Communication network architecture optimization method, device and system

By analyzing the packet length and protocol port parameters through edge access devices, sequence clustering characteristics and abnormal distribution signals are formed, the node health status is evaluated, and path allocation is dynamically adjusted, solving the problems of traffic fluctuations and path congestion in the communication network, and realizing efficient traffic management and adaptive resource allocation.

CN120639624AInactive Publication Date: 2025-09-12HOPU COMMUNICATIONS (SHENZHEN) CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202511023193.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-09-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing communication network architecture optimization technologies have difficulty identifying fine-grained fluctuations and abnormal changes in traffic behavior, resulting in delayed node responses and path congestion. They are unable to flexibly adjust scheduling logic, causing increased service forwarding delays and delayed resource allocation, and limited network adaptability.

Method used

By analyzing the packet length and protocol port parameters through edge access devices, sequence clustering features are formed, abnormal pairing distribution signals are identified, node health status is evaluated, and path allocation levels are dynamically adjusted to achieve real-time traffic management and resource redistribution.

Benefits of technology

Quickly discover potential abnormal flows and node fluctuations, proactively guide resource reallocation, shorten path switching response cycles, and improve forwarding continuity and network adaptability of high-priority tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639624A_ABST
    Figure CN120639624A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of architecture optimization, in particular to a communication network architecture optimization method, device and system, and the method comprises the following steps: based on edge access equipment, extracting and classifying data packet length and protocol port parameters, forming sequence clustering features, analyzing protocol and length pairing changes, and summarizing abnormal distribution signals; and combining node response characteristics to evaluate a health state, screening available paths, dynamically adjusting a data flow channel, and outputting a switching opportunity discrimination signal. According to the method, by dynamically collecting network multi-dimensional data and utilizing data flow feature classification, protocol pairing grading and node health association judgment, potential abnormal flow direction and node fluctuation are quickly found, resource redistribution and flow direction adjustment are actively guided, the phenomenon of uneven resource occupation caused by burst flow is effectively reduced, the path switching response period is shortened, and the network switching efficiency is improved. And the forwarding continuity of the high-priority task is improved, and self-adaptive flow control and task guarantee oriented to a multi-service network scene are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of architecture optimization, and in particular to a method, device, and system for optimizing a communication network architecture. Background Art

[0002] Architecture optimization technology involves adjusting and optimizing the structural relationships between computing systems, communication systems, and their constituent units to improve overall operational efficiency and resource utilization. This includes designing inter-node connectivity, establishing network hierarchical structures, resource allocation logic, and constructing task processing paths. This field is widely used in multiple scenarios, including communication networks, data centers, and edge computing. Traditional communication network architecture optimization involves adjusting the connectivity between network nodes by configuring static topologies or relying on fixed path planning logic to achieve network structure adjustments for data transmission tasks. This primarily addresses issues such as uneven resource utilization and path congestion in communication networks.

[0003] Existing technologies mostly rely on preset structural relationships and static path configurations, lack a comprehensive analysis of the real-time status of the network, and have difficulty identifying fine-grained fluctuations and abnormal changes in traffic behavior. When faced with sudden changes in traffic distribution, node response lags and long-term path congestion are prone to occur. Under conditions where multiple service priorities coexist or node performance is differentiated, the original means cannot flexibly adjust the scheduling logic, resulting in increased forwarding delays for some services, delayed resource allocation and scheduling, and limited overall network adaptability and high-priority service assurance effects. Summary of the Invention

[0004] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a method, device and system for optimizing a communication network architecture.

[0005] In order to achieve the above object, the present invention adopts the following technical solution: a method for optimizing a communication network architecture, comprising the following steps:

[0006] S1: Based on edge access devices, the collected data packet length parameters are analyzed. The attribution of each length parameter and protocol port parameter is located through indexing. The data stream sequence is classified based on business logic and structured by period to form sequence clustering features.

[0007] S2: Based on the sequence clustering characteristics, analyze the pairing changes between each group of length sequences and protocol types, compare the relationship between port numbers and protocol types, count the frequency of abnormal combinations, summarize the characteristics and classify them, and obtain the pairing abnormality distribution signal;

[0008] S3: Based on the paired abnormal distribution signals, compare the multi-service response time of the routing forwarding node, analyze the response time distribution of each cycle, identify cycles with low response ratios and response delays, group them by node identifier, record the abnormal response status, and obtain a node health assessment indicator;

[0009] S4: Based on the node health assessment indicators, unmarked nodes are screened, the queue status of the paths to which the nodes belong is analyzed, the path message return status is compared with the service priority waiting order, and the key data flows are allocated to the available paths to obtain the path allocation level.

[0010] The present invention has the following improvements: the sequence clustering features include flow pattern type, sequence normalization label, and feature vector set; the paired abnormal distribution signal includes abnormal combination mark, offset frequency factor, and hierarchical identification code; the node health assessment index includes node reliability coefficient, state fluctuation factor, and health distribution label; the path allocation level includes resource utilization level, path selection factor, and allocation priority group.

[0011] The present invention is improved in that the step of obtaining the sequence clustering feature is specifically as follows:

[0012] S111: Based on the edge access device, the packet length parameter and the protocol port parameter are analyzed, the original data streams in the same period are screened, the matching relationship between the length parameter and the port parameter corresponding to each data stream is calculated, the group affiliation is determined, and an affiliation classification identifier set is obtained;

[0013] S112: Based on the attribution classification identifier set, extract the timestamps of the data flows under each attribution classification, perform time period flow sequence comparison in the order of arrangement, identify data flows with the same business logic number under the same period, uniformly mark them with cluster labels, perform archiving processing, and obtain a label archiving structure sequence;

[0014] S113: Based on the label archiving structure sequence, statistics are performed on the data packet length distribution characteristics, the belonging number, the sequence index position and the time interval parameters, the behavioral feature difference aggregation amount is calculated, the structured object is embedded, and the structured combination is performed to form a sequence clustering feature.

[0015] The present invention is improved in that the step of obtaining the paired abnormal distribution signal is specifically as follows:

[0016] S211: Based on the sequence clustering features, extract the length sequence and protocol type of each group of communication behaviors, call the port number, count the number of occurrences of the combination pattern, group and mark each combination protocol type, compare according to the protocol standard combination rules, filter out combinations that deviate from the protocol standard, and obtain an abnormal combination feature set;

[0017] S212: Based on the abnormal combination feature set, analyze the corresponding distribution of port and protocol mapping for protocol port number, data packet length interval and communication behavior frequency, filter the key results of the combined abnormal extension, merge and mark the protocol segment category, and obtain the classified abnormal combination;

[0018] S213: Based on the classified abnormal combination, the recurrence frequency of each combination in the continuous monitoring period is summarized, encoded according to the protocol type and combination identifier, and hierarchically classified according to the cumulative change trend of the period to obtain a paired abnormal distribution signal.

[0019] The present invention is improved in that the steps of obtaining the node health assessment index are specifically as follows:

[0020] S311: Based on the paired abnormal distribution signal, extract service forwarding records for each node in the routing forwarding node cluster, periodically aggregate the response time of each node within a continuous service cycle according to the node identifier, call the number of response occurrences and response time of each node within the cycle, and statistically analyze the response performance in the cycle data to obtain a cycle response time feature group;

[0021] S312: Based on the periodic response time feature group, the number of responses and the response delay interval of each node over multiple periods are analyzed. By taking statistics on the number of periodic responses of each node and combining them with delayed response behaviors in consecutive periods, the numbers of nodes with abnormally frequent responses are extracted by comparing the differences in the number of responses, thereby obtaining a set of abnormal response nodes.

[0022] S313: Based on the response abnormal node set, call the node identification and cycle performance status, uniformly summarize the response times and performance patterns in each node abnormal cycle, organize the cycle stability performance, and organize it by node identification number to obtain the node health assessment index.

[0023] The present invention is improved in that the step of obtaining the path allocation level is specifically as follows:

[0024] S411: Based on the node health assessment indicator, unmarked nodes are screened, node identifiers are mapped to link path clusters, message queue data for each path in the path set is retrieved, the current number of service requests and the current queue length for each path are counted, and path queue status characteristics are obtained according to the order of data flow queues in the path.

[0025] S412: Based on the path queuing status characteristics, compare the message return status of each path, analyze the message return waiting order and the corresponding service priority label of each path, calculate the path misalignment distribution, and establish available path mapping data;

[0026] S413: Based on the available path mapping data, identify available paths with no misplaced data flow forwarding records, match labels of priority-critical data flows with path priority groups, and obtain path allocation levels.

[0027] The present invention is improved in that the steps further include:

[0028] S5: Based on the path allocation level, determine the queuing status trend of the allocated data flow path in consecutive cycles, analyze abnormal changes in the path return, determine path abnormalities by fluctuation amplitude, adjust the data flow channel when conditions are met, and obtain a switching timing determination signal;

[0029] The switching timing determination signal includes a switching trigger factor, a channel status identifier, and a timing warning identifier.

[0030] The present invention is improved in that the step of acquiring the switching timing determination signal is specifically as follows:

[0031] S511: Based on the path allocation level, analyze the queuing status trend of the allocated data flow path in consecutive cycles, compare the queue length and time parameters of each path in adjacent cycles, calculate the queue change amplitude between cycles, determine the distribution pattern of queue data between different paths, and obtain the path queue change trajectory;

[0032] S512: Based on the path queue change trajectory, compare the path return behavior parameters with the response time distribution of each cycle, screen the synchronization characteristics of the path response timing jump section and the queue change peak section, determine the location and structural differences of the overlapping distribution, and obtain the path return fluctuation characteristics;

[0033] S513: Based on the path return fluctuation characteristics, analyze the channel status identification and queue trend mutation segments in the return behavior, select the path numbers with continuous and drastic change characteristics, optimize the cross-comparison method of path identification and channel status, adjust the archiving order of channel tags, and obtain the switching timing judgment signal.

[0034] A system for optimizing a communication network architecture, comprising:

[0035] The data feature collection module, based on edge access devices, analyzes the length parameters of collected data packets, locates the relationship between each length parameter and the protocol port parameter through parameter indexing, categorizes data stream sequences based on business logic, determines the attribution of sequences within the same cycle, and performs structured combination to form sequence clustering features.

[0036] The abnormal distribution identification module analyzes the pairing changes between the length sequence and the protocol type corresponding to each group of communication behaviors based on the sequence clustering characteristics, compares the relationship between the port number and the protocol type, counts the combined features of the matching deviations in the communication behaviors, summarizes and grades the data stream features, and obtains the pairing abnormal distribution signal;

[0037] The node health assessment module compares the multi-service forwarding response time within the routing forwarding node cluster based on the paired abnormal distribution signal, analyzes the response time distribution of each node in each cycle, determines the cycle in which the response ratio of each node is low and the response is delayed, and uniformly records the status of the abnormal response node to obtain the node health assessment index;

[0038] The path allocation decision module screens unmarked nodes based on the node health assessment indicators, analyzes the service queuing status of a single path within the link scheduling path cluster to which the node belongs, compares the message return status of each path with the waiting order of the corresponding service priority, and allocates priority-critical data flows to available paths to obtain the path allocation level;

[0039] The channel switching judgment module determines the queuing status trend of the allocated data flow path in a continuous cycle based on the path allocation level, analyzes the changing characteristics of the path return anomaly, and judges the abnormality of the path by the continuous fluctuation amplitude. If the target conditions are met, the data flow channel is adjusted to obtain a switching timing judgment signal.

[0040] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the method for optimizing the communication network architecture as described above when executing the computer program.

[0041] Compared with the prior art, the advantages and positive effects of the present invention are:

[0042] In the present invention, by dynamically collecting multi-dimensional network data, using data flow feature classification, protocol pairing grading and node health association judgment, continuous linkage identification of traffic distribution, node operation status and path resource status is achieved. By adopting group classification, status aggregation and real-time trend analysis, potential abnormal flow directions and node fluctuations can be quickly discovered, resource reallocation and flow direction adjustment can be actively guided, and the uneven resource occupancy caused by burst traffic can be effectively reduced, the path switching response cycle can be shortened, the forwarding continuity of high-priority tasks can be improved, and adaptive flow control and task guarantee for multi-service network scenarios can be achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a flow chart of the main steps of the present invention;

[0044] Figure 2 This is a flow chart for obtaining sequence clustering features in the present invention;

[0045] Figure 3 This is a flow chart for obtaining paired abnormal distribution signals in the present invention;

[0046] Figure 4 This is a flowchart for obtaining node health assessment indicators in the present invention;

[0047] Figure 5 A flow chart for obtaining the path allocation level in the present invention;

[0048] Figure 6 This is a flow chart for obtaining the switching timing determination signal in the present invention. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0050] In the description of the present invention, it should be understood that the terms "length", "width", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating directions or positional relationships, are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing the present invention and simplifying the description. They do not indicate or imply that the devices or elements referred to must have a specific direction, be constructed and operate in a specific direction, and therefore should not be understood as limiting the present invention. In addition, in the description of the present invention, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0051] Example

[0052] See also Figure 1 The present invention provides a technical solution: a method for optimizing a communication network architecture, comprising the following steps:

[0053] S1: Based on edge access devices, it analyzes the collected data packet length parameters, locates the relationship between each length parameter and the protocol port parameter through parameter indexing, classifies data stream sequences based on business logic, determines the attribution of sequences within the same cycle, and combines this with behavioral feature extraction to perform structured combination and form sequence clustering features.

[0054] S2: Based on sequence clustering features, we analyze the changes in the pairing between the length sequence and protocol type corresponding to each group of communication behaviors, compare the relationship between port numbers and protocol types, and count the combined features of matching deviations in communication behaviors. By recording the frequency of anomalies, we summarize and classify the data stream features to obtain the pairing anomaly distribution signal.

[0055] S3: Based on the paired abnormal distribution signals, compare the multi-service forwarding response time within the routing forwarding node cluster, analyze the node response time distribution in each cycle, determine the cycles in which the node response ratio is low and the response is delayed, perform grouping based on the node identifier, and uniformly record the status of the abnormal response node to obtain the node health assessment indicator;

[0056] S4: Based on the node health assessment indicators, unmarked nodes are screened and the service queuing status of a single path within the link scheduling path cluster to which the node belongs is analyzed. The return status of packets on each path is compared with the waiting order of the corresponding service priority. Priority-critical data flows are allocated to available paths to obtain the path allocation level.

[0057] S5: Based on the path allocation level, determine the queuing status trend of the allocated data flow path in continuous cycles, analyze the changing characteristics of path return anomalies, and identify path anomalies based on the continuous fluctuation amplitude. If the target conditions are met, adjust the data flow channel to obtain a switching timing judgment signal.

[0058] Sequence clustering features include flow pattern type, sequence normalization label, and feature vector set; paired anomaly distribution signals include anomaly combination mark, offset frequency factor, and hierarchical identification code; node health assessment indicators include node reliability coefficient, state fluctuation factor, and health distribution label; path allocation level includes resource utilization level, path selection factor, and allocation priority group; switching timing judgment signals include switching trigger factor, channel state identification, and timing warning identification.

[0059] In S1, edge access devices refer to devices deployed at the edge of the communication network and responsible for accessing terminal user traffic, such as access switches, gateways, routers, etc., which are mainly used for preliminary reception, preprocessing and forwarding of data streams; the packet length parameter refers to the number of bytes of each network packet during transmission. This parameter is used to characterize traffic distribution, determine application types, and monitor anomalies; the protocol port parameter refers to the port number of the TCP / UDP protocol header in the data packet, which is used to distinguish different service types (such as HTTP, FTP, DNS, etc.) and is an important basis for protocol identification; the attribution relationship refers to binding or corresponding the collected data parameters with specific business logic numbers, network services, application types, etc. for subsequent grouping and tracing; business logic refers to the network processing flow formulated according to applications, services, and business needs, such as classification by user business, diversion by service priority, etc.; sequence attribution refers to archiving and classifying all collected data according to their business logic numbers within a set period, to facilitate subsequent data statistics and behavior judgment; behavioral feature extraction refers to obtaining characteristic information that can reflect the behavioral laws of data streams in the original data sequence through statistics, rule analysis, etc., such as length distribution, time series patterns, etc.; structured combination refers to combining and encapsulating multiple original parameters and behavioral features in a prescribed data structure to form data fragments or objects that are convenient for subsequent algorithm or logic processing.

[0060] In S2, communication behavior refers to the overall performance of a group of data packets in the network under specific time, path, and protocol conditions, including traffic characteristics, protocol usage, interaction methods, etc.; pairing change refers to the pairing method and change trend of different data packet lengths and corresponding protocol types in actual observations, which is used to judge the consistency of protocols and business behaviors; the combination characteristics of matching deviation refer to the difference between the actual observed port number and protocol type combination and the conventional standard, such as the length distribution of some ports that does not conform to the conventional protocol; the frequency of abnormal occurrence refers to the number or proportion of the above-mentioned pairing deviations during the monitoring period, which is used to quantify abnormal behavior; feature summarization and classification refers to summarizing the types of abnormal combinations monitored, and dividing them into different levels or categories according to standards such as the degree of abnormality and frequency of occurrence, for easy subsequent processing.

[0061] In S3, routing and forwarding nodes refer to key equipment nodes in the network that undertake functions such as data distribution, path selection, and forwarding, such as core routers and aggregation switches; response time refers to the time taken by routing and forwarding nodes to make a processing response after receiving a data forwarding instruction, reflecting the node load and operating status; execution grouping refers to grouping and classifying all nodes according to business indicators (such as health status and response latency) for subsequent grading, screening, and resource allocation; abnormal response node status refers to the current status of a node that is judged to be abnormal based on indicators such as response time and success rate, including its identification, performance indicators, etc.

[0062] In S4, unmarked nodes refer to nodes that have not been judged to be abnormal and are in an available state after the health check and classification of the previous nodes; link scheduling paths refer to the data transmission paths between nodes in the network, and the link combination used to carry data flows is dynamically selected in combination with the scheduling mechanism; the service queuing status refers to the number, length or related sorting indicators of service request queues on the current path or node, reflecting the busyness of the current link; the message return status refers to the normality and timeliness of return operations such as response and confirmation when the data flow passes through a specific path, which is used to assist in path health judgment; waiting order refers to the queue order of different services according to factors such as priority and arrival order during the data flow scheduling process; available paths refer to the transmission paths that meet the distribution scheduling conditions after health detection and evaluation in the current network environment.

[0063] In S5, the queue status trend refers to the changing trajectory of the service queue status of a certain path within a continuous period, which is used to monitor congestion evolution; path return anomaly refers to abnormal response phenomena that occur during the path return process, such as packet delay and loss; abnormal situation refers to data flow or link status that is significantly different from the normal service processing mode confirmed through statistical analysis; target condition refers to the scheduling, switching and other trigger criteria that are pre-set or dynamically evaluated in actual business. When the detection results meet such conditions, switching, adjustment and other operations are initiated.

[0064] See also Figure 2 , the steps for obtaining sequence clustering features are as follows:

[0065] S111: Based on the edge access device, the packet length parameter and the protocol port parameter are analyzed, the original data streams in the same period are screened, the matching relationship between the length parameter and the port parameter corresponding to each data stream is calculated, the group affiliation is determined, and an affiliation classification identifier set is obtained;

[0066] Based on the actual environment where edge access devices are deployed at the network access layer, the original data packet information is extracted from the real-time incoming data stream, the header field in the data packet is parsed, and the data packet length field is read to obtain the length value of each packet. At the same time, the source port number and the destination port number in the transport layer protocol are parsed to form the protocol port parameters. All data streams in multiple acquisition cycles are divided into time periods at the second level. The data packets belonging to the same time period are filtered and classified into a unified processing set. The length value and port number in each data stream are extracted and combined to form a binary data combination set. The combination items are cross-compared with a fixed protocol port number set to determine whether they belong to common service ports such as HTTP, DNS, FTP, etc. If the port number is not in the set, it is marked as a non-standard port. Further analysis is made to see whether the data packet length in each combination item is within the length range of known normal services, for example, 500 bytes to 1500 bytes is the standard service flow length range. Combination items falling within this interval are marked as normal length. The length and port correspondence of all combination items in each data flow are counted. If a data flow is found to contain only standard ports and the data packet length distribution is within a reasonable range, the data flow is classified as a standard belonging class. If there are non-standard ports in the combination items or the length value deviates significantly from the normal range, such as abnormal packets less than 100 bytes or greater than 2000 bytes, the data flow is marked as a non-standard belonging class. The belonging category judgment process needs to be carried out one by one on multiple data flows, and finally a set of belonging classification identifiers corresponding to each data flow is formed. For example, for a data flow, if its data packet port is 80 and the length is 1400, 1380, and 1420 bytes, it is marked as a standard belonging class. Another data flow has a port of 8080 and a length of 1600, 1800, and 2000 bytes, which is marked as a non-standard belonging class. After all data flows are classified, the belonging classification identifier set is obtained.

[0067] S112: Based on the attribution classification identifier set, extract the timestamps of the data flows under each attribution classification, complete the time period flow sequence comparison in the arrangement order, identify the data flows with the same business logic number in the same period, cluster the labels and uniformly mark them, perform archiving processing, and obtain the label archiving structure sequence;

[0068] The data streams that are judged to be of standard attribution are retrieved and processed one by one, and the timestamp field value of each data packet record in each data stream is read and arranged in chronological order to form a time-sorted stream sequence. The time interval between adjacent data packets is calculated within each sequence for subsequent behavior consistency judgment. The first packet time of all data streams classified under the same attribution classification identifier is further compared to determine whether they are within the same collection period. The collection period can be set to a fixed length such as one minute. If the first packet time difference between two data streams is less than 5% of the period, they are considered to belong to data streams generated in the same period. The streams are further compared based on whether they have the same business logic number field. If the numbers are the same, they are marked as the same type of business streams and given a unified clustering label. In this process, it is necessary to process a large number of timestamp arrangement and number field comparison operations of streams, such as setting a week. The period is 60 seconds. If the first packet times of the two flows are 08:00:01 and 08:00:02 respectively, and the time difference of the first packet is within three seconds, if the business logic number field is consistent, such as user number 1234 or service number A01, they are marked as the same business cluster, and the cluster label is such as G1234 or GA01. All flows belonging to this category are uniformly marked by the cluster label. Then, in the archiving processing stage, all data files of this type of flow will be packaged and archived with the cluster label as the index. The archive content includes the flow time series, data packet details, attribution classification identifier, business logic number and other fields, so that the archive structure can be directly accessed and referenced in subsequent processing, identification, reclassification and other operations. A unified management structure is formed through archiving. Each type of cluster label corresponds to an archiving unit and is associated with the attribution classification to obtain a complete label archiving structure sequence.

[0069] S113: Based on the tag filing structure sequence, statistics are collected on the data packet length distribution characteristics, the assigned number, the sequence index position, and the time interval parameters using the formula:

[0070]

[0071] Calculate the behavioral feature difference aggregation FE a , embedding structured objects, performing structured combination, forming sequence clustering features, where LE i Indicates the packet length parameter of the i-th data stream, ΔTE i Indicates the time interval parameter between the i-th data stream and its previous data stream, Eμ t Indicates the mean value of the time interval parameter under the current attribute number, N a Indicates the number of data flows in the current domain, R a Indicates the cumulative frequency of the assigned number, SE i Indicates the index parameter of the i-th position in the attribute number sequence, PE iIndicates the protocol number index parameter of the i-th position in the attribute number sequence.

[0072] The behavioral feature difference aggregation value represents the comprehensive comparison and difference aggregation of the main behavioral features of a group of data flows under the same category at the statistical level. The larger the value, the more complex the behavioral features within the data flow group or the more dispersed the distribution.

[0073] Assume that the label group currently being processed is numbered G7, and contains data stream samples A1, A2, A3, and A4. The corresponding original parameters are as follows: the packet length parameters are 848 bytes, 864 bytes, 840 bytes, and 848 bytes; the time interval parameters are 0.4 seconds, 0.5 seconds, 0.3 seconds, and 0.3 seconds; the attribution number indexes are 1, 2, 3, and 4; and the protocol number index is unified as 2. To facilitate subsequent calculations, each parameter is normalized and recorded as:

[0074] LE1=0.82, LE2=0.86, LE3=0.81, LE4=0.82, ΔTE1=0.42, ΔTE2=0.55, ΔTE3

[0075] =0.30, ΔTE4=0.30;

[0076] Attribution Number Index SE i The original values ​​remain unchanged, namely 1, 2, 3, and 4, corresponding to the protocol number index PE i =2, all data streams have the same protocol; this tag group contains a total of N data streams a =4, its assigned number appears 3 times in the previous cycle, set the assigned cumulative frequency R a =3, calculate the time interval mean Eμ based on the current time interval sequence t for:

[0077]

[0078] Substitute the parameters into the following formula:

[0079]

[0080] Execute the summation part:

[0081] Item 1:

[0082] LE1×|ΔTE1-Eμ t |=0.82×|0.42-0.3925|=0.82×0.0275=0.02255;

[0083] LE2×|ΔTE2-Eμ t|=0.86×|0.55-0.3925|=0.86×0.1575=0.13545;

[0084] LE3×|ΔTE3-Eμ t |=0.81×|0.30-0.3925|=0.81×0.0925=0.07493;

[0085] LE4×|ΔTE4-Eμ t |=0.82×|0.30-0.3925|=0.82×0.0925=0.07585;

[0086]

[0087] Item 2:

[0088] |SE1-PE1|=|1-2|=1;

[0089] |SE2-PE2|=|2-2|=0;

[0090] |SE3-PE3|=|3-2|=1;

[0091] |SE4-PE4|=|4-2|=2;

[0092]

[0093] Substituting the two terms into the formula:

[0094]

[0095] Calculate the behavioral feature difference aggregation amount FE a ≈2.01, which falls within the median of the preset difference reference interval [0.5, 2.5]. This indicates that the behavior differences of the data stream corresponding to the current clustering label G7 are moderately consistent and can be used as basic samples to participate in the subsequent feature clustering process to form sequence clustering features. The formula introduces the weighted product of the normalized length parameter and the time interval difference and combines it with the sum of index differences to measure the behavior differences with a composite structure. This allows the aggregation amount to have both continuous behavior offset and protocol identification mapping capabilities, and can effectively characterize the overall change trend and structural aggregation degree of the data stream in the structured combination.

[0096] See also Figure 3 , the specific steps for obtaining paired abnormal distribution signals are:

[0097] S211: Based on sequence clustering features, extract the length sequence and protocol type of each group of communication behaviors, call the port number, count the number of occurrences of the combination pattern, group and mark each combination protocol type, compare them according to the protocol standard combination rules, filter out combinations that deviate from the protocol standard, and obtain an abnormal combination feature set;

[0098] The communication behavior sequence corresponding to each clustering label in the archive structure is extracted one by one. In the specific execution, the length field values ​​of all data packets in the communication behavior are read to construct a length sequence. At the same time, the protocol type field value is extracted from the header of each data packet to form a protocol type sequence, and its port number parameter is synchronously called. In the processing process, first, index matching is performed according to the clustering label to which the data flow belongs. After all the communication behaviors under the label are arranged in chronological order, the value groups of the two dimensions of length and protocol type are extracted in sequence. Then, the combination pattern formed between the length and protocol type value groups and the port number is counted. Each time a new combination appears, it is counted as a new addition. If the same combination appears again, the count is accumulated by one. The combination pattern counting table is constructed in sequence. On this basis, for each different protocol type, the combination formed by the port number and the data packet length is grouped, and all combination units under the same protocol type are given a unified The tag value, for example, the combination of protocol type TCP is marked as T group, and the combination of protocol type UDP is marked as U group. The marked combination sets are compared one by one with the pre-set protocol standard combination rules. During the comparison operation, the port and length combination items allowed by each protocol in the standard rules are read, and the actual combination is compared to see whether it appears in the standard rule set. If it does not match successfully, it is judged as a deviation combination. For the judgment process, the combination deviation judgment threshold is set to 0, that is, as long as the rule is not matched, it is judged as an abnormality, rather than allowing a small proportion of error. Finally, all communication behavior items that deviate from the combination are recorded in the abnormal combination feature set. For example, it is found that the port number in a group of UDP data is 23 and the length is 3000 bytes. After checking, the UDP port 23 in the standard rule does not match this length range, which is marked as an abnormality. If the frequency of this combination exceeds 10 times, the tag field is synchronously added to the log to obtain the abnormal combination feature set.

[0099] S212: Based on the abnormal combination feature set, analyze the corresponding distribution of port and protocol mapping for the protocol port number, data packet length interval, and communication behavior frequency, using the formula:

[0100]

[0101] Filter the results of the combined abnormal expansion key, merge and mark the protocol segment category, and obtain the classified abnormal combination, among which GS b Gm represents the abnormal expansion of the combination of type b, b Gλ represents the average length of the data packets in the b-th combination, bGρ represents the average length of the standard protocol matching corresponding to the b-th combination, b represents the fluctuation scale of the b-type combined protocol mapping, GH b GQ represents the total number of communication rounds for the b-th combined communication behavior. b Indicates the total number of ports involved in the protocol type in the b-th combination, Gr b Gq represents the number of successful communication response interactions in the b-th combination, b Indicates the total number of communications of the b-th combination;

[0102] The combination "25-DNS" was selected as the analysis object. This combination appeared 38 times in the current monitoring period. The average length of the data packet was 112 bytes. The normal average length of the standard protocol DNS is 74 bytes. The length fluctuation scale was set to 16 bytes. After normalization, Gm was obtained. b =0.72, Gλ b =0.48, Gρ b =0.22, and the number of complete interaction rounds of the combination is 38, involving a total of 1 port number, normalized to GH b =0.63, GQ b =0.27, corresponding to 31 successful interactions and 38 total communications, which are Gr b =0.61, Gq b =0.74, and the normalized parameters are substituted into the formula to calculate the first length offset as follows:

[0103]

[0104] The second behavior density part is:

[0105]

[0106] The third communication integrity part is:

[0107]

[0108] The three superposition calculations yield:

[0109] GS b ≈1.0909+0.4124-0.8243=0.679;

[0110] The above results are the combined abnormal expansion GS of the combination "25-DNS" b , according to the set result classification standard, when GS bWhen <1.0, the combination is classified as a medium abnormal segment. Combined with the fact that its port "25" is identified as a mail service channel, the risk of mixed use of the DNS protocol is marked as belonging to the cross-protocol category in the mail segment. After aggregation, the combination is included in the classified abnormal combination. In the formula, Gm b , Gλ b 、Gρ b Respectively represent the average data length, standard matching length and fluctuation scale of the combination, forming the length offset term, reflecting the distance characteristics of the protocol application layer; GH b With GQ b Gr is the product of the frequency of combination occurrence and the ports involved, indicating its combination activity in the business behavior dimension; b With Gq b The interactive response ratio is used to measure the stability of the combination; the GS output after the three parts are combined is b The abnormal expansion degree of the current combination serves as the basis for stratification determination.

[0111] S213: Based on the classified abnormal combination, the recurrence frequency of each combination in the continuous monitoring period is summarized, encoded according to the protocol type and combination identifier, and hierarchically classified according to the cumulative change trend of the period to obtain a paired abnormal distribution signal.

[0112] The combined abnormal expansion refers to an indicator that reflects the overall abnormality between the protocol combination and the standard protocol behavior pattern in the communication network data analysis by performing multi-dimensional comprehensive measurement of multiple characteristics of each type (type bbb) of protocol combination (including the deviation between the actual data packet length and the standard protocol length, the protocol mapping fluctuation range, the communication rounds and port coverage, and the response interaction). The larger the value, the more prominent the comprehensive deviation of the combination in terms of behavior, structure, matching, etc.

[0113] Retrieve the record details of each abnormal combination in multiple continuous monitoring cycles, locate and retrieve each combination identifier according to the time axis, record whether it exists in each cycle, and make cumulative statistics. During the statistical process, set the cycle length to 60 seconds, and the total continuous monitoring time to 30 minutes, then the total number of cycles is 30. If a certain abnormal combination is detected to appear at least once in each cycle, it is regarded as a valid record. In this way, the number of valid records of all abnormal combinations in each cycle is summarized, and then all abnormal combinations are classified and coded according to the communication protocol type. For example, all TCP protocol combination codes start with T, and UDP protocol combination codes start with U. Abnormal combinations are added with a combination feature code such as port number plus length feature code after the protocol identifier to form a unique identifier. The combination identifier format is such as T-8080-1800 or U-9000-250. The results are recorded according to the periodic change trend, and the number of occurrences of each combination in the period is compared for the change trend. The trend evaluation window is set to 5 periods. If the combination appears in each period for 5 consecutive periods and the frequency is not less than twice, it is judged as a high-frequency anomaly and divided into the first-level classification. If the frequency is less than twice in three periods, it is classified as the third-level classification. The intermediate frequency is set as the second-level classification. The medium and high frequency judgment limit is set to more than eight times in the cumulative number of occurrences in five periods, and the low frequency judgment limit is set to less than three times in the cumulative number of occurrences in three periods. This hierarchical structure is used to distinguish the stability of anomalies. In actual data, for example, the combination T-8080-1800 appears 22 times in 30 periods, and the frequency in 7 of them exceeds 3 times. Its change trend is steadily increasing, and it is classified as a first-level high-frequency anomaly combination. The hierarchical classification results are structured and output to form a paired anomaly distribution signal.

[0114] See also Figure 4 ,The specific steps for obtaining node health assessment indicators are as follows:

[0115] S311: Based on the paired abnormal distribution signal, service forwarding records are extracted for each node in the routing forwarding node cluster. Response times within consecutive service cycles of each node are periodically aggregated according to node IDs. The number of responses and response durations of each node within the cycle are called. Response performance in the cycle data is statistically analyzed to obtain a cycle response time feature group.

[0116] According to the unique identification code of the router or switching device deployed in the node cluster, the node business forwarding log is called, and its business forwarding records in each sampling period are extracted one by one. The corresponding receiving time and response sending time fields are read for each record, and the response time value of the response is calculated. All response times of the same node in the same period are aggregated and sorted in order. At the same time, the total number of response operations performed by the node in the period is counted. For each node, a response time series and a response number series are constructed and the time index is retained. In the aggregated data set, the data of each period of each node is traversed, and the response duration field is taken out in turn and summarized in seconds. The evaluation period is set to 5 minutes and the sampling period is 30 seconds. Then each node corresponds to 10 groups of periodic data. In actual operation, if the number of responses of node N1 within five minutes is 48, 52, 49, 30, 20, 15, 55, 45, 20, and 10 respectively, The average response time should be 0.2 seconds, 0.25 seconds, 0.22 seconds, 0.5 seconds, 1.2 seconds, 2.1 seconds, 0.21 seconds, 0.23 seconds, 2.4 seconds, and 3.2 seconds respectively. The response time series of the node is marked as a fluctuating structure, and the maximum, minimum, average, and median response time of each cycle are recorded. The total number of responses of the node within five minutes is counted and compared with the standard response level. The standard is set to at least 40 responses every 30 seconds and the average response time does not exceed 0.5 seconds. If it is lower than this number or the response time is greater than the threshold, it is recorded as an abnormality. The response number threshold is set to 40 times, and the response time threshold is set to 0.5 seconds. The above two thresholds are derived from the long-term statistical median of typical business nodes in the actual network. The boundary value is extracted based on the 95th percentile. Combined with the above extraction logic, this processing flow is performed on all nodes to complete the statistics of the periodic response time feature group.

[0117] S312: Based on the periodic response time feature group, the number of responses and response delay intervals of each node over multiple periods are analyzed. By taking statistics on the number of periodic responses of each node and combining them with delayed response behavior in consecutive periods, the numbers of nodes with abnormally frequent response behaviors are extracted by comparing the differences in the number of responses, thereby obtaining a set of abnormal response nodes.

[0118] Retrieve the response times field and response duration field from the periodic statistical data of each node, construct a timeline structure in the order of the period number, compare the response times of each node in consecutive periods, and judge the change in the response times of the node in adjacent periods. If the response times drop by more than 50% or the response duration increases by more than two times in three consecutive periods, the node is recorded as an abnormal response behavior node. For the difference judgment in the response number statistics, perform a comparison of the absolute values ​​of the differences between adjacent periods. If the difference is greater than 20 times and the response times of the current period are less than those of the previous period, record a fluctuation behavior. At the same time, compare the response time of the period with that of the previous period. If the average response time is changed from If the response time increases from 0.3 seconds to 0.9 seconds, the two-fold growth condition is met. The response frequency difference threshold is set to 20 times, and the response time change rate judgment threshold is 2 times. This logic is used to traverse all cycle data of each node. After each abnormal behavior is found, the node number, cycle number, number of responses, response time and other indicators are recorded and included in the abnormal behavior counting table. When a single node has abnormal behavior more than three times in ten cycles, it is determined to be a frequent abnormal response node, and the node number is marked and included in the abnormal node preliminary screening set. For example, node N2 has the above two abnormal phenomena in cycles 3, 4, and 6, so its frequent abnormal behavior number is 3, which meets the selection conditions. The frequently abnormal response node numbers are sorted and collected to obtain the response abnormal node set.

[0119] S313: Based on the set of response abnormal nodes, the node identification and cycle performance status are called to uniformly summarize the response times and performance patterns of each node in the abnormal cycle, organize the cycle stability performance, and organize it by node identification number to obtain the node health assessment index;

[0120] Call the corresponding business cycle performance record according to each node number, read the number of responses and average response time fields of the node in each cycle marked as abnormal one by one, further extract the stability parameters in each abnormal cycle, including the standard deviation of response time, the variation range of the number of responses and the minimum response interval, and then establish a unified cycle stability performance list for each node after summarizing. Combined with the node number, the performance data are tabulated in chronological order. For a node, if the standard deviation exceeds 0.6 seconds in consecutive cycles, the number of responses drops by more than 40% and the minimum response interval is greater than 3 seconds, the cycle is marked as an unstable state cycle. For the cycle stability judgment logic, the upper limit of the standard deviation of the response time is set to 0.5 seconds, and the number of responses is set to 0.5 seconds. The threshold for number decrease is 40%, and the threshold for the minimum response interval is 3 seconds. These three indicators are the benchmark values ​​for judging the stability of the node. They are all derived from the upward fluctuation range of the average value of the normal business operation node in the 24-hour operation data. By horizontally comparing the performance of different nodes under the same behavior cycle, the number of unstable states of each node in the abnormal cycle is summarized and a node status score is generated. The score is presented as the proportion of stable performance times in the cycle. If a node is marked as unstable in 7 out of 10 cycles, its health score is 30%. Based on the scoring results, a list of node health assessment indicators is constructed, and the stability data, abnormal cycle number and health score corresponding to each node are structured and recorded to obtain the node health assessment indicator.

[0121] See also Figure 5 ,The specific steps for obtaining the path allocation level are:

[0122] S411: Based on the node health assessment indicators, unmarked nodes are screened, node identifiers are mapped to link path clusters, and the message queue data of each path in the path set is retrieved. The current number of service requests and the current queue length of each path are counted. The path queue status characteristics are obtained according to the order of the data flow queues in the path.

[0123] Extract the corresponding score record according to the node number and judge and process each record, set the health score threshold to 70%, when the node score is higher than the threshold, it is regarded as an unmarked node, and include the node number of this type in the candidate path node set, and correspond one-to-one with the link path cluster according to the node number, index match the node number with the preset path structure in the path table, locate the position of the path where each node is located in the link structure, and call the queue data field of all business messages under the path. When obtaining the path data, it is necessary to extract the current number of business requests, the current queue length and the waiting sequence number of each request of the path, traverse all paths and count the total number of business requests and the maximum queue length value, record the queue situation of each path in a structured manner, and then sequence it according to the order field of the internal data flow of the path. Reorganization: Each data flow request is reordered from smallest to largest based on its waiting position field in the queue and the sorting number sequence is recorded. The path message response time field is then extracted and combined with the current queue number field to generate a path queue status feature set. In an actual example, if the current number of requests on path P1 is 120, the queue length is 38, and the request arrangement order is 4th, 7th, 12th, etc., it indicates that the current service congestion level on this path is moderate. Conversely, if the queue length on path P2 reaches 90 and the waiting time of the first ten services is greater than 3 seconds, it is recorded as a queue delay state. The path queue feature will include fields such as maximum waiting position, average waiting time, current queue number, and maximum queue time. Each parameter can be obtained from the current path message cache queue data and constructed into a feature record to form a path queue status feature.

[0124] S412: Based on the path queuing status characteristics, the message return status of each path is compared, and the message return waiting order of each path and the corresponding service priority label are analyzed using the formula:

[0125]

[0126] Calculate the path dislocation distribution DV and establish the available path mapping data, where SV o Indicates the waiting sequence number for the packet return of path o, LV o Indicates the service priority label number of the o-th path, n DV represents the number of participating paths, and MV represents the number of aggregated service flows;

[0127] The path mismatch distribution quantifies the overall degree of mismatch between the actual return waiting order of packets and their service priority labels when different service data flows are assigned to different paths in the network. This reflects the deviation between the actual execution order and the expected allocation order when multiple paths simultaneously carry service flows of different priorities. This measure takes into account both the total amount of mismatch and the overall activity of service flows (reflected by the number of service flows). It can be used to optimize network link scheduling. By continuously observing its changing trends, it can monitor and determine the coordination of path resource allocation.

[0128] Compare the corresponding order between the message return status and the service priority label of each path one by one, and extract the queue position number of the return message of each path, which is defined as the waiting sequence number SV o , and extract the corresponding service flow priority label number LV o When the actual return order of a data flow is far lower than the position of its service label, a misalignment occurs. For example, in path P1, the service label numbered 7 is marked as priority 1, but it actually appears at position 22 in the queue, forming an obvious deviation. Suppose the number of paths is n DV =3, the participating paths are P1, P2, and P3, and their original data are: SV1=22, LV1=7, SV2=15, LV2=11, SV3=19, LV3=14, and the normalized results are:

[0129] |SV1-LV1|=0.60;

[0130] |SV2-LV2|=0.40;

[0131] |SV3-LV3|=0.33;

[0132] The number of aggregated service flows (MV) is set to 129. After normalization, the value is 11.36. Substitute this into the formula:

[0133]

[0134] The result shows that the path misalignment distribution value DV = 3.81 has exceeded the currently set upper limit of the scheduling consistency benchmark interval of 3.5, indicating that there is a significant priority mismatch between paths within the scheduling cycle. The actual return order of data streams deviates significantly from the expected order of their service labels, and the scheduling order is showing a disordered trend. This value, as a quantitative indicator of the degree of path misalignment, is directly used to determine whether there are scheduling offset anomalies in the current path set and to generate subsequent available path mapping data accordingly. In the formula, the size of the DV value determines whether the corresponding path needs to be screened out for path allocation adjustment. The larger the value, the higher the proportion of misaligned paths that need to be eliminated, which affects the construction boundary of the available path mapping data.

[0135] S413: Based on the available path mapping data, identify available paths with no misaligned data flow forwarding records, match the labels of the priority-critical data flows with the path priority groups, and obtain a path allocation level;

[0136] Traverse the forwarding behavior sequence and data flow forwarding index field recorded in each path, extract the data flow number and forwarding node number combination for each record, compare whether the forwarding path of each data flow in the record is consistent with the target path indicated by its business label, if a data flow appears outside its target path node set, it is judged to be a misplaced forwarding data flow, summarize the number of data flows with misplaced behavior in each path per unit period, if a path has not been detected with a misplaced data flow for five consecutive periods, it is marked as a structurally stable path, record the path number in the stable path set, further match the path in the set with the priority key label in the data flow, extract the data flow number set as a high priority mark in all key data flows, and then match the corresponding priority label in the path priority group according to the number to determine whether the data flow is assigned to its priority For a set of paths with the same level label, if a data flow is marked as "level 1" and its path priority group is "priority path group 1", it is considered a match. If a data flow is marked as "level 1" but is assigned to "priority path group 3", it is recorded as a priority mismatch. The overall priority mapping evaluation is completed by matching each data flow with the path group. The proportion of all high-priority data flows in the current cycle that are accurately assigned is counted. The accuracy of priority assignment is set as follows: above 90% is "high allocation level", 70% to 90% is "medium allocation level", and below 70% is "low allocation level". For example, if there are 100 key data flows in the current cycle and 92 of them are accurately assigned to corresponding path groups, the path assignment level for this cycle is marked as "high allocation level". The evaluation result is output as a combination of path number and corresponding assignment level identifier to obtain the path assignment level.

[0137] See also Figure 6 , the specific steps for obtaining the switching timing judgment signal are:

[0138] S511: Based on the path allocation level, analyze the queuing status trend of the allocated data flow paths in consecutive cycles, compare the queue length and time parameters of each path in adjacent cycles, calculate the queue change amplitude between cycles, determine the distribution pattern of queue data between different paths, and obtain the path queue change trajectory;

[0139] The queue status data of each assigned data flow path is retrieved in continuous cycles, and the number of queued messages, average queue time and maximum waiting number of the path in each cycle are extracted. The time series of queue indicators are constructed with the cycle as the horizontal axis, and the corresponding queue length and time parameters of each path in cycle 1 to cycle N are recorded. When performing the comparison operation, the absolute value of the difference between the queue lengths of two adjacent cycles of each path is taken and arranged in chronological order. If the difference exceeds the queue length set threshold of 10 messages, it is judged as a significant fluctuation. At the same time, the queue time parameters are processed in the same way. If the average queue time of a path is 0.4 seconds in cycle 2 and rises to 1.3 seconds in cycle 3, the time difference is 0.9 seconds, which exceeds the set queue time change threshold of 0.7 seconds, then it is marked as a path segment with drastic queue time changes. During the recording process For each path, a queue length change sequence and a queue time change sequence are generated. Then, the change sequences are aggregated and compared in the entire path set, and the path set with the largest queue state fluctuation in the current scheduling stage is statistically calculated. All associated data flow records are mapped through their path number indexes. Finally, a queue change trajectory structure for each path in consecutive cycles is constructed, where the trajectory structure field contains at least the cycle number, queue length change value, queue time difference, and the maximum queue length value in the corresponding cycle. In actual applications, for example, for path P3 in 10 cycles, the queue length changes from the 3rd to the 6th cycle are 8, 12, and 3, respectively, and the queue time changes are 0.3 seconds, 0.8 seconds, and 0.2 seconds, respectively. In this case, cycle 4 can be marked as the key change point. This path change trajectory record will be used as the core basis for subsequent judgment of fluctuation behavior and switching logic.

[0140] S512: Based on the path queue change trajectory, compare the path return behavior parameters with the response time distribution of each cycle, screen the synchronization characteristics of the path response timing jump section and the queue change peak section, determine the location and structural differences of the overlapping distribution, and obtain the path return fluctuation characteristics;

[0141] The return behavior log of the call path node is used to extract the return response start time, reception time and return status identification field recorded in the log. The response time distribution is calculated in each cycle of each path, and the maximum return time, average return time and number of failed return times are recorded. Within the same cycle range, the queue state change amplitude sequence of each path is aligned with the return time sequence, and the queue change peak value and return response time jump value in each cycle are compared item by item. If both have high amplitude increments at the same time in the same cycle, it is determined that the queue peak segment and the response jump segment are synchronized. The judgment standard is set to be that the queue length changes by more than 10 packets and the return time change exceeds 1 second, which is marked as an overlap phenomenon. All paths that meet this requirement are screened. The periodic segments of the synchronization conditions are recorded, and the corresponding queuing fluctuation structure and return behavior structure are checked for field overlap, including a comparison of the start time, end time, and maximum change time point. If the center points of the two time periods differ by no more than 5 seconds, it is recorded as a structural overlap. Subsequently, all overlapping period numbers and overlapping field difference values ​​are recorded by path number. Finally, the path return fluctuation characteristic structure is generated for each path. In actual scenarios, for example, if the queuing change value of path P5 in cycle 5 is 15 and the average return time increases from 0.5 seconds to 1.7 seconds, and both changes reach the set threshold at the same time, and the time overlap point differs by 3 seconds, it can be recorded as a synchronization fluctuation. The return fluctuation record sequence of this path is constructed and used for the next step of channel status correlation analysis.

[0142] S513: Based on the path return fluctuation characteristics, the channel status identifiers and queue trend mutation segments in the return behavior are analyzed, the path numbers with continuous and drastic changes are selected, the cross-comparison method of the path identifiers and channel status is optimized, the filing order of the channel tags is adjusted, and a switching timing judgment signal is obtained;

[0143] Extract the channel status identification of each path in continuous cycles, retrieve the channel valid status bit, channel load label and channel switching mark value in the identification field, summarize the channel status identification in each cycle, filter out the path number whose channel status mark change value is greater than two digits and the number of continuous cycles exceeds three cycles, and consider that the path has undergone continuous and drastic changes. After summarizing the path numbers, construct a temporary fluctuation path set, and then cross-compare the fluctuation path number with the corresponding queue trend mutation segment. If the number of coincidences between the starting cycle of the mutation segment and the channel status abnormal cycle exceeds twice, it is considered that the path has undergone strong fluctuation behavior synchronously at the state and queue levels. Further arrange the path channel status identification in chronological order, and perform a cross-comparison on the channel mark word in the tag. The segments are reordered, and the priority arrangement rule is used to queue the fluctuating segment tags in advance, and the non-fluctuating segments are arranged in order backward. The record index of the tag field is adjusted to the first field position of the archive structure to ensure that subsequent reads give priority to retrieving the segment status identifier. In this way, the channel tag archiving order is adjusted. In the final output, all path numbers that meet the continuous and drastic changes and structural overlap are summarized to generate a switching timing judgment signal. In the actual example, if the status tag value of path P6 in cycles 3 to 5 changes from 1→4→7→2, and the status difference is greater than two digits, the queue fluctuation record also exists in cycles 3 and 4, which constitutes a switching trigger condition. The path number is marked and entered into the switching timing judgment structure for reference in subsequent channel switching operations.

[0144] A system for optimizing a communication network architecture, the system comprising:

[0145] The data feature collection module, based on edge access devices, analyzes the length parameters of collected data packets, locates the relationship between each length parameter and the protocol port parameter through parameter indexing, categorizes data stream sequences based on business logic, determines the attribution of sequences within the same cycle, and performs structured combination to form sequence clustering features.

[0146] The abnormal distribution identification module analyzes the changes in the pairing between the length sequence and protocol type corresponding to each group of communication behaviors based on sequence clustering features, compares the relationship between port numbers and protocol types, and counts the combined features of matching deviations in communication behaviors. It then summarizes and classifies the data stream features to obtain a pairing abnormal distribution signal.

[0147] The node health assessment module compares the multi-service forwarding response time within the routing forwarding node cluster based on paired abnormal distribution signals, analyzes the node response time distribution in each cycle, determines the cycles in which each node has a low response ratio and delayed responses, and uniformly records the status of abnormal response nodes to obtain node health assessment indicators;

[0148] The path allocation decision module screens unmarked nodes based on node health assessment indicators, analyzes the service queuing status of a single path within the link scheduling path cluster to which the node belongs, compares the return status of packets on each path with the waiting order of the corresponding service priority, and allocates priority-critical data flows to available paths to obtain the path allocation level.

[0149] The channel switching judgment module judges the queuing status trend of the allocated data flow path in a continuous cycle based on the path allocation level, analyzes the changing characteristics of the path return anomaly, and judges the abnormality of the path by the continuous fluctuation amplitude. If the target conditions are met, the data flow channel is adjusted to obtain the switching timing judgment signal.

[0150] A computer device includes a memory and a processor. The memory stores a computer program, and the processor implements the above-mentioned method for optimizing the communication network architecture when executing the computer program.

[0151] The above are merely preferred embodiments of the present invention and do not limit the present invention in any other form. Any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.

Claims

1. A method for optimizing a communication network architecture, characterized in that: The following steps are involved: S1: Based on edge access devices, the collected data packet length parameters are analyzed. The attribution of each length parameter and protocol port parameter is located through indexing. The data stream sequence is classified based on business logic and structured by period to form sequence clustering features. S2: Based on the sequence clustering characteristics, analyze the pairing changes between each group of length sequences and protocol types, compare the relationship between port numbers and protocol types, count the frequency of abnormal combinations, summarize the characteristics and classify them, and obtain the pairing abnormality distribution signal; S3: Based on the paired abnormal distribution signals, compare the multi-service response time of the routing forwarding node, analyze the response time distribution of each cycle, identify cycles with low response ratios and response delays, group them by node identifier, record the abnormal response status, and obtain a node health assessment indicator; S4: Based on the node health assessment indicators, unmarked nodes are screened, the queue status of the paths to which the nodes belong is analyzed, the path message return status is compared with the service priority waiting order, and the key data flows are allocated to the available paths to obtain the path allocation level.

2. The method for optimizing the communication network architecture according to claim 1, wherein: The sequence clustering features include flow pattern type, sequence normalization label, and feature vector set; the paired anomaly distribution signal includes an anomaly combination mark, an offset frequency factor, and a hierarchical identification code; the node health assessment indicator includes a node reliability coefficient, a state fluctuation factor, and a health distribution label; and the path allocation level includes a resource utilization level, a path selection factor, and an allocation priority group.

3. The method for optimizing the communication network architecture according to claim 1, wherein: The steps for obtaining the sequence clustering features are specifically as follows: S111: Based on the edge access device, the packet length parameter and the protocol port parameter are analyzed, the original data streams in the same period are screened, the matching relationship between the length parameter and the port parameter corresponding to each data stream is calculated, the group affiliation is determined, and an affiliation classification identifier set is obtained; S112: Based on the attribution classification identifier set, extract the timestamps of the data flows under each attribution classification, perform time period flow sequence comparison in the order of arrangement, identify data flows with the same business logic number under the same period, uniformly mark them with cluster labels, perform archiving processing, and obtain a label archiving structure sequence; S113: Based on the label archiving structure sequence, statistics are performed on the data packet length distribution characteristics, the belonging number, the sequence index position and the time interval parameters, the behavioral feature difference aggregation amount is calculated, the structured object is embedded, and the structured combination is performed to form a sequence clustering feature.

4. The method for optimizing a communication network architecture according to claim 1, wherein: The steps of obtaining the paired abnormal distribution signal are specifically as follows: S211: Based on the sequence clustering features, extract the length sequence and protocol type of each group of communication behaviors, call the port number, count the number of occurrences of the combination pattern, group and mark each combination protocol type, compare according to the protocol standard combination rules, filter out combinations that deviate from the protocol standard, and obtain an abnormal combination feature set; S212: Based on the abnormal combination feature set, analyze the corresponding distribution of port and protocol mapping for protocol port number, data packet length interval and communication behavior frequency, filter the key results of the combined abnormal extension, merge and mark the protocol segment category, and obtain the classified abnormal combination; S213: Based on the classified abnormal combination, the recurrence frequency of each combination in the continuous monitoring period is summarized, encoded according to the protocol type and combination identifier, and hierarchically classified according to the cumulative change trend of the period to obtain a paired abnormal distribution signal.

5. The method for optimizing the communication network architecture according to claim 1, wherein: The steps for obtaining the node health assessment indicator are specifically as follows: S311: Based on the paired abnormal distribution signal, extract service forwarding records for each node in the routing forwarding node cluster, periodically aggregate the response time of each node within a continuous service cycle according to the node identifier, call the number of response occurrences and response time of each node within the cycle, and statistically analyze the response performance in the cycle data to obtain a cycle response time feature group; S312: Based on the periodic response time feature group, the number of responses and the response delay interval of each node over multiple periods are analyzed. By taking statistics on the number of periodic responses of each node and combining them with delayed response behaviors in consecutive periods, the numbers of nodes with abnormally frequent responses are extracted by comparing the differences in the number of responses, thereby obtaining a set of abnormal response nodes. S313: Based on the response abnormal node set, call the node identification and cycle performance status, uniformly summarize the response times and performance patterns in each node abnormal cycle, organize the cycle stability performance, and organize it by node identification number to obtain the node health assessment index.

6. The method for optimizing the communication network architecture according to claim 1, wherein: The steps for obtaining the path allocation level are specifically as follows: S411: Based on the node health assessment indicator, unmarked nodes are screened, node identifiers are mapped to link path clusters, message queue data for each path in the path set is retrieved, the current number of service requests and the current queue length for each path are counted, and path queue status characteristics are obtained according to the order of data flow queues in the path. S412: Based on the path queuing status characteristics, compare the message return status of each path, analyze the message return waiting order and the corresponding service priority label of each path, calculate the path misalignment distribution, and establish available path mapping data; S413: Based on the available path mapping data, identify available paths with no misplaced data flow forwarding records, match labels of priority-critical data flows with path priority groups, and obtain path allocation levels.

7. The method for optimizing the communication network architecture according to claim 1, wherein: The steps also include: S5: Based on the path allocation level, determine the queuing status trend of the allocated data flow path in consecutive cycles, analyze abnormal changes in the path return, determine path abnormalities by fluctuation amplitude, adjust the data flow channel when conditions are met, and obtain a switching timing determination signal; The switching timing determination signal includes a switching trigger factor, a channel status identifier, and a timing warning identifier.

8. The method for optimizing the communication network architecture according to claim 7, wherein: The steps for obtaining the switching timing determination signal are specifically as follows: S511: Based on the path allocation level, analyze the queuing status trend of the allocated data flow path in consecutive cycles, compare the queue length and time parameters of each path in adjacent cycles, calculate the queue change amplitude between cycles, determine the distribution pattern of queue data between different paths, and obtain the path queue change trajectory; S512: Based on the path queue change trajectory, compare the path return behavior parameters with the response time distribution of each cycle, screen the synchronization characteristics of the path response timing jump section and the queue change peak section, determine the location and structural differences of the overlapping distribution, and obtain the path return fluctuation characteristics; S513: Based on the path return fluctuation characteristics, analyze the channel status identification and queue trend mutation segments in the return behavior, select the path numbers with continuous and drastic change characteristics, optimize the cross-comparison method of path identification and channel status, adjust the archiving order of channel tags, and obtain the switching timing judgment signal.

9. A computer device comprising a memory and a processor, characterized in that: The memory stores a computer program, and when the processor executes the computer program, the method for optimizing the communication network architecture according to any one of claims 1 to 8 is implemented.

10. A system for optimizing communication network architecture, characterized in that: The system is used to implement the method for optimizing the communication network architecture according to any one of claims 1 to 8, and the system includes: The data feature collection module, based on edge access devices, analyzes the length parameters of collected data packets, locates the relationship between each length parameter and the protocol port parameter through parameter indexing, categorizes data stream sequences based on business logic, determines the attribution of sequences within the same cycle, and performs structured combination to form sequence clustering features. The abnormal distribution identification module analyzes the pairing changes between the length sequence and the protocol type corresponding to each group of communication behaviors based on the sequence clustering characteristics, compares the relationship between the port number and the protocol type, counts the combined features of the matching deviations in the communication behaviors, summarizes and grades the data stream features, and obtains the pairing abnormal distribution signal; The node health assessment module compares the multi-service forwarding response time within the routing forwarding node cluster based on the paired abnormal distribution signal, analyzes the response time distribution of each node in each cycle, determines the cycle in which the response ratio of each node is low and the response is delayed, and uniformly records the status of the abnormal response node to obtain the node health assessment index; The path allocation decision module screens unmarked nodes based on the node health assessment indicators, analyzes the service queuing status of a single path within the link scheduling path cluster to which the node belongs, compares the message return status of each path with the waiting order of the corresponding service priority, and allocates priority-critical data flows to available paths to obtain the path allocation level; The channel switching judgment module determines the queuing status trend of the allocated data flow path in a continuous cycle based on the path allocation level, analyzes the changing characteristics of the path return anomaly, and judges the abnormality of the path by the continuous fluctuation amplitude. If the target conditions are met, the data flow channel is adjusted to obtain a switching timing judgment signal.

Citation Information

Cited By

  • Industrial edge data acquisition gateway system and implementation method

    CN122027397A

  • An industrial edge data acquisition gateway system and implementation method

    CN122027397B