IP Library Granted Patent US 12671709
Granted Patent B2
US 12671709 · App. 18/786,542 · Granted Jun 30, 2026

Network anomaly detection method, electronic device, and storage medium

Inventor: Gang Yang (Fujian, CN)
Assignee: RUIJIE NETWORKS CO., LTD.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671709
App. No.
18/786,542
Granted
Jun 30, 2026
Kind
B2
Abstract

Embodiments of this application provide a network anomaly detection method, an electronic device, and a storage medium. The method includes: determining whether a target network device in a to-be-detected network has target port configuration information corresponding to routing and forwarding based on a layer 3 Internet Protocol IP address; and determining, based on the target port configuration information, whether the to-be-detected network is anomalous.

Claims (65)

1 . A network anomaly detection method, comprising:

determining whether a target network device in a to-be-detected network has target port configuration information corresponding to routing and forwarding based on a layer 3 Internet Protocol IP address; and

determining, based on the target port configuration information, whether the to-be-detected network is anomalous,

wherein the determining, based on the target port configuration information, whether the to-be-detected network is anomalous comprises:

when determining that the target port configuration information does not exist, detecting, based on upstream port information of the target network device and/or downstream port information of an upstream device, whether a virtual local area network identity VLAN ID parameter, corresponding to the target network device, in a data link layer is correct; and

when the VLAN ID parameter, corresponding to the target network device, in the data link layer is incorrect, determining that the to-be-detected network is anomalous.

2 . The method according to claim 1 , wherein the target port configuration information is information used to configure a target port as an interface.

3 . The method according to claim 2 , wherein the interface is an interface used for routing.

4 . The method according to claim 2 , wherein the interface used for routing is one of a physical routing interface and a virtual routing interface.

5 . The method according to claim 1 , wherein the determining, based on the target port configuration information, whether the to-be-detected network is anomalous comprises:

when determining that the target port configuration information exists, detecting whether the target port configuration information is correct; and

when the target port configuration information is incorrect, determining that the to-be-detected network is anomalous.

6 . The method according to claim 5 , wherein the determining that the target port configuration information exists comprises:

when the target port configuration information is found, determining that the target port configuration information exists.

7 . The method according to claim 1 , wherein the determining that the target port configuration information does not exist comprises:

when the target port configuration information is not found, determining that the target port configuration information does not exist.

8 . The method according to claim 1 , wherein the detecting, based on the upstream port information of the target network device and/or the downstream port information of the upstream device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct comprises:

detecting a VLAN ID parameter corresponding to the upstream port information of the target network device;

when a detection result for the VLAN ID parameter corresponding to the upstream port information of the target network device is success, detecting a VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device; and

when a detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device is success, determining that the VLAN ID parameter of the target network device in the data link layer is correct.

9 . The method according to claim 8 , wherein the detecting the VLAN ID parameter corresponding to the upstream port information of the target network device comprises:

configuring a preset value for the VLAN ID parameter corresponding to the upstream port information of the target network device;

transmitting a packet based on the target network device, and obtaining first detection information, wherein the first detection information comprises a first corresponding value of the VLAN ID parameter corresponding to the upstream port information; and

detecting whether the first corresponding value is equal to the preset value; and

the detecting, based on the upstream port information of the target network device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct further comprises:

determining, when the first corresponding value is not equal to the preset value, the detection result for the VLAN ID parameter corresponding to the upstream port information as failure; and

the determining whether the to-be-detected network is anomalous comprises:

when the detection result for the VLAN ID parameter corresponding to the upstream port information is failure, determining that the upstream port information is anomalous; and

generating a first anomalous information detection result, wherein the first anomalous information detection result comprises the upstream port information of the target network device.

10 . The method according to claim 9 , wherein the detecting the VLAN ID parameter corresponding to the downstream port information of the upstream device of the target network device comprises:

transmitting a packet based on the target network device, and obtaining second detection information, wherein the second detection information comprises a second corresponding value of the VLAN ID parameter corresponding to the downstream port information of the upstream device; and

when the second corresponding value is not zero, detecting whether the second corresponding value is equal to the preset value;

the detecting, based on the downstream port information of the upstream device of the target network device, whether the VLAN ID parameter corresponding to the target network device in the data link layer is correct comprises:

determining, when the second corresponding value is not equal to the preset value, the detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device as failure; and

the determining whether the to-be-detected network is anomalous comprises:

when the detection result for the VLAN ID parameter corresponding to the downstream port information of the upstream device is failure, determining that the downstream port information of the upstream device of the target network device is anomalous; and

generating a second anomalous information detection result, wherein the second anomalous information detection result comprises the downstream port information of the upstream device of the target network device.

11 . The method according to claim 8 , wherein the method further comprises:

when determining that a third corresponding value comprised in third detection information of the to-be-detected network does not correspond to a default value of the VLAN ID parameter corresponding to the upstream port information, generating an anomalous information detection result comprising the upstream port information of the target network device; or

when determining that a fourth corresponding value comprised in fourth detection information of the to-be-detected network does not correspond to a default value of the VLAN ID parameter corresponding to the downstream port information of the upstream device, generating an anomalous information detection result comprising the downstream port information of the upstream device of the target network device.

12 . The method according to claim 5 , wherein the detecting whether the target port configuration information is correct when determining that the target port configuration information exists comprises:

determining whether default routing information is set in a routing table of the target network device; and

when determining that the default routing information is not set in the routing table, determining that the target port configuration information is incorrect; and

the determining whether the to-be-detected network is anomalous comprises:

when determining that the target port configuration information is incorrect, determining that the to-be-detected network is anomalous; and

generating a third anomalous information detection result, wherein the third anomalous information detection result comprises device information of the target network device.

13 . The method according to claim 12 , wherein the method further comprises:

when determining that the default routing information is set in the routing table, determining whether the default routing information comprises an IP address in the target port configuration information;

when determining that the default routing information comprises the IP address in the target port configuration information, determining whether the routing table comprises a return route and a next hop address of the return route; and

when determining that the routing table does not comprise the return route and the next hop address of the return route, generating the third anomalous information detection result.

14 . The method according to claim 1 , wherein the method further comprises:

generating a network topology diagram based on a network topology structure of the to-be-detected network; and

displaying one or more anomalous information detection results in the network topology diagram.

15 . The method according to claim 1 , wherein the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address comprises:

obtaining device information of the target network device;

determining whether the device information comprises routing interface configuration information and/or switch virtual interface configuration information; and

when the device information comprises routing interface configuration information and/or switch virtual interface configuration information, determining that the target network device has the target port configuration information.

16 . The method according to claim 15 , wherein after the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address, the method further comprises:

when determining, by searching, that the device information comprises the routing interface configuration information and/or the switch virtual interface configuration information, determining that the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address.

17 . The method according to claim 1 , wherein the determining whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address comprises:

determining, by searching, whether the target network device in the to-be-detected network has the target port configuration information corresponding to routing and forwarding based on the layer 3 Internet Protocol IP address.

18 . An electronic device, comprising a memory and a processor, wherein

the memory is configured to store a program; and

the processor is coupled to the memory, and configured to execute the program stored in the memory, to implement the method according to claim 1 .

19 . A non-transitory machine-readable storage medium, wherein the non-transitory machine-readable storage medium stores executable code, and when the executable code is executed by a processor of an electronic device, the processor is enabled to perform the method according to claim 1 .