Network anomaly detection method, electronic device, and storage medium
Embodiments of this application provide a network anomaly detection method, an electronic device, and a storage medium. The method includes: determining whether a target network device in a to-be-detected network has target port configuration information corresponding to routing and forwarding based on a layer 3 Internet Protocol IP address; and determining, based on the target port configuration information, whether the to-be-detected network is anomalous.
1 . A network anomaly detection method, comprising:
determining whether a target network device in a to-be-detected network has target port configuration information corresponding to routing and forwarding based on a layer 3 Internet Protocol IP address; and
determining, based on the target port configuration information, whether the to-be-detected network is anomalous,
wherein the determining, based on the target port configuration information, whether the to-be-detected network is anomalous comprises:
when determining that the target port configuration information does not exist, detecting, based on upstream port information of the target network device and/or downstream port information of an upstream device, whether a virtual local area network identity VLAN ID parameter, corresponding to the target network device, in a data link layer is correct; and
when the VLAN ID parameter, corresponding to the target network device, in the data link layer is incorrect, determining that the to-be-detected network is anomalous.
2 . The method according to claim 1 , wherein the target port configuration information is information used to configure a target port as an interface.
3 . The method according to claim 2 , wherein the interface is an interface used for routing.
4 . The method according to claim 2 , wherein the interface used for routing is one of a physical routing interface and a virtual routing interface.
5 . The method according to claim 1 , wherein the determining, based on the target port configuration information, whether the to-be-detected network is anomalous comprises:
when determining that the target port configuration information exists, detecting whether the target port configuration information is correct; and
when the target port configuration information is incorrect, determining that the to-be-detected network is anomalous.
6 . The method according to claim 5 , wherein the determining that the target port configuration information exists comprises:
when the target port configuration information is found, determining that the target port configuration information exists.
7 . The method according to claim 1 , wherein the determining that the target port configuration information does not exist comprises:
when the target port configuration information is not found, determining that the target port configuration information does not exist.
8 . The method according to claim 1 , wherein the detecting, based on the upstream port information of the target network device and/or the downstream port information of the upstream device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct comprises:
detecting a VLAN ID parameter corresponding to the upstream port information of the target network device;
when a detection result for the VLAN ID parameter corresponding to the upstream port information of the target network device is success, detecting a VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device; and
when a detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device is success, determining that the VLAN ID parameter of the target network device in the data link layer is correct.
9 . The method according to claim 8 , wherein the detecting the VLAN ID parameter corresponding to the upstream port information of the target network device comprises:
configuring a preset value for the VLAN ID parameter corresponding to the upstream port information of the target network device;
transmitting a packet based on the target network device, and obtaining first detection information, wherein the first detection information comprises a first corresponding value of the VLAN ID parameter corresponding to the upstream port information; and
detecting whether the first corresponding value is equal to the preset value; and
the detecting, based on the upstream port information of the target network device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct further comprises:
determining, when the first corresponding value is not equal to the preset value, the detection result for the VLAN ID parameter corresponding to the upstream port information as failure; and
the determining whether the to-be-detected network is anomalous comprises:
when the detection result for the VLAN ID parameter corresponding to the upstream port information is failure, determining that the upstream port information is anomalous; and
generating a first anomalous information detection result, wherein the first anomalous information detection result comprises the upstream port information of the target network device.
10 . The method according to claim 9 , wherein the detecting the VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device comprises:
transmitting a packet based on the target network device, and obtaining second detection information, wherein the second detection information comprises a second corresponding value of the VLAN ID parameter corresponding to the downstream port information of the upstream device; and
when the second corresponding value is not zero, detecting whether the second corresponding value is equal to the preset value;
the detecting, based on the downstream port information of the upstream device of the target network device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct comprises:
determining, when the second corresponding value is not equal to the preset value, the detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device as failure; and
the determining whether the to-be-detected network is anomalous comprises:
when the detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device is failure, determining that the downstream port information of the upstream device of the target network device is anomalous; and
generating a second anomalous information detection result, wherein the second anomalous information detection result comprises the downstream port information of the upstream device of the target network device.
11 . The method according to claim 8 , wherein the method further comprises:
when determining that a third corresponding value comprised in third detection information of the to-be-detected network does not correspond to a default value of the VLAN ID parameter corresponding to the upstream port information, generating an anomalous information detection result comprising the upstream port information of the target network device; or
when determining that a fourth corresponding value comprised in fourth detection information of the to-be-detected network does not correspond to a default value of the VLAN ID parameter corresponding to the downstream port information of the upstream device, generating an anomalous information detection result comprising the downstream port information of the upstream device of the target network device.
12 . The method according to claim 5 , wherein the detecting whether the target port configuration information is correct when determining that the target port configuration information exists comprises:
determining whether default routing information is set in a routing table of the target network device; and
when determining that the default routing information is not set in the routing table, determining that the target port configuration information is incorrect; and
the determining whether the to-be-detected network is anomalous comprises:
when determining that the target port configuration information is incorrect, determining that the to-be-detected network is anomalous; and
generating a third anomalous information detection result, wherein the third anomalous information detection result comprises device information of the target network device.
13 . The method according to claim 12 , wherein the method further comprises:
when determining that the default routing information is set in the routing table, determining whether the default routing information comprises an IP address in the target port configuration information;
when determining that the default routing information comprises the IP address in the target port configuration information, determining whether the routing table comprises a return route and a next hop address of the return route; and
when determining that the routing table does not comprise the return route and the next hop address of the return route, generating the third anomalous information detection result.
14 . The method according to claim 1 , wherein the method further comprises:
generating a network topology diagram based on a network topology structure of the to-be-detected network; and
displaying one or more anomalous information detection results in the network topology diagram.
15 . The method according to claim 1 , wherein the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address comprises:
obtaining device information of the target network device;
determining whether the device information comprises routing interface configuration information and/or switch virtual interface configuration information; and
when the device information comprises routing interface configuration information and/or switch virtual interface configuration information, determining that the target network device has the target port configuration information.
16 . The method according to claim 15 , wherein after the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address, the method further comprises:
when determining, by searching, that the device information comprises the routing interface configuration information and/or the switch virtual interface configuration information, determining that the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address.
17 . The method according to claim 1 , wherein the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address comprises:
determining, by searching, whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address.
18 . An electronic device, comprising a memory and a processor, wherein
the memory is configured to store a program; and
the processor is coupled to the memory, and configured to execute the program stored in the memory, to implement the method according to claim 1 .
19 . A non-transitory machine-readable storage medium, wherein the non-transitory machine-readable storage medium stores executable code, and when the executable code is executed by a processor of an electronic device, the processor is enabled to perform the method according to claim 1 .