Network operation decision-making method, system and equipment based on flow information and medium
By integrating multi-source data and using dynamic decision-making models, the problems of biased and static decision-making in network operations have been solved, achieving accuracy and real-time performance in network resource scheduling and service optimization, and improving network operation efficiency.
Patent Information
- Application Number
- CN202511136504.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-14
- Publication Date
- 2025-10-21
AI Technical Summary
Network operation decisions rely on human experience or single-dimensional traffic data, lack multi-source data integration, have static decision models, limited evaluation indicators, and are difficult to achieve scientific optimization and real-time adjustment.
By acquiring multi-source data, cleaning and standardizing the format, extracting key features, constructing a dynamic decision-making model, generating and evaluating candidate solutions, establishing a closed-loop optimization mechanism, and monitoring and iteratively optimizing decisions in real time.
It has enabled full utilization of multi-source data, improved the scientific nature and real-time nature of decision-making, made resource scheduling more reasonable, optimized business more accurately, and significantly improved network operation efficiency.
Smart Images

Figure CN120825329A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network operation decision-making method, system, device and medium based on traffic intelligence. Background Art
[0002] Network operations decisions often rely on manual empirical analysis or single-dimensional traffic data, such as simple traffic statistics based on network device logs. Some automated tools only process basic network-layer data and lack multi-source data integration. Decision-making models are often static rules that rely on preset thresholds to generate scheduling plans, and evaluation metrics are limited to a single performance parameter. Insufficient integration of multi-source traffic data leads to one-sided decision-making. Data preprocessing lacks standardized processes, and feature extraction is limited to a single dimension, making it difficult to capture dynamic traffic characteristics. Evaluation metrics are incomplete and ignore the balance between cost and service experience.
[0003] Therefore, it is an urgent problem to realize the efficient integration and standardization of multi-source traffic intelligence data, build a comprehensive traffic feature system and dynamic decision-making model, realize the scientific selection and real-time optimization of decision-making solutions, and improve network operation efficiency. To this end, this application proposes a network operation decision-making method based on traffic intelligence. Summary of the Invention
[0004] This application provides a network operation decision-making method, system, device and medium based on traffic intelligence to address the shortcomings of current network operation decision-making solutions.
[0005] On the one hand, the present application provides a network operation decision-making method based on traffic intelligence, which includes the following steps: Step S1: Acquire multi-source data related to network operation, covering network traffic, user behavior and business operation data; Step S2: Clean, deduplicate and standardize the collected data to form a structured intelligence data set; Step S3: Extract key features from the preprocessed intelligence data, construct a traffic feature system, and perform trend analysis in combination with historical operation data; Step S4: Based on traffic characteristics and analysis results, establish an operation decision model to generate candidate decision plans for network resource scheduling and business optimization; Step S5: Quantitatively evaluate the candidate plans through preset evaluation indicators to screen the optimal decision plan.
[0006] In one implementation of the present application, the multi-source data includes: data packet traffic and session connection data at the network layer, user access logs and business request response data at the application layer, and industry traffic trend data of a third-party platform.
[0007] In one implementation of the present application, the key features include: traffic timing characteristics, user behavior characteristics, business load characteristics and abnormal traffic characteristics; the trend analysis includes traffic peak prediction, user behavior preference mining and business bottleneck identification.
[0008] In one implementation of the present application, the operation decision model includes: a traffic prediction sub-model based on machine learning, a resource allocation optimization sub-model and a business scheduling sub-model; the candidate decision schemes include server resource expansion strategy, bandwidth dynamic adjustment strategy and user access path optimization strategy.
[0009] In one implementation of the present application, the preset evaluation indicators include: network throughput improvement rate after decision execution, user access delay reduction rate, service failure rate reduction rate and operating cost saving rate.
[0010] In one implementation of the present application, the method further includes: applying the optimal solution to network operation practice, monitoring the execution effect in real time, and iteratively optimizing the decision model and solution based on feedback data; wherein, the optimization process includes: when it is monitored that the actual execution effect deviates from the expected effect by more than a preset threshold, triggering the model parameter update, regenerating the decision solution and executing it.
[0011] The present application also provides a network operation decision-making system based on traffic intelligence, which includes: a data acquisition module for acquiring multi-source data related to network operation to form original traffic intelligence; an intelligence processing module for cleaning, deduplicating and standardizing the original traffic intelligence and outputting structured intelligence data; a feature analysis module for extracting key features from the structured intelligence data and performing traffic trend and user behavior analysis; a decision generation module for constructing an operation decision model based on the feature analysis results, and generating and optimizing operation decision plans.
[0012] In one implementation of the present application, the data acquisition module supports multi-protocol data access, including TCP / IP, HTTP and WebSocket protocols; the decision generation module has a built-in evaluation index library and supports customized evaluation index weights to adapt to different operating scenarios.
[0013] The present application also provides a network operation decision-making device based on traffic intelligence, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to complete the aforementioned network operation decision-making method based on traffic intelligence.
[0014] The present application also provides a non-volatile computer storage medium for network operation decision-making based on traffic intelligence, which stores computer-executable instructions. The computer-executable instructions are executed by a processor to implement the aforementioned network operation decision-making method based on traffic intelligence.
[0015] The network operation decision-making method, system, device, and medium based on traffic intelligence provided by this application have the following beneficial effects:
[0016] (1) Multi-source data integration to solve the problem of one-sided decision-making: By acquiring multi-source data from the network layer, application layer, and third-party platforms, the limitations of single-dimensional data are broken. This integration method integrates multi-level information such as network operation, user behavior, and industry trends, providing a more comprehensive and three-dimensional intelligence foundation for network operation decisions, avoiding decision-making bias caused by relying solely on single data, and making decision-making more comprehensive.
[0017] (2) Improve data quality and feature analysis depth, and enhance trend prediction capabilities: Through cleaning, deduplication, and format standardization, a structured data set is formed to ensure data consistency and validity. At the same time, traffic time series characteristics, user behavior characteristics, business load characteristics, and abnormal traffic characteristics are extracted, and combined with historical data to predict traffic peaks, explore user behavior preferences, and identify business bottlenecks. This significantly improves the ability to accurately grasp network trends and provides support for early planning of resource scheduling and business optimization.
[0018] (3) Build a dynamic decision-making model to achieve precise operational optimization: Based on the machine learning traffic prediction sub-model, resource allocation optimization sub-model, and business scheduling sub-model, candidate solutions such as server resource expansion, dynamic bandwidth adjustment, and user access path optimization are generated. The optimal solution is evaluated and selected through quantitative indicators such as network throughput improvement rate, user access latency reduction rate, business failure rate reduction rate, and operating cost savings rate. This data- and model-based decision-making method replaces the traditional static rule-based model that relies on preset thresholds, making resource scheduling more reasonable and business optimization more precise, while taking into account both performance improvement and cost control.
[0019] (4) Establish a closed-loop optimization mechanism to ensure that decisions continuously adapt to network dynamics: A real-time monitoring and iterative optimization process is set up. After the optimal solution is applied, the execution effect is monitored by real-time collection of data such as throughput, latency, and failure rate. When the deviation between the actual effect and the expected effect exceeds the preset threshold, the model parameters are updated and the decision solution is regenerated. This closed-loop mechanism of "execution-monitoring-feedback-optimization" ensures that the decision model and solution can quickly respond to dynamic factors such as network traffic fluctuations and changes in user behavior, maintaining the continuous stability and efficiency of network operations. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0021] Figure 1 Flowchart of a network operation decision-making method based on traffic intelligence provided in an embodiment of the present application;
[0022] Figure 2 A diagram showing the composition of a network operation decision-making system based on traffic intelligence provided in an embodiment of the present application;
[0023] Figure 3 Schematic diagram of a network operation decision-making device based on traffic intelligence provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0025] The embodiments of the present application provide a network operation decision-making method, system, device and medium based on traffic intelligence. The technical solutions proposed in the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0026] Figure 1 Flowchart of the network operation decision-making method based on traffic intelligence provided by the embodiment of this application. Figure 1 As shown, the method mainly includes the following steps:
[0027] Step S1: Acquire multi-source data related to network operations, including network traffic, user behavior, and business operation data.
[0028] In an embodiment of the present application, the multi-source data includes: data packet traffic and session connection data at the network layer, user access logs and business request response data at the application layer, and industry traffic trend data of a third-party platform.
[0029] Specifically, the acquisition of multi-source data relies on a distributed collection architecture that is adaptable to multiple protocols: the network layer uses SPAN technology to replicate packet traffic through traffic mirroring modules deployed in core switches, while capturing five-tuple information of session connections based on the NetFlowv9 protocol, and supporting TCP / IP and other protocol parsing; the application layer uses server log aggregation tools to collect user access logs in real time, and embeds SDKs in business systems to asynchronously report request and response data in protobuf format; data from third-party platforms is obtained by regularly calling their open API interfaces, and is included in the collection stream after format conversion to ensure data real-time and integrity.
[0030] Step S2: Clean, deduplicate and standardize the collected data to form a structured intelligence data set.
[0031] In the embodiment of the present application, a hybrid processing framework of "rule engine + machine learning" is used to clean, deduplicate and standardize the collected data. The cleaning stage filters invalid data through preset rules, such as removing repeated heartbeat messages (the same five-tuple data packets with an interval of <10 seconds) in the network layer and invalid access logs with a response code of 404 in the application layer; the deduplication stage uses Bloom filters to quickly check for duplicates in structured fields (such as session IDs and request unique identifiers), and the false positive rate is controlled below 0.001%.
[0032] Format standardization unifies data dimensions: timestamps are converted to millisecond-level Unix time format, IP addresses are mapped to device asset tags, and unstructured firewall alarm descriptions are converted into structured fields through word segmentation and feature encoding, ultimately forming a multidimensional dataset containing "time-source IP-operation type-feature value", providing a consistent input format for subsequent feature extraction.
[0033] Step S3: Extract key features from the preprocessed intelligence data, build a traffic feature system, and perform trend analysis in combination with historical operation data.
[0034] In an embodiment of the present application, the key features include: traffic timing characteristics, user behavior characteristics, business load characteristics and abnormal traffic characteristics; the trend analysis includes traffic peak prediction, user behavior preference mining and business bottleneck identification.
[0035] Specifically, a multi-dimensional feature engineering approach is used to construct a traffic feature system when extracting key features from pre-processed intelligence data. Traffic time series features are extracted using a sliding window algorithm, such as the 5-minute granularity of traffic mean, variance, and fluctuation coefficient. Combined with Fourier transforms, these features decompose daily (24-hour) and weekly (168-hour) traffic patterns, providing time-domain features for peak prediction. User behavior features are acquired through sequence pattern mining, including access path sequences (such as the jump probability from "homepage-product details-payment page"), dwell time distribution (fitted using a Gamma distribution), and spatial clustering results of click hotspots. Business load features focus on server CPU utilization (sampling interval 10 seconds), memory occupancy, and the number of active database connection pools, mapped to the [0,1] interval through normalization. Abnormal traffic features are identified using the isolation forest algorithm, such as burst traffic that deviates by three standard deviations from the baseline and high-frequency port scanning during non-working hours.
[0036] The trend analysis phase integrates the time series model and the rule engine: the traffic peak prediction uses the LSTM network, which inputs the time series features of the previous 72 hours and outputs the traffic peak range for the next four hours (with an error control within 8%); user behavior preference mining uses the Apriori algorithm to discover association rules (such as "70% of users will trigger a download operation after visiting a certain function page"); business bottleneck identification combines load characteristics with threshold alarms. When the server response delay exceeds 200ms and the number of concurrent requests exceeds the threshold, it is marked as a potential bottleneck point, providing an accurate basis for resource scheduling.
[0037] Step S4: Based on the traffic characteristics and analysis results, an operation decision model is established to generate candidate decision plans for network resource scheduling and service optimization.
[0038] In an embodiment of the present application, the operation decision model includes: a traffic prediction sub-model based on machine learning, a resource allocation optimization sub-model and a business scheduling sub-model; the candidate decision schemes include server resource expansion strategy, bandwidth dynamic adjustment strategy and user access path optimization strategy.
[0039] Specifically, the operational decision-making model built based on traffic characteristics and analysis results adopts a three-level "prediction-optimization-scheduling" architecture, generating candidate solutions through the collaborative work of multiple sub-models. The bottom layer is an LSTM-based traffic prediction sub-model, which inputs 72 hours of traffic time series characteristics (such as the mean and fluctuation coefficient at a 5-minute granularity) and outputs the traffic peak range for the next 4 hours (with an error controlled within 8%), providing a time benchmark for resource scheduling. The middle-level resource allocation optimization sub-model is based on a genetic algorithm, with a dual objective function of "maximizing throughput and minimizing cost". Based on business load characteristics such as server CPU utilization and memory usage, it calculates resource expansion thresholds for different nodes (for example, triggering expansion when the load exceeds 80% for 10 minutes), and generates expansion strategies that include the number of new servers and deployment areas. The top-level business scheduling sub-model uses reinforcement learning training, combined with user access path sequences and latency data, to generate dynamic bandwidth adjustment rules (such as increasing the bandwidth priority of popular services by 30% during peak hours) and access path optimization solutions (such as allocating edge nodes based on the user's IP address). The candidate solutions cover 12-15 sub-strategies in three categories: resources, bandwidth, and paths. Each solution is accompanied by execution costs and expected effect parameters, providing a quantitative basis for subsequent evaluation.
[0040] It should be noted that the mathematical modeling of the multi-objective function of the resource allocation optimization sub-model is as follows.
[0041] Objective function:
[0042] Maximize throughput:
[0043]
[0044] Where N is the total number of server nodes participating in resource allocation in the network (such as the number of physical machines or cloud servers in a data center, which is dynamically adjusted according to the size of the cluster and usually ranges from 5 to 500); capacity i is the resource capacity of the i-th server node (unit: Mbps or TPS), which comprehensively reflects the node's bandwidth limit, CPU processing power and memory throughput, and is determined by the hardware configuration (such as high-end server capacity i Up to 1000Mbps, edge nodes may be 100Mbps). i is the load rate of the i-th node (value range 0-1), which is calculated through real-time monitoring (load i Actual processing traffic / maximum carrying traffic), 0 means idle, 1 means full load.
[0045] Minimize costs:
[0046]
[0047] Among them, server_costi is the unit time operation cost of the i-th server node (unit: yuan / hour), including hardware depreciation, energy consumption and maintenance costs (such as physical server server_cost i About 5-10 yuan / hour, cloud server elastic billing may be as low as 0.5 yuan / hour). bandwidth_cost i is the bandwidth usage cost of the i-th node (unit: yuan / Gbps·hour), which is determined by the operator's pricing and the actual bandwidth used (for example, the bandwidth cost during peak hours may be 30% higher than that during off-peak hours).
[0048] Load balancing:
[0049]
[0050] in, is the average load rate of all nodes, The value range is 0-1. i is the load rate of the i-th node. Constraint "≤0.15": The load balancing threshold (range 0-1), indicating that the relative deviation of the node load from the average value must be controlled within 15% (exceeding this value triggers resource scheduling).
[0051] Step S5: Quantitatively evaluate the candidate solutions using preset evaluation indicators to select the optimal decision solution.
[0052] In an embodiment of the present application, the preset evaluation indicators include: the network throughput improvement rate after the decision is executed, the user access delay reduction rate, the service failure rate reduction rate and the operating cost saving rate.
[0053] It should be noted that when quantitatively evaluating candidate solutions using preset evaluation indicators, a weighted scoring model is used to achieve multi-dimensional optimization. First, an evaluation indicator system is constructed, and the quantitative values of each indicator are calculated using the following formula: Network throughput improvement rate = (post-optimization throughput - pre-optimization throughput) / pre-optimization throughput × 100%, accurate to two decimal places, with a sampling period of 5 minutes and an average taken; User access delay reduction rate is calculated based on the 95th percentile delay, using the formula (baseline delay - post-optimization delay) / baseline delay × 100%, excluding single extreme value interference; Business failure rate reduction rate is the percentage reduction in the number of service interruptions per unit time, weighted by the number of users affected by the failure; Operating cost savings rate covers explicit costs such as server leasing and bandwidth resources, and is calculated as (original solution cost - optimized solution cost) / original solution cost × 100%.
[0054] During the evaluation process, the Analytic Hierarchy Process (AHP) was used to determine indicator weights. For example, in core business scenarios, user access latency was weighted at 35%, operating costs at 25%, and throughput and failure rate at 20% each. The system automatically calculated a weighted score for each candidate (out of 100). When the score difference was less than 5%, a secondary evaluation was triggered, incorporating decision execution complexity (such as the deployment time required for server expansion) as a supplementary indicator. Ultimately, the solution with the best overall benefits was selected, ensuring that the evaluation results balanced performance improvement with cost control.
[0055] Furthermore, after step S5, the method further includes: applying the optimal solution to network operation practice, monitoring the execution effect in real time, and iteratively optimizing the decision model and solution based on feedback data; wherein, the optimization process includes: when it is monitored that the deviation between the actual execution effect and the expected effect exceeds a preset threshold, triggering the model parameter update, regenerating the decision solution and executing it.
[0056] Specifically, when applying optimal solutions to network operations, dynamic optimization is achieved through a real-time monitoring engine and closed-loop feedback mechanism. During the deployment phase, decision-making solutions are converted into executable instructions (such as container orchestration scripts for server expansion and QoS configuration parameters for bandwidth adjustment) through APIs. These instructions are then integrated with the network performance monitoring system (collected via SNMP) and service tracking data (over 3,000 logs per second), establishing an "execution-monitoring-feedback" chain.
[0057] Furthermore, real-time monitoring focuses on four core metrics: throughput fluctuation (sampling interval: 10 seconds), latency percentile (95th percentile latency), fault alarm frequency, and resource consumption cost. These metrics are stored and trended in a time series database (such as InfluxDB). When the deviation between the actual and expected values exceeds a preset threshold (e.g., latency reduction rate falls below 15% of the expected value, or cost savings rate deviates by ±20%), the model's adaptive update mechanism is triggered. The parameter tuning module is invoked, and based on the feedback data, gradient descent is used to modify the LSTM weights of the traffic prediction submodel (with a learning rate set to 0.001). The genetic algorithm fitness function of the resource allocation submodel is then retrained.
[0058] Finally, the optimized model generates a new decision-making plan, and the effect is verified through a grayscale release strategy (covering 30% of traffic first). After confirming that the indicators meet the standards, full deployment is carried out. The entire iteration cycle is controlled within 15 minutes, ensuring a rapid response to traffic fluctuations and maintaining the continuous stability of network operations.
[0059] It should be noted that the traffic prediction sub-model is a spatiotemporal perception network architecture that integrates multi-dimensional features. Spatial feature layer: uses graph convolutional network (GCN) to model the network topology, inputs the connection relationship matrix (adjacency matrix) between nodes, and outputs the spatial dependency features of each node (such as link bandwidth utilization and node load distribution). Temporal feature layer: Improved CNN-LSTM-Attention architecture, with the following specific parameters: CNN layer: 3 1D convolution blocks, convolution kernel sizes of 5, 3, and 3, stride 1, padding 2, activation function LeakyReLU (α=0.1), and the number of output channels is 64, 128, and 256 respectively. LSTM layer: 2 layers of bidirectional LSTM stacked, 128 units per layer, dropout=0.2, and the return sequence is used for attention calculation. Attention mechanism: Bahdanau attention is used to calculate the energy value of each time step: e t,i =tanh(W h h t +W s s i +b)
[0060] Among them, h t is the LSTM output, s i It is the CNN output, generates weight coefficients through Softmax, and finally outputs the weighted time series feature vector.
[0061] In an embodiment of the present application, a dynamic threshold self-calibration mechanism can also be set. This mechanism optimizes the threshold parameters of the evaluation index in real time through reinforcement learning, solving the problem of insufficient adaptability of fixed thresholds in complex traffic scenarios. Specifically, the system will construct a reward function for threshold adjustment based on the historical 14-day decision execution data: when the actual deviation is within the threshold range and the decision effect meets the standard, a positive reward is given (reward value = 0.8×throughput improvement rate + 0.2×cost saving rate); when the deviation exceeds the threshold but the effect recovers after the model is quickly corrected, a neutral reward is given; when the deviation continues to exceed the threshold and causes damage to the business, a negative penalty is given. The threshold adjustment model is trained through the deep deterministic policy gradient (DDPG) algorithm, and a threshold update recommendation is generated every hour (such as dynamically adjusting the delay deviation threshold from 15% to a range of 12%-18%), and elastic calibration is performed in combination with the real-time traffic fluctuation coefficient (such as relaxing the peak period to 20%).
[0062] The above is a network operation decision-making method based on traffic intelligence provided by an embodiment of the present application. Based on the same inventive concept, an embodiment of the present application also provides a network operation decision-making system based on traffic intelligence. Figure 2 The network operation decision system based on traffic intelligence provided in the embodiment of the present application is composed of a diagram, such as Figure 2As shown, the system mainly includes: a data acquisition module 201, which is used to obtain multi-source data related to network operations and form raw traffic intelligence; an intelligence processing module 202, which is used to clean, deduplicate and standardize the raw traffic intelligence and output structured intelligence data; a feature analysis module 203, which is used to extract key features from structured intelligence data and perform traffic trend and user behavior analysis; a decision generation module 204, which is used to build an operation decision model based on the feature analysis results, generate and optimize operation decision plans. The data acquisition module supports multi-protocol data access, including TCP / IP, HTTP and WebSocket protocols; the decision generation module has a built-in evaluation index library and supports customized evaluation index weights to adapt to different operation scenarios.
[0063] The above is a network operation decision system based on traffic intelligence provided by an embodiment of the present application. Based on the same inventive concept, an embodiment of the present application also provides a network operation decision device based on traffic intelligence. Figure 3 A schematic diagram of a network operation decision-making device based on traffic intelligence provided in an embodiment of the present application is shown as follows: Figure 3 As shown, the device mainly includes: at least one processor 301; and a memory 302 communicatively connected to the at least one processor; wherein the memory 302 stores instructions that can be executed by the at least one processor 301, and the instructions are executed by the at least one processor 301 so that the at least one processor 301 can complete the aforementioned network operation decision-making method based on traffic intelligence.
[0064] In addition, an embodiment of the present application also provides a non-volatile computer storage medium for network operation decision-making based on traffic intelligence, which stores computer-executable instructions, and the computer-executable instructions are executed by a processor to implement the aforementioned network operation decision-making method based on traffic intelligence.
[0065] The following is an example of a specific application scenario.
[0066] The industrial Internet platform of a large-scale intelligent automobile manufacturing plant covers more than 1,200 industrial robots, more than 300 PLC control systems, more than 50 industrial servers and more than 2,000 IoT terminals in the four major production workshops of stamping, welding, painting and assembly. Data interoperability is achieved through industrial Ethernet with the MES system and ERP system. The factory has long faced security threats such as equipment firmware tampering, production instruction hijacking, and data transmission theft. Traditional security operations rely on manual analysis of firewall logs and equipment alarms, which have problems such as delayed threat identification, high false alarm rate (about 35%), and cumbersome response processes. There is an urgent need to improve security operation efficiency through intelligent means. Based on the above-mentioned network operation decision-making method and system based on traffic intelligence, the factory has built an industrial Internet security intelligent operation platform to realize automatic threat analysis and dynamic response, which is applied to normalized security operations and quarterly security drills.
[0067] The system accesses multi-source security intelligence through the data acquisition module: at the industrial network traffic level, it collects VLAN traffic of the workshop core switch (covering industrial protocols such as Modbus and Profinet) and device communication data packets of the edge gateway, processing approximately 5,000 traffic records per second; at the device and system log level, it integrates PLC operation logs, SCADA system operation records, MES system abnormal login logs and industrial firewall interception records; at the external threat intelligence level, it connects to the industry threat intelligence platform to obtain APT attack IOCs (such as malicious IP, feature codes) and vulnerability intelligence (such as PLC firmware vulnerabilities and industrial software vulnerabilities) targeting the automotive manufacturing industry.
[0068] A standardized cleaning process is used in the preprocessing stage: repeated heartbeat messages and normal operation logs (such as equipment scheduled inspection records) are filtered through the rule engine, and abnormal communication features (such as PLC configuration modification instructions during non-working hours) are retained; unstructured data (such as natural language alarm descriptions of firewalls) are segmented and feature encoded, and converted into structured fields; the timestamp format is unified (accurate to milliseconds), and the device IP and asset ledger are associated to form a standardized data set containing "time-source IP-destination IP-protocol-operation type-threat label", laying the foundation for subsequent feature extraction.
[0069] The feature analysis module extracts three core features from the preprocessed data: one is the traffic timing feature, including the diurnal fluctuation coefficient of the device communication frequency and the time interval between abnormal instruction outbreaks (such as five consecutive unauthorized write operations within one hour); the second is the behavioral baseline feature, which builds a device communication whitelist through 72 hours of historical normal data (such as a welding robot that only communicates with port 8080 of the MES server) and calculates the deviation of real-time behavior; the third is the threat association feature, which matches the IP and port in the traffic with the threat intelligence IOC to generate a threat matching score (0-10 points).
[0070] The decision model adopts a hierarchical construction strategy: the bottom layer is the anomaly detection sub-model, which predicts traffic trends based on the LSTM network, and marks it as an anomaly when the actual traffic deviates from the predicted value by 3 times the standard deviation; the middle layer is the threat analysis sub-model, which associates abnormal behaviors with historical handling cases through knowledge graphs (such as the characteristics of PLC firmware tampering incidents of a certain car company in 2023), and outputs the probability of threat types (such as the probability of "firmware tampering" is 85%, and the probability of "data theft" is 12%); the top layer is the response decision sub-model, which combines the factory production priority (such as the final assembly workshop is higher than the spare parts warehouse) to generate candidate solutions, including "temporarily isolating the equipment involved + blocking abnormal ports", "updating firewall rules + alerting the security team", etc. The solutions are accompanied by execution time (such as the isolation operation takes 2 minutes) and production impact (such as the risk level of line stoppage).
[0071] During normal operations, the system displays the threat handling process in real time through a zero-code interactive interface. When a painting robot is detected sending batch production drawings to an external IP at 2 a.m. (threat match score 9, behavioral deviation score 8.2), the model identifies it as a "high-risk data theft" and automatically triggers the optimal solution: first, the industrial firewall blocks the IP communication (taking 15 seconds), while simultaneously sending an alert (including the device location and associated production batches) to the security operations dashboard and invoking an API to notify the MES system to suspend the robot's data upload permissions. Security personnel can confirm the handling with a single click on the interface, and the system automatically records the response time (an average of 47 seconds from detection to blocking, an 85% reduction compared to manual handling).
[0072] The dynamic optimization mechanism continuously iterates through closed-loop feedback: daily operational reports are generated, counting false positives (such as misjudging a device restart as an abnormal login) and correcting behavioral baseline thresholds; when simulating a "new ransomware attack" in quarterly security drills, the characteristic data generated by the drills (such as the transmission protocol characteristics of encrypted files) are incorporated into the model training set, increasing the model's recognition rate for unknown threats by 20%; and decision weights are adjusted according to production plans (such as reducing the sensitivity of equipment isolation during production line switching to avoid accidental line stops). After six months of operation, the factory's average response time to security incidents has been reduced from 2 hours to 1.5 minutes, the false alarm rate has dropped to 8%, and there have been no more production interruptions due to security incidents.
[0073] This implementation demonstrates the effectiveness of traffic intelligence-based decision-making in the field of industrial internet security: By integrating multi-source data to overcome information silos, dynamic models enable accurate threat identification and graded responses, and closed-loop optimization mechanisms adapt to the complexities of industrial scenarios, providing a reusable intelligent solution for the security operations of large-scale manufacturing enterprises. In the annual industry security assessment, the factory's security operations maturity was upgraded from "passive response" to "active prediction," significantly enhancing the risk resilience of the industrial internet infrastructure.
[0074] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0075] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0076] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0077] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0078] The various embodiments in this application are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences from other embodiments. In particular, the device embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the partial description of the method embodiments.
[0079] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0080] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A network operation decision-making method based on traffic intelligence, characterized in that: The method comprises the following steps: Step S1: Acquire multi-source data related to network operations, including network traffic, user behavior, and business operation data; Step S2: Clean, remove duplicates, and standardize the collected data to form a structured intelligence data set; Step S3: Extract key features from the pre-processed intelligence data, build a traffic feature system, and perform trend analysis based on historical operation data; Step S4: Based on the traffic characteristics and analysis results, an operation decision model is established to generate candidate decision plans for network resource scheduling and service optimization; Step S5: Quantitatively evaluate the candidate solutions using preset evaluation indicators to select the optimal decision solution.
2. The network operation decision-making method based on traffic intelligence according to claim 1 is characterized in that: The multi-source data includes: data packet traffic and session connection data at the network layer, user access logs and business request response data at the application layer, and industry traffic trend data from third-party platforms.
3. The network operation decision-making method based on traffic intelligence according to claim 1 is characterized in that: The key features include: traffic timing features, user behavior features, business load features and abnormal traffic features; the trend analysis includes traffic peak prediction, user behavior preference mining and business bottleneck identification.
4. The network operation decision-making method based on traffic intelligence according to claim 1 is characterized in that: The operation decision model includes: a traffic prediction sub-model based on machine learning, a resource allocation optimization sub-model and a business scheduling sub-model; the candidate decision plans include server resource expansion strategy, bandwidth dynamic adjustment strategy and user access path optimization strategy.
5. The network operation decision-making method based on traffic intelligence according to claim 1 is characterized in that: The preset evaluation indicators include: network throughput improvement rate after decision execution, user access delay reduction rate, service failure rate reduction rate and operating cost saving rate.
6. The network operation decision-making method based on traffic intelligence according to claim 1, characterized in that: The method also includes: applying the optimal solution to network operation practice, monitoring the execution effect in real time, and iteratively optimizing the decision model and solution based on feedback data; wherein the optimization process includes: when it is monitored that the deviation between the actual execution effect and the expected effect exceeds a preset threshold, triggering the update of model parameters, regenerating the decision solution and executing it.
7. The network operation decision system based on traffic intelligence is characterized by: The system comprises: Data collection module, used to obtain multi-source data related to network operations and form raw traffic intelligence; The intelligence processing module is used to clean, deduplicate, and standardize raw traffic intelligence and output structured intelligence data; Feature analysis module, used to extract key features from structured intelligence data and analyze traffic trends and user behavior; The decision generation module is used to build an operation decision model based on the feature analysis results and generate an operation decision plan.
8. The network operation decision system based on traffic intelligence according to claim 7 is characterized in that: The data acquisition module supports multi-protocol data access, including TCP / IP, HTTP and WebSocket protocols; the decision generation module has a built-in evaluation index library and supports customized evaluation index weights to adapt to different operating scenarios.
9. Network operation decision-making equipment based on traffic intelligence, characterized by: The device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can complete the network operation decision-making method based on traffic intelligence as described in any one of claims 1-6.
10. A non-volatile computer storage medium for network operation decisions based on traffic intelligence, storing computer-executable instructions, characterized in that: The computer-executable instructions are executed by a processor to implement the network operation decision-making method based on traffic intelligence as described in any one of claims 1-6.
Citation Information
Cited By
Intelligent vehicle management and safety system performance evaluation and optimization method
CN121187916A