A non-stress measurement method for the availability of network agent services, and system thereof

A non-stress measurement method using data sampling and graph learning technology addresses inefficiencies in evaluating proxy service availability, ensuring real-time accuracy and robustness against network dynamics and attacks, enhancing network security and stability.

WO2026030881A1PCT designated stage Publication Date: 2026-02-12INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/109972
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-06
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing methods for evaluating network proxy service performance and availability are inefficient, time-consuming, and lack real-time accuracy, particularly in dynamic and complex network environments, and are prone to failure against unknown attacks.

Method used

A non-stress measurement method using advanced data sampling, time series prediction, and graph learning technology to evaluate proxy service availability in real-time, incorporating data set construction, model training, and multi-probe index data collection, with a robust graph learning and prediction model to ensure accurate and reliable evaluation.

Benefits of technology

Enables real-time, efficient, and accurate evaluation of proxy service availability, reducing the risk of network instability and improving network security and stability by providing a reliable tool for administrators to maintain and optimize proxy services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024109972_12022026_PF_FP_ABST
    Figure CN2024109972_12022026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of network management, and relates to a non-stress measurement method for the availability of network agent service (s), and system thereof. By adopting advanced data sampling, time series prediction and machine learning technology, the present invention can evaluate the availability of proxy services in real time and accurately, which is helpful for network administrators to better monitor, maintain and optimize proxy services and improve the overall security and stability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

A Non-stress Measurement Method for the Availability of Network Agent Services, and System thereofTechnical Field

[0001] The present invention belongs to the technical field of network management, and specifically relates to the performance measurement technology of network agent service (s) , in particular to a non-stress measurement method and system for evaluating the availability of network agent service (s) based on graph learning.

[0002] Background Arts

[0003] With the rapid development and popularization of network technology, proxy service, as an indispensable component in the network, its performance and availability have become the key to the safe and stable operation of the network. However, the performance of agent (proxy) service is influenced by many factors such as programming language, method and network environment, which makes it a complex system. Therefore, it is very complicated to evaluate its performance. Traditional stress testing methods often take a long time and can't meet the real-time evaluation requirements of agency service availability quickly and accurately.

[0004] In the current network environment, because proxy service is usually the intermediate node of network data transmission, it may face various attacks and threats from the network, such as DDoS attacks, phishing attacks and man-in-the-middle attacks. Attackers may try to steal, tamper with or destroy the data through proxy services by various means, such as taking advantage of loopholes in proxy services.

[0005] In order to counter these potential threats and attacks, researchers and engineers have developed various methods and tools, such as intrusion detection system (IDS) and firewall, to monitor and protect proxy services. However, these methods usually rely on predefined rules and patterns, and may not be able to effectively identify and prevent new and unknown attacks.

[0006] In addition, due to the complexity of proxy service, its performance and availability may be affected by different network conditions and configurations. The following are some common factors:

[0007] (1) Bandwidth: The bandwidth of the proxy server determines how much data traffic it can handle. Higher bandwidth means faster transmission speed and less delay.

[0008] (2) Processor: The processor performance of the proxy server has a great influence on the  number of requests it can handle and the response time. The faster the processor, the faster the proxy server can process requests and responses.

[0009] (3) Memory: The memory of the proxy server determines how many connections and requests it can handle at the same time. More memory can improve the performance of the proxy server.

[0010] (4) Hard disk: The performance of the hard disk of the proxy server has a great influence on caching and storing data. Faster hard disks can improve the performance of proxy servers.

[0011] (5) Network topology: The location of the proxy server and the network topology it is connected to will also affect the performance. The closer the proxy server is to the client and the target server, the better the performance will be.

[0012] (6) Cache setting: The cache setting of proxy server has great influence on response time and bandwidth usage. Reasonable cache settings can reduce the number of requests to the target server, thus improving performance.

[0013] (7) Security settings: The security settings of the proxy server will also affect the performance. Tighter security settings will increase the load and response time of the proxy server, but it can improve security.

[0014] (8) Concurrent connection: The number of concurrent connections of the proxy server will also affect the performance. A higher number of concurrent connections can improve the performance of the proxy server, but it may also increase the load and response time.

[0015] These factors are usually interrelated, and optimizing one of them may affect other factors. Therefore, the performance optimization of proxy server needs to consider many factors comprehensively. In order to ensure the stable operation of the proxy service, a real-time and accurate method is needed to evaluate the performance and availability of the proxy service. However, at present, there is no efficient evaluation method for non-pressure measurement of agency services.Summary of the invention

[0016] Based on the above background, the present invention proposes a novel non-stress measurement method for network proxy service availability. By adopting advanced data sampling, time series prediction and machine learning technology, this method can evaluate the availability of proxy services in real time and accurately, which is helpful for network administrators to better monitor, maintain and optimize proxy services and improve the overall security and stability of the network.

[0017] The non-stress measurement method for the availability of network agent services of the present invention, comprising

[0018] acquiring network bandwidth indicator data, network quality indicator data and agent software indicator data for feature extraction respectively;

[0019] building traffic graph according to extracted features;

[0020] constructing and training a graph learning and prediction model based on the traffic graph;

[0021] measuring the availability of the network agent service to be measured according to the trained graph learning and prediction model.

[0022] The non-stress measurement system for the availability of network agent services of the present invention, including

[0023] data set construction module for the construction of various multi-dimensional indexes of the training data set of the model;

[0024] model training module for the training of the model;

[0025] task scheduling module for the scheduling of all tasks in the system including data collection, model training and output of prediction results;

[0026] multi-probe multi-dimensional index data collection module for multi-dimensional index data collection;

[0027] model prediction result output module for the output of the availability of the network agent service.

[0028] The present invention proposes a non-pressure measurement method of network proxy service availability. Aiming at the problem of how to evaluate the availability of agency services in a non-pressure way, this method comprehensively considers the network environment parameters and the real-time performance of agency services, and realizes the efficient evaluation of the availability of agency services in an automated way. It is understood that there is no scheme to measure the proxy service through non-pressure method in the existing research. Compared with the traditional stress testing method, this patent method pays more attention to the real-time and dynamic evaluation of agency services in the real network environment, making the evaluation results more accurate and reliable.

[0029] The method of the present invention realizes the efficient and accurate evaluation of the availability of proxy services in the running process, and ensures the stable operation of proxy services under various network conditions.

[0030] By applying a variety of advanced data sampling tools and time series prediction models, this method can realize real-time monitoring and evaluation of proxy services, and effectively reduce the risk of proxy service interruption caused by network instability, programming errors and malicious attacks.

[0031] In addition, this method ensures the accuracy and robustness of the evaluation model by implementing hypothesis testing and parameter adjustment strategies, and provides a powerful tool for network administrators to maintain and optimize the performance and stability of proxy services, thus improving the reliability and security of the whole network system.

[0032] Compared with the published related technologies, the method and the system mainly have the following advantages:

[0033] 1. The present invention provides an agent service availability evaluation model based on graph learning, which is different from the conventional pressure measurement method and can evaluate the performance of the agent service more efficiently and accurately. By using a variety of contracting tools such as ab and iperf3, the network environment parameters are comprehensively sampled to obtain more accurate and comprehensive basic network parameters.

[0034] 2. In the aspect of feature collection, the invention uses a high-performance contracting tool constructed by Go language, and obtains basic network parameters, such as packet loss rate and number of successful requests, from tcp connection and pcap at the measuring end and the receiving end respectively, so as to eliminate the error influence of multiple factors and ensure the accuracy of the evaluation result.

[0035] 3. In terms of model construction, this approach constructs a flow graph to study the correlations between different flows and then uses graph neural networks for regression prediction. This method can quickly and accurately predict the availability of agency services from different perspectives and obtain the final prediction result through statistical methods such as extreme value elimination.

[0036] 4. The invention also introduces the steps of hypothesis testing and parameter adjustment, and ensures the robustness and reliability of the model in practical application by screening and optimizing independent variables, and verifying the model results by actual deployment and simulating CC attacks.

[0037] 5. Generally speaking, compared with the prior art, the invention has the advantages of accurate evaluation effect, high efficiency, robust and reliable model and the like, and can better meet the  requirements of agency service availability evaluation.Brief Description of Drawings

[0038] Figure 1 Schema of the method of the present invention

[0039] Figure 2 Architecture diagram of ProxyGAT Model

[0040] Figure 3 Architecture diagram of the system of the present inventionDetailed Description of the invention

[0041] As shown in Figure 1, the non-stress measurement method of network proxy service availability based on graph learning of the present invention mainly includes data acquisition and graph learning and forecasting. Next, these two parts will be introduced in detail, along with the non-pressure measurement system for network proxy service availability based on graph learning.

[0042] 1. Data sampling

[0043] Using a variety of contracting tools, the network environment parameters are sampled at the measuring end and the receiving end, and basic network parameters such as packet loss rate and number of successful requests are obtained. In the process of sampling, irregular and abnormal data packets are effectively filtered out by regulating and unifying the input format, thus ensuring the data quality. The main purpose of this part is to build a data set for model training and testing. The details of this step are as follows:

[0044] 1.1 Step 1: Data acquisition of standard test data label Y.

[0045] The key difficulty in this part is how to obtain accurate actual performance data of proxy services. Because of network fluctuation, application realization, network bandwidth and other reasons, the factors that affect the actual performance of an agent are often complicated, and the server results measured in different environments are often different.

[0046] The solution of the invention is as follows: for a given proxy server (including Socks4, Socks5 and HTTP) , we measure the upper limit of its proxy performance through various pressure methods, and take the maximum of all the results. The agent performance is mainly measured by two indicators, including BPS (Bits Per Second) and QPS (Queries Per Second) . BPS stands for the number of bits transmitted per second, which is a unit of rate and is used to describe the speed of digital information transmission or the speed of network connection. In network and performance testing, QPS stands for the rate of request query per second, which is used to measure the performance and load capacity of the system. It is usually used to describe the number of query requests that a database or server can handle per second.

[0047] (1) Mode 1: A contracting tool constructed with Go language.

[0048] It is measured by using the high-performance contracting tool ab (Apache Benchmark) built by Go language. The tool can be connected to the proxy service and measure the values of QPS(Queries Per Second) and BPS (Bits Per Second) in real time according to the returned results. This method focuses on using the performance of ab tool to obtain accurate measurement results through accurate and efficient packet transmission.

[0049] (2) Mode 2: Use multi-thread pressure measuring tools.

[0050] Use multi-thread stress measurement tools, such as JMeter, to connect to the proxy service and use it in combination with the Web application on the server side. This combination can measure QPS and BPS values in real time, and ensure accurate performance indicators in the actual operating environment. The use of multithreading can simulate the scene of multi-user concurrent access, which is closer to the actual network environment.

[0051] (3) Mode 3: Use distributed DDos attack tools.

[0052] Use the commonly used distributed DDOS (Distributed Denial of Service) attack tools, such as LOIC (Low Orbit Ion Cannon) , to connect to the proxy service for contracting. At the same time, start the Web application on the server side and measure the QPS and BPS values in real time. This method can simulate the performance of the server under extreme conditions (such as DDoS attacks) and help us better understand the performance and stability of the server under high pressure.

[0053] Traditional time series prediction is generally divided into time series regression and time series classification tasks. The performance of proxy service is actually a rough estimate, and each measurement is greatly affected by unused factors. According to the needs of proxy service performance measurement and the characteristics of its problems, we designed a measurement result grading strategy. Divide it into different levels of order of magnitude in detail.

[0054] 1.2 Step 2: Data collection of independent variable X.

[0055] The key part of this part lies in how to construct comprehensive independent variable characteristics at a faster speed. By measuring the characteristics of agent services in different dimensions, we can measure the variables of an agent to the greatest extent. Our collection characteristics include: server-side traffic characteristics, measuring client-side performance characteristics and proxy server active detection characteristics.

[0056] Characteristics of server-side traffic in 1.2.1

[0057] On the measurement server side, firstly, tcpdump is used to capture traffic data. Then the  corresponding traffic is filtered out according to the IP value of the agent to be measured. Then CICFlowMeter is used to extract stream-level features. For each divided network flow, the source address and destination address are determined according to the transmission direction of the first data packet. After removing irrelevant information such as IP address and port, we keep 76-dimensional features, which can be roughly divided into the following four categories.

[0058] Aggregation characteristics: Aggregation characteristics are the overall characteristics of traffic based on network flow, including total duration, total number of packets, total length of packets, etc.

[0059] Time characteristics: time characteristics mainly include the original and statistical characteristics related to time, including the average time between contracts and the total time between contracts.

[0060] Statistical characteristics: statistical characteristics are the characteristics obtained by statistics based on packet size (excluding aggregation characteristics) , including the number of uplink packets per second, the average packet length, the standard deviation of packet length, etc.

[0061] Content characteristics: Content characteristics are the characteristics of content fields of data packets, including the number of FIN packets, SYN packets and ACK packets.

[0062] Details of the extracted features are shown in Table 1. The initial features extracted from traffic packets are identified according to the flow. Specifically, for a certain proxy service, its characteristics are equal to the average of all the flow characteristics associated with it. In order to accelerate the convergence of model training, we normalized the flow characteristics to the maximum and minimum. After normalization, all data are converted into floating-point data in the range of 0-1.

[0063] Table 1 Detailed Table of Flow Characteristics

[0064] 1.2.2 measures client-side performance characteristics.

[0065] On the measurement client side, we use a variety of ways to comprehensively evaluate the performance of the agent under a small number of non-pressure measurement requests.

[0066] (1) The combination of iperf3 and proxychains is used to measure the values of limit bandwidth, delay jitter and packet loss rate. In order to ensure the stability of the test, all the results were tested for 5 times and averaged.

[0067] (2) Main detection module. In this module, the ab stress testing tool rewritten by go language is used to contract out the applications on the tested server with different orders of magnitude and different concurrent numbers, and the measurement data of network indicators are obtained. These data include the amount of data transmitted, the number of requests transmitted per second, the average transmission time of each request, the request completion rate and the number of concurrent requests.

[0068] (3) Measure the auxiliary network indicators through pymeter. Through this module, you can call the jmeter framework on the command line to realize the measurement. This module is mainly used to realize the measurement service architecture of measurement end-> proxy end-> sniffer end (application layer) , and its parameter collection is completed at the measurement client. This part of the indicators mainly includes the request packet loss rate, the amount of data transmitted, the number of requests transmitted per second, the average time of each request transmission, the number of concurrent requests, bandwidth and delay jitter.

[0069] Active detection characteristics of 1.2.3 proxy service

[0070] This part mainly determines the type of proxy by constructing the connection test package, such as Socks5, Socks4 or HTTP proxy. Secondly, by sending probe data packets, its types are determined. At present, there are two types, high-performance agents and ordinary agents. For  different types of agents, we will build different prediction models.

[0071] 2. Model construction and prediction

[0072] 2.1 Model construction

[0073] The key to model construction is building a robust graph learning and forecasting model to capture and fit the complex relationships between different flows and predicted values. In this paper, a state-of-the-art graph neural network model (ProxyGAT) is employed to quickly predict the availability of agency services from various perspectives. The graph learning mechanism is then used to integrate and refine the results, ensuring a comprehensive and accurate prediction.

[0074] Graph Construction Method

[0075] To extract graph structure features more comprehensively, we use a sliding window approach to sample the graph data. Within each traffic sliding window, we count the number of packet connections between any two nodes. Next, an edge is constructed between the nodes with more than one connection. ProxyGAT automatically learns the weights between different nodes through the attention mechanism. Thus the weights of all edges are set to be equal. The combined edge data and node data are the corresponding traffic graph data. We input all node features and edge data into the graph neural network (GNN) to reduce the reliance on expert knowledge. The complex feature selection process can be omitted by the graph neural network's powerful automatic feature selection capability. As shown in Algorithm 1, after generating the sliding traffic windows, all the sliding traffic windows are processed to generate traffic graphs sequentially. Each window corresponds to the generation of a traffic graph sample.

[0076] GAT Model Construction

[0077] GAT adds the attention mechanism to GCN. During the aggregation process of the GCN, the feature weights of all adjacent nodes are equal. In contrast, GAT uses the weighted representations of neighbor nodes to update nodes. GAT uses the multi-head attention mechanism to learn node features of different dimensions. In this work, we use three attention heads. Lines of different styles represent different dimensions of graph attention calculations. Finally, GAT combines the results of K times to obtain the final vector representation of this node. GAT adaptively learns the weights of different neighbor nodes from different dimensions, which enhances the expressive ability of the graph neural network.

[0078] Architecture of ProxyGAT Model

[0079] As shown in Figure 2, we obtained the optimal model structure after parameter optimization. The first two layers of the ProxyGAT are two consistent-shaped graph attention convolution layers. Both layers have sixty-four hidden layer cells, eight attention heads, and Relu activation functions. Moreover, they are separated by a dropout layer with a dropout rate of 0.5. After two graph attention convolution layers is a global average pooling layer. Finally, there is a linear layer of size 100. The activation function of the output node is the LogSoftmax function. LogSoftmax function can speed up the convergence, improve data stability and prevent data overflow.

Claims

1.A non-stress measurement method for the availability of network agent services, comprisingacquiring network bandwidth indicator data, network quality indicator data and agent software indicator data for feature extraction respectively;building traffic graph according to extracted features;constructing and training a graph learning and prediction model based on the traffic graph;measuring the availability of the network agent service to be measured according to the trained graph learning and prediction model.2.The method according to claim 1, wherein the extracted features of agent software indicator data include server-side traffic characteristics, measuring client-side performance characteristics and proxy server active detection characteristics.3.The method according to claim 1, wherein using hypothesis test method to screen and optimize the independent variables of the model.4.The method according to claim 1, wherein verifying the model by actual deployment verification and simulation of CC attack to adjust and optimize the model parameters according to verification results.5.The method according to claim 1, wherein using a variety of contracting tools to sample the network environment parameters at the measuring end and the receiving end.6.The method according to claim 5, wherein measuring the upper limit of given proxy server’s proxy performance through various pressure methods and taking the maximum of all the results.7.The method according to claim 1, wherein using a sliding window approach to sample graph data.8.The method according to claim 1, wherein the model uses the weighted representations of neighbor nodes to update nodes and uses the multi-head attention mechanism to learn node features of different dimensions.9.A non-stress measurement system for the availability of network agent services, includingdata set construction module for the construction of various multi-dimensional indexes of the training data set of the model of claim 1;model training module for the training of the model;task scheduling module for the scheduling of all tasks in the system including data collection, model training and output of prediction results;multi-probe multi-dimensional index data collection module for multi-dimensional index data collection;model prediction result output module for the output of the availability of the network agent service.10.The system according to claim 9, wherein further comprises hypothesis test and parameter adjustment module using hypothesis test method to screen and optimize the independent variables of the model and verifying the model by actual deployment verification and simulation of CC attack to adjust and optimize the model parameters according to verification results.

Citation Information

Patent Citations

  • Information pushing method and server

    CN106899681A

  • Data stream transmission method and device

    CN118400358A

  • Method for determining network optimization policy, apparatus, and system

    US20240214280A1