A kind of method for realizing Network Check by identifying network integrity attribute
Technical field
The present invention relates to technical field of network security, and in particular to a kind of to realize that network is examined by identifying network integrity attribute
The method looked into.
Background technology
Check, or upgrading existing network, or in the new agreement items of test, be required for pair to existing network
The reliability and validity of network are objectively assessed, and to reduce the investment risk of network construction, have planned network very high
Performance, or the performance for enabling test result truly to reflect new agreement.Traditional network designs and planing method is mainly by warp
Test, to complicated catenet, many places fail to grip with the main points of design due to that can not predict.Therefore one kind is had increasing need for
New Network Check and audit means.
Automatic check of network equipments configuration is faced with substantial amounts of technical barrier again, and the automatic identification of slave device is matched somebody with somebody to equipment
The automatic decision put, checks and the later stage automatically generates report, all there are more technological difficulties, especially in setting from magnanimity automatically
Safety is discriminated whether in standby information, if closes rule, if meet technical need.Set in addition, how not merely only to check one
It is standby, but check the attribute of network entirety, check whether every attribute between InterWorking Equipment matches, then become influence and check standard
True property and comprehensive important technology ability.Present networks inspection method creates one kind by analyzing network equipment information to net
The attribute of network entirety is identified, and then carries out compliance, matching, the method for compliance check, to solve automation inspection
Industry problem.
The network equipment includes all composition network principals and hardware unit for network connection, and Logistics networks connect
Logical non-in kind, the object that there is logically, including:The various ends such as PC terminals, private server, printer, mobile terminal
End equipment;Router, interchanger, fire wall, the networking special purpose device such as physical function module of independent grafting;Needed in networking
Physical circuit or logical connection, such as network cable, wireless connection;Non-physical target in logic, is such as filled by each network connection
Put " LAN " this pseudo-entity formed in itself or " cloud "(Pseudo-entity " cloud " is suitable for various application occasions, such as:By transporting
Seek backbone network that business provides etc.).
The content of the invention
The object of the present invention is to provide it is a kind of it is with operability, can automate and implement network equipment inspection and pass through mark
The method that network integrity attribute realizes Network Check is known, to overcome disadvantages mentioned above existing for currently available technology.
The purpose of the present invention is be achieved through the following technical solutions:
A kind of method for realizing Network Check by identifying network integrity attribute, comprises the following steps:
1)The data form of network integrity attribute is created according to network equipment information;
2)The attribute of network entirety and state are inserted in the network integrity attribute list;
3)Check whether the association attributes of whole network meets the inspection rule of setting;
4)Generate the report of coherence check result.
Further, step 1)In, for the information given, analyze that information includes sets the tables of data
Standby quantity, and an attribute database of the whole network correspondence establishment being made of all devices;
Further, step 2)In, after whole network corresponds to the data form foundation of attribute, analysis is directed to whole net
The relevant information of network;Wherein, the relevant information further corresponding is converted into the one of this network integrity attribute or state
Kind is a variety of.
Further, step 3)In, according to filled device attribute, the attribute and state of whole network are examined
Look into, and the attribute of whole network is verified one by one.
Further, step 4)In, one by one arrange out the entry that presets rule is not met during the inspection process,
Generation report.
Beneficial effects of the present invention are:The present invention uses brand-new network integrity attribute concept so that the magnanimity extracted
The confusing network equipment information, by it is neat, unified be identified as it is measurable, may compare, can determine whether, identifiable rule
The network integrity attribute information formatted.This method has surmounted the Network Check means that can only be simply checked network unit,
Realize from macroscopic perspective, have the comprehensive method of inspection to the state of network entirety, attribute, matching.This method is special at the same time
Suitable for the inspection and misarrangement of large and medium-sized network.
Brief description of the drawings
The present invention is described in further detail below according to attached drawing.
Fig. 1 is the flow chart of the present invention for realizing the method for Network Check by identifying network integrity attribute.
Embodiment
As shown in Figure 1, the method for realizing Network Check by identifying network integrity attribute described in the present embodiment, including such as
Lower step:
1)A Network Check project is created, and reads network equipment information.Implementor name in system automatic fitration information,
It is an equipment that the implementor name occurred, which is all regarded as, and creates a corresponding data form for each equipment and prepare to use
In each attribute for filling the equipment(Each equipment is a table).It is whole for identifying network that a single list is created at the same time
Body association attributes.
Such as:8 equipment are included in the network equipment information given(Each own different device name), except for this 8
Platform equipment is created outside corresponding 8 data forms, while creates a data form, for identifying by this 8 network equipment institutes
The overall attribute and state of the network of composition.And this 8 equipment are also one of attribute possessed by this network entirety in fact
(This network is comprising number of devices attribute:8);
2)Scanning information file again, integrally relevant state and attribute, correspondence are filled into network entirety with network
In attribute or state list.Some attributes and state that should integrally have comprising network in the database of each overall network,
In scanning process, once finding the mark of these attributes or state, i.e., corresponding mark is done in the database.
Such as:This network has integrally used OSPF Routing Protocols, and comprising 3 ospf areas, between ospf router
Not using MD5 effects etc., these information for being decomposed out, are all counted as a certain or more attribute of this whole network,
It is respectively identified in network integrity attribute.
3)After the attribute and state of network entirety are all analyzed.Start according to ready, be stored in rule database
Inspection rule, check network entirety association attributes whether meet rule;By to each in rule base in checking process
Requirement to network integrity attribute or state one by one verifies existing network integrity attribute and state.
Such as:The region of Cisco OSPF should be continuous, and all areas are all connected with area0.Such as there are respective regions not
Area0 is linked, then the OSPF Routing Areas of the network set and contain at least one mistake.
4)All underproof projects are listed in report during previous step is checked.
In this patent, the network equipment refers in particular to all composition network principals and hardware unit for network connection, and protects
The non-in kind, object that there is logically of barrier network-in-dialing, including:
1st, the various terminal equipment such as PC terminals, private server, printer, mobile terminal;
2nd, the networking special purpose device such as router, interchanger, fire wall and physical function module of independent grafting;
3rd, the physical circuit or logical connection needed in networking, such as network cable, wireless connection;
4th, non-physical target in logic, such as " LAN " this pseudo-entity being made of each network connection device
Itself or " cloud "(Pseudo-entity " cloud " is suitable for various application occasions, such as:Backbone network provided by operator etc.).
The present invention is not limited to above-mentioned preferred forms, anyone can show that other are various under the enlightenment of the present invention
The product of form, however, make any change in its shape or structure, it is every that there is skill identical or similar to the present application
Art scheme, is within the scope of the present invention.