Network load balancing algorithm based on credential platform and credential terminal
By collecting and processing real-time traffic data of multi-level abnormality detection on the Innovative Innovation Platform, protocol fingerprint extraction and timing neural network modeling are carried out, distribution weight factors are dynamically generated, and feed-forward load distribution is used to solve the problems of protocol compatibility and exception handling in the Innovative Innovation Platform network load balancing, and efficient and stable load balancing and service continuity are achieved.
Patent Information
- Application Number
- CN202510847378.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-06-24
AI Technical Summary
The existing network load balancing algorithm of the Innovative Innovation Platform is difficult to achieve efficient and accurate port-protocol association mapping in the face of a multi-protocol hybrid environment, and cannot capture dynamic traffic changes in real time, and abnormal traffic processing is not effective enough, resulting in load imbalance and system stability decline.
Real-time traffic data is collected for multi-level abnormality detection and isolation, protocol field standardization and multi-dimensional protocol fingerprint feature extraction, traffic prediction is used to use timing neural networks to dynamically generate distribution weight factors, and feedforward load distribution adjustment is realized through reinforcement learning scheduling agents, and combined with model self-learning to optimize protocol compatibility parameters.
The abnormal identification rate is improved, the high reliability of input data is ensured, the system stability and resource utilization rate are improved, the resource allocation priority of key business ports is ensured, and high-precision load balancing and service continuity are achieved.
Smart Images

Figure CN120474980A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information and communication technology, and in particular to a network load balancing algorithm and an information and communication terminal based on an information and communication platform. Background Art
[0002] With the rapid development of information technology, network scale continues to expand, business traffic is experiencing explosive growth, and network load balancing issues in heterogeneous protocol environments are becoming increasingly prominent. In network architectures built on xinchuang (information technology application innovation) platforms, due to the involvement of multiple protocol types, concurrent processing of multiple ports, and complex traffic patterns, traditional load balancing algorithms are gradually exposing numerous limitations when dealing with real-time traffic fluctuations, protocol compatibility differences, and abnormal traffic processing. Most existing load balancing solutions use static weight allocation or simple round-robin mechanisms, making them difficult to adapt to the diverse protocol types (e.g., new protocols like TCP, UDP, and HTTP / 3 coexisting with traditional protocols) in xinchuang platforms. These solutions lack the ability to deeply analyze protocol characteristics and cannot establish accurate port-protocol association mappings. This leads to low distribution efficiency in multi-protocol mixed environments and is prone to port load imbalance. Furthermore, traditional algorithms lack the ability to exploit the temporal characteristics of traffic and rely solely on static predictions based on historical load data. They are unable to capture dynamic traffic trends in real time. Especially in the case of sudden or abnormal traffic, they often need to wait for the anomaly to actually occur before making passive adjustments, which makes it difficult to meet the high reliability and low latency requirements of xinchuang platforms.
[0003] Furthermore, existing load balancing technologies have significant shortcomings in handling abnormal traffic. Their anomaly detection mechanisms typically focus on a single dimension, failing to perform multi-level anomaly detection and isolation on collected traffic data (including protocol type, port number, time series characteristics, and historical load change information). This can easily lead to the spread of abnormal traffic, impacting the stability of the entire network system. Furthermore, traditional solutions lack effective self-learning and parameter optimization mechanisms, making it difficult to continuously adjust strategies based on dynamic changes in protocol types and port distribution. As the network environment becomes more complex, their load balancing accuracy and distribution efficiency gradually decline.
[0004] Therefore, it is necessary to improve the network load balancing algorithm of the existing trusted computing platform to overcome the shortcomings of the existing technology. Summary of the Invention
[0005] In order to overcome the problems existing in the related technology, one of the purposes of the present invention is to provide a network load balancing algorithm based on the trusted computing platform. This method can improve data processing efficiency, realize load scheduling intelligence, ensure the resource allocation priority of the port of the trusted computing terminal, and ensure service continuity.
[0006] A network load balancing algorithm based on the Xinchuang platform includes the following steps:
[0007] S1. Collects real-time traffic data from multiple ports, including protocol type, port number, time series characteristics, and historical load change information. It then performs multi-level anomaly detection and isolation on the collected data and outputs the processed structured data.
[0008] S2. Preprocess the collected data by normalizing, removing outliers, and standardizing protocol fields to generate structured multi-port traffic data;
[0009] S3. Extract multi-dimensional protocol fingerprint features of each port traffic based on the protocol analysis algorithm, and establish a port-protocol association mapping table to achieve multi-protocol compatibility analysis;
[0010] S4. Use a time series neural network to model the historical and real-time traffic of each port, and output the traffic forecast value and abnormal traffic probability assessment in the short term in the future;
[0011] S5. Dynamically generate multi-port distribution weight factors based on the protocol characteristics of each port and traffic change trends to achieve adaptive parameter configuration in heterogeneous protocol environments;
[0012] S6. The prediction results and real-time load status are input into the reinforcement learning scheduling agent, which selects a feed-forward distribution strategy, including allocating redundant resources in advance, dynamically adjusting the weight of each port, or activating a backup link.
[0013] S7: When an abnormal traffic trend is detected, feed-forward load distribution adjustment is immediately performed without waiting for the actual abnormality to occur;
[0014] S8. Monitor the actual traffic distribution and system load performance after feedforward adjustment, and feed abnormal event processing results back into the prediction model and scheduling agent to achieve model self-learning and continuous parameter optimization;
[0015] S9. Regularly adapt and update the protocol compatibility parameter group based on the protocol type and port distribution to ensure continuous high-precision identification and distribution efficiency in a multi-port environment.
[0016] In a preferred technical solution of the present invention, in S1, anomaly detection includes packet loss rate detection, port activity status heartbeat detection, multi-feature consistency verification and anomaly cluster analysis.
[0017] In a preferred technical solution of the present invention, in S2, the data normalization method is Z-score standardization or Min-Max scaling.
[0018] In a preferred technical solution of the present invention, in said S3, the protocol fingerprint features include protocol name, version number, header features, extension flags, session duration distribution, typical message length sequence and header field variability.
[0019] In a preferred technical solution of the present invention, in S4, the temporal neural network is a long short-term memory network (LSTM) or a gated recurrent unit (GRU).
[0020] In a preferred technical solution of the present invention, in S5, the distribution weight factor is generated using principal component analysis (PCA) or an adaptive weighted fusion algorithm, and the weight factor is interval normalized and anomaly determined to ensure that the distribution sum is 1.
[0021] In a preferred technical solution of the present invention, in S6, the reinforcement learning scheduling agent adopts an intelligent decision-making algorithm based on a value function or a policy gradient to perform action scoring and optimization on a variety of distribution strategies.
[0022] In a preferred technical solution of the present invention, in S7, the feedforward adjustment strategy includes temporarily increasing the redundant bandwidth of the affected port, dynamically reducing the weight of the high-risk port, or switching part of the traffic to the backup link.
[0023] In a preferred technical solution of the present invention, in said S8, the closed-loop feedback data includes the flow distribution adjustment effect, abnormal recovery time and resource utilization, and is used for adaptive parameter optimization of the flow prediction model and the scheduling agent;
[0024] In said S9, the protocol compatibility parameter group includes feature extraction rules, protocol category labels and distribution priority settings, and the port-protocol association mapping table is updated in real time through the interface.
[0025] The second purpose of the present invention is to provide a trusted computing terminal, which is used to implement the network load balancing algorithm based on the trusted computing platform as described above.
[0026] The beneficial effects of the present invention are:
[0027] The present invention provides a network load balancing algorithm and a xinchuang terminal based on a xinchuang platform. The algorithm includes the following steps: collecting real-time traffic data from multiple ports, including protocol type, port number, time series characteristics and historical load change information, and performing multi-level anomaly detection and isolation processing on the collected data, and outputting the processed structured data; performing pre-processing of normalization, outlier removal and protocol field standardization on the collected data to generate structured multi-port traffic data; performing multi-dimensional protocol fingerprint feature extraction on the traffic of each port based on the protocol parsing algorithm, and establishing a port-protocol association mapping table to realize multi-protocol compatibility analysis; using a time series neural network to model the historical and real-time traffic of each port, and outputting the traffic forecast value and abnormal traffic probability assessment in the future short period of time; based on each Based on port protocol characteristics and traffic trends, the algorithm dynamically generates multi-port distribution weighting factors, enabling adaptive parameter configuration in heterogeneous protocol environments. The prediction results and real-time load status are fed into a reinforcement learning scheduling agent, which then selects a feed-forward distribution strategy, including pre-allocating redundant resources, dynamically adjusting port weights, or activating backup links. Upon detecting abnormal traffic trends, the agent immediately implements feed-forward load distribution adjustments without waiting for an actual anomaly to occur. The actual traffic distribution and system load performance after feed-forward adjustments are monitored, and the results of abnormal event processing are fed back into the prediction model and scheduling agent, enabling model self-learning and continuous parameter optimization. Based on protocol type and port distribution, the algorithm regularly adapts and updates protocol compatibility parameter sets to ensure consistently high-precision identification and distribution efficiency in multi-port environments. This algorithm utilizes a multi-layered anomaly detection and isolation mechanism to comprehensively screen traffic data. Compared to traditional single-dimensional detection, it effectively improves anomaly identification, ensures high reliability of input data, effectively prevents the spread of abnormal traffic, and enhances system stability. The time series neural network model effectively captures both long-term dependencies and short-term fluctuations in traffic data, providing a more accurate basis for load scheduling decisions. The reinforcement learning scheduling agent continuously optimizes the distribution strategy through a self-learning mechanism. In a heterogeneous protocol environment, the system load balance (standard deviation / mean) decreases, effectively improving resource utilization and reducing response delays. It can also dynamically adjust weight factors to ensure resource allocation priority for key business ports and guarantee service continuity. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 A flowchart of a network load balancing algorithm based on the trusted innovation platform is provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] The preferred embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although preferred embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments described herein. Rather, these embodiments are provided to make the present invention more thorough and complete and to fully convey the scope of the present invention to those skilled in the art.
[0030] The terms used in this invention are for the purpose of describing specific embodiments only and are not intended to limit the invention. The singular forms "a," "an," and "the" used in this invention and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0031] It should be understood that although the terms "first", "second", "third", etc. may be used to describe various information in the present invention, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "plurality" means two or more, unless otherwise clearly and specifically defined.
[0032] In existing technologies, most load balancing solutions use static weight distribution or simple polling mechanisms, which are difficult to adapt to scenarios with diverse protocol types under the trusted innovation platform (such as the coexistence of new protocols such as TCP, UDP, HTTP / 3 and traditional protocols). Such solutions lack the ability to deeply analyze protocol characteristics and cannot establish accurate port-protocol association mapping, resulting in low distribution efficiency in a multi-protocol mixed environment and prone to port load imbalance. At the same time, traditional algorithms do not adequately mine the time series characteristics of traffic, relying only on historical load data for static predictions, and are unable to capture the dynamic change trends of traffic in real time. Especially when bursty or abnormal traffic occurs, it is often necessary to wait until the abnormality actually occurs before making passive adjustments, which makes it difficult to meet the trusted innovation platform's requirements for high reliability and low latency. In addition, existing load balancing technologies have obvious defects in handling abnormal traffic. Its anomaly detection mechanism usually only stays in a single dimension and cannot perform multi-level anomaly detection and isolation on the collected traffic data (including protocol type, port number, time series characteristics and historical load change information, etc.), which can easily lead to the spread of abnormal traffic and affect the stability of the entire network system. In addition, traditional solutions lack effective self-learning and parameter optimization mechanisms, making it difficult to continuously adjust strategies based on dynamic changes in protocol types and port distribution. As the network environment becomes more complex, its load balancing accuracy and distribution efficiency will gradually decline.
[0033] Based on this, this application provides a network load balancing algorithm based on the trusted computing platform.
[0034] Example
[0035] like Figure 1 As shown, this embodiment provides a network load balancing algorithm based on the Xinchuang platform, including the following steps:
[0036] S1. Collects real-time traffic data from multiple ports, including protocol type, port number, time series characteristics, and historical load change information. It then performs multi-level anomaly detection and isolation on the collected data and outputs the processed structured data.
[0037] S2. Preprocess the collected data by normalizing, removing outliers, and standardizing protocol fields to generate structured multi-port traffic data;
[0038] S3. Extract multi-dimensional protocol fingerprint features of each port traffic based on the protocol analysis algorithm, and establish a port-protocol association mapping table to achieve multi-protocol compatibility analysis;
[0039] S4. Use a time series neural network to model the historical and real-time traffic of each port, and output the traffic forecast value and abnormal traffic probability assessment in the short term in the future;
[0040] S5. Dynamically generate multi-port distribution weight factors based on the protocol characteristics of each port and traffic change trends to achieve adaptive parameter configuration in heterogeneous protocol environments;
[0041] S6. The prediction results and real-time load status are input into the reinforcement learning scheduling agent, which selects a feed-forward distribution strategy, including allocating redundant resources in advance, dynamically adjusting the weight of each port, or activating a backup link.
[0042] S7: When an abnormal traffic trend is detected, feed-forward load distribution adjustment is immediately performed without waiting for the actual abnormality to occur;
[0043] S8. Monitor the actual traffic distribution and system load performance after feedforward adjustment, and feed abnormal event processing results back into the prediction model and scheduling agent to achieve model self-learning and continuous parameter optimization;
[0044] S9. Regularly adapt and update the protocol compatibility parameter group based on the protocol type and port distribution to ensure continuous high-precision identification and distribution efficiency in a multi-port environment.
[0045] Specifically, an implementation process of the method includes the following steps:
[0046] (1) Data collection and exception handling
[0047] In a certain cloud data center scenario, the system collects real-time traffic data through 16 Gigabit network ports. During the collection process, the protocol type (such as TCP, UDP), port number (1-65535), timestamp (accurate to the millisecond level), and port load history data for the past 24 hours (sampling interval is 100ms) are synchronously obtained for each data packet. For the collected data, multi-level anomaly detection is first performed:
[0048] Statistical feature detection: Calculate the mean and variance of traffic on each port and mark traffic points exceeding three times the standard deviation as abnormal.
[0049] Based on time series pattern recognition: Use a sliding window (window size of 5 minutes) to analyze traffic time series curves and use the dynamic time warping (DTW) algorithm to identify abnormal behaviors that deviate from historical patterns;
[0050] Protocol field verification: This feature checks the validity of TCP protocol flag combinations such as SYN and ACK, filtering out packets with abnormal FIN / FIN-ACK combinations. Upon detecting abnormal data, hardware isolation mechanisms are used to immediately direct the abnormal traffic to a dedicated cleaning link, ensuring the reliability of the output structured data reaches over 99.99%.
[0051] (2) Data preprocessing
[0052] The collected raw traffic data is input into the preprocessing module and first normalized: the Min-Max normalization method is used for different dimensional features such as the number of bytes and the number of packets, and mapped to the interval [0,1]. Secondly, the IQR (interquartile range) method is used to eliminate outliers outside the range of 1.5 times the upper and lower quartiles. Finally, the protocol fields are standardized. For example, the request methods of the HTTP protocol (GET, POST, etc.) are converted into enumeration values in a unified format to generate a structured multi-port traffic data set, providing standardized input for subsequent processing.
[0053] (3) Protocol fingerprint extraction and mapping
[0054] Using domestically produced protocol parsing algorithms, we conduct in-depth analysis of traffic on each port. Taking HTTP / 3 protocol traffic as an example, we extract the following multi-dimensional features to construct a protocol fingerprint:
[0055] Header field characteristics: QUIC version number, ConnectionID length, Transport Parameters field structure;
[0056] Data segment pattern characteristics: byte distribution entropy value of the encrypted payload, time interval pattern of frame type (DATA, ACK, PING, etc.);
[0057] Interaction timing characteristics: The time delay from the client's initial handshake to data transmission, as well as the variation patterns of the round-trip time (RTT). These characteristics are used to construct a protocol fingerprint library and establish a port-protocol association mapping table. For example, they can identify that port 8080 primarily carries HTTP / 3 protocol traffic, while port 443 carries both HTTPS and WebSocket protocol traffic, achieving a 98.7% accuracy rate in multi-protocol compatibility analysis.
[0058] (4) Traffic prediction modeling
[0059] An LSTM neural network is used to model traffic on each port. The network structure consists of two LSTM layers (128 neurons per layer), one fully connected layer, and a soft max output layer. Input features include traffic data from the past hour (one sampling point per minute), the corresponding protocol type distribution, and port load history. During training, the Adam optimizer is used with a learning rate of 0.001, a batch size of 32, and 50 iterations. The model outputs traffic forecasts for the next five minutes (including byte and packet count forecasts) and an assessment of the probability of abnormal traffic (e.g., a probability of exceeding a threshold of 0.12). The prediction mean square error (MSE) is kept below 5%.
[0060] (5) Dynamic generation of weight factors
[0061] The distribution weight factor for each port is dynamically generated based on the following parameters:
[0062] Resource consumption characteristics of protocol types: HTTP / 3 consumes higher CPU resources due to encryption processing, so the weight coefficient is set to 0.8; the TCP protocol weight coefficient is set to 1.0;
[0063] Current port load rate: Calculates the CPU utilization, memory usage, and bandwidth utilization of each port in real time, normalizes them, and then weights them to obtain the load rate indicator.
[0064] Historical traffic fluctuation range: calculates the standard deviation of traffic over the past 10 minutes to reflect traffic stability;
[0065] Predicting traffic trends: Weights are adjusted based on the LSTM model's output of traffic growth trends over the next five minutes (e.g., a 20% increase). Using the aforementioned parameters, a weighted summation formula is used to generate weight factors. For example, the weight for port A is calculated as: 0.4 × protocol coefficient + 0.3 × load factor + 0.2 × fluctuation amplitude + 0.1 × predicted trend. This enables adaptive parameter configuration in heterogeneous protocol environments.
[0066] (6) Reinforcement Learning Scheduling and Feedforward Strategy
[0067] The scheduling agent module is implemented using the PPO algorithm. Its state space includes 20-dimensional features, including real-time port load, predicted traffic volume, and protocol type distribution. Its action space includes six actions, including adjusting port weights (in steps of 0.05), allocating redundant CPU cores (1-4 cores), and activating backup links (1-2 links). The reward function is designed to be: 0.5 × load balancing + 0.3 × response latency optimization + 0.2 × resource utilization, where load balancing is defined as 1 minus the standard deviation / mean of the port load. When the LSTM model predicts that the probability of abnormal traffic in the next five minutes exceeds a threshold of 0.3, the scheduling agent immediately implements a feed-forward strategy: it pre-allocates two CPU cores to the high-load port, adjusts its weight from 0.7 to 0.5, and activates the backup link to share 30% of the traffic. The entire adjustment process is completed within 100ms.
[0068] (7) Model self-learning and parameter optimization
[0069] After feedforward adjustments, the system continuously monitors the actual traffic distribution of each port (for example, the port load standard deviation decreased from 0.4 to 0.2 after adjustment) and system load performance (response latency decreased from 50ms to 35ms). The results of abnormal event processing (including action type, adjustment parameters, and effect indicators) are fed back into the LSTM model and PPO scheduling agent as training samples. Using an online learning mechanism, the LSTM model's weight parameters (learning rate decayed by 0.95 times) and the PPO agent's policy network parameters are automatically updated after processing every 100 abnormal events, achieving continuous improvement in model accuracy. After 1,000 iterations, the accuracy of abnormal traffic prediction increased from 85% to 92%.
[0070] (8) Protocol parameter adaptation and update
[0071] The parameter update cycle is dynamically adjusted based on the frequency of network traffic changes (such as the daily low traffic period in the early morning) and protocol type updates (such as the addition of new domestic encryption protocols). In this embodiment, the protocol fingerprint library is automatically scanned weekly. When new protocol features are detected (such as the appearance of unknown protocol header fields), an immediate update process is triggered: through a combination of manual annotation and automatic clustering, the port-protocol mapping table is updated and the protocol parsing model is retrained to ensure that the protocol recognition accuracy in a multi-port environment is always maintained at above 98%.
[0072] The above-mentioned network load balancing algorithm is based on the trusted innovation platform. This algorithm realizes all-round screening of traffic data through a multi-level anomaly detection and isolation mechanism. Compared with traditional single-dimensional detection, it can effectively improve the anomaly recognition rate, ensure the high reliability of input data, effectively avoid the spread of abnormal traffic, and improve system stability. The time series neural network model can effectively capture the long-term dependencies and short-term fluctuation characteristics of traffic data, providing a more accurate decision-making basis for load scheduling. The reinforcement learning scheduling agent continuously optimizes the distribution strategy through a self-learning mechanism. In a heterogeneous protocol environment, the system load balancing degree (standard deviation / mean) decreases, effectively improving resource utilization and reducing response delays. It can also dynamically adjust the weight factor to ensure the resource allocation priority of key business ports and guarantee service continuity.
[0073] Furthermore, in S1, anomaly detection includes packet loss rate detection, port activity status heartbeat detection, multi-feature consistency verification and anomaly cluster analysis.
[0074] Specifically, S1: collects real-time traffic data from multiple ports on the trusted computing platform, including protocol type, port number, time series characteristics, and historical load change information.
[0075] This step is used to synchronously collect real-time network traffic data from multiple physical or virtual ports within the trusted computing platform environment, and to record in detail the protocol type, port number, time series characteristics, and historical load change information for each flow. As the fundamental data support for multi-port heterogeneous protocol identification and load balancing optimization, this step ensures high-quality raw data input for subsequent core algorithm modules such as data preprocessing, protocol feature extraction, and intelligent scheduling, and is the primary step in achieving efficient system compatibility and resilient distribution capabilities.
[0076] Said S1 comprises:
[0077] S1.1 monitors all target ports deployed on the trusted computing platform in real time, and continuously captures incoming and outgoing raw network data packets through high-performance data acquisition interfaces (such as DPDK, PF_R I NG, or self-developed high-concurrency acquisition engines) to obtain complete real-time traffic information.
[0078] Based on the captured original data packets, S1.2 parses and extracts the port number and session identification information of each data, and uses the protocol parsing library (such as Wiresharkdissector and customized protocol stack analyzer) to automatically identify the specific network protocol type to which the data packet belongs, realizing data classification and attribution in a multi-protocol environment.
[0079] S1.3 slices the data stream collected by each port according to the time window and counts the time series characteristic parameters including flow rate, peak value, number of packets, average message size, etc. to obtain a fine-grained timing load curve at the port level.
[0080] S1.4 associates the data collected at the current moment with the historical load change information of the port, maintains the port-level historical traffic data based on a ring buffer or a persistent database, and provides continuous input for subsequent traffic prediction and anomaly detection.
[0081] S1.5 monitors abnormal conditions during the collection process (such as packet loss, port failure, and data packet damage) in real time, uses anomaly detection algorithms to determine data integrity, mark and isolate abnormal data, and ensure that subsequent processing modules obtain highly reliable input.
[0082] Taking the port-level historical traffic data output by step S1.4 and the original data packets currently collected in real time as input objects, real-time detection of abnormal conditions is implemented for the entire process of traffic collection in the multi-port environment of the trusted computing platform.
[0083] Distributed collection and monitoring probes are used, combined with a high-precision clock synchronization mechanism, to achieve continuous monitoring of multi-dimensional indicators such as the data packet collection rate, data packet sequence integrity, and data frame validity of the collection link of each target port.
[0084] The sliding window packet loss rate detection algorithm (parameters: window length N, threshold P_thresh) compares the data packet sequence of each port within the set time window, counts the difference between the actual number of collected packets and the theoretical number of packets, and calculates the packet loss rate using the following formula:
[0085]
[0086] Among them, LossRate i is the packet loss rate of port i, Received i is the number of packets actually received, Expected i The theoretical number of packets that should be received.
[0087] Furthermore, the port activity status heartbeat detection mechanism (parameters: heartbeat period T_beat, loss threshold M) is used to continuously detect the port online activity. If no heartbeat response is received for M consecutive periods, it is determined to be a port failure and an alarm mark is triggered.
[0088] A multi-feature consistency verification algorithm is used to verify the integrity of key fields of captured data packets (such as protocol header, checksum, packet length, etc.). Potential data packet damage or tampering incidents are identified through CRC verification and hash comparison, and abnormal data is isolated and marked.
[0089] Based on anomaly clustering detection methods (such as DBSCAN or isolation forest algorithm), statistical analysis is performed on the frequency of abnormal events, spatial distribution and similarity with historical abnormal patterns to automatically determine whether they are systemic failures, sudden storms or occasional noise.
[0090] Through the above-mentioned multi-level anomaly detection and isolation processing, the marked abnormal data is eliminated from the structured collection results, and only the high-reliability traffic data that has passed the integrity verification and status confirmation is retained and output to the subsequent data preprocessing module.
[0091] Through the above-mentioned chained anomaly detection and isolation processing method, the original multi-port traffic data collected in the previous step is converted into high-integrity and high-reliability structured input data, thereby achieving data quality assurance and improved anomaly resilience of the multi-port load balancing system of the trusted computing platform in extreme scenarios.
[0092] For example, in a multi-port traffic collection on a bank's terminal access platform, the collection window length N is configured to be 10,000 packets, the packet loss rate alarm threshold P_thresh is set to 0.01 (1%), the heartbeat detection period T_beat is 5 seconds, and the loss threshold M is 3. In actual operation, within a certain period, port No. 2 should theoretically receive 10,000 packets, but actually receives 9,800 packets. The packet loss rate is:
[0093]
[0094] Because the packet loss rate was higher than the threshold, the system automatically marked the port as having a packet loss anomaly. At the same time, the port did not receive a signal for three consecutive heartbeat cycles, was judged to be a port failure, and triggered an alarm. Damage to some data packet headers was detected through CRC and hash checks, and these data were isolated and recorded in the anomaly log. During the one-week operation period, the isolation forest algorithm detected that port No. 5 had an abnormal pattern similar to previous network storms. After isolation processing, large-scale abnormal data was effectively prevented from affecting load balancing scheduling. The high-reliability traffic data finally output significantly improved the system's robustness and data credibility in extreme scenarios in the subsequent feature modeling and strategy generation process.
[0095] Furthermore, in S2, the data normalization method is Z-score standardization or Min-Max scaling.
[0096] S2: Preprocess the collected multi-port traffic data, including data normalization, outlier removal, and protocol field standardization, to improve subsequent recognition accuracy.
[0097] This step systematically preprocesses the multi-source traffic data collected from various ports on the Confidence Innovation platform, including data normalization, outlier removal, and protocol field standardization. By improving data consistency and validity, it provides a high-quality, structured input foundation for subsequent core processes such as protocol feature extraction, traffic prediction modeling, and distribution strategy optimization. This is a critical prerequisite for ensuring the accuracy of load balancing algorithms and the real-time performance of the system in heterogeneous protocol environments.
[0098] The S2 includes:
[0099] S2.1 performs format standardization processing on the raw traffic data collected from each port, including standard conversion of timestamps, port numbers, and protocol fields, to ensure the consistency of the multi-port and multi-source data input structure, facilitating subsequent batch processing and feature alignment.
[0100] S2.2 normalizes key numerical features in traffic data (such as packet length, traffic rate, connection delay, etc.) based on normalization algorithms (such as Z-score standardization or Min-Max scaling) to eliminate dimensional differences between different ports and improve the numerical stability of subsequent modeling processes.
[0101] S2.3 Apply statistical detection methods (such as the 3σ principle, IQR interval detection, etc.) to detect outliers in the historical and real-time traffic data of each port, identify and eliminate noise or invalid traffic records, and reduce the interference of extreme anomalies on model training and protocol analysis.
[0102] S2.4 performs standardized mapping processing on protocol fields, mapping the various protocol identifiers, version numbers, and extended attributes collected from different ports to a unified protocol category label through a protocol dictionary to facilitate subsequent heterogeneous protocol compatibility analysis and automatic identification.
[0103] S2.5 integrates the normalized and anomaly-free data and standardized protocol fields to form structured multi-port traffic preprocessing results, and outputs them to the feature extraction and modeling module, providing high-quality data input for the next step of protocol fingerprint extraction and traffic prediction modeling.
[0104] Furthermore, in S3, the protocol fingerprint features include protocol name, version number, header features, extension flags, session duration distribution, typical message length sequence and header field variability.
[0105] S3: Based on the heterogeneous protocol characteristics of each port, extract the multi-dimensional protocol fingerprint features and establish a port-protocol association mapping table to achieve multi-protocol compatibility analysis.
[0106] This step targets multi-port access scenarios on the trusted innovation platform. Based on the heterogeneous protocol characteristics of each port, it extracts multi-dimensional protocol fingerprint features and establishes a port-protocol association mapping table to implement compatibility analysis in a multi-protocol environment. This systematic extraction and mapping of protocol features effectively supports subsequent automatic protocol identification and dynamic adjustment of load distribution strategies, and is a key step in improving the adaptability of multi-port heterogeneous protocols and the accuracy of intelligent load balancing strategies.
[0107] The S3 includes:
[0108] S3.1 analyzes the pre-processed multi-port traffic data packet by packet based on protocol parsing algorithms (such as deep packet inspection (DPI) and rule-based protocol identification engines) to extract protocol-related fields, including but not limited to protocol name, version number, header features, extension flags, etc., to obtain the basic protocol attribute set for each data stream.
[0109] S3.2 uses feature engineering methods (such as statistical distribution analysis, temporal behavior modeling, and content entropy calculation) to extract multi-dimensional protocol fingerprint features for different types of protocol traffic, including session duration distribution, typical message length sequence, header field variability, encryption characteristic indicators, etc., to form a high-dimensional feature vector that can distinguish different protocols and their variants.
[0110] S3.3 uses clustering algorithms (such as DBSCAN, hierarchical clustering) or classifiers (such as decision trees, SVM) to classify and label the multiple protocol instances existing in the same port based on the extracted protocol fingerprint features, generates protocol category labels and their feature expressions, and improves the automatic recognition capability in heterogeneous protocol environments.
[0111] S3.4 establishes a port-protocol association mapping table, and structures the main protocol categories, fingerprint feature vectors and compatibility levels corresponding to each port. It implements efficient query and dynamic maintenance between port and protocol attributes through relational databases or high-performance key-value storage, providing underlying support for subsequent distribution weight generation and adaptive strategy configuration.
[0112] S3.5 performs regular consistency checks and real-time updates on the port-protocol mapping table. Based on newly added traffic samples or detected new protocol fingerprints, it automatically expands the fingerprint library and updates port attributes to ensure the system's continued compatibility with unknown or mutated protocol types, and improves long-term recognition accuracy and scalability in multi-port environments.
[0113] Furthermore, in S4, the temporal neural network is a long short-term memory network (LSTM) or a gated recurrent unit (GRU).
[0114] S4: Use a time series neural network to model the historical and real-time traffic of different ports, and output the traffic forecast value and abnormal traffic probability assessment for each port in the future short period of time.
[0115] This step utilizes a time-series neural network to model historical and real-time traffic flows across different ports, aiming to predict traffic trends and the probability of abnormal traffic within each port within a short period of time. Within the overall technical solution, this step plays a core role in providing feedforward decision support for the multi-port dynamic distribution and load balancing scheduling modules. By predicting traffic trends and conducting risk assessments, it enables proactive awareness of sudden abnormal events, providing a scientific basis for scheduling agents to proactively adjust distribution strategies, and enhancing the system's adaptability and resilience in extreme scenarios.
[0116] The S4 includes:
[0117] S4.1 performs time series feature alignment processing on structured multi-port historical and real-time traffic data, and uses a sliding window algorithm to synchronize and organize data from different ports according to unified time slices to obtain multi-dimensional time series samples that meet the modeling input requirements.
[0118] Based on the above time series samples, S4.2 uses normalization preprocessing methods (such as Z-score or Min-Max scaling) to standardize numerical features such as traffic rate, number of packets, and average message length, eliminating scale differences between different ports and providing numerically stable input for neural network model training.
[0119] S4.3 uses a time series neural network (such as LSTM or GRU) to perform modeling training on the historical and real-time traffic sequences of each port, fits the port-level traffic change pattern through supervised learning, and periodically optimizes the model parameters to improve the accuracy of traffic trend prediction.
[0120] S4.4 inputs the latest real-time traffic data into the trained time series neural network, makes a rolling prediction of the traffic values of each port in the future short period of time, and outputs the traffic trend in the future time window as input for subsequent decision-making.
[0121] S4.5 combines the prediction residuals, historical abnormal event labels and contextual statistical distribution output by the model, and uses probabilistic inference algorithms (such as Bayesian anomaly detection or statistical threshold method) to perform a probability assessment of abnormal traffic that may occur during the prediction period, and outputs the probability of future abnormal events occurring at each port.
[0122] S4.6 structures and archives the future traffic prediction values and corresponding abnormal probability results of each port, and simultaneously outputs them to the multi-port distribution weight generation and reinforcement learning scheduling agent module, providing high-quality prediction basis for dynamic weight adjustment and feedforward distribution decision-making.
[0123] Furthermore, in S5, the distribution weight factor is generated by using principal component analysis (PCA) or an adaptive weighted fusion algorithm, and the weight factor is interval normalized and abnormality judgment is performed to ensure that the distribution sum is 1.
[0124] S5: Dynamically generate multi-port distribution weight factors based on the protocol types and traffic change trends of different ports to achieve adaptive parameter configuration in heterogeneous protocol environments.
[0125] This step dynamically generates multi-port distribution weight factors based on the protocol types and traffic trends of different ports, enabling adaptive parameter configuration in heterogeneous protocol environments. This step serves as a core bridge in the overall technical solution, connecting front-end protocol characteristics with the analysis results of traffic prediction modeling. It also provides a real-time, adjustable distribution weight basis for subsequent intelligent scheduling and dynamic distribution, thereby supporting the implementation of efficient and refined load balancing strategies in multi-port environments.
[0126] The S5 includes:
[0127] S5.1 structures the protocol feature data of each port based on the protocol type and compatibility level of each port output by the protocol fingerprint extraction module, and constructs a port-protocol attribute vector through the protocol label mapping algorithm to provide an input basis for the generation of distribution weight factors.
[0128] S5.2 combines the future traffic trends and abnormal probability assessment results of each port output by the traffic prediction model with the real-time traffic change curve, and uses a weighted time series sliding window algorithm to dynamically calculate the traffic pressure index of each port to reflect the current and short-term future port load risks.
[0129] S5.3 uses multi-feature fusion algorithms (such as principal component analysis (PCA) or adaptive weighted fusion) to comprehensively model the protocol attribute vector and the traffic pressure index to form a port-level comprehensive load feature set, providing a high-dimensional feature basis for the parameterization of weight factors.
[0130] Based on the constructed comprehensive load feature set, S5.4 adopts an adaptive weight adjustment algorithm (such as dynamic allocation based on interval normalization, Bayesian optimization, etc.) to generate a distribution weight factor for each port in real time, realizing adaptive parameter adjustment under different protocol types and different traffic trends.
[0131] S5.5 performs boundary constraints and anomaly detection on the generated distribution weight factors, and uses threshold judgment and robustness analysis methods to eliminate mutations or abnormal parameters to ensure the legitimacy of all weight factors and the total distribution is 1, providing protection for the safe calling of subsequent scheduling modules.
[0132] S5.6 outputs the final calculated multi-port distribution weight factor to the load balancing scheduling and policy agent module, and synchronizes the current weight configuration and related original feature data through the interface to achieve full-link adaptive parameter transmission and subsequent feedback closed-loop optimization.
[0133] Furthermore, in S6, the reinforcement learning scheduling agent uses an intelligent decision-making algorithm based on a value function or a policy gradient to perform action scoring and optimization on multiple distribution strategies. S6 includes:
[0134] S6.1 collects the future traffic trends and abnormal probability assessment results of each port output by the traffic prediction model, and simultaneously obtains the current real-time load status parameters of all ports (such as bandwidth occupancy, number of connections, response delay, etc.) to form a complete input feature set required for scheduling decisions.
[0135] Based on the collected forecast and real-time load data, S6.2 uses a feature fusion algorithm to perform a multi-dimensional quantitative assessment of the risk level of each port, extract key indicators that affect the selection of distribution strategies (such as high-risk port identification and resource bottleneck location), and provide interpretable input for the scheduling agent.
[0136] S6.3 inputs the fused features into the reinforcement learning scheduling agent, and uses an intelligent decision-making algorithm based on value function or policy gradient to score and optimize candidate actions for different distribution strategies (such as redundant resource pre-allocation, dynamic weight adjustment, backup link activation, etc.) to obtain the optimal feedforward distribution strategy solution.
[0137] S6.4 takes the optimal strategy output by the scheduling agent and combines it with the current port compatibility parameters and system resource constraints to perform feasibility verification and parameter refinement on the specific distribution actions involved in the strategy, generating a feedforward resource allocation and traffic adjustment instruction set that can be directly issued for execution.
[0138] S6.5 will synchronously send the refined feedforward distribution instructions to the multi-port load balancing scheduling module, and record the key decision parameters, strategy selection basis and expected effect indicators of this round of decision-making process, providing data support for subsequent execution monitoring and closed-loop feedback optimization.
[0139] S7: When a sudden abnormal traffic trend is detected, feed-forward load distribution adjustment is immediately performed without waiting for the actual abnormality to occur, so as to improve the system response speed and load resilience in extreme scenarios. This step is designed to enable the system to immediately perform feed-forward load distribution adjustment when it detects a sudden abnormal traffic trend in the network, without waiting for the actual abnormality to occur. This function is crucial in the overall technical solution. Its role is to avoid the impact of extreme events such as network storms or traffic surges on the system load balancing performance in advance, significantly improve the system's response speed and resilience to extreme scenarios, and thus ensure high availability and service continuity in the multi-port environment of the trusted innovation platform.
[0140] Furthermore, in S7, the feedforward adjustment strategy includes temporarily increasing the redundant bandwidth of the affected port, dynamically reducing the weight of the high-risk port, or switching part of the traffic to the backup link.
[0141] The S7 includes:
[0142] S7.1 determines abnormal trends for all monitored ports based on the port-level future abnormal traffic probability assessment results output by the traffic prediction model. When the abnormal probability of a port or port combination exceeds the preset threshold, the feedforward load adjustment decision-making process is triggered to achieve early perception of potential emergencies.
[0143] S7.2 uses real-time load status and scheduling agent feedback to quickly generate targeted distribution adjustment strategies for ports identified as showing abnormal trends and their related traffic characteristics. These strategies include but are not limited to temporarily increasing the redundant bandwidth of affected ports, dynamically reducing the weight of high-risk ports, or switching some traffic to backup links, thereby achieving feed-forward resource reallocation.
[0144] S7.3 sends the generated feedforward adjustment strategy to the multi-port load balancing scheduling module, which automatically performs specific traffic redistribution actions based on the current number of connections, protocol compatibility, and hardware resource status of each port to ensure that the adjustment strategy can be implemented and take effect in the shortest time possible.
[0145] S7.4 monitors key parameters during the feedforward adjustment process (such as policy issuance delay, traffic switching time, actual traffic distribution changes, etc.) in real time, combines reinforcement learning scheduling agents to instantly evaluate the effectiveness of policy implementation, and dynamically fine-tune the adjustment amplitude or response range accordingly to maximize distribution efficiency and system resilience in abnormal scenarios.
[0146] S8: Monitor the actual traffic distribution and system load performance after feedforward adjustment, and feed the abnormal event processing results back to the prediction model and scheduling agent to achieve model self-learning and continuous parameter optimization.
[0147] This step continuously monitors the actual traffic distribution and overall system load performance of each port after performing feedforward traffic distribution adjustments. It also feeds the results of unexpected incidents back into the traffic prediction model and reinforcement learning scheduling agent as feedback data. This closed-loop feedback mechanism enables self-learning and continuous parameter optimization of the prediction and scheduling models, improving the system's adaptability to extreme scenarios and the accuracy of subsequent load balancing decisions. This is the core component of achieving highly resilient, multi-port adaptive load balancing.
[0148] Furthermore, in S8, the closed-loop feedback data includes the traffic distribution adjustment effect, abnormal recovery time, and resource utilization, and is used for adaptive parameter optimization of the traffic prediction model and the scheduling agent; S8 includes:
[0149] S8.1 collects and records the actual traffic data of each port and the overall system load performance in real time after the implementation of feedforward load adjustment. It uses a high-resolution monitoring module to obtain port-level traffic changes, system bandwidth occupancy, response delay and abnormal alarm information to fully reflect the real-time operating status after the distribution strategy adjustment.
[0150] Based on the real-time collected traffic and load performance data, S8.2 applies statistical analysis algorithms (such as moving average and anomaly detection) to compare the traffic distribution differences before and after feedforward adjustment, determine the effectiveness of abnormal event processing and identify potential distribution bottlenecks, and provide quantitative evaluation indicators for subsequent feedback.
[0151] S8.3 structures the actual results of each abnormal event handling, including key performance parameters such as traffic distribution adjustment effect, abnormal recovery time, and resource utilization, into training samples, which are input into the traffic prediction model as feedback data, and the model parameters are adaptively fine-tuned to improve the accuracy of future abnormal trend predictions.
[0152] S8.4 takes the feedback and sorts out the abnormal event processing results, and simultaneously inputs the relevant state characteristics and strategy execution results into the reinforcement learning scheduling agent. By updating the reward function or strategy value evaluation, it realizes the online optimization of the scheduling strategy parameters and improves the scheduling agent's adaptive response capability to extreme scenarios.
[0153] S8.5 regularly backtests and cross-validates the prediction model and scheduling agent model after feedback optimization. Through retraining with historical data and incremental learning with new samples, this ensures that model parameters are always optimized and can dynamically adapt to changing trends in protocols and traffic distribution in multi-port environments. In S9, the protocol compatibility parameter group includes feature extraction rules, protocol category labels, and distribution priority settings, and the port-protocol association mapping table is updated in real time through an interface.
[0154] S9: Regularly adapt and update protocol compatibility parameter groups based on different protocol types and port distribution conditions to ensure continuous high-precision identification and distribution efficiency in multi-port environments.
[0155] This step aims to regularly adapt and update the protocol compatibility parameter group based on different protocol types and port distribution conditions, thereby ensuring continuous high-precision protocol identification and traffic distribution efficiency in a multi-port environment. In the overall technical solution, it plays a key role in dynamically maintaining heterogeneous protocol compatibility, supporting port-protocol mapping adaptive adjustment, and improving the long-term scalability of the system, providing the underlying data foundation and compatibility guarantee for the load balancing scheduling strategy and distribution algorithm to continuously output the optimal configuration parameters. The S9 includes:
[0156] S9.1 performs periodic statistical analysis on the protocol fingerprint feature data and port distribution information collected in the current multi-port environment, and uses clustering and distribution detection algorithms (such as K-means and distribution entropy analysis) to identify the changing trends of protocol types and newly emerging protocol instances to obtain a real-time snapshot of the protocol distribution status.
[0157] Based on the protocol fingerprint library and port-protocol mapping table, S9.2 performs compatibility assessment on detected new or changed protocol types, uses the protocol semantic parsing engine to automatically determine the matching degree between the characteristic structure and interaction process of the new protocol and the existing distribution mechanism, and outputs a compatibility assessment report.
[0158] For new protocol types assessed as needing adaptation, S9.3 calls the parameter template generation module to automatically generate or optimize the compatibility parameter group based on the protocol field structure, communication characteristics and historical recognition accuracy, including feature extraction rules, protocol category labels, distribution priority settings, etc., to achieve rapid adaptation to the new protocol.
[0159] S9.4 synchronizes the newly generated or updated protocol compatibility parameter group to the multi-port protocol parsing and identification module through the interface, and updates the port-protocol association mapping table in real time to ensure that all subsequent identification and distribution links can perform high-precision protocol differentiation and traffic classification based on the latest parameters.
[0160] S9.5 regularly retrospectively evaluates the actual application effects of the adapted parameter group, using metrics such as accuracy and recall to analyze the performance of each protocol type in the multi-port recognition process. Combined with abnormal recognition logs, it identifies ports with declining recognition rates or mis-distributed ports, triggering parameter fine-tuning or manual review mechanisms. S9.6 archives key data generated during the parameter group adaptation and update process (such as change records between old and new parameters, recognition accuracy analysis results, port distribution dynamics, etc.) into the system management database, providing data support and audit basis for subsequent model retraining, abnormality tracking, and platform operation and maintenance.
[0161] Example 2
[0162] This embodiment provides a trusted terminal, which is used to implement the network load balancing algorithm based on the trusted platform as described above.
[0163] Specifically, the hardware of the ICT terminal includes a processor, storage devices, network interface cards, and other peripherals such as power modules and heat sinks. The processor's architecture meets ICT requirements and possesses powerful computing capabilities, enabling it to quickly handle large amounts of network traffic data collection, analysis, and load balancing algorithm computing tasks, providing a solid computing foundation for the terminal's efficient operation.
[0164] The application layer of the trusted innovation terminal deploys a data acquisition module, a data processing module, a protocol parsing and mapping module, a traffic prediction module, a load balancing and scheduling module, and a monitoring and feedback module. The data acquisition module is responsible for collecting real-time traffic data from multiple ports on the network interface card, including protocol type, port number, time series characteristics, and historical load change information. It then performs preliminary processing and format conversion on the collected data according to predefined rules, providing raw data for subsequent data processing.
[0165] The data processing module performs pre-processing operations such as multi-level anomaly detection and isolation, normalization, outlier removal, and protocol field standardization on the collected data, converting the raw data into structured multi-port traffic data to ensure that the data input into the algorithm model is accurate and valid.
[0166] Protocol parsing and mapping module: Based on the protocol parsing algorithm, it extracts multi-dimensional protocol fingerprint features of each port traffic and establishes a port-protocol association mapping table to realize the identification and management of different protocol traffic, providing protocol-level information support for the formulation of load balancing strategies.
[0167] The traffic prediction module uses a time series neural network to model the historical and real-time traffic of each port. By training the model to learn the time series patterns of traffic data, it outputs traffic forecast values and abnormal traffic probability assessments for a short period of time in the future, providing forward-looking data for load balancing decisions.
[0168] The load balancing scheduling module dynamically generates multi-port distribution weight factors based on the protocol characteristics of each port and the traffic change trend, and inputs the prediction results and real-time load status into the reinforcement learning scheduling agent. The agent selects a feedforward distribution strategy to achieve adaptive load balancing distribution of network traffic.
[0169] The monitoring and feedback module continuously monitors the actual traffic distribution and system load performance after feedforward adjustment, and feeds the abnormal event processing results back to the prediction model and scheduling agent to optimize model parameters and policy selection, so that the terminal can continuously adapt to changes in the network environment and improve the load balancing effect.
[0170] While various embodiments of the present invention have been described above, the foregoing description is intended to be illustrative, non-exhaustive, and not limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terminology used herein is selected to best explain the principles of the embodiments, their practical applications, or improvements to existing technologies, or to enable others skilled in the art to understand the embodiments disclosed herein.
Claims
1. A network load balancing algorithm based on the Xinchuang platform, characterized in that: The following steps are involved: S1. Collect real-time traffic data from multiple ports, including protocol type, port number, time series characteristics, and historical load change information. Perform multi-level anomaly detection and isolation on the collected data, and output the processed structured data. S2. Preprocess the collected data by normalizing, removing outliers, and standardizing protocol fields to generate structured multi-port traffic data; S3. Extract multi-dimensional protocol fingerprint features of each port traffic based on the protocol analysis algorithm and establish a port-protocol association mapping table; S4. Use a time series neural network to model the historical and real-time traffic of each port, and output the traffic forecast value and abnormal traffic probability assessment in the short term in the future; S5. Dynamically generate multi-port distribution weight factors based on the protocol characteristics of each port and traffic change trends to achieve adaptive parameter configuration in heterogeneous protocol environments; S6. The prediction results and the real-time load status are input into the reinforcement learning scheduling agent, which selects a feedforward dispatch strategy. S7, when abnormal traffic trends are detected, immediately perform feed-forward load distribution adjustments; S8. Monitor the actual traffic distribution and system load performance after feedforward adjustment, and feed the abnormal event processing results back to the prediction model and scheduling agent; S9. Regularly adapt and update the protocol compatibility parameter group based on the protocol type and port distribution.
2. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S1, anomaly detection includes packet loss rate detection, port activity status heartbeat detection, multi-feature consistency check and anomaly cluster analysis.
3. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S2, the data normalization method is Z-score standardization or Min-Max scaling.
4. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S3, the protocol fingerprint features include protocol name, version number, header features, extension flags, session duration distribution, typical message length sequence and header field variability.
5. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S4, the temporal neural network is a long short-term memory network or a gated recurrent unit.
6. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S5, the distribution weight factor is generated by using principal component analysis or adaptive weighted fusion algorithm, and the weight factor is interval normalized and abnormality judgment is performed to ensure that the distribution sum is 1.
7. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 6 is characterized in that: In S6, the reinforcement learning scheduling agent uses an intelligent decision-making algorithm based on a value function or a policy gradient to perform action scoring and optimization on a variety of distribution strategies.
8. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In S7, the feedforward adjustment strategy includes temporarily increasing the redundant bandwidth of the affected port, dynamically reducing the weight of the high-risk port, or switching part of the traffic to the backup link.
9. The network load balancing algorithm based on the Xinchuang platform as claimed in claim 1 is characterized in that: In said S8, the closed-loop feedback data includes the traffic distribution adjustment effect, abnormal recovery time and resource utilization, and is used for adaptive parameter optimization of the traffic prediction model and the scheduling agent; In said S9, the protocol compatibility parameter group includes feature extraction rules, protocol category labels and distribution priority settings, and the port-protocol association mapping table is updated in real time through the interface.
10. A credible terminal, characterized in that: Used to implement the network load balancing algorithm based on the trusted computing platform as described in any one of claims 1-9.
Citation Information
Patent Citations
Station area intelligent fusion terminal data processing system based on edge calculation
CN119440800A
Load balancing control method based on data traffic
CN119520409A
Network anomaly detection and automatic processing method and system, storage medium and equipment
CN119892476A
Intelligent portable WiFi traffic monitoring method and system based on 5G
CN120075872A
Network load balancing evaluation method based on deep learning model
CN120090980A
Cited By
Membrane pollution control method
CN121148507A
Message issuing speed control method and system based on AI large model
CN121283885A
CDN burst traffic coping method based on regional hot event perception
CN121907742A