Method and apparatus for detecting irregular business
By analyzing the traffic and port usage of home gateways and utilizing multi-layered filtering conditions and gateway restart technology, the problems of low efficiency and insufficient accuracy in PCDN illegal service detection were solved, achieving efficient and accurate detection of illegal services.
Patent Information
- Application Number
- CN202410379428.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-03-29
AI Technical Summary
Existing PCDN non-compliant service detection methods are inefficient, resource-intensive, and produce inaccurate results, posing security risks.
By receiving uplink and downlink traffic data from the home gateway, as well as the number of ports used in the data packets, abnormal behavior is identified using multi-layered filtering conditions. This includes re-analyzing traffic and port usage after restarting the gateway to determine whether it is a PCDN violation.
It improved testing efficiency, reduced resource consumption, enhanced testing accuracy, and lowered safety risks.
Smart Images

Figure CN118802681B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a method and device for detecting illegal business. BACKGROUND
[0002] A peer-to-peer content delivery network (PCDN) is a low-cost high-quality content delivery network service based on P2P technology, constructed by mining and utilizing massive fragmented idle resources of edge networks. PCDN illegal business refers to the situation that enterprises and individual customers rent a large amount of bandwidth from an operator, change the use of products at will, aggregate the uplink bandwidth for their own use to form a large bandwidth for traffic operation, and sell at a low price in the form of PCDN service. PCDN illegal business is usually accompanied by illegal arbitrage behavior, which greatly damages the interests of the operator and also poses a serious security risk.
[0003] The existing PCDN illegal business detection method is limited, and is generally based on online list analysis and customer traffic analysis. The existing PCDN illegal business detection method faces a large amount of data process, which requires a lot of resources, resulting in low detection efficiency. SUMMARY
[0004] The present application provides a method and device for detecting illegal business to improve the detection efficiency of PCDN illegal business detection.
[0005] The present application provides a method for detecting illegal business, comprising:
[0006] receiving reported data of a plurality of home gateways, the reported data comprising uplink traffic total data, downlink traffic total data, uplink traffic period data, downlink traffic period data and the number of ports used by data packets, the uplink traffic period data being uplink traffic data of each reporting period within a preset time period, and the downlink traffic period data being downlink traffic data of each reporting period within a preset time period;
[0007] screening the plurality of home gateways based on the uplink traffic total data, the downlink traffic total data and the uplink traffic period data to obtain a first screening result of uplink traffic total anomaly;
[0008] screening the home gateways in the first screening result based on the uplink traffic period data and the downlink traffic period data to obtain a second screening result of uplink traffic period anomaly;
[0009] Restart the home gateway in the second screening result, and screen the home gateway in the second screening result based on the restarted uplink traffic periodic data, the restarted downlink traffic periodic data and the number of ports used by the restarted data message, to obtain a third screening result, and determine the home gateway in the third screening result as a violation service gateway.
[0010] According to the application, a violation service detection method is provided, which screens the multiple home gateways based on the uplink traffic total data, the downlink traffic total data and the uplink traffic periodic data, to obtain a first screening result of uplink traffic total anomaly, including:
[0011] Based on the uplink traffic total data, the downlink traffic total data and the uplink traffic periodic data, a first screening condition is determined, and the multiple home gateways are screened based on the first screening condition, to obtain a first screening result of uplink traffic total anomaly.
[0012] The first screening condition includes:
[0013] The uplink traffic total data in the preset time period is greater than a preset uplink traffic total threshold;
[0014] The proportion of the uplink traffic total data in the preset time period is greater than the proportion of the downlink traffic total data in the preset time period;
[0015] The number of times that the uplink traffic periodic data exceeds a preset periodic traffic threshold in the preset time period is greater than a first preset periodic traffic number threshold.
[0016] According to the application, a violation service detection method is provided, which screens the multiple home gateways based on the uplink traffic periodic data and the downlink traffic periodic data, to obtain a second screening result of uplink traffic periodic anomaly, including:
[0017] Based on the uplink traffic periodic mean data and the downlink traffic periodic mean data, a second screening condition is determined, and the home gateway in the first screening result is screened based on the second screening condition, to obtain a second screening result of uplink traffic periodic anomaly.
[0018] The second screening condition includes:
[0019] In the preset time period, the number of times that the uplink traffic periodic data exceeds the downlink traffic periodic data is greater than a second preset periodic traffic number threshold;
[0020] In the preset time period, the number of times that the change amplitude of the uplink traffic periodic data is greater than the change amplitude of the downlink traffic periodic data is greater than a preset amplitude number threshold.
[0021] According to the method for detecting illegal service provided by the application, the home gateway in the second screening result is screened based on the uplink traffic periodic data after restart, the downlink traffic periodic data after restart and the port number used by the data packet after restart to obtain a third screening result, including:
[0022] The third screening condition is determined based on the uplink traffic periodic data after restart, the downlink traffic periodic data after restart and the port number used by the data packet after restart, and the home gateway in the second screening result is screened based on the third screening condition to obtain a third screening result.
[0023] The third screening condition includes:
[0024] The change amplitude of the uplink traffic periodic data after restart is greater than a preset change amplitude threshold, and the change amplitude of the downlink traffic periodic data after restart is less than the preset change amplitude threshold.
[0025] The growth amplitude of the port number used by the UDP data packet after restart is greater than a preset port change amplitude threshold, and the growth amplitude of the port number used by the TCP data packet after restart is less than the preset port change amplitude threshold.
[0026] According to the method for detecting illegal service provided by the application, the home gateway in the second screening result is screened based on the uplink traffic periodic data after restart, the downlink traffic periodic data after restart and the port number used by the data packet after restart to obtain a third screening result, including:
[0027] Based on the historical home network traffic demand in the home gateway, a target moment of the minimum home network traffic demand in the home gateway is determined.
[0028] At the target moment, the home gateway in the second screening result is restarted.
[0029] According to the method for detecting illegal service provided by the application, the home gateway in the second screening result is screened based on the uplink traffic periodic data after restart, the downlink traffic periodic data after restart and the port number used by the data packet after restart to obtain a third screening result, including:
[0030] Based on the home gateway in the second screening result, a restart gateway list is determined.
[0031] The restart gateway list is sent to a terminal management platform RMS platform, so that the RMS platform restarts the home gateway in the second screening result at the target moment.
[0032] The application further provides a device for detecting illegal service, including:
[0033] The receiving module is configured to receive report data of a plurality of home gateways, wherein the report data comprises uplink traffic total data, downlink traffic total data, uplink traffic period data, downlink traffic period data and a number of ports used by data packets, the uplink traffic period data is uplink traffic data of each reporting period within a preset time period, and the downlink traffic period data is downlink traffic data of each reporting period within the preset time period.
[0034] The first screening module is configured to screen the plurality of home gateways based on the uplink traffic total data, the downlink traffic total data and the uplink traffic period data, and obtain a first screening result of uplink traffic total anomaly.
[0035] The second screening module is configured to screen the home gateways in the first screening result based on the uplink traffic period data and the downlink traffic period data, and obtain a second screening result of uplink traffic period anomaly.
[0036] The third screening module is configured to restart the home gateways in the second screening result, screen the home gateways in the second screening result based on restarted uplink traffic period data, restarted downlink traffic period data and a number of ports used by data packets after the restart, obtain a third screening result, and determine that the home gateways in the third screening result are illegal service gateways.
[0037] The application further provides an electronic device, including a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the above-mentioned illegal service detection methods.
[0038] The application further provides a non-transitory computer readable storage medium, which stores a computer program, wherein the computer program is executed by a processor to implement any of the above-mentioned illegal service detection methods.
[0039] The application further provides a computer program product, which includes a computer program, wherein the computer program is executed by a processor to implement any of the above-mentioned illegal service detection methods.
[0040] The application provides a method and device for detecting illegal service, which analyzes the behavior characteristics of user spontaneous uplink traffic, and in addition to continuously generating a large amount of uplink traffic, a large amount of downlink traffic is also generated. Based on the comparison of the change trend of uplink traffic and downlink traffic and the change of the number of ports used by data packets, the case of abnormal decrease of uplink traffic and abnormal increase of the number of ports used by UDP packets is screened, so as to determine whether it is a suspected user of PCDN illegal service, so that the screening is more accurate. At the same time, the judgment process is realized based on the received reporting data, without additional resource consumption of data collection, saving a large amount of server resources and improving the detection efficiency. BRIEF DESCRIPTION OF DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the present application or prior art, the drawings needed to be used in the embodiments or prior art description will be briefly described below. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0042] Figure 1 is a flowchart of the method for detecting illegal service provided by the present application;
[0043] Figure 2 is a flowchart of the method for detecting illegal service provided by the present application;
[0044] Figure 3 is a flowchart of the method for detecting illegal service provided by the present application;
[0045] Figure 4 is a structural diagram of the device for detecting illegal service provided by the present application;
[0046] Figure 5 is a structural diagram of the electronic device provided by the present application. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the present application more clear, the technical solutions in the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0048] PCDN is a low-cost high-quality content distribution network service based on P2P technology, which is constructed by mining and utilizing the massive fragmented idle resources of edge networks. PCDN illegal business is that enterprises and individual customers rent a large amount of broadband (including home broadband products, business broadband products, and business dedicated line products) from operators, change the purpose of the products, aggregate the uplink bandwidth for traffic operation, and sell at a low price in the form of PCDN service. Some enterprises target home broadband users, offer a small amount of rewards, and use home broadband to share part of the traffic to save a large amount of bandwidth fees for enterprises. PCDN illegal business is usually accompanied by illegal arbitrage behavior, which greatly damages the interests of operators and also poses serious security risks.
[0049] The related method has limited detection methods for PCDN illegal business, mainly relying on AAA online list analysis and customer traffic analysis. The AAA online list analysis method is online data in a long period of time, which leads to problems such as too large data volume and difficult detection, and cannot efficiently and comprehensively detect the entire network. Moreover, the AAA online list is mainly used for authentication and charging, and the recorded online information is not comprehensive, which has limitations for analysis and detection. Customer traffic analysis needs to analyze the real online traffic of the client, which is highly invasive to the system and poses certain security risks, consumes a lot of resources, and can only analyze a small number of users, which is not comprehensive.
[0050] The defects in the related method include:
[0051] The AAA online list analysis method is mainly used for authentication and charging, and the recorded online information is not comprehensive, including all traffic data, which cannot filter traffic according to WAN;
[0052] The AAA online list analysis method needs to obtain the traffic timing data of the client through other systems, such as through the broadband access server (BRAS) using the remote user dial-in authentication system (RADIUS) protocol. The entire process is complex and consumes a lot of resources, and can only obtain traffic timing data for a part of the gateway;
[0053] The related method mainly uses the following methods to screen PCDN suspected users: uplink traffic exceeding a threshold, and uplink traffic being greater than downlink traffic for a long time. Although the screening method is simple, it cannot exclude user-initiated uplink traffic behavior such as video calls, live streaming, and remote operation, and the screening result is not accurate, which may affect normal use users;
[0054] The client flow data is acquired by a drainage mode for analysis, the system invasiveness is relatively large, there is certain signal security risk, resource consumption is extremely large, and only a small amount of users can be analyzed.
[0055] The TCP and UDP message numbers are acquired by analyzing the client flow data, and it is not accurate to determine that the PCDN is in violation of the behavior only because the TCP message number is relatively large.
[0056] The client IP address is acquired by analyzing the client flow data, and the method for determining that the PCDN domain name is resolved to the client by querying the domain name system (DNS) resolution log is also inaccurate. Because the DNS of a large number of users is not the default DNS provided by the operator, the resolution result cannot be queried.
[0057] In view of the defects in the related method, the application provides a method for detecting illegal business, Figure 1 The application provides a flowchart of the method for detecting illegal business. Referring to Figure 1 The application provides a method for detecting illegal business,
[0058] Step 110, receiving the reported data of a plurality of home gateways, the reported data comprising uplink flow total data, downlink flow total data, uplink flow period data, downlink flow period data and port number used by data messages, the uplink flow period data being uplink flow data of each reporting period in a preset time period, and the downlink flow period data being downlink flow data of each reporting period in a preset time period;
[0059] Step 120, screening the plurality of home gateways based on the uplink flow total data, the downlink flow total data and the uplink flow period data to obtain a first screening result of uplink flow total anomaly;
[0060] Step 130, screening the home gateway in the first screening result based on the uplink flow period data and the downlink flow period data to obtain a second screening result of uplink flow period anomaly;
[0061] Step 140, restarting the home gateway in the second screening result, and screening the home gateway in the second screening result based on the restarted uplink flow period data, the restarted downlink flow period data and the port number used by the data messages after the restart to obtain a third screening result, and determining that the home gateway in the third screening result is a gateway of illegal business.
[0062] The execution subject of the illegal service detection method provided by the application can be an electronic device, a component in the electronic device, an integrated circuit, or a chip. The electronic device can be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device can be a mobile phone, a tablet computer, a notebook computer, a palm computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), and the non-mobile electronic device can be a server, a network attached storage (NAS), or a personal computer (PC), without specific limitation of the application.
[0063] The technical solution of the application will be described in detail below with the computer executing the illegal service detection method provided by the application as an example.
[0064] In step 110, the reporting data of a plurality of home gateways is received, and the reporting data includes uplink traffic total data, downlink traffic total data, uplink traffic period data, downlink traffic period data, and the number of ports used by data packets. The uplink traffic period data is the uplink traffic data of each reporting period in a preset time period, and the downlink traffic period data is the downlink traffic data of each reporting period in a preset time period.
[0065] The reporting data of a plurality of home gateways is received. The home gateway refers to a device installed in a home network, which is used as a bridge between the internal devices (such as computers, mobile phones, and smart home devices) and external networks (such as the Internet). The home gateway usually has the functions of a router, a switch, a firewall, and a wireless access point, and can realize various network management and security protection functions.
[0066] The reporting data is the data related to the broadband Internet WAN reported by the home gateway periodically, including uplink traffic total data, downlink traffic total data, uplink traffic period data, downlink traffic period data, and the number of ports used by data packets.
[0067] The uplink traffic total data is the total data of the uplink traffic of the home gateway in a time period, and the downlink traffic total data is the total data of the downlink traffic of the home gateway in a time period.
[0068] The home gateway reports the reporting data once every reporting period. The preset time period can be one hour, one day, one week, etc., and can include multiple reporting periods. The uplink traffic period data is uplink traffic data of each reporting period in the preset time period, and the downlink traffic period data is downlink traffic data of each reporting period in the preset time period.
[0069] The number of ports used by the data message includes a number of ports used by a user datagram protocol (UDP) data message and a number of ports used by a transmission control protocol (TCP) data message.
[0070] In step 120, the multiple home gateways are screened based on the uplink traffic total data, the downlink traffic total data, and the uplink traffic period data, to obtain a first screening result of uplink traffic total abnormality.
[0071] It can be understood that general broadband users mainly watch videos and live broadcasts, browse web pages, download files, etc., and these behaviors mainly occupy downlink bandwidth, and the generated downlink traffic is much larger than uplink traffic. Occasionally, there are behaviors such as uploading files, which will only generate a large amount of uplink traffic for a short period of time. The characteristics of PCDN illegal service users are long-term and large occupation of uplink bandwidth, and continuous and periodic generation of a large amount of uplink traffic. According to the above-mentioned differences in traffic characteristics between general broadband users and PCDN illegal service users, the home gateways with abnormally high uplink traffic than general use are preliminarily screened out.
[0072] The specific screening process can screen the multiple home gateways based on the uplink traffic total data, the downlink traffic total data, and the uplink traffic period data, to determine the home gateways with uplink traffic total abnormality in the screening of the multiple home gateways.
[0073] In step 130, the home gateways in the first screening result are screened based on the uplink traffic period data and the downlink traffic period data, to obtain a second screening result of uplink traffic period abnormality.
[0074] After the preliminary screening of the multiple home gateway users, the multiple home gateways in the first screening result in step 120 are further screened based on the uplink traffic period data and the downlink traffic period data.
[0075] It's understandable that the gateways with abnormally high uplink traffic identified in step 120 might be experiencing frequent and prolonged video calls, live streaming, or remote operations by users. These activities generate not only a large amount of uplink traffic but also a significant amount of downlink traffic, and the trends of uplink and downlink traffic are generally synchronized, starting and ending simultaneously. In contrast, when users violating PCDN service regulations generate a large amount of uplink traffic, since downloading and uploading PCDN cached content generally don't occur simultaneously, a large amount of downlink traffic is unlikely to be generated at the same time, and the trends of uplink and downlink traffic are inconsistent. Given the difference in traffic patterns between general broadband users and users violating PCDN service regulations, if the average uplink traffic over multiple periods is significantly greater than the average downlink traffic over multiple periods, and uplink traffic increases dramatically multiple times while downlink traffic changes little or decreases within the same period, it indicates that internet access is primarily driven by uplink activity. This allows us to identify gateways with primarily uplink-driven activity.
[0076] Therefore, a further filtering process can be achieved based on both uplink and downlink traffic cycle data.
[0077] In step 140, the home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the home gateways in the second screening result are filtered to obtain a third screening result, and the home gateways in the third screening result are determined to be gateways for illegal services.
[0078] After secondary screening of multiple home gateway users, the home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the multiple home gateways in the second screening result in step 130 are further screened.
[0079] Understandably, for high-risk users suspected of violating PCDN regulations, further precise screening is required. The gateway SN list obtained from the second screening can be sent to the Remote Management Server (RMS) platform. Without affecting users' normal internet access, the RMS platform can remotely restart the gateway in the early morning.
[0080] After a gateway restart, public IPv4 addresses are typically reallocated. Existing PCDN resource requests become invalid, leading to a significant drop in uplink traffic for a period. However, normal user-generated uplink traffic, such as video surveillance uploads, recovers quickly. Simultaneously, the IPv4 address change necessitates renewed communication between PCDN terminals and the PCDN platform, typically using UDP for NAT traversal, resulting in a large number of UDP connections in a short period. During the early morning hours, when users are generally resting or sleeping, UDP traffic generated by activities like watching videos is minimal; standby devices primarily use TCP traffic. Given the different uplink traffic and UDP connection changes experienced by general broadband users and PCDN users after a gateway restart, a further filtering process can be implemented.
[0081] After further filtering the home gateways in the second screening results, a third screening result was obtained, and the home gateways in the third screening result were determined to be gateways for non-compliant services.
[0082] The method for detecting illegal services provided in this invention analyzes the characteristics of users' spontaneous uplink traffic behavior. Besides continuously generating a large amount of uplink traffic, it also generates a large amount of downlink traffic. Based on comparing the changing trends of uplink and downlink traffic, as well as the changes in the number of ports used by data packets, it filters out cases where uplink traffic abnormally decreases and the number of ports used by UDP packets abnormally increases to determine whether a user is suspected of engaging in illegal PCDN services, making the filtering more accurate. Simultaneously, the judgment process is implemented based on received and reported data, without consuming additional data collection resources, saving significant server resources and improving detection efficiency.
[0083] In one embodiment, filtering the multiple home gateways based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic cycle data to obtain a first filtering result of abnormal uplink traffic total includes: determining a first filtering condition based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic cycle data, and filtering the multiple home gateways based on the first filtering condition to obtain a first filtering result of abnormal uplink traffic total; the first filtering condition includes: the total uplink traffic data in a preset time period is greater than a preset total uplink traffic threshold; the proportion of the total uplink traffic data in the preset time period is greater than the proportion of the total downlink traffic data in the preset time period; and the number of times the uplink traffic cycle data in the preset time period exceeds a preset cycle traffic threshold is greater than a first preset cycle traffic frequency threshold.
[0084] Typical broadband users primarily engage in activities such as watching videos and live streams, browsing web pages, and downloading files. These activities mainly consume downlink bandwidth, generating significantly more downlink traffic than uplink traffic. Occasional file uploads only result in short-term surges in uplink traffic. In contrast, users of PCDN services that violate regulations consistently and excessively consume uplink bandwidth, generating large amounts of uplink traffic periodically. Based on these differences in traffic characteristics between typical broadband users and PCDN users violating regulations, we can initially screen home gateways with abnormally high uplink traffic compared to normal usage. Specifically, this screening can be based on a first screening criterion, which can include the following three characteristics:
[0085] Feature condition 1: The total uplink traffic of INTERNET WAN within a preset time period is greater than the preset total uplink traffic threshold.
[0086] Specifically, the preset time period can be daily, weekly, or monthly, with a summary cycle. Based on the data reported within the preset time period, the total uplink traffic and total downlink traffic for each gateway's Internet WAN are calculated, along with the number of times the uplink traffic period data exceeds the preset period traffic threshold.
[0087] Using feature condition 1, gateways with total Internet WAN uplink traffic exceeding a preset total uplink traffic threshold are selected. This preset threshold represents the uplink traffic generated by normal user activity.
[0088] Feature condition 2: The proportion of total Internet WAN uplink traffic data in the preset time period is greater than the proportion of total downlink traffic data in the preset time period.
[0089] Specifically, using feature condition 2, based on the fact that the proportion of total Internet WAN uplink traffic data in a preset time period is greater than the proportion of total downlink traffic data in the same preset time period, gateways with abnormally higher uplink traffic than downlink traffic are selected.
[0090] Feature condition 3: The number of times the INTERNET WAN uplink traffic cycle data exceeds the preset cycle traffic threshold within the preset time period is greater than the first preset cycle traffic count threshold.
[0091] Specifically, using feature condition 3, the number of times the uplink traffic periodic data exceeds the preset periodic traffic threshold within the preset time period is greater than the first preset periodic traffic frequency threshold. The first preset periodic traffic frequency threshold is the uplink traffic generated by normal user use within the software probe's periodic reporting interval. Normal user behavior involving large amounts of uplink traffic is short-term, and large amounts of uplink traffic within a short period may be normal user behavior. However, if there is a large amount of uplink traffic exceeding the specified number of periods, it indicates abnormal uplink traffic behavior.
[0092] After filtering based on the above three characteristics, home gateways with excessive uplink traffic were identified as potential users of PCDN services that violate regulations.
[0093] In one embodiment, based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first screening result are filtered to obtain a second screening result with abnormal uplink traffic cycles. This includes: determining a second screening condition based on the average uplink traffic cycle data and the average downlink traffic cycle data, and filtering the home gateways in the first screening result based on the second screening condition to obtain a second screening result with abnormal uplink traffic cycles. The second screening condition includes: the number of times the uplink traffic cycle data exceeds the downlink traffic cycle data within the preset time period is greater than a second preset cycle traffic frequency threshold; and the number of times the change amplitude of the uplink traffic cycle data is greater than the change amplitude of the downlink traffic cycle data within the preset time period is greater than a preset amplitude frequency threshold.
[0094] It's understandable that gateways with abnormally high uplink traffic usage might be experiencing frequent and prolonged video calls, live streaming, or remote operations by users. These activities generate not only a large amount of uplink traffic but also a significant amount of downlink traffic, and the trends of uplink and downlink traffic are generally synchronized, starting and ending simultaneously. In contrast, when users violating PCDN service regulations generate a large amount of uplink traffic, since downloading and uploading PCDN cached content generally don't occur simultaneously, a large amount of downlink traffic is usually not generated at the same time, and the trends of uplink and downlink traffic are inconsistent. Given the difference in traffic patterns between general broadband users and users violating PCDN service regulations, if the average uplink traffic over multiple periods is significantly greater than the average downlink traffic over multiple periods, and uplink traffic increases dramatically multiple times while downlink traffic changes little or decreases within the same period, it indicates that internet access is primarily driven by uplink activity. This allows us to identify gateways with primarily uplink-driven internet access.
[0095] Specifically, a further screening process can be implemented based on the second screening condition. The second screening condition includes feature condition 4 and feature condition 5.
[0096] Feature condition 4 is that, within the preset time period, the number of times the uplink traffic cycle data exceeds the downlink traffic cycle data is greater than the second preset cycle traffic number threshold.
[0097] Using feature condition 4, the number of times the average value of Internet WAN uplink traffic per cycle exceeds the average value of downlink traffic per cycle exceeds a specified number. This excludes frequent and prolonged user video calls, live streaming, remote operations, etc., as these behaviors generate both large amounts of uplink and downlink traffic. If only a large amount of uplink traffic is frequently generated within a cycle, while downlink traffic is normal or very low, this can be further identified as abnormal uplink traffic behavior.
[0098] Feature condition 5 is that, within the preset time period, the number of times the change amplitude of the uplink traffic cycle data is greater than the change amplitude of the downlink traffic cycle data is greater than a preset amplitude number threshold.
[0099] Using feature condition 5, the number of times the average change in Internet WAN uplink traffic over a period is significantly greater than the average change in the average change in downlink traffic over a period exceeds a specified number. This is mainly used to filter out instances where the average uplink traffic over a period increases significantly compared to the previous period, while the average downlink traffic over a period increases only slightly or decreases. This can further determine that the traffic changes in this period are mainly driven by pure uplink activity.
[0100] After the above screening, gateways with excessive abnormal uplink traffic, mainly consisting of upload activity, were identified as high-risk users suspected of violating PCDN regulations.
[0101] In one embodiment, a third filtering result is obtained by filtering home gateways in the second filtering result based on the uplink traffic cycle data, the downlink traffic cycle data, and the number of ports used by data packets after the reboot. This includes: determining a third filtering condition based on the uplink traffic cycle data, the downlink traffic cycle data, and the number of ports used by data packets after the reboot, and filtering home gateways in the second filtering result based on the third filtering condition. The third filtering condition includes: the change in uplink traffic cycle data after the reboot is greater than a preset change threshold, and the change in downlink traffic cycle data after the reboot is less than a preset change threshold; the increase in the number of ports used by UDP data packets after the reboot is greater than a preset port change threshold, and the increase in the number of ports used by TCP data packets after the reboot is less than the preset port change threshold.
[0102] Understandably, for high-risk users suspected of violating PCDN regulations, further precise screening is required. The gateway SN list obtained from the second screening can be sent to the Remote Management Server (RMS) platform. Without affecting users' normal internet access, the RMS platform can remotely restart the gateway in the early morning.
[0103] After a gateway restart, public IPv4 addresses are typically reallocated. Existing PCDN resource requests become invalid, leading to a significant drop in uplink traffic for a period. However, normal user-generated uplink traffic, such as video surveillance uploads, recovers quickly. Simultaneously, the IPv4 address change necessitates renewed communication between PCDN terminals and the PCDN platform, typically using UDP for NAT traversal, resulting in a large number of UDP connections in a short period. During the early morning hours, when users are generally resting or sleeping, UDP traffic generated by activities like watching videos is minimal; standby devices primarily use TCP traffic. Given the different uplink traffic and UDP connection changes experienced by general broadband users and PCDN users after a gateway restart, a further filtering process can be implemented.
[0104] Specifically, a further screening process can be implemented based on the third screening condition. The third screening condition includes feature condition 6 and feature condition 7.
[0105] Feature condition 6 is that the change amplitude of the uplink traffic cycle data after restart is greater than the preset change amplitude threshold, and the change amplitude of the downlink traffic cycle data after restart is less than the preset change amplitude threshold.
[0106] Using feature condition 6, after the gateway restarts, the gateway's IPv4 address changes, the average period of Internet WAN uplink traffic drops significantly, while the average period of downlink traffic remains relatively unchanged. The change in the IPv4 address after the gateway restarts restricts uplink traffic behavior, while the downlink traffic changes very little, indicating an abnormal decrease in uplink traffic.
[0107] Feature condition 7 is that the increase in the number of ports used by UDP datagrams after restart is greater than the preset port change threshold, and the increase in the number of ports used by TCP datagrams after restart is less than the preset port change threshold.
[0108] Using characteristic condition 7, after the gateway restarts, the IPv4 address changes, the number of ports used by UDP packets increases significantly, while the number of ports used by TCP packets changes very little. Since the gateway restarts in the early morning, there are very few UDP packets generated by user activity. The significant increase in UDP packets and the minimal change in TCP packets after the IPv4 address change strongly suggest non-user activity, making it highly likely that P2P is using UDP for NAT traversal.
[0109] In one embodiment, restarting the home gateway in the second filtering result includes: determining a target time when the home network traffic demand in the home gateway is the minimum based on the historical home network traffic demand in the home gateway; and restarting the home gateway in the second filtering result at the target time.
[0110] First, it's necessary to analyze the historical traffic demands of the home network to understand its peak and off-peak periods, in order to determine the optimal time to reboot. This data can be obtained through network devices or traffic monitoring tools.
[0111] By analyzing historical data, we can determine the target time when home network traffic demand is minimal. This time is typically late at night or early morning, as most family members are resting and network usage is low.
[0112] At the designated target time, the home gateway can be restarted through its management interface or other means.
[0113] In one embodiment, restarting the home gateways in the second filtering result at the target time includes: determining a restart gateway list based on the home gateways in the second filtering result; and sending the restart gateway list to the terminal management platform RMS platform so that the RMS platform restarts the home gateways in the second filtering result at the target time.
[0114] The confirmed list of gateways to be restarted is sent to the terminal management platform, RMS. RMS is a system for centralized management and monitoring of network devices, enabling remote management and control of these devices.
[0115] At the designated target time, the RMS platform will automatically trigger a restart operation for the home gateways in the second filtered result. The system will restart each gateway one by one according to the preset plan to ensure that the operation is carried out in an orderly manner.
[0116] During the reboot process, it is necessary to continuously monitor the feedback information from the RMS platform to ensure that each home gateway successfully reboots and that network services are restored in a timely manner.
[0117] The following is a flowchart illustrating the non-compliance detection method provided by this invention:
[0118] like Figure 2 As shown, the specific process is implemented based on the first filtering module, the second filtering module, and the third filtering module:
[0119] Receive data periodically reported by the home gateway's soft probe;
[0120] Based on the first filtering criteria in the first filtering module, gateways with abnormally high uplink traffic usage are identified. The first filtering module may include the following three characteristic criteria:
[0121] Feature condition 1: The total uplink traffic of INTERNET WAN within a preset time period is greater than the preset total uplink traffic threshold.
[0122] Feature condition 2: The proportion of total Internet WAN uplink traffic data in the preset time period is greater than the proportion of total downlink traffic data in the preset time period.
[0123] Feature condition 3: The number of times the INTERNET WAN uplink traffic cycle data exceeds the preset cycle traffic threshold within the preset time period is greater than the first preset cycle traffic count threshold.
[0124] Based on the second filtering criteria in the second filtering module, gateways with abnormally high uplink traffic usage, primarily consisting of upload activity, are identified. The second filtering module can include the following two characteristic criteria:
[0125] Feature condition 4 is that, within the preset time period, the number of times the uplink traffic cycle data exceeds the downlink traffic cycle data is greater than the second preset cycle traffic number threshold.
[0126] Feature condition 5 is that, within the preset time period, the number of times the change amplitude of the uplink traffic cycle data is greater than the change amplitude of the downlink traffic cycle data is greater than a preset amplitude number threshold.
[0127] Based on the third filtering criteria in the third filtering module, gateways exhibiting an abnormal decrease in uplink traffic and an abnormal increase in UDP packets are identified. The third filtering module can include the following two characteristic criteria:
[0128] Feature condition 6 is that the change amplitude of the uplink traffic cycle data after restart is greater than the preset change amplitude threshold, and the change amplitude of the downlink traffic cycle data after restart is less than the preset change amplitude threshold.
[0129] Feature condition 7 is that the increase in the number of ports used by UDP datagrams after restart is greater than the preset port change threshold, and the increase in the number of ports used by TCP datagrams after restart is less than the preset port change threshold.
[0130] Based on the above 7 characteristics, the system can determine whether the user corresponding to the home gateway is a PCDN violation user.
[0131] The specific implementation process can be as follows: Figure 3 The flowchart for determining PCDN violators provided by this invention is shown in the figure.
[0132] The home gateway's soft probe periodically reports data. The first filtering module determines whether the reported data is Internet WAN port traffic.
[0133] If the traffic is determined to be Internet WAN port traffic, it is filtered based on feature conditions 1, feature conditions 2 and feature conditions 3 of the first filtering module to identify the gateway with abnormally high uplink traffic usage.
[0134] Further screening is carried out based on the second screening module. The second screening module implements the screening process based on feature condition 4 and feature condition 5, and determines that the uplink traffic is abnormally high, mainly uploading, and is a high-risk suspected PCDN non-compliant business.
[0135] Based on the RMS platform, the gateways selected in the second filtering module are remotely restarted in the early morning, and the restarted gateways are further filtered based on the third filtering module.
[0136] After the gateway restarts, does the IPv4 address change? Based on feature conditions 6 and 7, a final filtering process is implemented to determine the gateways involved in PCDN violations.
[0137] Understandably, the data is based directly on the periodic reports from the home gateway's software probe, covering the vast majority of smart home gateways and providing comprehensive coverage. It only considers user internet traffic information from the INTERNET WAN port, excluding non-user internet traffic such as IPTV, resulting in more accurate traffic data.
[0138] The periodic data reported by the probe is the customer's traffic time series data. The new filtering module can be used for calculation without consuming additional data collection resources, thus saving a lot of server resources.
[0139] Based on the characteristics of users' spontaneous uplink traffic behavior, in addition to continuously generating a large amount of uplink traffic, a large amount of downlink traffic will also be generated. By comparing the changing trends of uplink and downlink traffic, if the changes are not synchronized and the uplink traffic increases alone, it can be identified as a suspected PCDN user, making the screening more accurate.
[0140] By using soft probes to periodically report data, there is no need to collect user traffic data, which is safe, simple, and saves resources.
[0141] After remotely restarting the gateway through the terminal management system, the changes in uplink and downlink traffic, as well as the changes in the number of ports used by TCP and UDP packets, are compared. Cases of abnormally reduced uplink traffic and abnormally increased number of ports used by UDP packets are filtered out to determine whether UDP is attempting to NAT traverse, thus identifying PCDN violations more accurately.
[0142] Figure 4 This is a schematic diagram of the structure of the illegal business detection device provided by the present invention, as shown below. Figure 4 The device includes:
[0143] The receiving module 410 is used to receive reported data from multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period.
[0144] The first filtering module 420 is used to filter the multiple home gateways based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data to obtain a first filtering result with abnormal total uplink traffic.
[0145] The second filtering module 430 is used to filter the home gateways in the first filtering result based on the uplink traffic cycle data and the downlink traffic cycle data to obtain a second filtering result with abnormal uplink traffic cycles.
[0146] The third filtering module 440 is used to restart the home gateways in the second filtering result, and filter the home gateways in the second filtering result based on the uplink traffic cycle data, the downlink traffic cycle data, and the number of ports used by the data packets after the restart, to obtain the third filtering result, and determine that the home gateways in the third filtering result are illegal service gateways.
[0147] The illegal service detection device provided in this invention analyzes the characteristics of users' spontaneous uplink traffic behavior. Besides continuously generating a large amount of uplink traffic, it also generates a large amount of downlink traffic. Based on comparing the changing trends of uplink and downlink traffic, as well as the changes in the number of ports used by data packets, it filters out cases where uplink traffic abnormally decreases and the number of ports used by UDP packets abnormally increases to determine whether a user is suspected of engaging in illegal PCDN services, making the filtering more accurate. Simultaneously, the judgment process is implemented based on received reported data, without consuming additional data collection resources, saving significant server resources and improving detection efficiency.
[0148] In one embodiment, the first filtering module 420 is specifically used for:
[0149] Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodicity data, the multiple home gateways are filtered to obtain a first filtering result for abnormal total uplink traffic, including:
[0150] Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, a first filtering condition is determined, and based on the first filtering condition, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic.
[0151] The first filtering criteria include:
[0152] The total uplink traffic within the preset time period exceeds the preset total uplink traffic threshold.
[0153] The proportion of total uplink traffic data in the preset time period is greater than the proportion of total downlink traffic data in the preset time period;
[0154] The number of times the uplink traffic cycle data exceeds the preset cycle traffic threshold within the preset time period is greater than the first preset cycle traffic number threshold.
[0155] In one embodiment, the second filtering module 430 is specifically used for:
[0156] Based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles, including:
[0157] Based on the average uplink traffic cycle data and the average downlink traffic cycle data, a second filtering condition is determined, and based on the second filtering condition, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles.
[0158] The second screening criteria include:
[0159] During the preset time period, the number of times the uplink traffic cycle data exceeds the downlink traffic cycle data is greater than the second preset cycle traffic number threshold.
[0160] Within the preset time period, the number of times the change amplitude of the uplink traffic cycle data is greater than the change amplitude of the downlink traffic cycle data exceeds the preset amplitude threshold.
[0161] In one embodiment, the third filtering module 440 is specifically used for:
[0162] Based on the uplink traffic cycle data, downlink traffic cycle data, and the number of ports used by data packets after the reboot, the home gateways in the second filtering result are filtered to obtain the third filtering result, including:
[0163] Based on the uplink traffic cycle data after the restart, the downlink traffic cycle data after the restart, and the number of ports used by the data packets after the restart, the third filtering condition is determined, and based on the third filtering condition, the home gateways in the second filtering result are filtered to obtain the third filtering result;
[0164] The third screening criteria include:
[0165] The change in uplink traffic cycle data after restarting is greater than the preset change threshold, while the change in downlink traffic cycle data after restarting is less than the preset change threshold.
[0166] After restarting, the increase in the number of ports used by UDP datagrams is greater than the preset port change threshold, while the increase in the number of ports used by TCP datagrams is less than the preset port change threshold.
[0167] In one embodiment, the third filtering module 440 is further specifically used for:
[0168] Restart the home gateway in the second filtering result, including:
[0169] Based on the historical home network traffic demand in the home gateway, determine the target time when the home network traffic demand in the home gateway is minimized;
[0170] At the target time, the home gateway in the second screening result is restarted.
[0171] In one embodiment, the third filtering module 440 is further specifically used for:
[0172] At the target time, restarting the home gateway in the second filtering result includes:
[0173] Based on the home gateways in the second filtering results, determine the list of gateways to restart;
[0174] The list of restarted gateways is sent to the terminal management platform RMS platform, so that the RMS platform restarts the home gateways in the second filtering result at the target time.
[0175] Figure 5 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 5As shown, the electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540, wherein the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call logical instructions in the memory 530 to execute a method for detecting unauthorized services, the method including:
[0176] Receive data reported by multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period.
[0177] Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic.
[0178] Based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles.
[0179] The home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the home gateways in the second screening result are filtered to obtain a third screening result, and the home gateways in the third screening result are determined to be gateways for illegal services.
[0180] Furthermore, the logical instructions in the aforementioned memory 530 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0181] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, wherein when the program instructions are executed by a computer, the computer is able to execute the illegal business detection method provided by the above methods, the method comprising:
[0182] Receive data reported by multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period.
[0183] Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic.
[0184] Based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles.
[0185] The home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the home gateways in the second screening result are filtered to obtain a third screening result, and the home gateways in the third screening result are determined to be gateways for illegal services.
[0186] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the aforementioned methods for detecting illegal business operations, the method comprising:
[0187] Receive data reported by multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period.
[0188] Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic.
[0189] Based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles.
[0190] The home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the home gateways in the second screening result are filtered to obtain a third screening result, and the home gateways in the third screening result are determined to be gateways for illegal services.
[0191] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0192] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0193] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for detecting non-compliant business operations, characterized in that, The method includes: Receive data reported by multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period. Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic. Based on the uplink traffic cycle data and the downlink traffic cycle data, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles. The home gateways in the second screening result are restarted, and based on the uplink traffic cycle data, downlink traffic cycle data and the number of ports used by the data packets after the restart, the home gateways in the second screening result are filtered to obtain a third screening result, and the home gateways in the third screening result are determined to be gateways for illegal services.
2. The method for detecting illegal business operations according to claim 1, characterized in that, The process of filtering the multiple home gateways based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic cycle data to obtain a first filtering result for abnormal total uplink traffic includes: Based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, a first filtering condition is determined, and based on the first filtering condition, the multiple home gateways are filtered to obtain a first filtering result with abnormal total uplink traffic. The first filtering criteria include: The total uplink traffic within the preset time period exceeds the preset total uplink traffic threshold. The proportion of total uplink traffic data in the preset time period is greater than the proportion of total downlink traffic data in the preset time period; The number of times the uplink traffic cycle data exceeds the preset cycle traffic threshold within the preset time period is greater than the first preset cycle traffic number threshold.
3. The method for detecting illegal business operations according to claim 1, characterized in that, The process of filtering home gateways in the first filtering result based on the uplink traffic cycle data and the downlink traffic cycle data to obtain a second filtering result with abnormal uplink traffic cycles includes: Based on the average uplink traffic cycle data and the average downlink traffic cycle data, a second filtering condition is determined, and based on the second filtering condition, the home gateways in the first filtering result are filtered to obtain a second filtering result with abnormal uplink traffic cycles. The second screening criteria include: During the preset time period, the number of times the uplink traffic cycle data exceeds the downlink traffic cycle data is greater than the second preset cycle traffic number threshold. Within the preset time period, the number of times the change amplitude of the uplink traffic cycle data is greater than the change amplitude of the downlink traffic cycle data exceeds the preset amplitude threshold.
4. The method for detecting illegal business operations according to claim 1, characterized in that, The third filtering result is obtained by filtering the home gateways in the second filtering result based on the uplink traffic cycle data, downlink traffic cycle data, and the number of ports used by the data packets after the restart, including: Based on the uplink traffic cycle data after the restart, the downlink traffic cycle data after the restart, and the number of ports used by the data packets after the restart, the third filtering condition is determined, and based on the third filtering condition, the home gateways in the second filtering result are filtered to obtain the third filtering result; The third screening criteria include: The change in uplink traffic cycle data after restarting is greater than the preset change threshold, while the change in downlink traffic cycle data after restarting is less than the preset change threshold. After restarting, the increase in the number of ports used by UDP datagrams is greater than the preset port change threshold, while the increase in the number of ports used by TCP datagrams is less than the preset port change threshold.
5. The method for detecting illegal business operations according to claim 1, characterized in that, Restarting the home gateway in the second screening result includes: Based on the historical home network traffic demand in the home gateway, determine the target time when the home network traffic demand in the home gateway is minimized; At the target time, the home gateway in the second screening result is restarted.
6. The method for detecting illegal business operations according to claim 5, characterized in that, The step of restarting the home gateway in the second filtering result at the target time includes: Based on the home gateways in the second filtering results, determine the list of gateways to restart; The list of restarted gateways is sent to the terminal management platform RMS platform, so that the RMS platform restarts the home gateways in the second filtering result at the target time.
7. A device for detecting irregular business operations, characterized in that, include: The receiving module is used to receive data reported by multiple home gateways. The reported data includes total uplink traffic data, total downlink traffic data, uplink traffic periodic data, downlink traffic periodic data, and the number of ports used by the data packets. The uplink traffic periodic data is the uplink traffic data for each reporting period within a preset time period, and the downlink traffic periodic data is the downlink traffic data for each reporting period within a preset time period. The first filtering module is used to filter the multiple home gateways based on the total uplink traffic data, the total downlink traffic data, and the uplink traffic periodic data, and obtain a first filtering result for abnormal total uplink traffic. The second filtering module is used to filter the home gateways in the first filtering result based on the uplink traffic cycle data and the downlink traffic cycle data, and obtain a second filtering result with abnormal uplink traffic cycles. The third filtering module is used to restart the home gateways in the second filtering result, and filter the home gateways in the second filtering result based on the uplink traffic cycle data, the downlink traffic cycle data, and the number of ports used by the data packets after the restart, to obtain the third filtering result, and determine the home gateways in the third filtering result as non-compliant service gateways.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the illegal business detection method as described in any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the illegal business detection method as described in any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the illegal business detection method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Encryption attack network flow detection method
CN111010409A
Broadband service management and control method, device and equipment and storage medium
CN117278479A