A traffic anomaly detection method and device, a server and a medium
By performing hierarchical and cluster analysis on the location coding and internet access characteristics of terminal devices, the problem of misjudgment of traffic anomalies in existing technologies has been solved, and more accurate traffic anomaly detection and batch detection have been achieved.
Patent Information
- Application Number
- CN202211618084.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-15
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2042-12-15
AI Technical Summary
In existing technologies, regardless of the type of user, traffic anomalies are only identified when the traffic volume of a single internet session exceeds a general traffic threshold. This can lead to false positives and low accuracy in traffic anomaly detection.
By acquiring the location coding information and internet access characteristic information of the terminal device, performing hierarchical processing and cluster analysis, and determining whether the abnormal traffic judgment conditions are met based on the category to which the internet access characteristic information belongs, it is possible to determine whether the terminal device has abnormal traffic.
It improves the accuracy of traffic anomaly detection, enables batch traffic anomaly detection for multiple terminal devices, and improves detection efficiency.
Smart Images

Figure CN116133005B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and particularly relates to a traffic anomaly detection method and device, a server and a medium. BACKGROUND
[0002] With the rapid development of economy and technology, the frequency of users obtaining network information through terminal equipment increases. Since the traffic package of the user is fixed, the user hopes to know whether the current traffic use is abnormal in time to avoid the situation that the traffic exceeds the limit and causes the deduction.
[0003] In the prior art, when detecting traffic anomaly, it is usually determined that the traffic is abnormal when it is detected that the traffic of the user's daily continuous online behavior bill exceeds the traffic threshold. However, in the prior art, no matter which user, it is only determined that the traffic is abnormal when the traffic of the user's online behavior exceeds the general traffic threshold, which may cause traffic anomaly misjudgment, and thus the accuracy of traffic anomaly detection is low. SUMMARY
[0004] The present application provides a traffic anomaly detection method, device, server and medium, which is used to solve the problem that in the prior art, no matter which user, it is only determined that the traffic is abnormal when the traffic of the user's online behavior exceeds the general traffic threshold, which may cause traffic anomaly misjudgment, and thus the accuracy of traffic anomaly detection is low.
[0005] In a first aspect, the present application provides a traffic anomaly detection method, comprising:
[0006] A server acquires position coding information and online feature information corresponding to the identifiers of a plurality of terminal devices; wherein the online feature information comprises traffic use information;
[0007] The server performs hierarchical processing on the online feature information according to the position coding information to acquire a plurality of layers of online feature information;
[0008] The server performs clustering processing on the traffic use information for each layer of online feature information to acquire a plurality of classes of online feature information, and acquires the class to which each online feature information in the each layer of online feature information belongs;
[0009] The server judges whether each online feature information satisfies the abnormal traffic judgment condition corresponding to the class to which the online feature information belongs, and determines that the terminal device corresponding to the online feature information has traffic anomaly when it is judged that the online feature information satisfies the abnormal traffic judgment condition.
[0010] In the preferred technical solutions of the traffic anomaly detection method, the server determines whether the online feature information meets the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs for each online feature information, and determines that the terminal device corresponding to the online feature information has traffic anomaly when it is determined that the online feature information meets the abnormal traffic judgment condition, including:
[0011] The server determines a clustering ratio according to the number of all online feature information corresponding to the category to which the online feature information belongs and the number of all online feature information corresponding to the identifier of the plurality of terminal devices.
[0012] The server determines that the online feature information meets the abnormal traffic judgment condition when it is determined that the clustering ratio is less than a preset clustering ratio corresponding to the category to which the online feature information belongs.
[0013] The server determines that the terminal device corresponding to the online feature information has traffic anomaly when it is determined that the online feature information meets the abnormal traffic judgment condition.
[0014] In the preferred technical solutions of the traffic anomaly detection method, the server determines that the online feature information meets the abnormal traffic judgment condition when it is determined that the clustering ratio is less than a preset clustering ratio corresponding to the category to which the online feature information belongs, including:
[0015] The server determines whether the traffic usage information is greater than a preset traffic usage threshold when it is determined that the clustering ratio is less than the preset clustering ratio.
[0016] The server determines that the online feature information meets the abnormal traffic judgment condition when it is determined that the traffic usage information is greater than the preset traffic usage threshold.
[0017] In the preferred technical solutions of the traffic anomaly detection method, the traffic usage information is daily traffic usage information and / or current period traffic usage information.
[0018] The server determines that the online feature information meets the abnormal traffic judgment condition when it is determined that the traffic usage information is greater than the preset traffic usage threshold, including:
[0019] The server determines that the online feature information meets the abnormal traffic judgment condition when it is determined that the daily traffic usage information is greater than a preset daily traffic usage threshold.
[0020] Or,
[0021] The server determines that the online feature information meets the abnormal traffic judgment condition when it is judged that the current period traffic usage information is greater than a preset current period traffic usage threshold.
[0022] Or,
[0023] The server determines that the online feature information meets the abnormal traffic judgment condition when it is judged that the daily traffic usage information is greater than the preset daily traffic usage threshold and the current period traffic usage information is greater than the preset current period traffic usage threshold.
[0024] In the preferred technical solutions of the traffic anomaly detection method, the online feature information further includes service package information.
[0025] The server performs clustering processing on the traffic usage information for each layer of online feature information, obtains multiple classes of online feature information, and obtains the class to which each online feature information in the each layer of online feature information belongs, including:
[0026] The server performs quantile discretization processing and grouping processing on the online feature information according to the service package information for each layer of online feature information, and obtains multiple groups of online feature information.
[0027] The server performs clustering processing on the traffic usage information for each group of online feature information, obtains multiple classes of online feature information, and obtains the class to which each online feature information in the each group of online feature information belongs.
[0028] In the preferred technical solutions of the traffic anomaly detection method, further comprising:
[0029] The server generates traffic anomaly alarm information when it is determined that the terminal device corresponding to the online feature information has traffic anomaly.
[0030] The server sends the traffic anomaly alarm information to the terminal device.
[0031] In a second aspect, the application provides a traffic anomaly detection device, comprising:
[0032] A transceiving module is configured to obtain location encoding information and online feature information corresponding to the identifiers of multiple terminal devices, wherein the online feature information includes traffic usage information.
[0033] A processing module is configured to perform hierarchical processing on the online feature information according to the location encoding information, and obtain multiple layers of online feature information.
[0034] The processing module is further configured to perform clustering processing on the traffic usage information for each layer of online feature information, to obtain multiple categories of online feature information, and to obtain a category to which each online feature information in the each layer of online feature information belongs.
[0035] The processing module is further configured to determine, for each online feature information, whether the online feature information satisfies an abnormal traffic determination condition corresponding to a category to which the online feature information belongs, and to determine that a terminal device corresponding to the online feature information has abnormal traffic when it is determined that the online feature information satisfies the abnormal traffic determination condition.
[0036] In the preferred technical solutions of the above traffic anomaly detection apparatus, the processing module is specifically configured to:
[0037] determine a clustering ratio according to a number of all online feature information corresponding to the category to which the online feature information belongs and a number of all online feature information corresponding to the identifier of the terminal device;
[0038] determine that the online feature information satisfies the abnormal traffic determination condition when it is determined that the clustering ratio is less than a preset clustering ratio corresponding to the category to which the online feature information belongs;
[0039] determine that a terminal device corresponding to the online feature information has abnormal traffic when it is determined that the online feature information satisfies the abnormal traffic determination condition.
[0040] In the preferred technical solutions of the above traffic anomaly detection apparatus, the processing module is specifically configured to:
[0041] determine whether the traffic usage information is greater than a preset traffic usage threshold when it is determined that the clustering ratio is less than the preset clustering ratio;
[0042] determine that the online feature information satisfies the abnormal traffic determination condition when it is determined that the traffic usage information is greater than the preset traffic usage threshold.
[0043] In the preferred technical solutions of the above traffic anomaly detection apparatus, the traffic usage information is daily traffic usage information and / or current period traffic usage information.
[0044] The processing module is specifically configured to:
[0045] determine that the online feature information satisfies the abnormal traffic determination condition when it is determined that the daily traffic usage information is greater than a preset daily traffic usage threshold.
[0046] or
[0047] determining that the online feature information meets the abnormal traffic judgment condition when it is judged that the current period traffic usage information is greater than the preset current period traffic usage threshold;
[0048] or,
[0049] determining that the online feature information meets the abnormal traffic judgment condition when it is judged that the current period traffic usage information is greater than the preset current period traffic usage threshold;
[0050] In the preferred technical scheme of the traffic anomaly detection device, the online feature information further includes service package information.
[0051] The processing module is specifically configured to:
[0052] For each layer of online feature information, the online feature information is subjected to quantile discretization processing and grouping processing according to the service package information, so as to obtain multiple groups of online feature information.
[0053] For each group of online feature information, the traffic usage information is subjected to clustering processing, so as to obtain multiple categories of online feature information and the category to which each online feature information in each group of online feature information belongs.
[0054] In the preferred technical scheme of the traffic anomaly detection device,
[0055] The processing module is further configured to generate traffic anomaly alarm information when it is determined that the terminal device corresponding to the online feature information has traffic anomaly.
[0056] The transceiver module is further configured to send the traffic anomaly alarm information to the terminal device.
[0057] In a third aspect, the present application provides a server, comprising:
[0058] a processor and a memory connected to the processor in communication;
[0059] The memory is configured to store computer execution instructions.
[0060] The processor is configured to execute the computer execution instructions stored in the memory, so as to implement the traffic anomaly monitoring method of the first aspect.
[0061] In a fourth aspect, the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the traffic anomaly detection method of the first aspect.
[0062] This application provides a method, apparatus, server, and medium for detecting abnormal traffic. In this method, the server acquires location coding information and internet access characteristic information corresponding to the identifiers of multiple terminal devices, wherein the internet access characteristic information includes traffic usage information. Based on the location coding information, the server performs layered processing on the internet access characteristic information to obtain multiple layers of internet access characteristic information. For each layer of internet access characteristic information, the server performs clustering processing on the traffic usage information to obtain multiple categories of internet access characteristic information and obtains the category to which each internet access characteristic information belongs. For each internet access characteristic information, when the server determines that the internet access characteristic information meets the abnormal traffic judgment conditions corresponding to the category to which the internet access characteristic information belongs, it determines that the terminal device corresponding to the internet access characteristic information has experienced abnormal traffic. Compared to existing technologies that only identify traffic anomalies when a user's traffic exceeds a general traffic threshold in a single online activity, regardless of the user type, potentially leading to false positives and low accuracy in traffic anomaly detection, this application first groups internet access characteristics of devices belonging to the same location area into the same layer for centralized detection based on the location coding information of the terminal device. Then, for each layer of internet access characteristics, traffic usage information is clustered to further classify the information and determine the category to which each internet access characteristic belongs. Based on the abnormal traffic judgment conditions corresponding to the category to which the internet access characteristic belongs, the application can specifically determine whether the terminal device corresponding to the internet access characteristic has experienced traffic anomalies, thus improving the accuracy of traffic anomaly detection and solving the problem of low accuracy in traffic anomaly detection caused by existing technologies that only identify traffic anomalies when a user's traffic exceeds a general traffic threshold in a single online activity, regardless of the user type. In addition, this application can identify other terminal devices with the same type of internet access feature information that have abnormal traffic when it is determined that a terminal device corresponding to one internet access feature information has abnormal traffic, thus realizing batch detection of traffic abnormalities for multiple terminal devices and improving the efficiency of traffic abnormality detection. Attached Figure Description
[0063] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0064] Figure 1 A structural diagram of a traffic anomaly detection system provided in this application;
[0065] Figure 2 A flowchart illustrating an embodiment of a traffic anomaly detection method provided in this application;
[0066] Figure 3A flowchart of a flow anomaly detection method provided in Embodiment Two of the present application is shown in FIG. 1.
[0067] Figure 4 A flowchart of a flow anomaly detection method provided in Embodiment Three of the present application is shown in FIG. 2.
[0068] Figure 5 A structural diagram of a flow anomaly detection device provided in the present application is shown in FIG. 3.
[0069] Figure 6 A structural diagram of a server provided in the present application is shown in FIG. 4. DETAILED DESCRIPTION
[0070] In order to make the technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments will be described in detail below with reference to the drawings in the embodiments. The described embodiments are some embodiments of the present application, but not all embodiments of the present application. Based on the embodiments of the present application, other embodiments made by those skilled in the art based on the inspiration of the present embodiments are within the scope of protection of the present application.
[0071] The terms "first", "second", "third", "fourth" and the like (if any) in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.
[0072] The prior art detects flow anomaly when the flow of a user's daily continuous online behavior call record exceeds the flow threshold. However, this flow anomaly detection method determines that the flow is abnormal only when the flow of the user's daily continuous online behavior call record exceeds the general flow threshold, regardless of the user. This may result in flow anomaly misjudgment, leading to low accuracy of flow anomaly detection.
[0073] Based on the above technical problems, the technical concept of the present application is how to accurately detect flow anomaly.
[0074] Figure 1 A structural diagram of a flow anomaly detection system provided in the present application is shown in FIG. 5. Figure 1As shown, the system includes a server 101 and a plurality of terminal devices. Exemplarily, Figure 1 Three terminal devices are shown, namely terminal device 102, terminal device 103 and terminal device 104.
[0075] It should be noted that, Figure 1 is only a structural diagram of a traffic anomaly detection system provided by the present application, and the present application does not limit the actual form and interaction mode of various devices included in the present application. Figure 1
[0076] The traffic anomaly detection scheme of the present application will be described in detail below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0077] Figure 2 is a flowchart of an embodiment of a traffic anomaly detection method provided by the present application.
[0078] Referring to Figure 2 , the method specifically includes the following steps:
[0079] S201: The server obtains location coding information and online feature information corresponding to the identifiers of a plurality of terminal devices.
[0080] In this embodiment, the server can obtain the location coding information and the online feature information corresponding to the identifiers of a plurality of terminal devices through a communication connection with the plurality of terminal devices, wherein the online feature information includes traffic usage information. The location coding information is information reflecting the location of the terminal device when online. For example, the location coding information can be a public network allocation address.
[0081] It should be noted that the identifier of the terminal device can be a mobile phone number corresponding to the terminal device, or an International Mobile Equipment Identity (IMEI) corresponding to the terminal device.
[0082] S202: The server performs hierarchical processing on the online feature information according to the location coding information to obtain a plurality of layers of online feature information.
[0083] In this embodiment, the server can perform hierarchical processing on the online feature information according to the location coding information to obtain a plurality of layers of online feature information.
[0084] Optionally, the location coding information can be regional coding information (such as A region, B region, etc.), optionally, the location coding information can be provincial coding information (such as C province, D province, etc.), and optionally, the location coding information can be city coding information (such as Q city, F city, etc.).
[0085] For example, when the location coding information is province coding information, the server can perform hierarchical processing on the online feature according to the province coding information corresponding to the terminal device, and divide the online feature information of the terminal device corresponding to province C and the online feature information of the terminal device corresponding to province D into the same layer.
[0086] S203: The server performs clustering processing on the traffic usage information for each layer of online feature information, obtains multiple categories of online feature information, and obtains the category to which each online feature information in each layer of online feature information belongs.
[0087] In this embodiment, after the server performs hierarchical processing on the online feature information, the server performs clustering processing on the traffic usage information for each layer of online feature information to obtain multiple categories of online feature information. Optionally, the server can use a Gaussian Mixture Model (GMM) to perform clustering processing on the traffic usage information. Optionally, the server can use a K-means clustering algorithm to perform clustering processing on the traffic usage information.
[0088] After the server performs clustering processing on the traffic usage information, the server can obtain multiple categories of online feature information and obtain the clustering category to which each online feature information belongs. For example, the server can obtain three categories of online feature information, wherein the traffic usage information in the first category of online feature information is between 0G-1G, the clustering category is low traffic usage category; the traffic usage information in the second category of online feature information is between 1G-3G, the clustering category is ordinary traffic usage category, and the traffic usage information in the third category of online feature information is greater than 3G, the clustering category is high traffic usage category.
[0089] It should be noted that before the server performs clustering on the traffic usage information, the server can perform feature standardization processing on the traffic usage information to make the numerical value of the traffic usage information fall within a specific range. For example, the server can perform normalization processing on the traffic usage information to make the numerical value of the traffic usage information fall within the interval [0, 1].
[0090] S204: The server determines whether the online feature information satisfies the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs for each online feature information.
[0091] In this embodiment, the server pre-stores the correspondence between the cluster category and the abnormal traffic judgment condition. For each online feature information, the server can obtain the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs after obtaining the category to which the online feature information belongs. After obtaining the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs, the server can determine whether the online feature information satisfies the abnormal traffic judgment condition, and when it is determined that the online feature information satisfies the abnormal traffic judgment condition, S205 is performed; when it is determined that the online feature information does not satisfy the abnormal traffic judgment condition, it is determined that the terminal device corresponding to the online feature information does not have traffic anomaly, and the process ends.
[0092] S205: The server determines that the terminal device corresponding to the online feature information has traffic anomaly.
[0093] In this embodiment, when it is determined that the online feature information satisfies the abnormal traffic judgment condition, the server can determine that the terminal device corresponding to the online feature information has traffic anomaly.
[0094] It should be noted that when the server determines that the terminal device corresponding to the online feature information has traffic anomaly, the server can generate traffic anomaly alarm information and send the traffic anomaly alarm information to the terminal device to enable the user to know that the current traffic anomaly occurs through the terminal device. In addition, the server can also add 1 to the number of traffic anomalies corresponding to the terminal device when it is determined that the terminal device corresponding to the online feature information has traffic anomaly. When the server detects that the number of traffic anomalies corresponding to the terminal device exceeds a set threshold, the server performs traffic anomaly processing on the terminal device, wherein the traffic anomaly processing can be secondary real-name verification or shutdown processing.
[0095] In this embodiment, the server obtains location coding information corresponding to the identifiers of the plurality of terminal devices and online feature information, wherein the online feature information includes traffic usage information; the server performs hierarchical processing on the online feature information according to the location coding information, obtains a plurality of layers of online feature information, performs clustering processing on the traffic usage information for each layer of online feature information, obtains a plurality of categories of online feature information, and obtains the category to which each online feature information in each layer of online feature information belongs; and the server determines that the terminal device corresponding to each online feature information has abnormal traffic when it is determined that the online feature information meets the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs. Compared with the prior art in which it is determined that the traffic is abnormal only when the traffic of a user's online behavior is determined to exceed the general traffic threshold regardless of the user, the present application can first perform hierarchical processing on the online feature information corresponding to the identifiers of the plurality of terminal devices according to the location coding information corresponding to the terminal devices, so as to concentrate the online feature information corresponding to the terminal devices in the same location area in the same layer for centralized detection, then perform clustering on the traffic usage information for each layer of online feature information and determine the category to which each online feature information belongs, thereby determining whether the terminal device corresponding to the online feature information has abnormal traffic according to the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs, improving the detection accuracy of traffic abnormalities, and solving the problem of low accuracy of traffic anomaly detection in the prior art in which it is determined that the traffic is abnormal only when the traffic of a user's online behavior is determined to exceed the general traffic threshold regardless of the user, which may result in misjudgment of traffic abnormalities. In addition, the present application can determine that the terminal devices corresponding to other online feature information belonging to the same category have abnormal traffic when it is determined that the terminal device corresponding to one online feature information has abnormal traffic, thereby realizing batch detection of traffic abnormalities of a plurality of terminal devices and improving the efficiency of traffic anomaly detection.
[0096] Figure 3 A flowchart of a second embodiment of a traffic anomaly detection method provided by the present application is shown.
[0097] Referring to Figure 3 , the method specifically includes the following steps:
[0098] S301: The server obtains location coding information corresponding to the identifiers of the plurality of terminal devices and online feature information.
[0099] S302: The server performs hierarchical processing on the online feature information according to the location coding information, and obtains a plurality of layers of online feature information.
[0100] S303: The server clusters the traffic usage information according to each layer of online feature information, obtains multiple categories of online feature information, and obtains the category to which each online feature information in each layer of online feature information belongs.
[0101] In this embodiment, the server can cluster the traffic usage information according to each layer of online feature information, and obtain multiple categories of online feature information.
[0102] Optionally, the server can directly cluster the traffic usage information according to each layer of online feature information, and obtain multiple categories of online feature information.
[0103] Optionally, when the online feature information includes service package information, the server can further discretize the online feature information according to the service package information and group the online feature information before clustering the traffic usage information, to obtain multiple groups of online feature information. After obtaining the multiple groups of online feature information, the server clusters the traffic usage information according to each group of online feature information, to obtain multiple categories of online feature information, and obtains the category to which each online feature information in each group of online feature information belongs.
[0104] Specifically, in the process of discretizing the online feature information according to quantile and grouping the online feature information to obtain multiple groups of online feature information, the server can discretize the online feature information according to quantile according to the service package information, group the discretized online feature information according to service quantile values, and obtain multiple groups of online feature information. For example, the server can set the quantile discretization to quartile, and the service quantile values are 10G, 20G, and 30G. The server can discretize the online feature information according to quantile according to the service quantile values, group the discretized online feature information, and obtain multiple groups of online feature information. The service package information in the first group of online feature information is within the range of 0G-10G, the service package information in the second group of online feature information is within the range of 10G-20G, the service package information in the third group of online feature information is within the range of 20G-30G, and the service package information in the fourth group of online feature information is greater than 30G.
[0105] S304: The server determines the clustering ratio according to the number of all online feature information corresponding to the category to which the obtained online feature information belongs and the number of all online feature information corresponding to the identifier of the multiple terminal devices.
[0106] In the embodiment, the server can determine the number of all online feature information corresponding to the category to which the online feature information belongs through the counting module, and determine the number of all online feature information corresponding to the identifiers of the plurality of terminal devices. The counting module is one of the functional modules of the server and can realize the counting function.
[0107] After the server obtains the number of all online feature information corresponding to the category to which the online feature information belongs and the number of all online feature information corresponding to the identifiers of the plurality of terminal devices, the server can determine the clustering ratio according to the above information. For example, the server obtains that the number of all online feature information corresponding to the category to which the online feature information belongs is 900, and the number of all online feature information corresponding to the identifiers of the plurality of terminal devices is 10000, and can determine the clustering ratio as 900 / 10000=0.09 according to the above information.
[0108] S305: The server determines whether the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs.
[0109] In the embodiment, the preset clustering ratio corresponding to the category to which the online feature information belongs is stored in the server in advance.
[0110] After the server obtains the clustering ratio, the server can determine whether the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs. When the server determines that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs, S306 is performed; when the server determines that the clustering ratio is greater than or equal to the preset clustering ratio corresponding to the category to which the online feature information belongs, the process ends.
[0111] S306: The server determines that the online feature information satisfies the abnormal traffic judgment condition.
[0112] In the embodiment, when the server determines that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs, the server determines that the online feature information is the feature information of non-normal online, and at this time, it can be determined that the online feature information satisfies the abnormal traffic judgment condition. For example, when the server determines that the clustering ratio (0.09) is less than the preset clustering ratio (0.1), the server determines that the online feature information is the feature information of non-normal online, and at this time, it can be determined that the online feature information satisfies the abnormal traffic judgment condition.
[0113] S307: When the server determines that the online feature information satisfies the abnormal traffic judgment condition, the server determines that the terminal device corresponding to the online feature information has abnormal traffic.
[0114] The embodiment is further based on the foregoing embodiments, and further illustrates a specific implementation manner of determining whether the terminal device corresponding to the online feature information appears traffic anomaly according to the abnormal traffic judgment condition corresponding to the category to which the online feature information belongs, that is, determining the clustering ratio according to the number of all online feature information corresponding to the category to which the obtained online feature information belongs and the number of all online feature information corresponding to the identifiers of the plurality of terminal devices, and determining that the online feature information meets the abnormal traffic judgment condition when it is determined that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs, that is, determining that the terminal device corresponding to the online feature information appears traffic anomaly. Compared with the prior art in which it is determined that traffic anomaly occurs only when it is determined that the traffic of a user's online behavior once exceeds a general traffic threshold regardless of the user, the application can determine whether the online feature information is abnormal online feature information according to whether the number of online feature information in the category to which the online feature information determined based on the traffic usage information belongs is small, that is, determine whether the terminal device corresponding to the online feature information appears traffic anomaly, thereby improving the detection accuracy of traffic anomaly and solving the problem of the prior art in which it is determined that traffic anomaly occurs only when it is determined that the traffic of a user's online behavior once exceeds a general traffic threshold regardless of the user, which may result in traffic anomaly misjudgment and low accuracy of traffic anomaly detection.
[0115] Based on the method embodiment two, the specific implementation manners of S305 and S306 are described below in method embodiment three.
[0116] Figure 4 A flowchart of a traffic anomaly detection method embodiment three provided by the application is shown.
[0117] Referring to Figure 4 The method specifically includes the following steps:
[0118] S401: The server determines whether the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs.
[0119] In this embodiment, the server pre-stores the preset clustering ratio corresponding to the category to which the online feature information belongs.
[0120] After obtaining the clustering ratio, the server can determine whether the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs. When it is determined that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs, the server performs S402; when it is determined that the clustering ratio is greater than or equal to the preset clustering ratio corresponding to the category to which the online feature information belongs, the process ends.
[0121] S402: The server determines whether the traffic usage information is greater than a preset traffic usage threshold.
[0122] In this embodiment, when the server determines that the clustering ratio is less than the preset clustering ratio, the server can determine whether the traffic usage information is greater than a preset traffic usage threshold, wherein the traffic usage information is daily traffic usage information and / or current-period traffic usage information. When the server determines that the traffic usage information is greater than the preset traffic usage threshold, the server performs S403; when the server determines that the traffic usage information is less than or equal to the preset traffic usage threshold, the server ends.
[0123] Optionally, the server can determine whether the daily traffic usage information is greater than a preset daily traffic usage threshold. When the server determines that the daily traffic usage information is greater than the preset daily traffic usage threshold, the server performs S403; when the server determines that the daily traffic usage information is less than or equal to the preset daily traffic usage threshold, the server ends.
[0124] Optionally, the server can determine whether the current-period traffic usage information is greater than a preset current-period traffic usage threshold. When the server determines that the current-period traffic usage information is greater than the preset current-period traffic usage threshold, the server performs S403; when the server determines that the current-period traffic usage information is less than or equal to the preset current-period traffic usage threshold, the server ends.
[0125] Optionally, the server can determine whether the daily traffic usage information is greater than a preset daily traffic usage threshold and the current-period traffic usage information is greater than a preset current-period traffic usage threshold. When the server determines that the daily traffic usage information is greater than the preset daily traffic usage threshold and the current-period traffic usage information is greater than the preset current-period traffic usage threshold, the server performs S403; when the server determines that the daily traffic usage information is less than or equal to the preset daily traffic usage threshold and / or the current-period traffic usage information is less than or equal to the preset current-period traffic usage threshold, the server ends.
[0126] S403: The server determines that the online feature information meets the abnormal traffic determination condition.
[0127] This embodiment further describes the specific process of determining whether the online feature information meets the abnormal traffic determination condition from different dimensions when the traffic usage information is daily traffic usage information and / or current-period traffic usage information on the basis of the foregoing embodiments, thereby improving the accuracy of determining whether the online feature information meets the abnormal traffic determination condition and further improving the accuracy of determining that the terminal device corresponding to the online feature information has abnormal traffic.
[0128] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiments of the present application. For details not disclosed in the apparatus embodiments of the present application, refer to the method embodiments of the present application.
[0129] Figure 5This application provides a schematic diagram of the structure of a flow anomaly detection device; as shown below. Figure 5 As shown, the traffic anomaly detection device 50 includes a transceiver module 51 and a processing module 52. The transceiver module 51 is used to acquire location coding information and internet access characteristic information corresponding to the identifiers of multiple terminal devices; wherein the internet access characteristic information includes traffic usage information. The processing module 52 is used to perform layered processing on the internet access characteristic information based on the location coding information to obtain multi-layered internet access characteristic information. The processing module 52 is also used to perform clustering processing on the traffic usage information for each layer of internet access characteristic information to obtain multiple categories of internet access characteristic information, and to obtain the category to which each internet access characteristic information belongs in each layer of internet access characteristic information. The processing module 52 is also used to determine whether each internet access characteristic information meets the abnormal traffic judgment conditions corresponding to the category to which the internet access characteristic information belongs, and when it is determined that the internet access characteristic information meets the abnormal traffic judgment conditions, it determines that the terminal device corresponding to the internet access characteristic information has traffic anomalies.
[0130] The flow anomaly detection device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0131] In one possible implementation, the processing module 52 is specifically used to: determine the clustering ratio based on the number of all Internet access feature information corresponding to the category to which the acquired Internet access feature information belongs and the number of all Internet access feature information corresponding to the identifiers of multiple terminal devices; when it is determined that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the Internet access feature information belongs, determine that the Internet access feature information meets the abnormal traffic judgment condition; when it is determined that the Internet access feature information meets the abnormal traffic judgment condition, determine that the terminal device corresponding to the Internet access feature information has abnormal traffic.
[0132] The flow anomaly detection device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0133] In one possible implementation, the processing module 52 is specifically used to: determine whether the traffic usage information is greater than the preset traffic usage threshold when the clustering ratio is determined to be less than the preset clustering ratio; and determine whether the internet access feature information meets the abnormal traffic judgment condition when the traffic usage information is determined to be greater than the preset traffic usage threshold.
[0134] The flow anomaly detection device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.
[0135] In a possible implementation, the traffic usage information is daily traffic usage information and / or current period traffic usage information; and the processing module 52 is specifically configured to: determine that the online feature information meets the abnormal traffic judgment condition when it is judged that the daily traffic usage information is greater than a preset daily traffic usage threshold; or determine that the online feature information meets the abnormal traffic judgment condition when it is judged that the current period traffic usage information is greater than a preset current period traffic usage threshold; or determine that the online feature information meets the abnormal traffic judgment condition when it is judged that the daily traffic usage information is greater than a preset daily traffic usage threshold and the current period traffic usage information is greater than a preset current period traffic usage threshold.
[0136] The traffic anomaly detection apparatus provided by the embodiments of the present application can execute the technical solutions shown in the method embodiments, and the implementation principles and beneficial effects are similar, which will not be repeated here.
[0137] In a possible implementation, the online feature information further includes service package information; and the processing module 52 is specifically configured to: for each layer of online feature information, perform quantile discretization processing and grouping processing on the online feature information according to the service package information, to obtain multiple groups of online feature information; and for each group of online feature information, perform clustering processing on the traffic usage information, to obtain multiple categories of online feature information, and to obtain a category to which each online feature information in each group of online feature information belongs.
[0138] The traffic anomaly detection apparatus provided by the embodiments of the present application can execute the technical solutions shown in the method embodiments, and the implementation principles and beneficial effects are similar, which will not be repeated here.
[0139] In a possible implementation, the processing module 52 is further configured to generate traffic anomaly alarm information when it is determined that the online feature information corresponds to a terminal device that has traffic anomaly; and the transceiver module 51 is further configured to send the traffic anomaly alarm information to the terminal device.
[0140] The traffic anomaly detection apparatus provided by the embodiments of the present application can execute the technical solutions shown in the method embodiments, and the implementation principles and beneficial effects are similar, which will not be repeated here.
[0141] Figure 6 A structural schematic diagram of a server provided by the present application is shown in FIG. 6. As shown in FIG. 6, the server 60 includes a processor 61 and a memory 62; the processor 61 is in communication connection with the memory 62; the memory 62 is configured to store computer execution instructions; and the processor 61 is configured to execute the technical solutions in any of the preceding method embodiments by executing the computer execution instructions stored in the memory 62. Figure 6
[0142] Optionally, the memory 62 can be independent or integrated with the processor 61. Optionally, when the memory 62 is independent of the processor 61, the server 60 can further include a bus for connecting the above-mentioned devices.
[0143] The server is configured to execute the technical solutions in any of the preceding method embodiments, and has similar implementation principles and technical effects, which will not be described here.
[0144] The embodiments of the present application further provide a computer readable storage medium, which stores computer execution instructions. When the computer execution instructions are executed by a processor, the computer execution instructions are configured to implement the technical solutions provided by any of the preceding method embodiments.
[0145] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction-related hardware. The above-mentioned program can be stored in a computer readable storage medium. When the program is executed, the program executes the steps of the above-mentioned method embodiments; and the above-mentioned storage medium includes ROM, RAM, magnetic disk or optical disk and various storage media that can store program codes.
[0146] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the above-mentioned embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A method of detecting flow anomalies, characterized by, The application comprises the following steps: A server acquires location coding information and online feature information corresponding to the identification of a plurality of terminal devices, wherein the online feature information comprises traffic usage information; The server performs hierarchical processing on the online feature information according to the location coding information to acquire a plurality of layers of online feature information; The server performs clustering processing on the traffic usage information for each layer of online feature information to acquire a plurality of categories of online feature information and the category to which each online feature information in each layer of online feature information belongs; The server determines a clustering ratio according to the number of all online feature information corresponding to the category to which the online feature information belongs and the number of all online feature information corresponding to the identification of the plurality of terminal devices; When the server determines that the clustering ratio is less than a preset clustering ratio corresponding to the category to which the online feature information belongs, the server determines that the online feature information meets an abnormal traffic judgment condition; When the server determines that the online feature information meets the abnormal traffic judgment condition, the server determines that a terminal device corresponding to the online feature information has abnormal traffic.
2. The method of claim 1, wherein When the server determines that the clustering ratio is less than the preset clustering ratio corresponding to the category to which the online feature information belongs, the server determines that the online feature information meets the abnormal traffic judgment condition, comprising: When the server determines that the clustering ratio is less than the preset clustering ratio, the server determines whether the traffic usage information is greater than a preset traffic usage threshold; When the server determines that the traffic usage information is greater than the preset traffic usage threshold, the server determines that the online feature information meets the abnormal traffic judgment condition.
3. The method of claim 2, wherein The traffic usage information is daily traffic usage information and / or current period traffic usage information; When the server determines that the traffic usage information is greater than the preset traffic usage threshold, the server determines that the online feature information meets the abnormal traffic judgment condition, comprising: When the server determines that the daily traffic usage information is greater than a preset daily traffic usage threshold, the server determines that the online feature information meets the abnormal traffic judgment condition; Or, When the server determines that the current period traffic usage information is greater than a preset period traffic usage threshold, the server determines that the online feature information meets the abnormal traffic judgment condition; Or, When the server determines that the daily traffic usage information is greater than the preset daily traffic usage threshold and the current period traffic usage information is greater than the preset period traffic usage threshold, the server determines that the online feature information meets the abnormal traffic judgment condition.
4. The method of claim 1, wherein The online feature information further comprises service package information; When the server performs clustering processing on the traffic usage information for each layer of online feature information to acquire a plurality of categories of online feature information and the category to which each online feature information in each layer of online feature information belongs, comprising: The server performs quantile discretization processing and grouping processing on the online feature information according to the service package information for each layer of online feature information to acquire a plurality of groups of online feature information; The server performs clustering processing on the traffic usage information for each group of online feature information, obtains multiple categories of online feature information, and obtains a category to which each online feature information in the each group of online feature information belongs.
5. The flow abnormality detection method according to any one of claims 1 to 4, characterized by, Further comprising: The server generates traffic anomaly alarm information when determining that the terminal device corresponding to the online feature information has traffic anomaly; The server sends the traffic anomaly alarm information to the terminal device.
6. A flow abnormality detection device characterized by comprising: Comprising: The transceiving module is configured to obtain location coding information and online feature information corresponding to identifiers of multiple terminal devices, wherein the online feature information comprises traffic usage information; The processing module is configured to perform hierarchical processing on the online feature information according to the location coding information, and obtain multiple layers of online feature information; The processing module is further configured to perform clustering processing on the traffic usage information for each layer of online feature information, obtain multiple categories of online feature information, and obtain a category to which each online feature information in the each layer of online feature information belongs; The processing module is further configured to determine a clustering ratio according to a number of all online feature information corresponding to the category to which the online feature information belongs and a number of all online feature information corresponding to the identifiers of the multiple terminal devices, determine that the online feature information satisfies an abnormal traffic judgment condition when determining that the clustering ratio is less than a preset clustering ratio corresponding to the category to which the online feature information belongs, and determine that a terminal device corresponding to the online feature information has traffic anomaly when determining that the online feature information satisfies the abnormal traffic judgment condition.
7. The flow abnormality detecting apparatus according to claim 6, characterized by The processing module is specifically configured to: determine whether the traffic usage information is greater than a preset traffic usage threshold when determining that the clustering ratio is less than the preset clustering ratio, and determine that the online feature information satisfies the abnormal traffic judgment condition when determining that the traffic usage information is greater than the preset traffic usage threshold.
8. The flow abnormality detecting apparatus according to claim 7, characterized by The traffic usage information is daily traffic usage information and / or current period traffic usage information. The processing module is specifically configured to: determine that the online feature information satisfies the abnormal traffic judgment condition when determining that the daily traffic usage information is greater than a preset daily traffic usage threshold, or determine that the online feature information satisfies the abnormal traffic judgment condition when determining that the current period traffic usage information is greater than a preset current period traffic usage threshold, or determine that the online feature information satisfies the abnormal traffic judgment condition when determining that the daily traffic usage information is greater than the preset daily traffic usage threshold and the current period traffic usage information is greater than the preset current period traffic usage threshold.
9. The flow abnormality detecting apparatus according to claim 6, characterized by The online feature information further comprises service package information. The processing module is specifically configured to: perform quantile discretization processing and grouping processing on the online feature information according to the service package information for each layer of online feature information, and obtain multiple groups of online feature information. For each group of online feature information, the traffic usage information is clustered to obtain multiple categories of online feature information, and a category to which each online feature information in the group of online feature information belongs is obtained.
10. The traffic anomaly detection apparatus according to any one of claims 6-9, characterized in that, The processing module is further configured to generate traffic anomaly alarm information when it is determined that the terminal device corresponding to the online feature information has traffic anomaly. The transceiving module is further configured to send the traffic anomaly alarm information to the terminal device.
11. A server, characterized by Comprising: a processor, and a memory connected to the processor in communication; the memory is used to store computer execution instructions; the processor is used to execute the computer execution instructions stored in the memory to realize the traffic anomaly detection method in any one of claims 1-5.
12. A computer-readable storage medium, characterized in that, The computer readable storage medium has computer execution instructions stored therein, and the computer execution instructions are executed by the processor to realize the traffic anomaly detection method in any one of claims 1-5.
Citation Information
Patent Citations
Internet surfing unusual flow detection method and device
CN103117903A
Network abnormity detection method based on traffic mode
CN111556440A