Gateway management method and device for enterprise system network, equipment and medium
By deploying proxy gateways in the enterprise system network and dynamically adjusting routing using predictive models, the problem of high availability and security in traditional solutions is solved, and effective management of the network egress gateway of the enterprise system and accurate analysis of traffic requirements is achieved.
Patent Information
- Application Number
- CN202510527508.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-09-02
AI Technical Summary
Traditional enterprise system network egress gateway management solutions cannot be dynamically adjusted according to real-time network status and application requirements, and it is difficult to meet high availability and security requirements, especially in the case of multi-egress gateways, which cannot accurately analyze traffic requirements.
By deploying N proxy gateways, network status and application requirements are collected in real time, prediction models are used to predict network and application requirements at the next moment, and target proxy gateways are determined in combination with gateway status for traffic management, and dynamic routing adjustment is achieved.
It realizes the availability management of the network exit gateway of the enterprise system, meets diversified needs, improves network utilization and data transmission efficiency, and ensures high availability and security.
Smart Images

Figure CN120582979A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of gateway management technology, and in particular to a gateway management method, apparatus, device, and medium for an enterprise system network. Background Art
[0002] With the rapid development of the internet, enterprises are increasingly demanding the management of network egress. Traditional egress gateway solutions typically employ fixed routing policies that are unable to dynamically adjust to real-time network status and application requirements. Furthermore, traditional solutions lack application authentication and fault degradation, making them difficult to meet high availability and security requirements.
[0003] Currently, existing methods use dynamic routing adjustment strategies for network allocation. When using traffic for network scheduling, these strategies can collect real-time traffic statistics for each service node and predict traffic trends based on the collected traffic data. This allows for dynamic traffic scheduling strategies for the data plane, alleviating traffic load imbalances and improving network utilization. However, for enterprise-level systems (such as banking and securities systems) with multiple egress gateways, dynamic routing adjustments typically rely on traffic trend prediction strategies, which cannot accurately analyze the exact traffic demands of each egress gateway.
[0004] Therefore, how to manage the availability of egress gateways while achieving dynamic routing adjustments to meet the diverse needs of enterprises for network egress management has become an urgent issue to be resolved. Summary of the Invention
[0005] In view of this, the embodiments of the present application provide a gateway management method, device, equipment and medium for an enterprise system network to solve the problem of how to manage the availability of the export gateway under the condition of dynamic routing adjustment to meet the diverse needs of enterprises for network export management.
[0006] In a first aspect, an embodiment of the present application provides a gateway management method for an enterprise system network, wherein the enterprise system network deploys N proxy gateways, each proxy gateway is used to receive an application request from the enterprise system and send the application request to a firewall side, where N is an integer greater than 1, including: Obtain the current network status and current application requirements, and collect the gateway status of all proxy gateways in real time; Inputting the current network state and the current application demand into a preset prediction model, outputting the network state at a next moment and the application demand at a next moment, and determining the traffic demand at a next moment based on the network state at the next moment and the application demand at the next moment; The target proxy gateway is determined according to the traffic demand at the next moment and the gateway state of each proxy gateway, and after obtaining the application request at the next moment, the application request at the next moment is output through the target proxy gateway.
[0007] In a second aspect, an embodiment of the present application provides a gateway management device for an enterprise system network, wherein the enterprise system network deploys N proxy gateways, each proxy gateway is configured to receive an application request from the enterprise system and send the application request to a firewall, where N is an integer greater than 1, including: The network information acquisition module is used to obtain the current network status and current application requirements, and collect the gateway status of all proxy gateways in real time; a demand prediction module, configured to input the current network state and the current application demand into a preset prediction model, output the network state at a next moment and the application demand at a next moment, and determine the traffic demand at a next moment based on the network state at a next moment and the application demand at a next moment; The target output module is used to determine the target proxy gateway according to the traffic demand at the next moment and the gateway status of each proxy gateway, and after obtaining the application request at the next moment, output the application request at the next moment through the target proxy gateway.
[0008] In a third aspect, an embodiment of the present application provides a computer device, comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the gateway management method for an enterprise system network as described in the first aspect is implemented.
[0009] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the gateway management method for an enterprise system network as described in the first aspect is implemented.
[0010] Compared with the prior art, the embodiments of the present application have the following beneficial effects: In this application, the enterprise system network deploys N proxy gateways, each of which is used to receive application requests from the enterprise system and send the application requests to the firewall side. By obtaining the current network status and current application requirements, and collecting the gateway status of all proxy gateways in real time, the current network status and the current application requirements are input into the preset prediction model, and the network status at the next moment and the application requirements at the next moment are output. According to the network status at the next moment and the application requirements at the next moment, the traffic requirements at the next moment are determined. According to the traffic requirements at the next moment and the gateway status of each proxy gateway, the target proxy gateway is determined. After obtaining the application request at the next moment, the application request at the next moment is output through the target proxy gateway. By using the prediction model to determine the traffic requirements for the network status and application requirements, the target proxy gateway is determined in combination with the gateway status, so as to realize the output of the application request at the next moment and realize the availability management of the export gateway to meet the diverse needs of the enterprise for network export management. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0012] Figure 1 This is a schematic diagram of an application environment of a gateway management method for an enterprise system network provided in Example 1 of the present application; Figure 2 This is a flow chart of a gateway management method for an enterprise system network provided in Example 2 of the present application; Figure 3 This is a flow chart of a gateway management method for an enterprise system network provided in Example 3 of the present application; Figure 4 This is a flow chart of a gateway management method for an enterprise system network provided in Example 4 of the present application; Figure 5 This is a flow chart of a gateway management method for an enterprise system network provided in Example 5 of the present application; Figure 6 This is a structural diagram of a gateway management device for an enterprise system network provided in Example 6 of the present application; Figure 7 This is a structural diagram of a computer device provided in Example 7 of the present application. DETAILED DESCRIPTION
[0013] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0014] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0015] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0016] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0017] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0018] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0019] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, techniques, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to achieve optimal results.
[0020] Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0021] It should be understood that the size of the serial numbers of the steps in the following embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0022] In order to illustrate the technical solution of the present application, specific embodiments are provided below.
[0023] The first embodiment of the present application provides a gateway management method for an enterprise system network, which can be applied in Figure 1 In an application environment, the client communicates with the server. The server, as a carrier device of the enterprise system, can be connected to the client through the enterprise system network. N proxy gateways are deployed in the enterprise system network. Each proxy gateway is used to receive application requests from the enterprise system and send the application requests to the firewall side, so that the client obtains data passing through the firewall or sends data to the server through the firewall.
[0024] The above-mentioned enterprise systems may include but are not limited to financial systems, such as banking systems and securities systems, and medical systems, such as medical insurance systems and social security systems. System development is carried out through the Software Development Kit (SDK). Specifically, application authentication modules, intelligent routing modules, high-availability management modules, etc. can be developed. These modules can be connected with the user management system within the enterprise system to realize the corresponding management functions.
[0025] Clients include, but are not limited to, PDAs, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud-based terminal devices, personal digital assistants (PDAs), and other computer devices. Servers can be standalone servers or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0026] See also Figure 2 , is a flow chart of a gateway management method for an enterprise system network provided in Example 2 of the present application. The gateway management method for an enterprise system network can be applied to Figure 1 The server in the system, as the support of the enterprise system, can configure the corresponding proxy gateway in the server network, and is equipped with application authentication, intelligent routing, management and other functions.
[0027] like Figure 2 As shown, the gateway management method for an enterprise system network may include the following steps: Step S201 , obtaining the current network status and current application requirements, and collecting the gateway status of all proxy gateways in real time.
[0028] A high-availability management module is developed using the framework SDK to monitor the status of the proxy gateway cluster in real time. Network status can refer to network connectivity, download speed, upload speed, packet loss rate, and other factors. Application requirements can refer to data requests, such as sending and receiving data, that users need to perform through the enterprise system. Application requirements are based on task requirements sent by applications within the enterprise system or those authenticated within it.
[0029] Of course, the management module can be used to manage gateways, including but not limited to selecting a target gateway, or automatically triggering a failover mechanism to switch traffic to other available proxy gateways when a failure is detected. Gateway status includes but is not limited to gateway occupancy, gateway connection status, and gateway permissions.
[0030] Develop application authentication modules using the framework SDK, supporting multiple authentication methods (such as OAuth and Token authentication). The authentication module can connect to internal enterprise user management systems (such as Lightweight Directory Access Protocol (LDAP) and Active Directory), ensuring that only authenticated applications can transmit data through the egress gateway.
[0031] An intelligent routing module is developed through the framework SDK. By configuring machine learning algorithms (such as random forests and neural networks) in it, it analyzes real-time network status and application requirements, and dynamically adjusts routing strategies to obtain the target path, thereby improving data transmission efficiency.
[0032] Step S202: Input the current network status and the current application demand into a preset prediction model, output the network status at the next moment and the application demand at the next moment, and determine the traffic demand at the next moment based on the network status at the next moment and the application demand at the next moment.
[0033] Among them, the preset prediction model can be a machine learning model, including but not limited to a neural network model, a random forest model, etc. The prediction model includes time series and can output the prediction data for the next moment based on historical data.
[0034] Using network status and application requirements to train the prediction model can enable the prediction model to have the ability to predict the network status and application requirements at the next moment. Based on the network status and application requirements at the next moment, the traffic demand at the next moment can be predicted. The traffic demand represents the size of single transmission data, permissions, etc.
[0035] Step S203: determining a target proxy gateway according to the next moment traffic demand and the gateway status of each proxy gateway, and after obtaining the next moment application request, outputting the next moment application request through the target proxy gateway.
[0036] Among them, the traffic demand at the next moment is matched with the gateway status of each of the above-mentioned proxy gateways to determine the target proxy gateway, which can meet the traffic demand at the next moment, including but not limited to permission requirements, upload rate requirements, etc.
[0037] After obtaining the application request at the next moment, the application request at the next moment can be output through the target proxy gateway. The target proxy gateway can be determined in advance, so that the call can be implemented at the next moment, thereby improving output efficiency.
[0038] Optionally, determining the target proxy gateway according to the traffic demand at the next moment and the gateway state of each proxy gateway includes: Determining a target routing path based on the traffic demand at the next moment and the gateway status of each proxy gateway; A target proxy gateway is determined according to the target routing path.
[0039] The target routing path is determined by matching the traffic demand at the next moment with the gateway state of each proxy gateway, and the target proxy gateway is determined in the routing path.
[0040] Optionally, before outputting the next-moment application request through the target proxy gateway, the method further includes: Obtaining an application identifier and an application password corresponding to the next-moment application request; The application identifier and the application password are verified using a preset authentication method, and after the verification is passed, the application request at the next moment is output through the target proxy gateway.
[0041] Among them, the application authentication module constructed above needs to obtain the application identifier and application password of the application corresponding to the application request at the next moment, and verify the y application identifier and application password based on the preset authentication method. After the verification is passed, it can be indicated that the application request at the next moment can be output, that is, the application request at the next moment can be executed and output through the target proxy gateway.
[0042] Optionally, determining the traffic demand at the next moment according to the network state at the next moment and the application demand at the next moment includes: Determining the total network traffic based on the application demand at the next moment; According to the network state at the next moment, the total network traffic is decomposed to determine the traffic demand at the next moment.
[0043] Among them, the application demand at the next moment can include the traffic required for each application demand, so that the total network traffic can be determined. The network state at the next moment expresses the network state that can perform transmission. Based on the network state, the total network traffic can be decomposed to determine the traffic demand at the next moment.
[0044] The sample code of the management module is as follows: class AvailabilityManager: def __init__(self, proxy_cluster): self.proxy_cluster = proxy_cluster self.health_check_interval = 5 # seconds def monitor(self): while True: # Check the proxy gateway status for proxy in self.proxy_cluster: if not self.is_healthy(proxy): # Trigger the fault degradation mechanism self.failover(proxy) time.sleep(self.health_check_interval).
[0045] The sample code for the application verification module is as follows: class AuthService: def __init__(self, config): self.config = config self.credentials = {} def authenticate(self, app_id, token): # Verify the application ID and token if app_id in self.credentials and self.credentials[app_id] == token: return True return False.
[0046] The sample code of the intelligent routing module is as follows: class SmartRouter: def __init__(self, network_monitor): self.network_monitor = network_monitor self.models = {} def predict_route(self, app_request): # Get real-time network status network_state = self.network_monitor.get_state() # Use machine learning models to predict target routes optimal_route = self.models['traffic_predictor'].predict(network_state, app_request) return optimal_route.
[0047] In the embodiment of the present application, N proxy gateways are deployed in the enterprise system network. Each proxy gateway is used to receive application requests from the enterprise system and send the application requests to the firewall side. By obtaining the current network status and current application requirements and collecting the gateway status of all proxy gateways in real time, the current network status and the current application requirements are input into a preset prediction model, and the network status at the next moment and the application requirements at the next moment are output. According to the network status at the next moment and the application requirements at the next moment, the traffic requirements at the next moment are determined. According to the traffic requirements at the next moment and the gateway status of each proxy gateway, the target proxy gateway is determined. After obtaining the application request at the next moment, the application request at the next moment is output through the target proxy gateway. By using the prediction model to determine the traffic requirements for the network status and application requirements, the target proxy gateway is determined in combination with the gateway status, so as to realize the output of the application request at the next moment and realize the availability management of the export gateway to meet the diverse needs of the enterprise for network export management.
[0048] See also Figure 3 , is a flow chart of a gateway management method for an enterprise system network provided in Example 3 of this application. Figure 3 As shown, in the above step S203, when outputting the next moment application request through the target proxy gateway, the following steps may be included: Step S301: obtaining the real-time gateway status of the target proxy gateway in real time.
[0049] Step S302: Detect whether the real-time gateway state is faulty. If it is detected that the real-time gateway state is faulty, obtain a fault degradation mechanism.
[0050] Step S303: Determine a target switching gateway from all proxy gateways according to the fault degradation mechanism.
[0051] Step S304: Obtain the remaining information of the next moment application request, and switch the remaining information to the target switching gateway for output.
[0052] Among them, when using the target proxy gateway to output the next moment application request, it is necessary to collect the real-time gateway status of the target proxy gateway in real time to determine whether a fault occurs. If a fault occurs, gateway switching is required in order not to affect data transmission.
[0053] The target switching gateway needs to determine the target switching gateway from gateways other than the target proxy gateway through a preset fault degradation mechanism, so that the remaining information is output through the target switching gateway.
[0054] The embodiment of the present application detects the real-time gateway status of the gateway, thereby achieving gateway switching in the event of a network failure, thereby improving transmission efficiency and accuracy.
[0055] See also Figure 4 , is a flow chart of a gateway management method for an enterprise system network provided in the fourth embodiment of the present application. Figure 4 As shown, the preset prediction model includes a trained random forest model, and the training process of the trained random forest model may include the following steps: Step S401: Acquire first traffic data within a historical time period, and acquire historical network status and corresponding historical application requirements at each moment from the traffic data.
[0056] Step S402 : Fusing the historical network status at each moment with the corresponding historical application requirements to obtain a fused feature vector at the corresponding moment.
[0057] Step S403: Randomly sample all fused feature vectors to obtain M random samples, and construct a decision tree for each random sample to obtain M decision trees.
[0058] Wherein, M is an integer greater than 1; Step S404: Voting is performed on the M decision trees to determine a target decision tree, and the target decision tree is used as a trained random forest model.
[0059] The random forest module is an ensemble learning method used for classification and regression tasks. It consists of multiple decision trees and improves the accuracy and stability of the model by integrating the prediction results of these decision trees.
[0060] Full decision trees are built in parallel using random bootstrapped samples of the dataset and features. Each tree randomly samples a subset of the training data in a process called bootstrapped aggregation, and the model is fit on these smaller datasets and the predictions are aggregated. By sampling with replacement, several instances of the same data are reused, and the trees are not only trained on different datasets, but also use different features to make decisions.
[0061] The embodiment of the present application uses a random forest module to perform accurate predictions. The construction process of the random forest model is relatively simple and can facilitate the use of predictions to a certain extent.
[0062] See also Figure 5 , is a flow chart of a gateway management method for an enterprise system network provided in Example 5 of this application. Figure 5 As shown, the preset prediction model includes a trained neural network model, and the training process of the trained neural network model may include the following steps: Step S501: Acquire second traffic data within a historical time period, and acquire historical network status and corresponding historical application requirements at each moment from the second traffic data.
[0063] Step S502: for any moment, input the historical network state at the moment into a state encoder to obtain a state feature, and input the historical application demand at the moment into a demand encoder to obtain a demand feature.
[0064] In step S503, the state features and the demand features are input into the hidden layer through the input layer, and the prediction result corresponding to the moment is output through the output layer. The state encoder, the demand encoder, the input layer, the hidden layer and the output layer are trained based on the stochastic gradient descent method to obtain a trained neural network model.
[0065] Among them, the neural network model may include BP neural network, long short-term memory network (Long Short-Term Memory, LSTM), etc.
[0066] The encoder is used to encode the features of different data, and then jointly train them with the input layer, hidden layer and output layer, so that the trained neural network model can accurately predict data.
[0067] Corresponding to the gateway management method for an enterprise system network in the above embodiment, Figure 6 The structure diagram of the gateway management device for enterprise system network provided by the sixth embodiment of the present application is shown. The gateway management device for enterprise system network can be applied to Figure 1 The server side in the embodiment of the present invention is provided with a proxy gateway, etc., which is configured in the server side network as the support of the enterprise system, and is equipped with application authentication, intelligent routing, management and other functions. For the sake of convenience, only the parts related to the embodiment of the present application are shown.
[0068] See also Figure 6 , the gateway management device for an enterprise system network includes: The network information acquisition module 61 is used to obtain the current network status and current application requirements, and collect the gateway status of all proxy gateways in real time; a demand prediction module 62 configured to input the current network state and the current application demand into a preset prediction model, output the network state at a next moment and the application demand at a next moment, and determine the traffic demand at a next moment based on the network state at a next moment and the application demand at a next moment; The target output module 63 is used to determine the target proxy gateway according to the traffic demand at the next moment and the gateway status of each proxy gateway, and after obtaining the application request at the next moment, output the application request at the next moment through the target proxy gateway.
[0069] Optionally, the target output module 63 includes: a routing path determining unit, configured to determine a target routing path according to the traffic demand at the next moment and the gateway state of each proxy gateway; The target gateway determining unit is configured to determine a target proxy gateway according to the target routing path.
[0070] Optionally, the gateway management device for the enterprise system network further includes: an identification information acquisition module, configured to acquire an application identifier and an application password corresponding to the next moment application request before outputting the next moment application request through the target proxy gateway; The application authentication module is used to verify the application identifier and the application password using a preset authentication method, and after the verification is passed, output the application request at the next moment through the target proxy gateway.
[0071] Optionally, the gateway management device for the enterprise system network further includes: A gateway status acquisition module, which obtains the real-time gateway status of the target proxy gateway in real time when the application request at the next moment is output through the target proxy gateway; A fault detection module is used to detect whether the real-time gateway state has a fault, and if it is detected that the real-time gateway state has a fault, obtain a fault degradation mechanism; A gateway switching module, configured to determine a target switching gateway from all proxy gateways according to the fault degradation mechanism; The switching output module is used to obtain the remaining information of the application request to send at the next moment, and switch the remaining information to the target switching gateway for output.
[0072] Optionally, the preset prediction model includes a trained random forest model, and the training process of the trained random forest model is as follows: Acquire first traffic data within a historical time period, and obtain historical network status and corresponding historical application requirements at each moment from the traffic data; The historical network status at each moment and the corresponding historical application requirements are fused to obtain the fused feature vector at the corresponding moment; Randomly sample all fused feature vectors to obtain M random samples, and construct a decision tree for each random sample to obtain M decision trees, where M is an integer greater than 1; Voting is performed on the M decision trees to determine a target decision tree, and the target decision tree is used as the trained random forest model.
[0073] Optionally, the preset prediction model includes a trained neural network model, and the training process of the trained neural network model is as follows: Acquire second traffic data within a historical time period, and obtain a historical network state and corresponding historical application requirements at each moment from the second traffic data; For any moment, the historical network state at that moment is input into the state encoder to obtain the state feature, and the historical application demand at that moment is input into the demand encoder to obtain the demand feature; The state features and the demand features are input into the hidden layer through the input layer, and the prediction result corresponding to the moment is output through the output layer. The state encoder, the demand encoder, the input layer, the hidden layer and the output layer are trained based on the stochastic gradient descent method to obtain a trained neural network model.
[0074] Optionally, the demand forecasting module 62 includes: A total flow determination unit, configured to determine the total network flow according to the application demand at the next moment; The demand prediction unit is used to decompose the total network traffic according to the network status at the next moment and determine the traffic demand at the next moment.
[0075] It should be noted that the information interaction, execution process, etc. between the above-mentioned modules, units, and sub-units are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment section and will not be repeated here.
[0076] Figure 7 This is a schematic diagram of the structure of a computer device provided in Example 7 of this application. Figure 7 As shown, the computer device of this embodiment includes: at least one processor ( Figure 7Only one is shown), a memory, and a computer program stored in the memory and executable on at least one processor, which implements any of the above-mentioned steps in the gateway management method for an enterprise system network or in the embodiment of the gateway management method for an enterprise system network when the processor executes the computer program.
[0077] The computer device may include, but is not limited to, a processor and a memory. It will be understood by those skilled in the art that Figure 7 The above is merely an example of a computer device and does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include a network interface, a display screen, and an input device.
[0078] The processor may be a CPU, other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0079] Memory includes readable storage media, internal memory, and the like. Internal memory can be the internal memory of a computer device, providing an environment for the operation of the operating system and computer-readable instructions stored in the readable storage medium. The readable storage medium can be the computer device's hard drive. In other embodiments, it can also be an external storage device, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, or a flash memory card. Furthermore, memory can include both the computer device's internal storage unit and external storage devices. Memory is used to store the operating system, application programs, boot loaders, data, and other programs, such as the program code of computer programs. Memory can also be used to temporarily store data that has been output or is about to be output.
[0080] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process steps in the above-described method embodiments by instructing the relevant hardware through a computer program. The computer program may be stored in a computer-readable storage medium. When executed by a processor, the computer program implements the steps of the above-described method embodiments. The computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. Computer-readable media may include at least: any entity or device capable of carrying computer program code, recording media, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunications signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunications signals.
[0081] The present application implements all or part of the processes in the above-mentioned embodiment method, and can also be completed through a computer program product. When the computer program product runs on a computer device, the computer device can implement the steps in the above-mentioned method embodiment when executing it.
[0082] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0083] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0084] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer equipment and methods can be implemented in other ways. For example, the apparatus / computer equipment embodiments described above are merely schematic. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the apparatus or unit, which can be electrical, mechanical or other forms.
[0085] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0086] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A gateway management method for an enterprise system network, characterized in that: The enterprise system network deploys N proxy gateways, each of which is used to receive application requests from the enterprise system and send the application requests to the firewall side, where N is an integer greater than 1, including: Obtain the current network status and current application requirements, and collect the gateway status of all proxy gateways in real time; Inputting the current network state and the current application demand into a preset prediction model, outputting the network state at a next moment and the application demand at a next moment, and determining the traffic demand at a next moment based on the network state at the next moment and the application demand at the next moment; The target proxy gateway is determined according to the traffic demand at the next moment and the gateway state of each proxy gateway, and after obtaining the application request at the next moment, the application request at the next moment is output through the target proxy gateway.
2. The gateway management method for an enterprise system network according to claim 1, characterized in that: The step of determining the target proxy gateway according to the traffic demand at the next moment and the gateway status of each proxy gateway includes: Determining a target routing path based on the traffic demand at the next moment and the gateway status of each proxy gateway; A target proxy gateway is determined according to the target routing path.
3. The gateway management method for an enterprise system network according to claim 1, characterized in that: Before outputting the next moment application request through the target proxy gateway, the method further includes: Obtaining an application identifier and an application password corresponding to the next-moment application request; The application identifier and the application password are verified using a preset authentication method, and after the verification is passed, the application request at the next moment is output through the target proxy gateway.
4. The gateway management method for an enterprise system network according to claim 1, characterized in that: When outputting the next moment application request through the target proxy gateway, the method further includes: Obtaining the real-time gateway status of the target proxy gateway in real time; Detecting whether a fault occurs in the real-time gateway state, and if a fault occurs in the real-time gateway state, obtaining a fault degradation mechanism; According to the fault degradation mechanism, determining a target switching gateway from all proxy gateways; Obtain the remaining information of the next moment application request, and switch the remaining information to the target switching gateway for output.
5. The gateway management method for an enterprise system network according to any one of claims 1 to 4, characterized in that: The preset prediction model includes a trained random forest model. The training process of the trained random forest model is as follows: Acquire first traffic data within a historical time period, and obtain historical network status and corresponding historical application requirements at each moment from the traffic data; The historical network status at each moment and the corresponding historical application requirements are fused to obtain the fused feature vector at the corresponding moment; Randomly sample all fused feature vectors to obtain M random samples, and construct a decision tree for each random sample to obtain M decision trees, where M is an integer greater than 1; Voting is performed on the M decision trees to determine a target decision tree, and the target decision tree is used as the trained random forest model.
6. The gateway management method for an enterprise system network according to any one of claims 1 to 4, characterized in that: The preset prediction model includes a trained neural network model. The training process of the trained neural network model is as follows: Acquire second traffic data within a historical time period, and obtain a historical network state and corresponding historical application requirements at each moment from the second traffic data; For any moment, the historical network state at that moment is input into the state encoder to obtain the state feature, and the historical application demand at that moment is input into the demand encoder to obtain the demand feature; The state features and the demand features are input into the hidden layer through the input layer, and the prediction result corresponding to the moment is output through the output layer. The state encoder, the demand encoder, the input layer, the hidden layer and the output layer are trained based on the stochastic gradient descent method to obtain a trained neural network model.
7. The gateway management device for an enterprise system network according to claim 1, characterized in that: The determining the traffic demand at the next moment according to the network state at the next moment and the application demand at the next moment includes: Determining the total network traffic based on the application demand at the next moment; According to the network state at the next moment, the total network traffic is decomposed to determine the traffic demand at the next moment.
8. A gateway management device for an enterprise system network, characterized in that: The enterprise system network deploys N proxy gateways, each of which is used to receive application requests from the enterprise system and send the application requests to the firewall side, where N is an integer greater than 1, including: The network information acquisition module is used to obtain the current network status and current application requirements, and collect the gateway status of all proxy gateways in real time; a demand prediction module, configured to input the current network state and the current application demand into a preset prediction model, output the network state at a next moment and the application demand at a next moment, and determine the traffic demand at a next moment based on the network state at a next moment and the application demand at a next moment; The target output module is used to determine the target proxy gateway according to the traffic demand at the next moment and the gateway status of each proxy gateway, and after obtaining the application request at the next moment, output the application request at the next moment through the target proxy gateway.
9. A computer device, characterized in that: The computer device includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the gateway management method for an enterprise system network according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the gateway management method for an enterprise system network according to any one of claims 1 to 7 is implemented.