A network traffic spatiotemporal feature mining method based on model detection
By building closure space and Kripke structures and using STMCP spatiotemporal model detectors, the problem of complex and inaccurate network traffic anomaly detection in the prior art is solved, and efficient detection and analysis of spatiotemporal characteristics of network traffic is realized.
Patent Information
- Application Number
- CN202310507508.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2043-05-08
AI Technical Summary
The existing network traffic anomaly detection methods are complex and inaccurate, making it difficult to effectively simplify the analysis process and accurately detect the spatiotemporal characteristics of network traffic.
The spatial and temporal feature mining method of network traffic based on model detection is adopted, and a complete formal model is formed to detect the spatial and temporal anomaly characteristics of network traffic by constructing closure space, Kripke structure and STMCP spatial and temporal model detectors.
This method can automatically and completely detect the traffic distribution characteristics in the network space-time model, simplify the analysis process, improve the accuracy of the detection results, and greatly reduce the workload.
Smart Images

Figure CN116684911B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic anomaly detection, and in particular to a network traffic spatiotemporal feature mining method based on model detection. Background Art
[0002] With the development of wireless communication technology, mobile devices have become increasingly popular and diversified. The sharp increase in data traffic has promoted the development and commercialization of 5G technology. As a new generation of wireless communication standard, 5G technology not only provides efficient solutions for application scenarios closely related to daily life such as Internet of Vehicles, wireless home entertainment, and wireless medical care, but also provides an important communication foundation for the development of cloud AR / VR, AI smart cities, and industrial Internet of Things.
[0003] With the rapid development of big data technology in recent years, operators have realized the importance of large amounts of data records in their own networks and are committed to making them play a greater role as much as possible. At present, more and more measured data are being used by operators themselves or transferred to corresponding researchers for information mining, in order to discover the generation patterns hidden in mobile user behavior and data traffic distribution. Cellular networks and other systems related to human activities, such as transportation systems, social networks and residential planning are very relevant. The operating characteristics of these systems are essentially rooted in human daily behavior.
[0004] In areas where communication macro base stations are densely deployed, the traffic load will show obvious characteristics in certain time and space. The spatial characteristics mean that the business volume varies greatly in different geographical locations, and a small number of macro base stations may occupy most of the overall traffic; the temporal characteristics mean that the traffic demand in the same area changes regularly at different times, and there are peaks and valleys in the traffic size. The spatiotemporal characteristics of traffic mean that the traffic demand shows different special patterns in different time periods (such as office hours and dinner time) in the spatial dimension. For example, schools and hospitals have a huge difference in the flow of people during the day and at night. At the same time, the popularization of new 5G applications such as telemedicine and distance education means that 5G base stations need to meet huge traffic demands during the day, but at night, macro base stations are generally underloaded, resulting in energy waste.
[0005] In existing technical solutions, the detection of abnormal characteristics of network traffic is usually carried out by analyzing historical traffic data through machine learning methods or network traffic monitors to obtain detection results. However, machine learning methods require a large amount of measured data as the basis for model training, and there is no unified standard for the collection and preprocessing of network traffic data. This will make different machine learning methods have no unified prerequisites, which will affect the accuracy of the final detection results. The network traffic monitor requires a professional and complex architecture, and complex business codes must be written according to relevant detection requirements to implement historical traffic data analysis. Once the detection requirements change, the business code needs to be rewritten, and the analysis process is complicated and the workload is large. Summary of the invention
[0006] The problem to be solved by the present invention is to provide a network traffic spatiotemporal feature mining method based on model detection, which can simplify the analysis process and accurately find abnormal network traffic features.
[0007] To solve the above problems, the present invention provides a network traffic spatiotemporal feature mining method based on model detection, comprising the following steps:
[0008] Step S1, constructing each cellular network system cell into hexagonal units with the macro base station of each cellular network system cell as the center, and connecting two adjacent hexagonal units to obtain a closed space;
[0009] Step S2, constructing multiple groups of network space models based on the closed space and the cellular traffic data corresponding to each of the cellular network system cells, each group of the network space models corresponds to a spatiotemporal snapshot, and constructing a spatiotemporal snapshot model according to the data content of each of the spatiotemporal snapshots;
[0010] Step S3, based on the Kripke structure, a network spatiotemporal model is constructed according to the spatiotemporal snapshot model;
[0011] Step S4, obtaining an STMCP space-time model detector and adding multiple space-time property specifications to the STMCP space-time model detector;
[0012] Step S5, inputting the network spatiotemporal model into the STMCP spatiotemporal model detector, and controlling the STMCP spatiotemporal model detector to detect the network space model based on each of the spatiotemporal property specifications to obtain corresponding network traffic anomaly feature mining results.
[0013] In this solution, the cellular traffic data is formally modeled through the closure space and the Kripke structure, and the inconsistency of machine learning methods for cellular traffic data is solved through a complete formal model. At the same time, considering that the consumption of communication resources in the network has time-space related properties, the time-space anomaly characteristics, that is, the network traffic anomaly characteristics, can be described by adding multiple time-space property specifications to the STMCP time-space model detector, and the network traffic anomaly situation is expressed using the time-space property specifications, and the time-space property specifications are used as the input of the STMCP time-space model detector, which is equivalent to a more efficient abnormal property query statement, which can avoid complex programming work in the data analysis process, thereby simplifying the analysis process.
[0014] Furthermore, the use of the STMCP spatiotemporal model detector can automatically and completely detect traffic distribution characteristics in the network spatiotemporal model, which can greatly reduce the workload.
[0015] Preferably, the cellular traffic data corresponding to each of the cellular network system cells respectively include network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data within the coverage area of the macro base station corresponding to the cellular network system cell. In the step S2, a plurality of groups of network space models are constructed based on the closure space and the network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data corresponding to each of the cellular network system cells.
[0016] In this solution, the network traffic data, the instant short message receiving data, the instant short message sending data, the voice call access data, the voice call outgoing data and the macro base station power consumption data are used as the network traffic data corresponding to the cellular network system cell. The rich quantity, type and data volume can improve the accuracy of the network traffic anomaly feature mining results.
[0017] Preferably, in step S2, the network space model is defined as follows:
[0018]
[0019] in,
[0020] X represents a set of cells of the cellular network system in the closed space;
[0021] represents the closure operator;
[0022] A set representing the adjacency relationship between cells of each cellular network system;
[0023] Represents a set of assignment functions corresponding to the atomic attributes of each cell of the cellular network system.
[0024] Preferably, in step S2, the spatiotemporal snapshot model is defined as follows:
[0025]
[0026] in,
[0027] represents the spatiotemporal snapshot model;
[0028] T represents the time series;
[0029] representing the cyberspace model;
[0030] Represents the spatial structure (X,C);
[0031] Indicates that at the i-th spatiotemporal snapshot, the assignment function Atomic propositions mapped based on atomic properties.
[0032] Preferably, in step S3, the network spatiotemporal model is defined as follows:
[0033]
[0034] in,
[0035] represents the network spatiotemporal model;
[0036] represents the spatial part composed of the closure space;
[0037] X represents a set of cells of the cellular network system in the closed space;
[0038] represents the closure operator;
[0039] (S,S 0 , R) represents the time part of the Kripke structure;
[0040] S represents a set of state nodes in the Kripke structure;
[0041] S 0 Represents the initial state node;
[0042] R represents the state transition relationship between state nodes, and P represents the assignment function The set of atomic propositions in each of the above;
[0043] Represents the traffic distribution status of all state nodes in space and time.
[0044] Preferably, in step S4, each of the spatiotemporal property specifications is constructed based on the formal syntax of the STLCS logic formula, and the formal syntax of the STLCS logic formula is as follows:
[0045]
[0046] in,
[0047] p represents an atomic proposition;
[0048] Represents the adjacency relationship of state nodes in the space;
[0049] represents the bracketing operator;
[0050] In the space, Φ is satisfied 1 The state node is Φ 2 The state nodes are surrounded by;
[0051] Represents all paths;
[0052] Indicates that there is a path;
[0053] Representing the next state of the network spatiotemporal model;
[0054] It means that there is a state satisfying Φ in the path;
[0055] Indicates that all state nodes of the detected path satisfy Φ;
[0056] Indicates that the state nodes on the path always satisfy Φ 1 Until Φ is satisfied 2 The status node appears.
[0057] Preferably, each of the spatiotemporal property specifications is as follows:
[0058]
[0059] in,
[0060] φ3 Indicates the persistence of the aggregate in time;
[0061] High indicates a high load state;
[0062] Indicates that there is a path;
[0063] represents a time series operator;
[0064] I represents the distance operator;
[0065] Represents all paths;
[0066] low indicates low load status;
[0067] φ 4 Indicates the impact range of traffic aggregation in space;
[0068] φ 5 Indicates dynamically expanding traffic aggregation;
[0069] Indicates adjacent cells of the cellular network system;
[0070] represents the outer boundary of the low-load cluster;
[0071] φ 6 Indicates dynamically shrinking traffic aggregation;
[0072] φ 7 Indicates that the cellular network system cell currently in a low-load state is always at the center of a low-load cluster in the next n steps;
[0073] Indicates being in the center of a low-load cluster;
[0074] n represents the number of continuous steps in the time dimension;
[0075] φ 8 Indicates that the macro base station meeting the low load condition needs to be adjacent to more than two cells of the cellular network system in a low load state;
[0076] represents a conditional operator;
[0077] Represents the Degree operator;
[0078] h 2 Indicates the number of base stations. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] Figure 1is a flow chart of the steps of the present invention;
[0080] Figure 2 is a schematic diagram of a closed cell of the present invention;
[0081] Figure 3 The four sets of property verification results of property 1 and property 2 in Example 1 of the present invention;
[0082] Figure 4 The result of property verification is displayed in the time slice of 12 noon for property 5 in the first embodiment of the present invention;
[0083] Figure 5 This is the detection result of property 4 at 20:00 at night in Example 1 of the present invention. DETAILED DESCRIPTION
[0084] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, specific embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0085] In a preferred embodiment of the present invention, based on the above problems existing in the prior art, a network traffic spatiotemporal feature mining method based on model detection is provided. Figure 1 As shown, the following steps are included:
[0086] Step S1, constructing each cellular network system cell into hexagonal units with the macro base station of each cellular network system cell as the center, and connecting two adjacent hexagonal units to obtain a closed space;
[0087] Step S2, constructing multiple groups of network space models based on the closed space and the cellular traffic data corresponding to each cellular network system cell, each group of network space models corresponds to a spatiotemporal snapshot, and constructing a spatiotemporal snapshot model according to the data content of each spatiotemporal snapshot;
[0088] Step S3, based on the Kripke structure, a network spatiotemporal model is constructed according to the spatiotemporal snapshot model;
[0089] Step S4, obtaining an STMCP space-time model detector and adding multiple space-time property specifications to the STMCP space-time model detector;
[0090] Step S5, input the network spatiotemporal model into the STMCP spatiotemporal model detector, and control the STMCP spatiotemporal model detector to detect the network space model based on various spatiotemporal property specifications to obtain corresponding network traffic anomaly feature mining results.
[0091] Specifically, in this embodiment, cellular traffic data is formally modeled through closure space and Kripke structure, and the inconsistency of machine learning methods for cellular traffic data is solved through a complete formal model. At the same time, considering that the consumption of communication resources in the network has time-space related attributes, the time-space anomaly characteristics, that is, the network traffic anomaly characteristics, can be described by adding multiple time-space property specifications to the STMCP time-space model detector. The network traffic anomaly is expressed using the time-space property specifications, and the time-space property specifications are used as the input of the STMCP time-space model detector, which is equivalent to a more efficient abnormal property query statement, which can avoid complex programming work in the data analysis process, thereby simplifying the analysis process.
[0092] Preferably, the use of the STMCP spatiotemporal model detector can automatically and completely detect the traffic distribution characteristics in the network spatiotemporal model, which can greatly reduce the workload.
[0093] Specifically, in this embodiment, steps S1 to S3 are for formally modeling the cellular traffic data to obtain a network spatiotemporal model of the Kripke structure. The cellular traffic data is essentially a summary of individual user traffic demands, and reflects the demand through the resource consumption of local macro base stations. The wireless communication base station is the main part of the access network in the cellular network system, responsible for the connectivity between mobile users and the core network. Usually, several micro base stations and macro base stations will jointly form a cellular network system cell for communication. Adjacent cellular network system cells use different frequencies to avoid interference so as to increase the total capacity of the system. The operator configures different types of probes at each base station to collect and monitor network activity data, and compiles statistics in the form of the sum of the cellular network system cells to reduce the impact of random fluctuations in the traffic of individual macro base stations.
[0094] Preferably, Figure 2 As shown in the figure, in the spatial dimension, it is assumed that the communication range and shape of all cellular network system cells are consistent, and the distance between cellular network system cells is consistent, and the spatial distribution structure of the macro base station does not change during the study. The cell centered on the macro base station is modeled as a standard hexagonal unit, and the single side length of the cellular network system cell is set to R. Then the distance between the cellular network system cells is The coverage area of a single cellular network system cell is The total number of cells in the cellular network system is n, and the set is represented by X = {x 1 ,x 2 ,x 3 ,…,x n}, in terms of the attribute content of the closure interval, the network activity parameters undertaken by the macro base station will constitute the atomic attributes of each node in the closure interval, and the sum of the attributes of each macro base station in the same cellular network system cell will serve as the overall attribute of the cellular network system cell.
[0095] Specifically, in this embodiment, the formal formula of the spatiotemporal property of the traffic demand distribution requires a corresponding model detector to obtain the verification result. In order to efficiently complete the property detection work, this embodiment will use a model detector based on spatiotemporal modal logic (STLCS). Python (STMCP), STMCP is a global model detector that can verify STLCS formulas on finite models. The detector is written in Python. The tool implements the combination of spatial modal logic (SLCS) operators and branching computation tree logic (CTL) operators. Spatiotemporal operators can be nested on this basis. The model detector consists of a time part and a space part. The time part is input by a state transfer file, and the spatial state at each time point is an independent object; the space part is a finite quasi-discrete closure space, and the topological relationship is passed in the form of an adjacency matrix. The atomic proposition is provided by a value file. Each line in the file is an atomic attribute of a point in space and time. The properties to be tested will be presented in the form of logical formulas. The formula formally expresses the valuable characteristics of the model, such as the clustering of low-load base stations. The verification result is a set of qualified space-time point sets, which are presented in a visual way to provide a basis for optimizing the energy consumption strategy of the base station system.
[0096] Preferably, STLCS has powerful expression capabilities and can express many complex spatiotemporal properties. Meanwhile, STMCP has strong scalability and can subsequently combine multiple technologies to improve performance.
[0097] In a preferred embodiment of the present invention, the cellular traffic data corresponding to each cellular network system cell respectively include network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data within the coverage area of the macro base station corresponding to the cellular network system cell. In step S2, multiple groups of network space models are constructed based on the closure space and the network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data corresponding to each cellular network system cell.
[0098] Specifically, in this embodiment, the network traffic data, the instant short message receiving data, the instant short message sending data, the voice call incoming data, the voice call outgoing data and the macro base station power consumption data are used as the network traffic data corresponding to the cellular network system cell. The rich quantity, type and data volume can improve the accuracy of the network traffic anomaly feature mining results.
[0099] Preferably, the network traffic data represents the sum of communication resources consumed by all users uploading and downloading through the Internet within the coverage of the macro base station, the instant short message reception data represents the sum of SMS messages received by all users from other regions within the coverage of the macro base station, the instant short message sending data represents the sum of SMS messages sent by all users to other regions within the coverage of the macro base station, the voice call access data represents the records of all users answering voice calls from other regions within the coverage of the macro base station, the voice call outgoing data represents the records of all users making voice calls to other regions within the coverage of the macro base station, and the macro base station power consumption data represents the power consumption of the macro base station at the current activity level.
[0100] In a preferred embodiment of the present invention, in step S2, the definition of the network space model is as follows:
[0101]
[0102] in,
[0103] X represents the set of cells of each cellular network system in the closed space;
[0104] represents the closure operator;
[0105] A set representing the adjacency relationship between cells in each cellular network system;
[0106] Represents a set of assignment functions corresponding to the atomic properties of each cell in the cellular network system.
[0107] Specifically, in this embodiment, the model detection technology requires a strict spatial model as a basis. The spatial layer input of the STMCP spatiotemporal model detector must be a closed space model with finite nodes. Therefore, the spatial model of the cellular network system cell is constructed as a closed space model. The network space model based on the closed space is defined as a triple X={x 1 ,x 2 ,x 3 ,…,x n} is the set of cellular network system cells in the closure space, is the closure operator of the network space model, Represents the set of adjacency relationships between cells in a cellular network system, such as Figure 2 The distance between the center of cells A and B is D, which is an adjacent relationship. Construct the corresponding closure relationship.
[0108] In a preferred embodiment of the present invention, in step S2, the definition of the spatiotemporal snapshot model is as follows:
[0109]
[0110] in,
[0111] Represents a spatiotemporal snapshot model;
[0112] T represents the time series;
[0113] representing the cyberspace model;
[0114] Represents the spatial structure (X,C);
[0115] Represents the atomic proposition mapped based on atomic properties in the assignment function V at the i-th space-time snapshot.
[0116] Specifically, in this embodiment, each group of network space models They all reflect a spatiotemporal snapshot in the system state space, and each spatiotemporal snapshot has a corresponding flow space distribution state, namely X T The data content of each spatiotemporal snapshot can be constructed into a spatiotemporal snapshot model based on the data content.
[0117] Preferably, each spatiotemporal snapshot are the same, reflecting the invariance of the spatial structure in the space-time snapshot model.
[0118] In a preferred embodiment of the present invention, in step S3, the network spatiotemporal model is defined as follows:
[0119]
[0120] in,
[0121] Represents a network spatiotemporal model;
[0122] Represents the space part composed of the closure space;
[0123] X represents the set of cells of each cellular network system in the closed space;
[0124] represents the closure operator;
[0125] (S,S 0 ,R) represents the time part of the Kripke structure;
[0126] S represents the set of state nodes in the Kripke structure;
[0127] S0 Represents the initial state node;
[0128] R represents the state transition relationship between state nodes, and P represents the assignment function The set of atomic propositions in
[0129] Represents the traffic distribution status of all state nodes in space and time.
[0130] Specifically, in this embodiment, the space-time snapshot model is a basic space-time model, and the Kripke structure is a labeled state transition diagram used for model detection, which consists of nodes and directed edges. The nodes represent the reachable states of the system, and the edges represent the conversion relationship between the states. The Kripke structure is often used in traditional temporal logic model detection such as CTL. In this embodiment, the Kripke structure is used to improve the space-time snapshot model to obtain a network space-time model.
[0131] Preferably, the network spatiotemporal model is defined as a seven-tuple , P = {InternetTraffic, SMSIn, SMSOut, CallIn, CallOut, electricity} is the set of atomic propositions in the model. The assignment of atomic propositions depends not only on the spatial distribution state but also on the time period in which the space is located. The assignment function X×S→2 P , which means that the atomic proposition is assigned to the spatial point set X of each state in S, and the result is 2 P Boolean value, indicating the traffic distribution status of all nodes in space and time, specifically:
[0132]
[0133]
[0134] In a preferred embodiment of the present invention, in step S4, each spatiotemporal property specification is constructed based on the formal syntax of the STLCS logic formula, and the formal syntax of the STLCS logic formula is as follows:
[0135]
[0136] in,
[0137] p represents an atomic proposition;
[0138] Represents the adjacency relationship of state nodes in the space;
[0139] represents the bracketing operator;
[0140] In the space, Φ is satisfied 1 The state node is Φ 2 The state nodes are surrounded by;
[0141] Represents all paths;
[0142] Indicates that there is a path;
[0143] Represents the next state of the network spatiotemporal model;
[0144] It means that there is a state satisfying Φ in the path;
[0145] Indicates that all state nodes of the detected path satisfy Φ;
[0146] Indicates that the state nodes on the path always satisfy Φ 1 Until Φ is satisfied 2 The status node appears.
[0147] Specifically, in this embodiment, in order to formally express the spatiotemporal properties of cellular network traffic distribution, the spatiotemporal modal logic STLCS based on closure space is used in this embodiment. The time dimension of the logic is composed of traditional branching computation tree logic (CTL), and the space dimension is closure space modal logic (SLCS), which mainly includes the space representing topological proximity. (near) operator, and spatial enclosing (surrounded) operator, etc. The following will supplement the specific content of STLCS. The system model is the network space-time model based on Kripke structure in the previous section. The following is the formal syntax of STLCS logic formula, where p represents an atomic proposition, and the truth value of formula Φ is represented by a set of points x∈X in the closure space model when the state s∈S is denoted as
[0148] Preferably, in the formal syntax of the STLCS logic formula, p represents an atomic proposition, which represents the basic attributes of the nodes in the model, such as the traffic value in the cell; is the proximity operator, used to represent the adjacency relationship of spatial nodes; S is the enclosing operator; In the space, Φ is satisfied 1 The point is satisfied by Φ 2 surrounded by points.
[0149] Preferably, the STLCS is characterized by having a CTL path qualifier (all paths) and (there is a path), the path qualifier must have a path-specific temporal operator, the temporal operators are: Next operator, used to describe the next state in the model; is the Eventually operator, indicating that there is a state satisfying Φ in the path; It is a Globally operator, which requires that all state nodes of the detected path satisfy Φ; Until operator, requiring the state nodes on the path to always satisfy Φ 1 , until Φ is satisfied 2 Nodes appear. Unlike CTL, in STLCS, proposition Φ can be a spatial operator, and the nesting of these operators can express specific time and space properties.
[0150] Preferably, the formal syntax of STLCS logic formulas is Interpretation: Satisfy φ 2 A spatial point whose topological adjacent nodes satisfy φ 1 The number of nodes is n, and if n satisfies the conditional expression of f (f is usually a function of the value range of n), the output is true.
[0151] In a preferred embodiment of the present invention, the spatiotemporal properties are specified as follows:
[0152]
[0153] in,
[0154] φ 3 Indicates the persistence of the aggregate in time;
[0155] High indicates a high load state;
[0156] Indicates that there is a path;
[0157] represents a time series operator;
[0158] I represents the distance operator;
[0159] Represents all paths;
[0160] low indicates low load status;
[0161] φ 4 Indicates the impact range of traffic aggregation in space;
[0162] φ 5 Indicates dynamically expanding traffic aggregation;
[0163] Indicates adjacent cells of the cellular network system;
[0164] represents the outer boundary of the low-load cluster;
[0165] φ 6 Indicates dynamically shrinking traffic aggregation;
[0166] φ 7 Indicates that the cellular network system cell currently in a low-load state is always at the center of a low-load cluster in the next n steps;
[0167] Indicates being in the center of a low-load cluster;
[0168] n represents the number of continuous steps in the time dimension;
[0169] φ 8 Indicates that the macro base station meeting the low load condition needs to be adjacent to more than two cells of the cellular network system in a low load state;
[0170] represents a conditional operator;
[0171] Represents the Degree operator;
[0172] h 2 Indicates the number of base stations.
[0173] Specifically, in this embodiment, according to the detection requirements of dense traffic aggregation, φ 3 Indicates the persistence of aggregation over time. The formula is two-layer Operator nesting indicates that the high load state of the cell in the cellular network system lasts for three time segments in the model; φ 4 It represents the influence range of traffic aggregation in space. The formula uses the internal operator I (interior). In the closure space The operator indicates that points that satisfy IΦ are only connected to points that satisfy Φ. The nesting of a single I operator is expressed in the form of an exponential. The third-order I indicates the distance that traffic aggregation passes through three nodes starting from the edge.
[0174] Preferably, φ 5 and φ 6 represents the dynamic change process of detection aggregation, φ 5 Represents dynamically expanding traffic aggregation. The formula requires finding the outer boundary of the first-order high-load cell cluster. At the next time step, the adjacent cells topologically connected to it are transformed into a high-load state, so that the traffic aggregation expands outward as a whole; φ 6Indicates the traffic aggregation of dynamic shrinkage, requiring that the detected cell is currently in the first-order high-load state, but changes to the normal state in the next time step, which is different from φ 3 and φ 4 ,The expansion and shrinkage of aggregation is a spatiotemporal property, which changes in space as time progresses, showing the evolution of aggregation.
[0175] Preferably, φ 7 and φ 8 Indicates detection of dormant cold areas, φ 7 The explanation is that the cell currently in the low-load state will always be at the center of the low-load cluster in the next n steps; the formula uses the Global operator, whose subscript represents the number of continuous steps of the operator in the time dimension, that is, from the current time point t to t+h 2 step, the specification is always met; φ 8 The Degree operator is used in the formula, which explains the degree of independence of the cold zone. The formula requires that a base station that meets the low load requirement needs to be adjacent to more than two low-load cells.
[0176] Embodiment 1:
[0177] By analyzing the relevant data of Telecom Italia Big Data Challenge, the spatiotemporal properties of cellular network traffic distribution are verified. This dataset is released under the Open Database License (ODbL) and included in the Harvard Dataverse. The data collects relevant data of all telecommunication activities in Milan, Italy from November 1, 2013 to January 1, 2014, including network traffic, short message sending records, call records and base station power consumption data. The adjacency relationship of the cell in the data is converted into its surrounding nodes. After analysis, it can be seen that the city's points of interest have a great impact on the traffic distribution characteristics.
[0178] Figure 3 It is property 1(φ 3 ) and Property 2(φ 4 ) are the time slices at 11:00 noon and 20:00 pm. In the specific verification process, the network traffic load threshold C is set to 3000. The nodes in the figure are divided into four types: dark brown nodes (such as No. 341) are nodes that meet the requirements of φ 3 ,φ 4 The space-time nodes of φ represent large-scale traffic aggregation; the black nodes (such as No. 391 at 11 o'clock) conform to φ 5 formula, representing a dynamically expanding aggregation; the light gray nodes (such as No. 309 at 11 o'clock) meet the φ 6The formula represents the aggregation that is in dynamic shrinkage. The verification results show that the traffic aggregation centers in Milan are roughly divided into the church area, Navigli area, Milan Central Station, and Garibaldi Station. 11:00 noon is the peak of crowd activity in the church area. The results truly reflect the traffic aggregation trend in the No. 341 church area. At the same time, each traffic aggregation generally shows an expansion trend, and the city as a whole is in an active state. 20:00 at night is another representative time point. Since the closing time of scenic spots in the church area is generally around 19:00 at night, the test results show that the traffic aggregation is constantly shrinking, indicating that users active in this area are losing, but the traffic aggregation phenomenon in the Navigli area is dynamically expanding at night. Obviously, this is related to the widely distributed hotels and other facilities in the area, and the station area maintains a high traffic load throughout the day, which is in line with its functional characteristics as a transportation hub.
[0179] Figure 4 It is property 5(φ 7 ) shows the result of the property verification with a time slice at 12 noon, reflecting the spatiotemporal accessibility of a specific point of interest. Since a specific destination needs to be set, the University of Milan (node 491) is used as the spatiotemporal destination in the experiment. The verified formula φ tn The number of iterations n in is set to 8, and the user speed is one unit distance per unit time. It should be noted that in this property, the user's stay in the path and the existence of loops are not considered. Only the user's shortest path to the destination is considered. Due to the restriction on the length of the space-time path in the formula, a large number of nodes at a long distance do not meet the property requirements. Therefore, the research scope is further narrowed to better display the verification results. The church area is located to the north of the University of Milan. Although the two are close in space, their dense traffic load conditions make it impossible for any path to pass through here. However, there are some space-time paths in the Navigli area, which can reach the destination relatively easily. The Crocetta area (node 470) on the right side of the University of Milan has relatively smooth communication, and a large number of space-time paths start here. In addition to being applied to static data analysis, the reachability analysis can also be used in real-time systems to provide assistance for path selection, which is also an exploration of the use of space-time model detection technology.
[0180] Figure 5 It is property 4(φ 6 ) The detection results at 20:00 at night, the brown nodes meet φ 7 ,φ 8 The constraint of φ describes the flow cold zone that meets the dormancy requirements. 7 middle The subscript n of the operator is 3, requiring that the property lasts for 3 time slices, i.e., 30 minutes, in all branches. The nodes detected in the figure have different distribution characteristics for the same property. Since the studied area is located in the core of the city, it is obvious that the city as a whole is still active during this period. Figure 5 From the results, we can find that dormant cold zones generally exist in the gaps between traffic aggregation and are distributed in a band-like manner. Similar features exist during peak hours during the day. As user activity decreases at night, traffic load cold zones exist on a large scale in the middle of the night.
[0181] The computational complexity of the model checking algorithm is linearly related to the model scale and the number of sub-formulas in the verification formula. In the experiment, the model node scale is set to 6 levels. According to the number of spatial nodes and time snapshot nodes, the spatial nodes are divided into 25*25 and 100*100, and the snapshot nodes are divided into 144, 331 and 497. The verification time of each property is shown in Table 1. The time increases linearly with the increase of the number of snapshots, while the increase of the spatial node scale greatly increases the verification time, indicating that the spatial scale has a greater impact on the time complexity. In each formula, φ t8 The verification time is longer because it has more internal iterative sub-formulas. The performance of other formulas is similar, but different formulas have different sensitivities to time and space complexity.
[0182] Table 1 Verification time under different model scales
[0183]
[0184] Although the disclosure is disclosed as above, the protection scope of the disclosure is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the disclosure, and these changes and modifications will fall within the protection scope of the present invention.
Claims
1. A network traffic spatiotemporal feature mining method based on model detection, It is characterized in that The following steps are involved: Step S1, constructing each cellular network system cell into hexagonal units with the macro base station of each cellular network system cell as the center, and connecting two adjacent hexagonal units to obtain a closed space; Step S2, constructing multiple groups of network space models based on the closed space and the cellular traffic data corresponding to each of the cellular network system cells, each group of the network space models corresponds to a spatiotemporal snapshot, and constructing a spatiotemporal snapshot model according to the data content of each of the spatiotemporal snapshots; Step S3, based on the Kripke structure, a network spatiotemporal model is constructed according to the spatiotemporal snapshot model; Step S4, obtaining an STMCP space-time model detector and adding multiple space-time property specifications to the STMCP space-time model detector; Step S5, inputting the network spatiotemporal model into the STMCP spatiotemporal model detector, and controlling the STMCP spatiotemporal model detector to detect the network space model based on each of the spatiotemporal property specifications to obtain corresponding network traffic anomaly feature mining results.
2. According to the network traffic spatiotemporal feature mining method of claim 1, It is characterized in that The cellular traffic data corresponding to each of the cellular network system cells respectively include the network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data within the coverage area of the macro base station corresponding to the cellular network system cell. In the step S2, a plurality of groups of the network space models are constructed based on the closure space and the network traffic data, instant short message reception data, instant short message sending data, voice call access data, voice call outgoing data and macro base station power consumption data corresponding to each of the cellular network system cells.
3. The network traffic spatiotemporal feature mining method according to claim 1, It is characterized in that In step S2, the network space model is defined as follows: in, X represents a set of cells of the cellular network system in the closed space; represents the closure operator; A set representing the adjacency relationship between cells of each cellular network system; Represents a set of assignment functions corresponding to the atomic attributes of each cell of the cellular network system.
4. The network traffic spatiotemporal feature mining method according to claim 3, It is characterized in that In step S2, the definition of the spatiotemporal snapshot model is as follows: in, represents the spatiotemporal snapshot model; T represents the time series; representing the cyberspace model; Represents the spatial structure (X,C); Indicates that at the i-th spatiotemporal snapshot, the assignment function Atomic propositions mapped based on atomic properties.
5. The network traffic spatiotemporal feature mining method according to claim 4, It is characterized in that In step S3, the network spatiotemporal model is defined as follows: in, represents the network spatiotemporal model; represents the spatial part composed of the closure space; X represents a set of cells of the cellular network system in the closed space; represents the closure operator; (S,S 0 , R) represents the time part of the Kripke structure; S represents a set of state nodes in the Kripke structure; S 0 Represents the initial state node; R represents the state transition relationship between state nodes, and P represents the assignment function The set of atomic propositions in each of the above; Represents the traffic distribution status of all state nodes in space and time.
6. The network traffic spatiotemporal feature mining method according to claim 1, It is characterized in that In step S4, each of the spatiotemporal property specifications is constructed based on the formal syntax of the STLCS logic formula, and the formal syntax of the STLCS logic formula is as follows: in, p represents an atomic proposition; Represents the adjacency relationship of state nodes in the space; represents the bracketing operator; In the space, Φ is satisfied 1 The state node is Φ 2 The state nodes are surrounded by; Represents all paths; Indicates that there is a path; Representing the next state of the network spatiotemporal model; It means that there is a state satisfying Φ in the path; Indicates that all state nodes of the detected path satisfy Φ; Indicates that the state nodes on the path always satisfy Φ 1 Until Φ is satisfied 2 The status node appears.
7. The network traffic spatiotemporal feature mining method according to claim 6, It is characterized in that The space-time properties are as follows: in, φ 3 Indicates the persistence of the aggregate in time; High indicates a high load state; Indicates that there is a path; represents a time series operator; I represents the distance operator; Represents all paths; low indicates low load status; φ 4 Indicates the impact range of traffic aggregation in space; φ 5 Indicates dynamically expanding traffic aggregation; Indicates adjacent cells of the cellular network system; represents the outer boundary of the low-load cluster; φ 6 Indicates dynamically shrinking traffic aggregation; φ 7 Indicates that the cellular network system cell currently in a low-load state is always at the center of a low-load cluster in the next n steps; Indicates being in the center of a low-load cluster; n represents the number of continuous steps in the time dimension; φ 8 Indicates that the macro base station meeting the low load condition needs to be adjacent to more than two cells of the cellular network system in a low load state; represents a conditional operator; Represents the Degree operator; h 2 Indicates the number of base stations.
Citation Information
Patent Citations
Traffic volume prediction method and device based on space-time big data
CN113053123A
Flow prediction method and system based on dynamic space-time hypergraph convolutional network
CN115866658A