupervised learning algorithms, especially partitioning algorithms, are widely used in network fault detection and location due to their ability to handle complex, high-dimensional, and unstructured data. By analyzing patterns and characteristics of network behavior, they enable automatic identification of faulty devices. However, existing unsupervised learning-based fault location solutions still face the aforementioned challenges, particularly in handling the temporal nature and propagation path complexity of traffic drop events. Common location systems still cannot accurately pinpoint the faulty network device within the network.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This disclosure provides a network fault location method, system, and electronic device to at least solve the technical problem of poor accuracy in locating faulty network devices in the network in related technologies.
[0005] According to one aspect of the present disclosure, a network fault location method is provided, comprising: in response to detecting a traffic drop behavior of at least one network device in a target network, dividing the traffic drop behavior of the at least one network device into at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; extracting features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; and determining a target network device from the at least one network device based on the drop signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the fault in the at least one network device.
[0006] According to one aspect of the present disclosure, a network fault location method is also provided, comprising: obtaining traffic decline behavior of at least one network device in a target network by calling a first interface, wherein the first interface includes a first parameter, and the parameter value of the first parameter includes the traffic decline behavior of at least one network device; dividing the traffic decline behavior of at least one network device to obtain at least one set of traffic decline behavior, wherein the network devices corresponding to different traffic decline behaviors in the same set of traffic decline behavior are interconnected, and the network devices corresponding to traffic decline behaviors in different sets of traffic decline behavior are independent of each other; extracting features from the traffic decline behaviors in different sets of traffic decline behavior to determine the decline signal strength of different network devices, wherein the decline signal strength is used to quantify the degree and / or range of the traffic decline behavior occurring in the network device; determining a target network device from the at least one network device based on the decline signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the fault in the at least one network device; and outputting network fault alarm information containing the target network device by calling a second interface, wherein the second interface includes a second parameter, and the parameter value of the second parameter includes the network fault alarm information.
[0007] According to one aspect of the present disclosure, a network fault location apparatus is also provided, comprising: a first segmentation module configured to, in response to detecting a traffic drop behavior of at least one network device in a target network, segment the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors, wherein network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; a first extraction module configured to extract features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; and a device determination module configured to determine a target network device from the at least one network device based on the drop signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the fault in the at least one network device.
[0008] According to one aspect of the present disclosure, a network fault location device is also provided, comprising: a first invocation module configured to obtain traffic decline behavior of at least one network device in a target network by invoking a first interface, wherein the first interface includes a first parameter, and the parameter value of the first parameter includes the traffic decline behavior of at least one network device; a second division module configured to divide the traffic decline behavior of at least one network device to obtain at least one set of traffic decline behavior, wherein network devices corresponding to different traffic decline behaviors in the same set of traffic decline behavior are interconnected, and network devices corresponding to traffic decline behaviors in different sets of traffic decline behavior are independent of each other; the second invocation module is configured to obtain the traffic decline behavior of at least one network device by invoking a first interface, wherein network devices corresponding to different traffic decline behaviors in the same set of traffic decline behavior are interconnected, and network devices corresponding to different traffic decline behaviors in different sets of traffic decline behavior are independent of each other; the second invocation module is configured to obtain the traffic decline behavior of at least one network device in a target network by invoking a first interface, wherein the ... independent of each other; the second invocation module is configured to obtain the traffic decline behavior The first module is configured to extract features from traffic decline behaviors in different sets of traffic decline behaviors to determine the decline signal strength of different network devices, wherein the decline signal strength is used to quantify the degree and / or range of traffic decline behaviors occurring in network devices; the second module is configured to determine a target network device from at least one network device based on the decline signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the failure in at least one network device; the second module is configured to output network fault alarm information containing the target network device by calling a second interface, wherein the second interface includes a second parameter, and the parameter value of the second parameter includes the network fault alarm information.
[0009] According to another aspect of the embodiments of this disclosure, a network fault location system is also provided, comprising: a monitoring device configured to monitor whether a plurality of network devices in a target network experience traffic drop behavior; and a fault location device connected to the monitoring device, configured to, in response to the monitoring device detecting traffic drop behavior of at least one network device, divide the traffic drop behavior of the at least one network device into at least one set of traffic drop behaviors, extract features from the traffic drop behaviors in different sets of traffic drop behaviors, determine the drop signal strength of different network devices, and determine a target network device from the at least one network device based on the drop signal strength of different network devices, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other, the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device, and the target network device is used to characterize the root cause device of the fault in the at least one network device.
[0010] According to another aspect of the present disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor configured to run the program, wherein the program executes the methods in various embodiments of the present disclosure when it runs.
[0011] According to another aspect of the embodiments of the present disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is executed, it controls the device where the computer-readable storage medium is located to perform the methods of the various embodiments of the present disclosure.
[0012] According to another aspect of the embodiments of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this disclosure.
[0013] According to another aspect of the embodiments of this disclosure, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods in various embodiments of this disclosure.
[0014] According to another aspect of the embodiments of this disclosure, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this disclosure.
[0015] In this embodiment, in response to detecting a traffic drop in at least one network device in the target network, the traffic drop behavior of the at least one network device is divided into at least one set of traffic drop behaviors. Features are extracted from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices. Based on the drop signal strength of different network devices, the target network device is determined from the at least one network device. By dividing the traffic drop behaviors occurring in the target network and extracting features from the divided traffic drop behaviors, the drop signal strength of different network devices in the divided sets can be obtained, that is, the degree and / or range of traffic drop behavior of the network device. According to the determined drop signal strength, the positioning system can determine the faulty target network device from the network devices included in different sets, thereby increasing the basis for determining the target network device and effectively avoiding the error of judging the corresponding device as faulty solely based on the occurrence of traffic drop behavior. This improves the accuracy of the determined target network device and solves the technical problem of poor accuracy in locating faulty network devices in the related art.
[0016] It is worth noting that the above general description and the following detailed description are merely for illustrative and explanatory purposes and do not constitute a limitation thereof. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this disclosure, illustrate exemplary embodiments of the present disclosure and are used to explain the disclosure, but do not constitute an undue limitation of the disclosure. In the drawings:
[0018] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a network fault location method according to an embodiment of the present disclosure;
[0019] Figure 2 is a structural block diagram of a computing environment according to an embodiment of the present disclosure;
[0020] Figure 3 is a structural block diagram of a service mesh according to an embodiment of the present disclosure;
[0021] Figure 4 is a flowchart illustrating a network fault location method according to an embodiment of the present disclosure;
[0022] Figure 5 is a schematic diagram illustrating a downward behavior segmentation process according to an embodiment of the present disclosure;
[0023] Figure 6 is a schematic diagram illustrating the propagation process of a decrease in traffic flow according to an embodiment of the present disclosure;
[0024] Figure 7 is a schematic diagram of a simplified structure of a positioning system according to an embodiment of the present disclosure;
[0025] Figure 8 is a schematic diagram illustrating the selection process of a target sub-network device set according to an embodiment of the present disclosure;
[0026] Figure 9 is a flowchart illustrating another network fault location method according to an embodiment of the present disclosure;
[0027] Figure 10 is a structural block diagram of a network fault location device according to an embodiment of the present disclosure;
[0028] Figure 11 is a structural block diagram of another network fault location device according to an embodiment of the present disclosure;
[0029] Figure 12 is a structural block diagram of a network fault location system according to an embodiment of the present disclosure;
[0030] Figure 13 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation
[0031] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.
[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0033] First, some nouns or terms that appear in the description of the embodiments of this disclosure shall be interpreted as follows:
[0034] Signal strength: refers to the strength of a signal in wireless communication or a network.
[0035] Traffic drop: Traffic refers to the amount of data transmitted by a communication entity in a network. Common units include bits and bytes. It is often used to measure network load. Drop refers to the behavior of a sudden decrease in traffic in a short period of time.
[0036] According to embodiments of this disclosure, a network fault location method is provided. It should be noted that the steps shown in the flowcharts in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0037] The method embodiments provided in this disclosure can be executed in a mobile terminal, computer terminal, or similar computing device. FIG1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a network fault location method according to an embodiment of this disclosure. As shown in FIG1, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. It will be understood by those skilled in the art that the structure shown in FIG1 is only illustrative and does not limit the structure of the above-described electronic device. For example, the computer terminal 10 may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.
[0038] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in embodiments of this disclosure, the data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0039] The memory 104 can be configured to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method in the embodiments of this disclosure. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the method in the above embodiments. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0040] The transmission device 106 is configured to receive or transmit data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module configured to communicate wirelessly with the Internet.
[0041] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface 20 of the computer terminal 10 (or mobile device).
[0042] The hardware structure block diagram shown in Figure 1 can serve as an exemplary block diagram not only for the aforementioned computer terminal 10 (or mobile device) but also for the aforementioned server. In an optional embodiment, Figure 2 illustrates an example using the computer terminal 10 (or mobile device) shown in Figure 1 as a computing node in the computing environment 201. Figure 2 is a structural block diagram of a computing environment according to an embodiment of this disclosure. As shown in Figure 2, the computing environment 201 includes multiple computing nodes (such as servers) running on a distributed network (shown as 210-1, 210-2, ... in the figure). Each computing node contains local processing and memory resources, and the end user 202 can remotely run applications or store data in the computing environment 201. Applications can be provided as multiple services 220-1, 220-2, 220-3, and 220-4 in the computing environment 201, representing services "A", "D", "E", and "H", respectively.
[0043] End user 202 can provide and access services through a web browser or other software application on a client. In some embodiments, the provisioning and / or requests of end user 202 can be provided to ingress gateway 230. Ingress gateway 230 may include a corresponding agent to handle the provisioning and / or requests for services (one or more services provided in computing environment 201).
[0044] The services are provided or deployed based on various virtualization technologies supported by the computing environment 201. In some embodiments, services may be provided based on virtual machine (VM)-based virtualization, container-based virtualization, and / or similar methods. VM-based virtualization can simulate a real computer by initializing a virtual machine, executing programs and applications without directly accessing any actual hardware resources. While the machine is virtualized by a virtual machine, container-based virtualization can launch containers to virtualize an entire operating system (OS), allowing multiple workloads to run on a single OS instance.
[0045] In one embodiment based on container virtualization, several containers of a service can be assembled into a Pod (e.g., a Kubernetes Pod). For example, as shown in Figure 2, service 220-2 can be equipped with one or more Pods 240-1, 240-2, ..., 240-N (collectively referred to as Pods). A Pod can include a proxy 245 and one or more containers 242-1, 242-2, ..., 242-M (collectively referred to as containers). One or more containers in a Pod handle requests related to one or more corresponding functions of the service. The proxy 245 typically controls service-related network functions such as routing and load balancing. Other services can also be equipped with similar Pods.
[0046] During operation, executing a user request from end user 202 requires calling one or more services in computing environment 201, and executing one or more functions of one service requires calling one or more functions of another service. As shown in Figure 2, service "A" 220-1 receives the user request from end user 202 from the ingress gateway 230. Service "A" 220-1 can call service "D" 220-2, and service "D" 220-2 can request service "E" 220-3 to execute one or more functions.
[0047] The aforementioned computing environment can be a cloud computing environment, where resource allocation is managed by cloud services, allowing functionality development without needing to consider implementation, adjustment, or server scaling. This computing environment allows developers to execute event-responsive code without building or maintaining complex infrastructure. Services can be partitioned into a set of functions that can automatically and independently scale, rather than scaling a single hardware device to handle potential loads.
[0048] In another alternative embodiment, FIG3 illustrates, in block diagram, an example of using the computer terminal 10 (or mobile device) shown in FIG1 above as a service mesh. FIG3 is a structural block diagram of a service mesh according to an embodiment of the present disclosure. As shown in FIG3, the service mesh 300 is mainly used to facilitate secure and reliable communication between multiple microservices. Microservices refer to decomposing an application into multiple smaller services or instances and distributing them across different clusters / machines.
[0049] As shown in Figure 3, a microservice may include application service instance A and application service instance B, which together form the functional application layer of service mesh 300. In one implementation, application service instance A runs as a container / process 308 on machine / workload container group 314 (Pod), and application service instance B runs as a container / process 310 on machine / workload container group 316 (Pod).
[0050] In one implementation, application service instance A can be a product query service, and application service instance B can be a product order placement service.
[0051] As shown in Figure 3, application service instance A and grid proxy (sidecar) 303 coexist in machine / workload container group 314, and application service instance B and grid proxy 305 coexist in machine / workload container group 316. Grid proxy 303 and grid proxy 305 form the data plane layer of service mesh 300. Grid proxy 303 and grid proxy 305 run as containers / processes 304 and 306 respectively, and can receive requests 312 for product query services. Grid proxy 303 and application service instance A can communicate bidirectionally, and grid proxy 305 and application service instance B can also communicate bidirectionally. Furthermore, grid proxy 303 and grid proxy 305 can also communicate bidirectionally with each other.
[0052] In one implementation, traffic from application service instance A is routed to the appropriate destination via mesh proxy 303, and network traffic from application service instance B is routed to the appropriate destination via mesh proxy 305. It should be noted that the network traffic mentioned here includes, but is not limited to, Hypertext Transfer Protocol (HTTP), Representational State Transfer (REST), high-performance, general-purpose open-source frameworks (Google Remote Procedure Call, gRPC), and open-source in-memory data structure storage systems (Redis).
[0053] In one implementation, the functionality of the extended data plane layer can be achieved by writing custom filters for the proxy (Envoy) in service mesh 300. The service mesh proxy configuration can enable the service mesh to correctly proxy service traffic, achieving service interoperability and service governance. Mesh proxies 303 and 305 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability.
[0054] As shown in Figure 3, the service mesh 300 also includes a control plane layer. This control plane layer can consist of a set of services running in a dedicated namespace, managed by a managed control plane component 301 within machine / workload container groups (machine / Pods) 302. As shown in Figure 3, the managed control plane component 301 communicates bidirectionally with mesh agents 303 and 305. The managed control plane component 301 is configured to perform control and management functions. For example, it receives telemetry data from mesh agents 303 and 305 and can further aggregate this telemetry data. The managed control plane component 301 can also provide a user-facing Application Programming Interface (API) for these services, facilitating easier manipulation of network behavior and providing configuration data to mesh agents 303 and 305.
[0055] Under the above operating environment, this disclosure provides a network fault location method as shown in Figure 4. Figure 4 is a flowchart illustrating a network fault location method according to an embodiment of this disclosure. As shown in Figure 4, the method may include the following steps:
[0056] Step S402: In response to detecting a traffic drop behavior of at least one network device in the target network, the traffic drop behavior of the at least one network device is divided to obtain at least one set of traffic drop behaviors.
[0057] Within the same set of traffic decline behaviors, the network devices corresponding to different traffic decline behaviors are interconnected, while the network devices corresponding to traffic decline behaviors in different sets of traffic decline behaviors are independent of each other.
[0058] The aforementioned interconnection relationship can refer to the connection relationship between different network devices, such as physical interconnection, logical interconnection, virtual interconnection, and equal-cost multipath interconnection.
[0059] In one optional embodiment, considering that network traffic is one of the important indicators of the operating status of different network devices in the network, it can intuitively reflect the load, performance and health status of different network devices. When network devices malfunction, such as link interruption, network congestion or network attack, network traffic often drops. Therefore, in order to ensure the normal operation of the network, the network fault location system (hereinafter referred to as the location system) can monitor the network traffic transmitted by different network devices in the network in real time and determine whether the corresponding network device can operate normally based on the changes in network traffic.
[0060] While network devices may exhibit traffic drops when malfunctioning, this doesn't necessarily mean the device is faulty. It could be due to normal processes like changes in upper-layer network tasks, network traffic scheduling, or the device being affected by other malfunctioning devices in the target network due to interconnections. Therefore, to avoid false detections that could disrupt normal network operation, when a traffic drop is detected in at least one network device in the target network (e.g., a sudden decrease in traffic transmission from a device), the location system can determine the interconnections between these devices. Since devices without interconnections are unlikely to interfere with each other's traffic, after identifying these interconnections, the system can further categorize the devices and their corresponding traffic drops based on these relationships, resulting in at least one set of traffic drop behaviors. The location system can then identify the fault in the target network from these categorized sets, thus improving the efficiency and accuracy of network fault location. Since the traffic drop behavior set is obtained based on the interconnection relationship between network devices, the network devices corresponding to different traffic drop behaviors in the same traffic drop behavior set have the above interconnection relationship, while the network devices corresponding to traffic drop behaviors in different traffic drop behavior sets are independent of each other.
[0061] To facilitate understanding of the above-described segmentation operation, Figure 5 is a schematic diagram illustrating a traffic decline behavior segmentation process according to an embodiment of this disclosure. As shown in Figure 5, assuming that devices a, b, c, d, and e have experienced a failure, and these five devices are located in data centers A, B, C, D, and E, respectively, there are network links between devices a, b, and c, and between devices d and e. Correspondingly, during the segmentation, the positioning system can segment these five devices based on the regional and network link relationships between them, grouping devices a, b, and c into one traffic decline behavior set, and devices d and e into another. It should be noted that setting up different data centers for different devices is to illustrate that in a large-scale failure scenario, the impact between different network devices can propagate across regions, and the size of the region is not limited. In practice, when segmenting multiple network devices experiencing traffic decline behavior, the interconnection relationship between these network devices is still the basis.
[0062] Step S404: Extract features from the traffic decline behaviors in different traffic decline behavior sets to determine the decline signal strength of different network devices.
[0063] The drop signal strength is used to quantify the degree and / or range of traffic drop behavior occurring on network devices.
[0064] In one optional embodiment, considering that although both the network device that actually malfunctions and the network device that is affected may experience a drop in traffic, the degree of the drop may be different. The reference signal will be lost during propagation, and the degree of traffic drop will also be weakened during propagation. Figure 6 is a schematic diagram of the propagation process of the degree of traffic drop according to an embodiment of this disclosure. As shown in Figure 6, taking the traffic drop of the target network device that actually malfunctions as 1 as an example, assuming that devices j and k are currently connected to the target network device, devices m and n are connected to device j, and devices o and p are connected to device k, then in a real scenario, the drop between the target network device and device j can be 0.7, the drop between the target network device and device k can be 0.3, the drop between device j and device m can be 0.6, the drop between device j and device n can be 0.1, the drop between device k and device o can be 0.15, and the drop between device k and device p can be 0.15. Based on this, the positioning system can determine whether the corresponding network device has actually failed by analyzing the degree of traffic decline in different network devices within different sets of link decline behaviors, thereby enabling fault location.
[0065] Therefore, after identifying at least one set of traffic drop behaviors, network devices can first extract features from different traffic drop behaviors within these sets to obtain the drop signal strength of different network devices. This allows them to determine the degree of traffic drop in different network devices within the set, for example, by using the amount of traffic drop to determine the extent of the traffic drop behavior occurring in different network devices. Furthermore, considering that when a network device experiences a traffic drop behavior, it actually means that the traffic transmitted through different ports within the network device has decreased, the drop signal strength extracted from the traffic drop behavior can also reflect the range of the traffic drop behavior occurring in the corresponding network device. For example, a positioning system can determine the impact range of a network device when a traffic drop behavior occurs by using information such as the number and type of ports where traffic drop occurs, or determine the temporal range of the network device when a traffic drop behavior occurs based on data such as the traffic drop sequence, traffic drop time, and traffic recovery time of the ports where traffic drop behavior occurs.
[0066] Step S406: Based on the drop signal strength of different network devices, determine the target network device from at least one network device.
[0067] The target network device is used to characterize the root cause device of a failure in at least one network device.
[0068] The aforementioned root cause device can refer to a device in the target network that actually malfunctions, leading to a drop in traffic.
[0069] In one optional embodiment, after extracting the drop signal strength corresponding to different network devices, the positioning system can determine the target network device that actually has a network failure from at least one network device that has experienced traffic drop behavior based on the drop signal strength. For example, the positioning system can compare the drop signal strength of different network devices in the same set of traffic drop behavior and select the network device with the largest drop signal strength as the target network device, thereby determining the root cause device that caused the traffic drop behavior of different network devices in the set.
[0070] In this embodiment, in response to detecting a traffic drop in at least one network device in the target network, the traffic drop behavior of the at least one network device is divided into at least one set of traffic drop behaviors. Features are extracted from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices. Based on the drop signal strength of different network devices, the target network device is determined from the at least one network device. By dividing the traffic drop behaviors occurring in the target network and extracting features from the divided traffic drop behaviors, the drop signal strength of different network devices in the divided sets can be obtained, i.e., the degree and range of traffic drop behavior of the network devices. Based on the determined drop signal strength, the positioning system can determine the faulty target network device from the network devices included in different sets, thereby increasing the basis for determining the target network device and effectively avoiding the error of judging the corresponding device as faulty solely based on the occurrence of traffic drop behavior. This improves the accuracy of the determined target network device and solves the technical problem of poor accuracy in locating faulty network devices in related technologies.
[0071] In related technologies, the accuracy of locating faulty network devices is relatively poor. For ease of understanding, the aforementioned location system can be roughly divided into three parts. Figure 7 is a schematic diagram of a simplified structure of a location system according to an embodiment of this disclosure. As shown in Figure 7, the location system may include: a fault domain topology generation module, a traffic drop intensity generation module, and a root cause device location module. These three modules are connected in sequence. The fault domain topology generation module can be configured to divide at least one network device exhibiting traffic drop behavior to obtain at least one corresponding set of traffic drop behaviors, and generate a corresponding topology diagram based on the interconnection relationship between different network devices for easy viewing by the user. The traffic drop intensity generation module can be configured to determine the degree of traffic drop of different network devices in different sets. Since the degree of traffic drop can reflect whether the corresponding network device is the root cause device of the fault, the importance of the traffic drop intensity generation module is relatively higher than the other two modules. The root cause device location module can be configured to locate the actual root cause device of the fault based on the degree of traffic drop of different network devices in the same set. The following describes these three modules in detail.
[0072] In this embodiment of the disclosure, feature extraction is performed on the traffic decline behavior in different traffic decline behavior sets to determine the decline signal strength of different network devices, including: based on the traffic decline behavior in any traffic decline behavior set, determining the average traffic decline amount corresponding to the traffic decline behavior of different network devices, and the number of target ports on different network devices where traffic decline behavior occurs; and based on the average traffic decline amount and the number of target ports, determining the decline signal strength of different network devices.
[0073] The aforementioned average traffic drop can refer to the average traffic drop over a specified period of time across one or more ports of a network device.
[0074] In one optional embodiment, to accurately determine the corresponding drop signal strength for the traffic drop behavior of different network devices, in the drop strength generation module, the positioning system can first determine the average traffic drop amount corresponding to the traffic drop behavior of different network devices in any set of traffic drop behaviors. This average traffic drop amount reflects the degree of the current traffic drop behavior of the corresponding network device. Simultaneously, the positioning system can detect the traffic transmitted on different ports in the network device and determine the number of target ports where traffic drop is occurring. This number of target ports reflects the range of the current traffic drop behavior of the corresponding network device. After determining the average drop amount and the number of target ports for different network devices, the positioning system can determine the drop signal strength corresponding to different network devices based on the average drop amount and the corresponding number of target ports, thereby ensuring the accuracy of the determined drop signal strength.
[0075] In this embodiment of the disclosure, based on the traffic decline behavior in any set of traffic decline behaviors, the average traffic decline corresponding to the traffic decline behavior of different network devices is determined, including: determining the total number of ports on different network devices; summarizing the traffic decline corresponding to the traffic decline behavior of different network devices to obtain the total traffic decline of different network devices; and determining the ratio of the total traffic decline to the total number to obtain the average traffic decline.
[0076] In one optional embodiment, when determining the average traffic drop, the positioning system can first determine the total number of ports used for traffic transmission on different network devices, and then summarize the traffic drop behavior of different network devices to obtain the total traffic drop of the corresponding network devices. Then, based on the ratio of the total traffic drop to the total number, the average traffic drop is determined.
[0077] For example, suppose device a currently has 3 ports. By summarizing the traffic drop of device a, we know that the total traffic drop of device a is 36. Then the corresponding average traffic drop of device a can be 36 / 3, which is 12.
[0078] In this embodiment of the disclosure, determining the drop signal strength of different network devices based on the average traffic drop and the number of target ports includes: normalizing the average traffic drop to obtain a normalized traffic drop; normalizing the number of target ports to obtain a normalized number; and determining the drop signal strength of different network devices based on the normalized traffic drop and the normalized number.
[0079] In one optional embodiment, considering that there may be a large difference between the average traffic drop and the number of target ports for different network devices, and that there is a difference in units between the average traffic drop and the number of target ports, simply summing up the traffic drop and the number of target ports may not intuitively reflect the degree of signal drop between different network devices. Therefore, in order to make it easier for users to understand while determining the signal drop strength, when determining the signal drop strength based on the average traffic drop and the number of target ports, the positioning system can first normalize the average traffic drop to obtain the normalized traffic drop for different network devices, and at the same time normalize the number of target ports to obtain the normalized number for different network devices. Then, the signal drop strength of different network devices is determined based on the normalized traffic drop and the normalized number.
[0080] For example, a positioning system can use a Min-Max normalization algorithm to linearly map the average traffic drop of different network devices and the number of target ports to the range [0, 1]. The mapping formula can be:
[0081] Where X represents the raw data, i.e., the average traffic drop or the number of target ports. scaled This represents the normalized data, i.e., the normalized decrease in flow or the normalized quantity, X. max With X min These represent the minimum and maximum values of the original data, respectively.
[0082] In this embodiment of the disclosure, the traffic drop behavior of at least one network device is divided to obtain at least one set of traffic drop behaviors, including: determining the interconnection relationship between different network devices; and based on the interconnection relationship, dividing the traffic drop behavior of at least one network device to obtain at least one set of traffic drop behaviors.
[0083] In one optional embodiment, in order to accurately classify the traffic drop behavior of at least one network device, in the fault domain topology generation module, the positioning system can first determine the interconnection relationship between different network devices, and then classify the traffic drop behavior of at least one network device based on the determined interconnection relationship to obtain at least one set of drop behaviors, thereby improving the accuracy of the classified set of traffic drop behaviors.
[0084] In this embodiment of the disclosure, based on interconnection relationships, the traffic decline behavior of at least one network device is divided to obtain at least one set of traffic decline behaviors, including: dividing at least one network device based on interconnection relationships to obtain at least one set of network devices; determining that the traffic decline behavior of network devices in the same set of network devices belongs to the same set of traffic decline behaviors, and determining that the traffic decline behavior of network devices in different sets of network devices belongs to different sets of traffic decline behaviors.
[0085] In one optional embodiment, when classifying traffic drop behavior based on interconnection relationships, the positioning system can first classify the at least one network device based on interconnection relationships to obtain at least one set of network devices. Then, the traffic drop behavior of network devices in the same set of network devices is determined to belong to the same set of traffic drop behavior, and the traffic drop behavior of network devices in different sets of network devices is determined to belong to different sets of traffic drop behavior, thereby realizing the operation of classifying traffic drop behavior and ensuring the accuracy of the classified sets of traffic drop behavior.
[0086] In this embodiment of the disclosure, determining a target network device from at least one network device based on the drop signal strength of different network devices includes: determining candidate network devices among the network devices based on the drop signal strength of network devices corresponding to different traffic drop behavior sets, wherein the candidate network devices are used to characterize the root cause device of the failure in the network devices located in the same traffic drop behavior set; and summarizing the candidate network devices corresponding to different traffic drop behavior sets to determine the target network device.
[0087] In one optional embodiment, to accurately determine the target network device, the root cause device localization module can first analyze the signal strength of network devices corresponding to different traffic drop behavior sets to identify candidate network devices that may be faulty, i.e., the root cause devices that have failed in different traffic drop behavior sets. After identifying the candidate network devices, the localization system can continue to aggregate the candidate network devices corresponding to different traffic drop behavior sets to determine the target network device currently experiencing a fault in the target network, thereby ensuring the accuracy of the identified target network device.
[0088] In this embodiment of the disclosure, determining candidate network devices based on the fall signal strength of network devices corresponding to different sets of traffic fall behavior includes: inputting the fall signal strength of network devices corresponding to different sets of traffic fall behavior into a partitioning model; using the partitioning model to partition the network devices corresponding to different sets of traffic fall behavior to obtain at least one set of sub-network devices and a central network device for each set of sub-network devices; determining a target set of sub-network devices from the at least one set of sub-network devices based on the fall signal strength of the central network devices for each set of sub-network devices; and determining network devices in the target set of sub-network devices as candidate network devices.
[0089] The aforementioned partitioning model can refer to a model trained through unsupervised learning without predefined target variables, used for unsupervised clustering. It can improve partitioning efficiency by automatically identifying potential structures or patterns in traffic drop behaviors and grouping different traffic drop behaviors into different sets. The aforementioned central network device can refer to the network device corresponding to the cluster center point of different sub-network device sets.
[0090] In one optional embodiment, when selecting candidate network devices, the positioning system can first divide the different network devices according to the drop signal strength corresponding to different network devices in different traffic drop behavior sets, using the above-mentioned partitioning model to obtain at least one set of sub-network devices and the central network device corresponding to each set of sub-network devices. Then, based on the drop signal strength of the central network devices in different sets of sub-network devices, at least one target set of sub-network devices is determined from the set of sub-network devices. For example, the positioning system can first sort the at least one set of sub-network devices from largest to smallest according to the drop signal strength of different central network devices, and then select the at least one target set of sub-network devices from the at least one set of sub-network devices according to preset percentages, quantities, and other parameters. The network devices in the target set of sub-network devices can be regarded as candidate network devices that may fail. Alternatively, the sub-network device set where the central network device with the largest drop signal strength is located can be directly selected as the target set of sub-network devices to improve efficiency.
[0091] In this embodiment of the disclosure, determining a target sub-network device set from at least one sub-network device set based on the drop signal strength of the central network device in different sub-network device sets includes: determining a distance vector of different sub-network device sets based on the distance between the drop signal strength of different central network devices and a preset signal strength; determining a candidate sub-network device set from at least one sub-network device set based on the distance vector of different sub-network device sets, wherein the distance vector of the candidate sub-network device set is greater than the distance vector of a first sub-network device set, and the first sub-network device set is any sub-network device set other than the candidate sub-network device set in the at least one sub-network device set; determining an average distance vector of the candidate sub-network device set based on the distance vector of the candidate sub-network device set and the number of network devices in the candidate sub-network device set; and determining a target sub-network device set from the candidate sub-network device set based on the average distance vector of the candidate sub-network device set, wherein the average distance vector of the target sub-network device set is greater than the distance vector of a second sub-network device set, and the second sub-network device set is any sub-network device set other than the target sub-network device set in the candidate sub-network device set.
[0092] In one optional embodiment, to ensure the rationality of the determined target sub-network device set, the positioning system can determine the distance vector of different sub-network device sets based on the distance between the drop signal strength of different central network devices and a preset signal strength, such as a point with a signal strength of 0. It should be noted that the aforementioned distance vector can reflect the probability that a device in a different sub-network device set is the root cause device. Therefore, the preset signal strength is usually selected as a point with a signal strength of 0, i.e., the strength feature is [0, 0]. After determining the distance vector set, the positioning system can first determine a candidate sub-network device set from at least one sub-network device set, i.e., a set that may contain the root cause device. Correspondingly, the distance vector of the candidate sub-network device set is greater than the distance vector of the first sub-network device set, which is any sub-network device set other than the candidate sub-network device set among at least one sub-network device set. After determining the candidate sub-network device set, the positioning system can further determine the average distance vector of different candidate sub-network device sets based on the distance vector of the candidate sub-network device set and the number of network devices contained in the set. Finally, based on the average distance vector of different candidate sub-network device sets, the target sub-network device set is determined from the candidate sub-network device set, thereby ensuring the rationality of the determined target sub-network device set.
[0093] For ease of understanding, the formula for selecting the target sub-network device set can be as follows:
[0094] Among them, D n M represents the magnitude of the distance vector of cluster n, i.e., the magnitude of the distance vector of the candidate sub-network device set. n This indicates the number of devices contained in cluster n.
[0095] Figure 8 is a schematic diagram illustrating the selection process of a target sub-network device set according to an embodiment of the present disclosure. The figure includes (a), (b), and (c), representing the results of three different stages in the selection process. In the figure, the horizontal axis represents the average traffic drop of different network devices in the same drop behavior set, the vertical axis represents the number of ports of different network devices, and the dashed arrows represent the average distance vectors corresponding to different sets. As shown in Figure 8, when selecting the target sub-network device set, the positioning system can first divide different devices into 4 sets based on the drop signal strength corresponding to the average traffic drop and the number of ports, as shown in (a); then, based on the distance vector corresponding to the drop signal strength of the central network device of these 4 sets, 3 candidate sets are selected, namely the 3 sets circled in dashed form, as shown in (b); finally, based on the average distance vector of these 3 sets, the target sub-network device set is determined, namely the set circled in solid form, as shown in (c).
[0096] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.
[0097] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, because according to this disclosure, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.
[0098] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solutions of this disclosure, in essence, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this disclosure.
[0099] According to embodiments of this disclosure, another network fault location method is also provided. Figure 9 is a flowchart illustrating another network fault location method according to embodiments of this disclosure. As shown in Figure 9, the method may include the following steps:
[0100] Step S902: Obtain the traffic drop behavior of at least one network device in the target network by calling the first interface.
[0101] The first interface includes a first parameter, the value of which includes the traffic drop behavior of at least one network device.
[0102] Step S904: Divide the traffic drop behavior of at least one network device to obtain at least one set of traffic drop behaviors.
[0103] Within the same set of traffic decline behaviors, the network devices corresponding to different traffic decline behaviors are interconnected, while the network devices corresponding to traffic decline behaviors in different sets of traffic decline behaviors are independent of each other.
[0104] Step S906: Extract features from the traffic decline behaviors in different traffic decline behavior sets to determine the decline signal strength of different network devices.
[0105] The drop signal strength is used to quantify the degree and / or range of traffic drop behavior occurring on network devices.
[0106] Step S908: Based on the drop signal strength of different network devices, determine the target network device from at least one network device.
[0107] The target network device is used to characterize the root cause device of a failure in at least one network device.
[0108] Step S910: Output network fault alarm information containing the target network device by calling the second interface.
[0109] The second interface includes a second parameter, the value of which includes network fault alarm information.
[0110] In one optional embodiment, the positioning system can obtain a first parameter by calling a first interface, namely, to obtain the traffic decline behavior of at least one network device in the target network. Then, the traffic decline behavior of the at least one network device is divided into at least one set of traffic decline behaviors. Features are extracted from the traffic decline behaviors in different sets to determine the decline signal strength of different network devices. Finally, based on the decline signal strength of different network devices, the target network device is determined from the at least one network device, and network fault alarm information containing the target network device is output through a second interface. In this embodiment, network devices corresponding to different traffic decline behaviors within the same set are interconnected, while network devices corresponding to traffic decline behaviors in different sets are independent of each other. The decline signal strength is used to quantify the degree, range, and other parameters of the traffic decline behavior occurring in the network device, and the target network device is used to characterize the root cause device of the fault in the at least one network device.
[0111] The specific positioning process can be found in the previous text, and will not be repeated here.
[0112] According to an embodiment of this disclosure, a network fault location device for implementing the above-described network fault location method is also provided. FIG10 is a structural block diagram of a network fault location device according to an embodiment of this disclosure. As shown in FIG10, the device includes: a first division module 1002, a first extraction module 1004, and a device determination module 1006.
[0113] The first segmentation module 1002 is configured to, in response to detecting a traffic drop behavior of at least one network device in the target network, segment the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; the first extraction module 1004 is configured to extract features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; the device determination module 1006 is configured to determine the target network device from the at least one network device based on the drop signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.
[0114] In this embodiment of the disclosure, the first extraction module 1004 is further configured to: determine the average traffic drop amount corresponding to the traffic drop behavior of different network devices and the number of target ports on different network devices where traffic drop behavior occurs, based on the traffic drop behavior in any set of traffic drop behaviors; and determine the drop signal strength of different network devices based on the average traffic drop amount and the number of target ports.
[0115] In this embodiment of the disclosure, the first extraction module 1004 is further configured to: determine the total number of ports on different network devices; summarize the traffic drop amounts corresponding to the traffic drop behaviors of different network devices to obtain the total traffic drop amount of different network devices; and determine the ratio of the total traffic drop amount to the total number to obtain the average traffic drop amount.
[0116] In this embodiment of the disclosure, the first extraction module 1004 is further configured to: normalize the average traffic drop to obtain a normalized traffic drop; normalize the number of target ports to obtain a normalized number; and determine the drop signal strength of different network devices based on the normalized traffic drop and the normalized number.
[0117] In this embodiment of the disclosure, the first division module 1002 is further configured to: determine the interconnection relationship between different network devices; and based on the interconnection relationship, divide the traffic drop behavior of at least one network device to obtain at least one set of traffic drop behaviors.
[0118] In this embodiment of the disclosure, the first partitioning module 1002 is further configured to: partition at least one network device based on interconnection relationship to obtain at least one set of network devices; determine the traffic drop behavior of network devices in the same set of network devices to belong to the same set of traffic drop behavior, and determine the traffic drop behavior of network devices in different sets of network devices to belong to different sets of traffic drop behavior.
[0119] In this embodiment of the disclosure, the device determination module 1006 is further configured to: determine candidate network devices among network devices based on the drop signal strength of network devices corresponding to different traffic drop behavior sets, wherein the candidate network devices are used to characterize the root cause device of the failure among network devices located in the same traffic drop behavior set; and summarize the candidate network devices corresponding to different traffic drop behavior sets to determine the target network device.
[0120] In this embodiment of the disclosure, the device determination module 1006 is further configured to: input the drop signal strength of the network devices corresponding to different traffic drop behavior sets into the partitioning model; use the partitioning model to partition the network devices corresponding to different traffic drop behavior sets to obtain at least one sub-network device set and a central network device for each sub-network device set; determine a target sub-network device set from the at least one sub-network device set based on the drop signal strength of the central network device for each sub-network device set; and determine the network devices in the target sub-network device set as candidate network devices.
[0121] In this embodiment of the disclosure, the device determination module 1006 is further configured to: determine the distance vectors of different sub-network device sets based on the distance between the drop signal strength of different central network devices and a preset signal strength; determine candidate sub-network device sets from at least one sub-network device set based on the distance vectors of the different sub-network device sets, wherein the distance vector of the candidate sub-network device set is greater than the distance vector of a first sub-network device set, and the first sub-network device set is any sub-network device set other than the candidate sub-network device set in the at least one sub-network device set; determine the average distance vector of the candidate sub-network device set based on the distance vector of the candidate sub-network device set and the number of network devices in the candidate sub-network device set; and determine the target sub-network device set from the candidate sub-network device set based on the average distance vector of the candidate sub-network device set, wherein the average distance vector of the target sub-network device set is greater than the distance vector of a second sub-network device set, and the second sub-network device set is any sub-network device set other than the target sub-network device set in the candidate sub-network device set.
[0122] It should be noted that the first partitioning module 1002, the first extraction module 1004, and the device determination module 1006 mentioned above correspond to steps S402 to S406 in the above embodiments. The three modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of a device and run in the computer terminal 10 provided in the above embodiments.
[0123] According to an embodiment of this disclosure, another network fault location device for implementing the above-described network fault location method is also provided. FIG11 is a structural block diagram of another network fault location device according to an embodiment of this disclosure. As shown in FIG11, the device includes: a first calling module 1102, a second dividing module 1104, a second extraction module 1106, a second determining module 1108, and a second calling module 1110.
[0124] The first calling module 1102 is configured to obtain the traffic decline behavior of at least one network device in the target network by calling a first interface, wherein the first interface includes a first parameter, and the parameter value of the first parameter includes the traffic decline behavior of at least one network device; the second partitioning module 1104 is configured to partition the traffic decline behavior of at least one network device to obtain at least one set of traffic decline behavior, wherein the network devices corresponding to different traffic decline behaviors in the same set of traffic decline behavior are interconnected, and the network devices corresponding to traffic decline behaviors in different sets of traffic decline behavior are independent of each other; the second extraction module 1106 is configured to extract traffic decline behaviors from different traffic devices. The traffic decline behavior in the decline behavior set is feature extracted to determine the decline signal strength of different network devices, wherein the decline signal strength is used to quantify the degree and / or range of the traffic decline behavior occurring in the network device; the second determination module 1108 is configured to determine a target network device from at least one network device based on the decline signal strength of different network devices, wherein the target network device is used to characterize the root cause device of the failure in at least one network device; the second calling module 1110 is configured to output network fault alarm information containing the target network device by calling a second interface, wherein the second interface includes a second parameter, and the parameter value of the second parameter includes the network fault alarm information.
[0125] It should be noted that the first calling module 1102, the second partitioning module 1104, the second extraction module 1106, the second determining module 1108, and the second calling module 1110 correspond to steps S902 to S910 in the above embodiments. The five modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of a device and run in the computer terminal 10 provided in the above embodiments.
[0126] According to an embodiment of this disclosure, a network fault location system for implementing the above-described network fault location method is also provided. FIG12 is a structural block diagram of a network fault location system according to an embodiment of this disclosure. As shown in FIG11, the device includes a monitoring device 1202 and a fault location device 1204.
[0127] The monitoring device 1202 is configured to monitor whether multiple network devices in the target network experience traffic drop behavior. The fault location device 1204 is connected to the monitoring device and is configured to, in response to the monitoring device detecting traffic drop behavior of at least one network device, divide the traffic drop behavior of the at least one network device into at least one set of traffic drop behaviors, extract features from the traffic drop behaviors in different sets of traffic drop behaviors, determine the drop signal strength of different network devices, and determine the target network device from the at least one network device based on the drop signal strength of different network devices. The network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other. The drop signal strength is used to quantify the degree and / or range of the traffic drop behavior of the network device, and the target network device is used to characterize the root cause device of the fault in the at least one network device.
[0128] In this embodiment of the disclosure, the fault location device 1204 includes: a fault domain topology generation module, configured to divide the traffic drop behavior of at least one network device to obtain at least one set of traffic drop behaviors; a drop intensity generation module, configured to extract features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal intensity of different network devices; and a root cause device location module, configured to determine the target network device from at least one network device based on the drop signal intensity of different network devices.
[0129] It should be noted that the preferred embodiments involved in the above embodiments of this disclosure are the same as the solutions, application scenarios and implementation processes provided in the above embodiments, but are not limited to the solutions provided in the above embodiments.
[0130] Embodiments of this disclosure can provide an electronic device, which can be any one of a group of electronic devices. Optionally, in this embodiment, the aforementioned electronic device can also be replaced with a terminal device such as a mobile terminal.
[0131] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.
[0132] In this embodiment, the electronic device described above can execute the program code in the method.
[0133] Optionally, FIG13 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. As shown in FIG13, the electronic device A may include: one or more (only one is shown in the figure) processors 1302, memory 1304, memory controller, and peripheral interface, wherein the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0134] The memory can be configured to store software programs and modules, such as the program instructions / modules corresponding to the methods and apparatus in the embodiments of this disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the methods in the above embodiments. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to terminal A via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0135] The processor can invoke information and application programs stored in memory via a transmission device to perform the following steps: in response to detecting a traffic drop behavior of at least one network device in a target network, classifying the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; extracting features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; and based on the drop signal strength of different network devices, determining the target network device from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.
[0136] Those skilled in the art will understand that the structure shown in Figure 13 is merely illustrative, and the electronic device may also be a smartphone, tablet computer, PDA, mobile internet device (MID), PAD, or other terminal device. This figure does not limit the structure of the aforementioned electronic device. For example, electronic device A may include more or fewer components (such as network interfaces, display devices, etc.) than shown in the figure, or may have a different configuration than shown in the figure.
[0137] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.
[0138] Embodiments of this disclosure also provide a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium may be configured to store program code executed by the method provided in the above embodiments.
[0139] Optionally, in this embodiment, the storage medium may be located in any one of the electronic devices in the group of electronic devices in the computer network, or in any one of the mobile terminals in the group of mobile terminals.
[0140] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: in response to detecting a traffic drop behavior of at least one network device in a target network, the traffic drop behavior of the at least one network device is divided to obtain at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; features are extracted from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; based on the drop signal strength of different network devices, a target network device is determined from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.
[0141] Embodiments of this disclosure also provide a computer program product. Optionally, in this embodiment, the computer program product may include a computer program that, when executed by a processor, implements the methods provided in the embodiments described above.
[0142] Embodiments of this disclosure also provide a computer program product. Optionally, the computer program product may include a non-volatile computer-readable storage medium configured to store a computer program that, when executed by a processor, implements the methods provided in the embodiments described above.
[0143] Embodiments of this disclosure also provide a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it implements the method provided in the above embodiments.
[0144] In the above embodiments of this disclosure, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0145] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection of units or modules may be electrical or other forms.
[0146] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0147] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0148] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0149] The above are merely preferred embodiments of this disclosure. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this disclosure, and these improvements and modifications should also be considered within the scope of protection of this disclosure.
Claims
1. A network fault location method, comprising: In response to detecting a traffic drop behavior of at least one network device in the target network, the traffic drop behavior of the at least one network device is divided to obtain at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other. Feature extraction is performed on traffic decline behaviors in different sets of traffic decline behaviors to determine the decline signal strength of different network devices, wherein the decline signal strength is used to quantify the degree and / or range of traffic decline behavior occurring in the network device; Based on the drop signal strength of different network devices, a target network device is determined from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.
2. The method according to claim 1, wherein, The step of extracting features from traffic decline behaviors in different sets of traffic decline behaviors to determine the decline signal strength of different network devices includes: Based on the traffic decline behaviors in any set of traffic decline behaviors, determine the average traffic decline amount corresponding to the traffic decline behaviors of different network devices, and the number of target ports on different network devices where the traffic decline behaviors occur. Based on the average traffic drop and the number of target ports, the drop signal strength of different network devices is determined.
3. The method according to claim 2, wherein, The step of determining the average traffic drop amount corresponding to the traffic drop behavior of different network devices based on the traffic drop behavior in any set of traffic drop behavior includes: Determine the total number of ports on different network devices; The total traffic drop for different network devices is obtained by summing up the traffic drop behavior of different network devices. The average flow rate decrease is obtained by determining the ratio of the total flow rate decrease to the total quantity.
4. The method according to claim 2, wherein, The determination of the drop signal strength of different network devices based on the average traffic drop and the number of target ports includes: The average flow rate drop is normalized to obtain the normalized flow rate drop. The number of target ports is normalized to obtain a normalized number; Based on the normalized traffic drop and the normalized quantity, the drop signal strength of different network devices is determined.
5. The method according to any one of claims 1 to 4, wherein, The step of classifying the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors includes: Determine the interconnection relationships between different network devices; Based on the interconnection relationship, the traffic drop behavior of the at least one network device is divided to obtain the at least one set of traffic drop behaviors.
6. The method according to claim 5, wherein, Based on the interconnection relationship, the traffic decline behavior of the at least one network device is divided to obtain a set of at least one traffic decline behavior, including: Based on the interconnection relationship, the at least one network device is divided to obtain at least one set of network devices; Determine the traffic drop behavior of network devices within the same set of network devices as belonging to the same set of traffic drop behaviors, and determine the traffic drop behavior of network devices within different sets of network devices as belonging to different sets of traffic drop behaviors.
7. The method according to any one of claims 1 to 4, wherein, The determination of the target network device from the at least one network device based on the falling signal strength of different network devices includes: Based on the drop signal strength of network devices corresponding to different traffic drop behavior sets, candidate network devices are determined among the network devices, wherein the candidate network devices are used to characterize the root cause device of the failure among network devices located in the same traffic drop behavior set; The candidate network devices corresponding to different traffic drop behaviors are summarized to determine the target network device.
8. The method according to claim 7, wherein, The process of determining candidate network devices based on the fall signal strength of network devices corresponding to different sets of traffic fall behavior includes: The signal strength of the network devices corresponding to different traffic drop behavior sets is input into the partitioning model. The partitioning model is used to partition the network devices corresponding to different traffic drop behavior sets to obtain at least one sub-network device set and the central network device of different sub-network device sets. Based on the dropout signal strength of the central network device in different sub-network device sets, a target sub-network device set is determined from the at least one sub-network device set; The network devices in the target sub-network device set are identified as the candidate network devices.
9. The method according to claim 8, wherein, The determination of the target sub-network device set from the at least one sub-network device set based on the drop signal strength of the central network device in different sub-network device sets includes: Based on the distance between the drop signal strength of different central network devices and the preset signal strength, the distance vector of different sub-network device sets is determined; Based on the distance vectors of different sub-network device sets, a candidate sub-network device set is determined from the at least one sub-network device set, wherein the distance vector of the candidate sub-network device set is greater than the distance vector of the first sub-network device set, and the first sub-network device set is any sub-network device set other than the candidate sub-network device set in the at least one sub-network device set; Based on the distance vector of the candidate sub-network device set and the number of network devices in the candidate sub-network device set, the average distance vector of the candidate sub-network device set is determined. Based on the average distance vector of the candidate sub-network device set, the target sub-network device set is determined from the candidate sub-network device set, wherein the average distance vector of the target sub-network device set is greater than the distance vector of the second sub-network device set, and the second sub-network device set is any sub-network device set other than the target sub-network device set in the candidate sub-network device set.
10. A network fault location method, comprising: The traffic decline behavior of at least one network device in the target network is obtained by calling a first interface, wherein the first interface includes a first parameter, and the parameter value of the first parameter includes the traffic decline behavior of the at least one network device. The traffic drop behavior of the at least one network device is divided to obtain at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other. Feature extraction is performed on traffic decline behaviors in different sets of traffic decline behaviors to determine the decline signal strength of different network devices, wherein the decline signal strength is used to quantify the degree and / or range of traffic decline behavior occurring in the network device; Based on the drop signal strength of different network devices, a target network device is determined from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device; The network fault alarm information of the target network device is output by calling the second interface, wherein the second interface includes a second parameter, and the parameter value of the second parameter includes the network fault alarm information.
11. A network fault location system, comprising: The monitoring equipment is configured to monitor whether multiple network devices in the target network are experiencing a drop in traffic. A fault location device, connected to the monitoring device, is configured to, in response to the monitoring device detecting a traffic drop behavior of at least one network device, classify the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors, extract features from the traffic drop behaviors in different sets of traffic drop behaviors, determine the drop signal strength of different network devices, and, based on the drop signal strength of different network devices, determine a target network device from the at least one network device. The network devices corresponding to different traffic drop behaviors within the same set of traffic drop behaviors are interconnected, while the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other. The drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device, and the target network device is used to characterize the root cause device of the fault in the at least one network device.
12. The system according to claim 11, wherein, The fault location device includes: The fault domain topology generation module is configured to divide the traffic drop behavior of the at least one network device to obtain the at least one set of traffic drop behaviors; The drop signal strength generation module is configured to extract features from the traffic drop behavior in different sets of traffic drop behavior to determine the drop signal strength of different network devices. The root cause device location module is configured to determine the target network device from the at least one network device based on the falling signal strength of different network devices.
13. The system according to claim 12, wherein, The traffic drop intensity generation module is further configured to: determine the average traffic drop amount corresponding to the traffic drop behavior of different network devices, and the number of target ports on different network devices where the traffic drop behavior occurs, based on the traffic drop behavior in any set of traffic drop behaviors; Based on the average traffic drop and the number of target ports, the drop signal strength of different network devices is determined.
14. The system according to claim 13, wherein, The traffic drop intensity generation module is also configured to: determine the total number of ports on different network devices; and summarize the traffic drop amounts corresponding to the traffic drop behaviors of different network devices to obtain the total traffic drop amount of different network devices. The average flow rate decrease is obtained by determining the ratio of the total flow rate decrease to the total quantity.
15. The system according to claim 13, wherein, The drop intensity generation module is further configured to: normalize the average traffic drop to obtain a normalized traffic drop; and normalize the number of target ports to obtain a normalized number. Based on the normalized traffic drop and the normalized quantity, the drop signal strength of different network devices is determined.
16. The system according to any one of claims 11 to 15, wherein, The fault domain topology generation module is further configured to: determine the interconnection relationship between different network devices; and based on the interconnection relationship, classify the traffic drop behavior of the at least one network device to obtain the at least one set of traffic drop behaviors.
17. The system according to claim 16, wherein, The fault domain topology generation module is further configured to: divide the at least one network device based on the interconnection relationship to obtain at least one set of network devices; determine the traffic drop behavior of network devices in the same set of network devices, which belong to the same set of traffic drop behaviors, and determine the traffic drop behavior of network devices in different sets of network devices, which belong to different sets of traffic drop behaviors.
18. The system according to claim 12, wherein, The root cause device location module is further configured to: determine candidate network devices among the network devices based on the fall signal strength of network devices corresponding to different sets of traffic fall behavior, wherein the candidate network devices are used to characterize the root cause device that has failed among network devices located in the same set of traffic fall behavior; and summarize the candidate network devices corresponding to different sets of traffic fall behavior to determine the target network device.
19. An electronic device comprising: Memory, which stores executable programs; A processor is configured to run the program, wherein the program, when running, performs the following method: in response to detecting a traffic drop behavior of at least one network device in a target network, classifying the traffic drop behavior of the at least one network device to obtain at least one set of traffic drop behaviors, wherein network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; extracting features from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; and based on the drop signal strength of different network devices, determining a target network device from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.
20. A computer-readable storage medium comprising a stored executable program, wherein, When the executable program runs, it controls the device containing the storage medium to perform the following method: in response to detecting a traffic drop behavior of at least one network device in the target network, the traffic drop behavior of the at least one network device is divided into at least one set of traffic drop behaviors, wherein the network devices corresponding to different traffic drop behaviors in the same set of traffic drop behaviors are interconnected, and the network devices corresponding to traffic drop behaviors in different sets of traffic drop behaviors are independent of each other; features are extracted from the traffic drop behaviors in different sets of traffic drop behaviors to determine the drop signal strength of different network devices, wherein the drop signal strength is used to quantify the degree and / or range of the traffic drop behavior occurring in the network device; based on the drop signal strength of different network devices, a target network device is determined from the at least one network device, wherein the target network device is used to characterize the root cause device of the failure in the at least one network device.