US2022029900A1PendingUtilityA1

Detecting sources of computer network failures

Assignee: TWITTER INCPriority: Nov 10, 2017Filed: Sep 16, 2021Published: Jan 27, 2022
Est. expiryNov 10, 2037(~11.3 yrs left)· nominal 20-yr term from priority
H04L 43/026H04L 41/0677H04L 49/50H04L 43/16H04L 43/0811H04L 43/10H04L 41/0695H04L 49/25H04L 43/0882
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for detecting sources of computer network failures. One of the methods includes identifying a network flow in a computer network between a source and a destination; performing a first probe to determine whether there is end-to-end connectivity between the source and the destination; in response to determining that there is no end-to-end connectivity between the host and the destination, performing one or more additional probes including a second probe to determine whether each hop in the path of the network flow between the source and the destination is operational including requesting that the source transmit a respective first trace diagnostic packet to each hop in the path of the network flow; and determining whether at least one link of the computer network that is part of the path of the network flow has failed based on the results.

Claims

exact text as granted — not AI-modified
1 - 19 . (canceled) 
     
     
         20 . A method comprising:
 identifying a particular path of a network flow in a computer network between a source and a destination, wherein the particular path comprises one or more network devices coupled by one or more links; and   in response to a determination that there is no end-to-end connectivity between the source and the destination along the particular path, determining whether a network component of the particular path in the network flow has failed comprising:
 requesting that the destination transmit a respective trace diagnostic packet to each network device along the particular path, wherein each trace diagnostic packet is configured to follow the particular path and has a particular value in a time-to-live field configured to cause a corresponding network device to send at least a time exceeded message in response to that trace diagnostic packet, wherein the time exceeded message includes a portion of the trace diagnostic packet that includes a packet identifier inserted into a first plurality of bits of the trace diagnostic packet; and 
 determining whether at least one network component that is part of the particular path of the network flow has failed based on results of the trace diagnostic packets. 
   
     
     
         21 . The method of  claim 20 , wherein determining whether at least one network component has failed comprises:
 determining whether the destination has received a time exceeded message from a particular network device;   in response to determining that the destination has received the time exceeded message from a particular network device, determining that the particular network device is operational from the source along the particular path; and   in response to determining that the destination has not received the time exceeded message from a particular network device, determining that the particular network device has failed from the source along the particular path.   
     
     
         22 . The method of  claim 20 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising a header portion and a body portion, wherein the header portion comprises an 8-bit type field and an 8-bit code field set as respective values to indicate that the ICMP message is a time exceeded message. 
     
     
         23 . The method of  claim 20 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising the first plurality of bits of the trace diagnostic packet that trigger the time exceeded message, wherein the first plurality of bits are the first 64 bits of the trace diagnostic packet. 
     
     
         24 . The method of  claim 20 , wherein the first plurality of bits of the trace diagnostic packet where the packet identifier is inserted comprise one of a sequence number of a TCP packet or a length field of a UDP packet. 
     
     
         25 . The method of  claim 20 , further comprising:
 estimating a low reliability for a link of the one or more links in the particular path based on a count of trace diagnostics packets observed to have traveled the link;   determining the low reliability corresponds to a low utilization of the link; and   in response, determining that the estimated low reliability for the link is a false positive detection.   
     
     
         26 . The method of  claim 20 , wherein the determination that there is no end-to-end connectivity between the source and the destination comprises:
 performing a first probe to determine whether there is end-to-end connectivity between the source and the destination including requesting that the destination transmit an end-to-end diagnostic packet to the source, wherein the end-to-end diagnostic packet includes information comprising a source identifier field and a destination identifier field that include identifiers for the source and destination, respectively, that match the packets in the network flow between the source and destination such that one or more network devices in the computer network forward the end-to-end diagnostic packet on the particular path of the network flow.   
     
     
         27 . A system comprising:
 one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to perform operations comprising:
 identifying a particular path of a network flow in a computer network between a source and a destination, wherein the particular path comprises one or more network devices coupled by one or more links; and 
 in response to a determination that there is no end-to-end connectivity between the source and the destination along the particular path, determining whether a network component of the particular path in the network flow has failed comprising:
 requesting that the destination transmit a respective trace diagnostic packet to each network device along the particular path, wherein each trace diagnostic packet is configured to follow the particular path and has a particular value in a time-to-live field configured to cause a corresponding network device to send at least a time exceeded message in response to that trace diagnostic packet, wherein the time exceeded message includes a portion of the trace diagnostic packet that includes a packet identifier inserted into a first plurality of bits of the trace diagnostic packet; and 
 determining whether at least one network component that is part of the particular path of the network flow has failed based on results of the trace diagnostic packets. 
 
   
     
     
         28 . The system of  claim 27 , wherein determining whether at least one network component has failed comprises:
 determining whether the destination has received a time exceeded message from a particular network device;   in response to determining that the destination has received the time exceeded message from a particular network device, determining that the particular network device is operational from the source along the particular path; and   in response to determining that the destination has not received the time exceeded message from a particular network device, determining that the particular network device has failed from the source along the particular path.   
     
     
         29 . The system of  claim 27 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising a header portion and a body portion, wherein the header portion comprises an 8-bit type field and an 8-bit code field set as respective values to indicate that the ICMP message is a time exceeded message. 
     
     
         30 . The system of  claim 27 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising the first plurality of bits of the trace diagnostic packet that trigger the time exceeded message, wherein the first plurality of bits are the first 64 bits of the trace diagnostic packet. 
     
     
         31 . The system of  claim 27 , wherein the first plurality of bits of the trace diagnostic packet where the packet identifier is inserted comprise one of a sequence number of a TCP packet or a length field of a UDP packet. 
     
     
         32 . The system of  claim 27 , further comprising:
 estimating a low reliability for a link of the one or more links in the particular path based on a count of trace diagnostics packets observed to have traveled the link;   determining the low reliability corresponds to a low utilization of the link; and   in response, determining that the estimated low reliability for the link is a false positive detection.   
     
     
         33 . The system of  claim 27 , wherein the determination that there is no end-to-end connectivity between the source and the destination comprises:
 performing a first probe to determine whether there is end-to-end connectivity between the source and the destination including requesting that the destination transmit an end-to-end diagnostic packet to the source, wherein the end-to-end diagnostic packet includes information comprising a source identifier field and a destination identifier field that include identifiers for the source and destination, respectively, that match the packets in the network flow between the source and destination such that one or more network devices in the computer network forward the end-to-end diagnostic packet on the particular path of the network flow.   
     
     
         34 . One or more non-transitory computer storage media encoded with computer program instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:
 identifying a particular path of a network flow in a computer network between a source and a destination, wherein the particular path comprises one or more network devices coupled by one or more links; and   in response to a determination that there is no end-to-end connectivity between the source and the destination along the particular path, determining whether a network component of the particular path in the network flow has failed comprising:
 requesting that the destination transmit a respective trace diagnostic packet to each network device along the particular path, wherein each trace diagnostic packet is configured to follow the particular path and has a particular value in a time-to-live field configured to cause a corresponding network device to send at least a time exceeded message in response to that trace diagnostic packet, wherein the time exceeded message includes a portion of the trace diagnostic packet that includes a packet identifier inserted into a first plurality of bits of the trace diagnostic packet; and 
 determining whether at least one network component that is part of the particular path of the network flow has failed based on results of the trace diagnostic packets. 
   
     
     
         35 . The one or more non-transitory computer storage media of  claim 34 , wherein determining whether at least one network component has failed comprises:
 determining whether the destination has received a time exceeded message from a particular network device;   in response to determining that the destination has received the time exceeded message from a particular network device, determining that the particular network device is operational from the source along the particular path; and   in response to determining that the destination has not received the time exceeded message from a particular network device, determining that the particular network device has failed from the source along the particular path.   
     
     
         36 . The one or more non-transitory computer storage media of  claim 34 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising a header portion and a body portion, wherein the header portion comprises an 8-bit type field and an 8-bit code field set as respective values to indicate that the ICMP message is a time exceeded message. 
     
     
         37 . The one or more non-transitory computer storage media of  claim 34 , wherein the time exceeded message is an internet control message protocol (ICMP) message comprising the first plurality of bits of the trace diagnostic packet that trigger the time exceeded message, wherein the first plurality of bits are the first 64 bits of the trace diagnostic packet. 
     
     
         38 . The one or more non-transitory computer storage media of  claim 34 , wherein the first plurality of bits of the trace diagnostic packet where the packet identifier is inserted comprise one of a sequence number of a TCP packet or a length field of a UDP packet. 
     
     
         39 . The one or more non-transitory computer storage media of  claim 34 , further comprising:
 estimating a low reliability for a link of the one or more links in the particular path based on a count of trace diagnostics packets observed to have traveled the link;   determining the low reliability corresponds to a low utilization of the link; and   in response, determining that the estimated low reliability for the link is a false positive detection.   
     
     
         40 . The one or more non-transitory computer storage media of  claim 34 , wherein the determination that there is no end-to-end connectivity between the source and the destination comprises:
 performing a first probe to determine whether there is end-to-end connectivity between the source and the destination including requesting that the destination transmit an end-to-end diagnostic packet to the source, wherein the end-to-end diagnostic packet includes information comprising a source identifier field and a destination identifier field that include identifiers for the source and destination, respectively, that match the packets in the network flow between the source and destination such that one or more network devices in the computer network forward the end-to-end diagnostic packet on the particular path of the network flow.

Join the waitlist — get patent alerts

Track US2022029900A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.