Network anomaly detection method, device, equipment and storage medium
By acquiring the target and historical index values of the network, calculating fluctuation values and scores, and filtering and generating alarm information, the problem of low accuracy in network anomaly detection in existing technologies is solved, and more accurate network anomaly detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-08-29
- Publication Date
- 2026-08-04
AI Technical Summary
In existing technologies, when anomaly detection is performed by judging the magnitude of network performance indicators, the amount of reference information is relatively small, resulting in low accuracy of network anomaly detection results.
By acquiring the target indicator value and multiple historical indicator values, the network's fluctuation value and score are determined. Fluctuation values that are less than or equal to the target fluctuation value are filtered out. Based on the preset correspondence between fluctuation values and scores, the overall fluctuation score is calculated, and alarm information is generated to indicate whether the network is in an abnormal state.
It improves the accuracy of network anomaly detection, enabling timely assessment of network fluctuations and anomaly probabilities, and providing valuable detection references.
Smart Images

Figure CN117081955B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device and storage medium for network anomaly detection. Background Technology
[0002] In recent years, with the development of communication technology, the interaction between user equipment has become more and more frequent, and the demand for network management between user equipment has also increased. For example, anomaly detection in the network between user equipment.
[0003] Currently, in the process of detecting network anomalies between user equipment, it is necessary to determine whether the network performance indicators between user equipment are within a preset threshold range to determine whether the network is in an abnormal operating state, thereby achieving network anomaly detection. However, in the above technical solutions, network anomaly detection is performed solely by judging the magnitude of network performance indicators, which provides limited reference information and reduces the accuracy of network anomaly detection results. Summary of the Invention
[0004] This application provides a method, apparatus, device, and storage medium for network anomaly detection, which addresses the problem of low accuracy in network anomaly detection results.
[0005] To achieve the above objectives, this application adopts the following technical solution:
[0006] Firstly, this application provides a network anomaly detection method, comprising: a network anomaly detection device (hereinafter referred to as a "detection device") acquiring a target index value and multiple first historical index values, wherein the target index value is the index value of a target network performance index of the network under test at the current time, and the first historical index values are the index values of the target network performance index of the network under test at a first historical time. The detection device determines a target fluctuation value of the network under test at the current time based on the target index value and the multiple first historical index values. The detection device filters out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. The detection device determines a first fluctuation score corresponding to each first fluctuation value based on a preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores. The detection device sums the multiple first fluctuation scores to obtain a target fluctuation score of the network under test at the current time. If the target fluctuation score is greater than or equal to a preset score threshold, the detection device generates target alarm information, which indicates that the network under test is in an abnormal operating state at the current time.
[0007] The technical solution provided in this application brings at least the following beneficial effects: The detection device can acquire a target index value and multiple first historical index values. The target index value is the index value of the target network performance index of the network under test at the current moment, and the first historical index values are the index values of the target network performance index of the network under test at the first historical moment. Next, the detection device can determine the target fluctuation value of the network under test at the current moment based on the target index value and multiple first historical index values, and filter out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. Then, the detection device can determine the first fluctuation score corresponding to each first fluctuation value based on a preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores. Next, the detection device can sum the multiple first fluctuation scores to obtain the target fluctuation score of the network under test at the current moment, and determine whether the target fluctuation score is less than a preset score threshold. If the detection device determines that the target fluctuation score is greater than or equal to the preset score threshold, the detection device can generate target alarm information, which is used to indicate that the network under test is in an abnormal operating state at the current moment. In other words, the detection device can determine the degree of fluctuation of the network under test at the current moment based on the network performance index values at the current moment and historical moments, and assess the probability of abnormal fluctuations in the network under test at the current moment. This allows for the determination of whether the network under test is in an abnormal operating state, ultimately achieving anomaly detection. Thus, it can provide valuable reference for network anomaly detection and improve the accuracy of anomaly detection results.
[0008] Optionally, the method further includes: the detection device acquiring multiple sets of historical indicator values based on multiple preset historical times, where each preset historical time corresponds to one set of historical indicator values; a second historical time corresponding to any indicator value in the corresponding set of historical indicator values is greater than or equal to the preset historical time; and the indicator values in the set of historical indicator values are the indicator values of the target network performance indicators of the network under test at the corresponding second historical time. For each set of historical indicator values, the detection device determines a preset fluctuation value of the network under test at the preset historical time based on the indicator values in the set of historical indicator values, thereby obtaining multiple preset fluctuation values, where each preset fluctuation value corresponds to one set of historical indicator values. The detection device determines a preset fluctuation score corresponding to each preset fluctuation value based on the multiple preset fluctuation values, thereby obtaining multiple preset fluctuation scores. The detection device generates a preset correspondence relationship based on the multiple preset fluctuation values and the multiple preset fluctuation scores.
[0009] Optionally, the method described above, which involves "the detection device determining a preset fluctuation score corresponding to each preset fluctuation value based on multiple preset fluctuation values," includes: for each preset fluctuation value, the detection device determines a preset fluctuation score corresponding to each preset fluctuation value through a target operation. The target operation includes: the detection device calculating the difference between a second fluctuation value and each of the multiple preset fluctuation values to obtain multiple target fluctuation differences, where the second fluctuation value is any one of the multiple preset fluctuation values. The detection device updates the multiple target fluctuation differences based on a preset fluctuation difference threshold and preset parameters to obtain updated multiple target fluctuation differences. The updated multiple target fluctuation differences include: fluctuation differences less than or equal to the preset fluctuation difference threshold and multiple preset parameters. The number of preset parameters in the updated multiple target fluctuation differences is equal to the number of fluctuation differences greater than the preset fluctuation difference threshold. The detection device calculates a weighted average of the updated multiple target fluctuation differences based on preset weight values to obtain the preset fluctuation score corresponding to the second fluctuation value.
[0010] Optionally, the difference between the current time and any two adjacent times among multiple first historical times is equal to a preset time difference, and the difference between any two adjacent second historical times in the set of historical index values is equal to a preset time difference.
[0011] Optionally, the target network performance metrics can be any of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, and data retransmission rate.
[0012] Secondly, this application provides a network anomaly detection device, which includes an acquisition module and a processing module.
[0013] The acquisition module acquires a target indicator value and multiple first historical indicator values. The target indicator value is the performance indicator value of the network under test at the current time, and the first historical indicator values are the performance indicator values of the network under test at the first historical time. The processing module determines the target fluctuation value of the network under test at the current time based on the target indicator value and the multiple first historical indicator values. The processing module also filters out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. Furthermore, the processing module determines the first fluctuation score corresponding to each first fluctuation value based on a preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores. The processing module also sums the multiple first fluctuation scores to obtain the target fluctuation score of the network under test at the current time. Finally, if the target fluctuation score is greater than or equal to a preset score threshold, the processing module generates a target alarm message indicating that the network under test is in an abnormal operating state at the current time.
[0014] Optionally, the acquisition module is further configured to acquire multiple sets of historical indicator values based on multiple preset historical time points. Each preset historical time point corresponds to one set of historical indicator values. A second historical time point is defined as a preset historical time point that is greater than or equal to any indicator value in the corresponding set of historical indicator values. The indicator values in the set of historical indicator values represent the target network performance indicators of the network under test at the corresponding second historical time point. The processing module is further configured to determine, for each set of historical indicator values, a preset fluctuation value for the network under test at the preset historical time point based on the indicator values in the set of historical indicator values, thereby obtaining multiple preset fluctuation values. Each preset fluctuation value corresponds to one set of historical indicator values. The processing module is further configured to determine a preset fluctuation score corresponding to each preset fluctuation value, thereby obtaining multiple preset fluctuation scores. The processing module is further configured to generate a preset correspondence relationship based on the multiple preset fluctuation values and the multiple preset fluctuation scores.
[0015] Optionally, the processing module is specifically used to determine a preset fluctuation score corresponding to each preset fluctuation value through a target operation. The target operation includes: calculating the difference between a second fluctuation value and each of the multiple preset fluctuation values to obtain multiple target fluctuation differences, where the second fluctuation value is any one of the multiple preset fluctuation values. Based on a preset fluctuation difference threshold and preset parameters, the multiple target fluctuation differences are updated to obtain updated multiple target fluctuation differences. The updated multiple target fluctuation differences include: fluctuation differences less than or equal to the preset fluctuation difference threshold and multiple preset parameters. The number of preset parameters in the updated multiple target fluctuation differences is equal to the number of fluctuation differences greater than the preset fluctuation difference threshold. Based on preset weight values, the weighted average of the updated multiple target fluctuation differences is calculated to obtain the preset fluctuation score corresponding to the second fluctuation value.
[0016] Optionally, the difference between the current time and any two adjacent times among multiple first historical times is equal to a preset time difference, and the difference between any two adjacent second historical times in the set of historical index values is equal to a preset time difference.
[0017] Optionally, the target network performance metrics can be any of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, and data retransmission rate.
[0018] Thirdly, this application provides a network anomaly detection device, which includes a processor and a memory coupled together. The memory is used to store one or more programs, which include computer-executable instructions. When the network anomaly detection device is running, the processor executes the computer-executable instructions stored in the memory to implement any of the network anomaly detection methods described in the first aspect above.
[0019] Fourthly, this application provides a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform any of the network anomaly detection methods described in the first aspect above.
[0020] Fifthly, this application provides a computer program product applied to a server. The computer program product includes computer instructions, which, when executed on the server, enable the server to implement any of the network anomaly detection methods described in the first aspect above.
[0021] The technical problems that the network anomaly detection device, equipment, computer storage medium or computer program product can solve and the technical effects it can achieve can be found in the technical problems and effects solved in the first aspect above, and will not be repeated here. Attached Figure Description
[0022] Figure 1 A schematic diagram of a communication system provided in an embodiment of this application;
[0023] Figure 2 A flowchart illustrating a network anomaly detection method provided in an embodiment of this application;
[0024] Figure 3 A flowchart illustrating another network anomaly detection method provided in this application embodiment;
[0025] Figure 4 A flowchart illustrating another network anomaly detection method provided in this application embodiment;
[0026] Figure 5 A schematic diagram illustrating an example of a network anomaly detection result provided in an embodiment of this application;
[0027] Figure 6 This is a schematic diagram of the structure of a network anomaly detection device provided in an embodiment of this application;
[0028] Figure 7 This is a schematic diagram of the structure of a network anomaly detection device provided in an embodiment of this application;
[0029] Figure 8 A conceptual partial view of a computer program product provided for an embodiment of this application. Detailed Implementation
[0030] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0031] In this article, the character " / " generally indicates that the objects before and after it are in an "or" relationship. For example, A / B can be understood as A or B.
[0032] The terms “first” and “second” in the specification and claims of this application are used to distinguish different objects, rather than to describe a specific order of objects.
[0033] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or modules is not limited to the steps or modules listed, but may optionally include other steps or modules not listed, or may optionally include other steps or modules inherent to such process, method, product, or device.
[0034] Furthermore, in the embodiments of this application, the words "exemplary" or "for example" are used to indicate that they are examples, illustrations, or descriptions. Any embodiment or design that is described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design options. Specifically, the use of the words "exemplary" or "for example" is intended to present concepts in a concrete manner.
[0035] Before providing a detailed description of the network anomaly detection method provided in the embodiments of this application, the implementation environment and application scenarios of the embodiments of this application will be introduced first.
[0036] First, the application scenarios of the embodiments of this application will be introduced.
[0037] The 5G era is an era of network convergence and service diversification. The network plays the role of the "foundation" for upper-layer services. The reliability and stability of the network are crucial to upper-layer services. In actual operation and maintenance, network performance indicators are often used to judge whether the network is operating normally. Therefore, timely detection of abnormal network performance indicators and taking countermeasures are important means to ensure network reliability and stability.
[0038] Existing technologies for detecting abnormal network performance metrics include the following three methods:
[0039] Method 1, Post-Discovery: This refers to a situation where users have already perceived a significant malfunction in the front-end service and have reported the issue to the back-end. Subsequently, manual analysis is conducted to determine the cause of the malfunction and to identify abnormal network performance metrics.
[0040] However, the above methods can only detect abnormal network performance indicators after the fact, and lack timeliness.
[0041] Method 2, manual inspection: This refers to the operation and maintenance personnel checking the collected network performance indicators in the operation and maintenance system in real time to see if there are any abnormalities.
[0042] However, the second method mentioned above requires a large amount of labor costs and cannot be implemented 24 hours a day.
[0043] Method 3, Threshold Detection: This method compares the collected network performance index values with a predetermined threshold to detect whether the collected network performance index values exceed the predetermined threshold range.
[0044] However, the third method mentioned above requires manual intervention to set the threshold range for each network performance indicator. The workload of manual setting is large, and the set threshold range is not objective enough. In addition, this method can only detect whether the network performance indicator value exceeds the predetermined threshold range, but cannot detect whether there are unreasonable fluctuations in the network performance indicator value, and its function is limited.
[0045] In other words, in the process of detecting network anomalies between user devices, relying solely on the magnitude of network performance indicators for anomaly detection provides limited information and reduces the accuracy of the anomaly detection results.
[0046] To address the aforementioned issues, this application provides a network anomaly detection method, applicable to scenarios involving network anomaly detection. The detection device can determine a target fluctuation value, indicating the degree of fluctuation of the network under test at the current moment, based on the network performance index values of the network under test at the current and historical moments. Next, the detection device filters out multiple first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values, and determines a first fluctuation score corresponding to each first fluctuation value based on the correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores. Then, the detection device can sum the multiple first fluctuation scores to obtain a target fluctuation score indicating the probability of abnormal fluctuation in the network under test at the current moment, and determine whether the network under test is in an abnormal operating state by comparing the target fluctuation score with a preset score threshold. If the detection device determines that the target fluctuation score is greater than or equal to the preset score threshold, the detection device generates target alarm information indicating that the network under test is in an abnormal operating state at the current moment. In other words, the detection device can determine the degree of fluctuation of the network under test at the current moment based on the network performance index values at the current moment and historical moments, and assess the probability of abnormal fluctuations in the network under test at the current moment. This allows for the determination of whether the network under test is in an abnormal operating state, ultimately achieving anomaly detection. Thus, it can provide valuable reference for network anomaly detection and improve the accuracy of anomaly detection results.
[0047] The implementation environment of the embodiments of this application is described below.
[0048] like Figure 1 The diagram shown is a schematic representation of a communication system provided in an embodiment of this application. The communication system may include a detection device (such as a terminal 101) and a network to be detected (such as a server 102). The terminal 101 can communicate with the server 102 via wired / wireless communication.
[0049] Specifically, server 102 can collect the target indicator value of the network performance indicator to be detected at the current moment and send the target indicator value to terminal 101. Then, terminal 101 can receive the target indicator value from server 102 and obtain multiple first historical indicator values of the network performance indicator to be detected at the first historical moment from the stored historical indicator values. Next, terminal 101 can determine a target fluctuation value to indicate the degree of fluctuation of server 102 at the current moment based on the target indicator value and the multiple first historical indicator values, and filter out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. Then, terminal 101 can determine a first fluctuation score corresponding to each first fluctuation value based on the preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores, and sum the multiple first fluctuation scores to obtain a target fluctuation score to indicate the probability of abnormal fluctuation in server 102 at the current moment. Subsequently, if terminal 101 determines that the target fluctuation score is greater than or equal to the preset score threshold, terminal 101 can generate target alarm information to indicate that server 102 is in an abnormal operating state at the current moment.
[0050] In this embodiment, the server (such as server 102) can be a single physical server, or a server cluster consisting of multiple servers. Alternatively, the server cluster can be a distributed cluster. Alternatively, the server can be a cloud server. This embodiment does not limit the specific implementation of the server.
[0051] The terminal (such as terminal 101) can be a mobile phone, tablet computer, desktop computer, laptop computer, handheld computer, notebook computer, ultra-mobile personal computer (UMPC), netbook, or other device with sending and receiving functions. This application does not impose any special restrictions on the specific form of the terminal. It can interact with the user through one or more methods such as keyboard, touchpad, touch screen, remote control, voice interaction, or handwriting device.
[0052] After introducing the application scenarios and implementation environment of the embodiments of this application, the network anomaly detection method provided by the embodiments of this application will be described in detail below in conjunction with the above implementation environment.
[0053] The methods in the following embodiments can all be implemented in the above-described application scenarios and implementation environments. The embodiments of this application will now be specifically described using a detection device as the execution subject, in conjunction with the accompanying drawings.
[0054] Figure 2 This is a flowchart illustrating a network anomaly detection method provided in an embodiment of this application. Figure 2As shown, the method may include: S201-S207.
[0055] S201, The detection device acquires the target index value and multiple first historical index values.
[0056] The target index value is the target network performance index value of the network under test at the current time, and the first historical index value is the target network performance index value of the network under test at the first historical time, which is before the current time.
[0057] In one possible implementation, the detection device can receive an anomaly detection request message from the network to be detected. This message may include: the identifier of the network to be detected, the identifier of the target network performance indicator, the target indicator value, and the current time. Then, the detection device can retrieve multiple first historical indicator values from stored historical indicator values based on the identifier of the network to be detected, the identifier of the target network performance indicator, and the current time.
[0058] In one possible design, the detection device stores a preset time difference and a preset sampling number. During the acquisition of multiple first historical indicator values, the detection device can determine multiple first historical moments based on the current time, the preset time difference, and the preset sampling number. The number of first historical moments equals the preset sampling number, and the difference between the current time and any two adjacent first historical moments equals the preset time difference. Subsequently, the detection device can retrieve the first historical indicator value corresponding to each first historical moment from the stored historical indicator values based on the identifier of the network to be detected, the identifier of the target network performance indicator, and the multiple first historical moments, thereby obtaining multiple first historical indicator values.
[0059] For example, the stored historical indicator values may include the network latency (i.e., the target network performance indicator) of the network under test at each moment between 8:00 AM and 10:00 AM. If the current time t is 10:05 AM, and the preset time difference s is 15 minutes and the preset sampling number is 5, the detection device can determine multiple first historical moments between 8:00 AM and 10:00 AM: ts at 9:50 AM, t-2 s at 9:35 AM, t-3 s at 9:20 AM, t-4 s at 9:05 AM, and t-5 s at 8:50 AM. Then, the detection device can obtain multiple first historical indicator values from the stored historical indicator values based on times ts, t-2 s, t-3 s, t-4 s, and t-5 s: the indicator value v corresponding to time ts. t-s The index value v corresponding to time t-2·s t-2·s The index value v corresponding to time t-3·s t-3·sThe index value v corresponding to time t-4·s t-4·s The index value v corresponding to time t-5·s t-5·s Among them, the index value v t-s With a delay of 3 seconds, the index value v t-2·s With a delay of 2.6 seconds, the index value v t-3·s With a delay of 4 seconds, the index value v t-4·s With a delay of 1.2 seconds, the index value v t-5·s The delay is 0.9 seconds.
[0060] In one possible implementation, the detection device can generate a target indicator value set based on the target indicator value and multiple first historical indicator values. The target indicator value set includes the target indicator value and multiple first historical indicator values.
[0061] In one possible design, the set of target index values can be represented by Formula 1.
[0062] Z = {v t v t-s v t-2·s , ..., v t-n·s Formula 1.
[0063] Where Z indicates the set of target index values, v indicates the index value of the target network performance index at different times, t indicates the current time, s indicates the preset time difference, and n indicates the preset number of samples.
[0064] It should be noted that, in the embodiments of this application, the target network performance indicators can be any of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, data retransmission rate, and network traffic.
[0065] In other words, the detection device can analyze the values of different network performance indicators of the network under test to determine the fluctuations in the network and thus determine whether the network is in an abnormal operating state. This provides valuable reference for detecting the network's operating status and improves the accuracy of anomaly detection results.
[0066] S202. The detection device determines the target fluctuation value of the network to be detected at the current moment based on the target index value and multiple first historical index values.
[0067] The target index value is used to indicate the degree of fluctuation of the network under test at the current moment.
[0068] It should be noted that the embodiments of this application do not limit the relationship between fluctuation value and fluctuation degree.
[0069] In one possible design, the fluctuation value is positively correlated with the degree of fluctuation.
[0070] In other words, a larger fluctuation value indicates a more drastic level of fluctuation; a smaller fluctuation value indicates a more stable level of fluctuation.
[0071] In another possible design, the volatility value is negatively correlated with the degree of volatility.
[0072] In other words, a larger fluctuation value indicates a more stable level of fluctuation; a smaller fluctuation value indicates a more volatile level of fluctuation.
[0073] In one possible implementation, the detection device can determine the target fluctuation value by inputting the target index value and multiple first historical index values into a preset fluctuation algorithm.
[0074] It should be noted that the preset fluctuation algorithm is not limited in the embodiments of this application. For example, the preset fluctuation algorithm can be a variance calculation formula. Another example is that the preset fluctuation algorithm can be a standard deviation calculation formula, or a mean squared error calculation formula.
[0075] In one possible design, the preset volatility algorithm can be a variance calculation formula, and the target volatility value can be represented by formulas two and three.
[0076]
[0077]
[0078] Where u is used to indicate the arithmetic mean of the target index value set Z, and v i Let b be any index value in the target index value set Z, and i be any index value in the target index value set Z. i The corresponding time is i∈{t, ts, t-2·s, ..., tn·s}.
[0079] S203. The detection device selects a first fluctuation value that is less than or equal to the target fluctuation value from a plurality of preset fluctuation values to obtain a plurality of first fluctuation values.
[0080] In one possible implementation, the detection device stores preset fluctuation values of the target network performance indicators of the network to be detected at multiple preset historical times. The detection device can obtain multiple first fluctuation values by comparing the target fluctuation value with each preset fluctuation value and selecting the fluctuation value that is less than or equal to the target fluctuation value from among the multiple preset fluctuation values.
[0081] For example, multiple preset fluctuation values may include: fluctuation value A, fluctuation value B, fluctuation value C, fluctuation value D, and fluctuation value E. Wherein, fluctuation value A is 12, fluctuation value B is 5, fluctuation value C is 7.2, fluctuation value D is 6.2, and fluctuation value E is 3.3. If the target fluctuation value is 6.5, the detection device can determine multiple first fluctuation values including: fluctuation value B, fluctuation value D, and fluctuation value E.
[0082] S204. The detection device determines the first fluctuation score corresponding to each first fluctuation value according to the preset correspondence between multiple preset fluctuation values and multiple preset fluctuation scores, so as to obtain multiple first fluctuation scores.
[0083] In one possible implementation, the detection device stores a preset correspondence between multiple preset fluctuation values and multiple preset fluctuation scores. For each first fluctuation value, the detection device determines the fluctuation value that is the same as the first fluctuation value from the multiple preset fluctuation values, and according to the preset correspondence, takes the preset fluctuation score corresponding to the fluctuation value that is the same as the first fluctuation value from the multiple preset fluctuation values as the first fluctuation score, and determines the first fluctuation score corresponding to the first fluctuation value to obtain multiple first fluctuation scores.
[0084] In one possible design, the pre-defined correspondence can be represented by Formula 4.
[0085]
[0086] Where, d i Used to indicate the i-th predefined correspondence, b′ i w′ is used to indicate the i-th fluctuation value among multiple preset fluctuation values. i Used to indicate the i-th fluctuation score among multiple preset fluctuation scores, i∈{t, ts, t-2·s, ..., tn·s}.
[0087] In this embodiment of the application, the fluctuation score is used to indicate the probability that the network has abnormal fluctuations at a corresponding time, and the fluctuation score is positively correlated with the probability of abnormal fluctuations.
[0088] In other words, a larger fluctuation score indicates a higher probability that the network has abnormal fluctuations at the corresponding time; conversely, a smaller fluctuation score indicates a lower probability that the network has abnormal fluctuations at the corresponding time.
[0089] S205. The detection device sums up multiple first fluctuation scores to obtain the target fluctuation score of the network to be detected at the current moment.
[0090] The target fluctuation score is used to indicate the probability that the network under test has abnormal fluctuations at the current moment.
[0091] In one possible design, the target fluctuation score can be represented by Formula 5.
[0092] w=∑(w′ i |b′ i ≤b) Formula 5.
[0093] Where w is used to indicate the target fluctuation score, i∈{t, ts, t-2·s, ..., tn·s}.
[0094] S206. The detection device determines whether the target fluctuation score is less than the preset score threshold.
[0095] In some embodiments, if the detection device determines that the target fluctuation score is greater than or equal to a preset score threshold, the detection device executes S207.
[0096] S207. The detection device generates target alarm information.
[0097] Among them, the target alarm information is used to indicate that the network under test is in an abnormal operating state at the current moment.
[0098] In one possible design, the target alarm information may include: target indicator value, target fluctuation value, and target fluctuation score.
[0099] The technical solution provided by the above embodiments brings at least the following beneficial effects: The detection device can acquire a target index value and multiple first historical index values. The target index value is the index value of the target network performance index of the network under test at the current time, and the first historical index value is the index value of the target network performance index of the network under test at a first historical time. Next, the detection device can determine the target fluctuation value of the network under test at the current time based on the target index value and multiple first historical index values, and filter out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. Then, the detection device can determine the first fluctuation score corresponding to each first fluctuation value based on a preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores. Next, the detection device can sum the multiple first fluctuation scores to obtain the target fluctuation score of the network under test at the current time, and determine whether the target fluctuation score is less than a preset score threshold. If the detection device determines that the target fluctuation score is greater than or equal to the preset score threshold, the detection device can generate target alarm information, which is used to indicate that the network under test is in an abnormal operating state at the current time. In other words, the detection device can determine the degree of fluctuation of the network under test at the current moment based on the network performance index values at the current moment and historical moments, and assess the probability of abnormal fluctuations in the network under test at the current moment. This allows for the determination of whether the network under test is in an abnormal operating state, ultimately achieving anomaly detection. Thus, it can provide valuable reference for network anomaly detection and improve the accuracy of anomaly detection results.
[0100] In other embodiments, if the detection device determines that the target fluctuation score is less than a preset score threshold, the detection device can generate target detection information. This target detection information indicates that the network under test is in normal operating condition at the current moment.
[0101] In one possible design, target detection information may include: target index value, target fluctuation value, and target fluctuation score.
[0102] Understandably, once the testing device determines that the network under test is operating normally at the current moment, it can generate target detection information indicating that the network is indeed operating normally. This target detection information, carrying target indicator values, target fluctuation values, and target fluctuation scores, presents the network's current operating status, fluctuation level, and the probability of abnormal fluctuations to the staff. This provides data support for staff to manage the network under test, improving management efficiency.
[0103] In some embodiments, such as Figure 3As shown, before S201, the method may also include: S301-S304.
[0104] S301. The detection device acquires multiple sets of historical indicator values based on multiple preset historical times.
[0105] In this context, a preset historical time corresponds to a set of historical indicator values. The preset historical time is greater than or equal to the second historical time corresponding to any indicator value in the set of historical indicator values. The difference between any two adjacent second historical times in the set of historical indicator values is equal to the preset time difference. The indicator values in the set of historical indicator values are the indicator values of the target network performance indicators of the network to be tested at the corresponding second historical time.
[0106] It should be noted that the process by which the detection device obtains multiple sets of historical index values based on multiple preset historical times can be referred to the above description of the detection device determining multiple first historical times based on the current time, preset time difference and preset sampling quantity, which will not be repeated here.
[0107] S302. For each set of historical index values, the detection device determines the preset fluctuation value of the network to be detected at a preset historical time based on the index values in the set of historical index values, so as to obtain multiple preset fluctuation values.
[0108] One preset fluctuation value corresponds to one set of historical indicator values.
[0109] It should be noted that the process by which the detection device determines the preset fluctuation value of the network to be detected at a preset historical time based on the index values in the set of historical index values can be referred to the above description of the detection device determining the target fluctuation value of the network to be detected at the current time based on the target index value and multiple first historical index values, which will not be repeated here.
[0110] In one possible implementation, the detection device can generate a target fluctuation value set based on multiple preset fluctuation values, the target fluctuation value set including multiple preset fluctuation values.
[0111] In one possible design, the target set of fluctuation values can be represented by Equation 6.
[0112] Y = {b1, b2, b3, ..., b} m Formula 6.
[0113] Where Y is used to indicate the target set of fluctuation values, b is used to indicate the fluctuation value of the network to be detected at different times, and m is used to indicate the number of preset fluctuation values.
[0114] S303. The detection device determines the preset fluctuation score corresponding to each preset fluctuation value based on multiple preset fluctuation values, so as to obtain multiple preset fluctuation scores.
[0115] In one possible implementation, for each preset fluctuation value, the detection device can determine a preset fluctuation score corresponding to each preset fluctuation value through a target operation, which may include:
[0116] Step 1: The detection device calculates the difference between the second fluctuation value and each of the multiple preset fluctuation values to obtain multiple target fluctuation differences.
[0117] The second fluctuation value is any one of multiple preset fluctuation values, and the multiple target fluctuation differences are all fluctuation differences corresponding to the second fluctuation value.
[0118] For example, the preset volatility values include 1.2, 2.5, 1.9, and 3.7. If the second volatility value is 1.9, then the target volatility differences corresponding to 1.9 include 0.7, 0.6, 0, and 1.8.
[0119] Step 2: The detection device updates the fluctuation difference values of multiple targets according to the preset fluctuation difference threshold and preset parameters, and obtains the updated fluctuation difference values of multiple targets.
[0120] The updated target fluctuation difference includes: fluctuation difference values that are less than or equal to a preset fluctuation difference threshold and multiple preset parameters. The number of preset parameters in the updated target fluctuation difference is equal to the number of fluctuation difference values that are greater than the preset fluctuation difference threshold.
[0121] For example, the target volatility differences include 0.5, 1.1, 0.62, and 0.27. If the preset volatility threshold is 0.6 and the preset parameter is 0, the updated target volatility differences can include 0.5, 0, 0, and 0.27.
[0122] Step 3: The detection device calculates the weighted average of the updated target fluctuation differences based on the preset weight values to obtain the preset fluctuation score corresponding to the second fluctuation value.
[0123] In one possible design, the preset fluctuation score corresponding to the second fluctuation value can be represented by Formula 7.
[0124]
[0125] Where 'a' indicates the preset weight value, and 'c' indicates the preset weight value. j Used to indicate the j-th updated target volatility difference among the multiple updated target volatility differences corresponding to the i-th preset volatility value in Y.
[0126] In one possible implementation, the detection device can preprocess multiple updated target fluctuation differences according to a preset ratio to obtain multiple first fluctuation differences, with one target fluctuation difference corresponding to one first fluctuation difference. Next, the detection device can perform an exponential operation on each first preset difference to obtain multiple second fluctuation differences, with one second fluctuation difference corresponding to one first fluctuation difference. Then, the detection device calculates a weighted average of the multiple second fluctuation differences according to preset weight values to obtain a preset fluctuation score corresponding to each second fluctuation value.
[0127] In one possible design, the preset fluctuation scores corresponding to the first fluctuation difference, the second fluctuation value, and the second fluctuation value can be represented by Formula 8, Formula 9, and Formula 10, respectively.
[0128]
[0129]
[0130]
[0131] Where, c′ j Used to indicate the j-th first fluctuation difference among multiple first fluctuation differences, f is used to indicate the preset ratio, c″ j Used to indicate the j-th second fluctuation difference among multiple second fluctuation differences, e is used to indicate the exponential operation.
[0132] In one possible implementation, after the detection device determines the fluctuation scores corresponding to multiple preset fluctuation values, the detection device can normalize the fluctuation scores corresponding to the multiple preset fluctuation values to obtain multiple preset fluctuation scores, with one preset fluctuation value corresponding to one preset fluctuation score.
[0133] In one possible design, the preset fluctuation score can be represented by Equation 11.
[0134]
[0135] Where, k i k is used to indicate the volatility score corresponding to the i-th preset volatility value among multiple preset volatility scores. j Indicates the volatility score corresponding to the j-th preset volatility value among multiple preset volatility values.
[0136] S304. The detection device generates a preset correspondence based on multiple preset fluctuation values and multiple preset fluctuation scores.
[0137] Understandably, the detection device can determine the preset fluctuation value and preset fluctuation score of the network under test at each preset historical time based on the target network performance index values at multiple preset historical time points and the target network performance index values at multiple second historical time points prior to each first preset historical time point. It can also establish a correspondence between multiple preset fluctuation values and multiple preset fluctuation scores to obtain a preset correspondence. In other words, the detection device can determine the degree of fluctuation and the probability of abnormal fluctuations in the network under test at historical time points based on the network performance index values. This provides valuable reference for network anomaly detection and improves the accuracy of anomaly detection results.
[0138] The network anomaly detection method provided in this application will be described below with specific examples. For instance... Figure 4 As shown, the specific steps are as follows:
[0139] S401. The detection device reads historical data of network performance indicators and calculates the fluctuation value based on the time span.
[0140] In this embodiment of the application, the detection device can read historical data and perform data preprocessing.
[0141] In one possible implementation, the detection device can read historical network performance data according to a preset time period T (10 days in this embodiment) to obtain a historical data set List1. Let the number of data in List1 be N (14400 in this embodiment). For the data at each historical time t (t = 0, 1, 2, ..., N), according to a preset time span win (5 in this embodiment), extract the indicator values within the most recent win time period of each historical time t and mark them as a set List_t (i.e., the set of historical indicator values), resulting in N List_t sets. For each set List_t, a state is defined.
[0142] In one possible design, List_t can be represented by Equation Twelve.
[0143] List_t = {v t v t-1 v t-2 , ..., v t-win} Formula 12.
[0144] Where t represents a historical moment and v represents the index value at that time.
[0145] Afterwards, the detection device can calculate the fluctuation value of the List_t data set, express it in terms of variance, and obtain var_t (i.e., the preset fluctuation value). It can obtain N fluctuation values corresponding to N List_t sets, which are recorded as a set and labeled as List_var.
[0146] In one possible design, var_t and List_var can be represented by Formula Thirteen and Formula Fourteen, respectively.
[0147]
[0148] List_var = {var_1, var_2, ..., var_N} Formula Fourteen.
[0149] Where, x i ∈List_t, u is the arithmetic mean of List_t.
[0150] S402, The detection device learns the distribution characteristics of fluctuation values.
[0151] In this embodiment of the application, the detection device can train a model to learn the distribution characteristics of the fluctuation value set List_var, and perform the following calculations for each element var_i (i = 1, 2, 3, ..., N) of the fluctuation value set List_var:
[0152] Step A: The detection device calculates the difference between var_i and the data elements in the fluctuation value set List_var to obtain the set List2 (i.e., multiple target fluctuation differences).
[0153] Step B: The detection device compares each element in the set List2 with the preset parameter h (i.e., the preset fluctuation difference threshold). If the absolute value of the element is less than or equal to h, it is retained. If the absolute value of the element is greater than h, it is set to 0 (i.e., the preset parameter), thus obtaining the set List3 (i.e., the updated multiple target fluctuation differences).
[0154] Step C: The detection device divides the elements in set List3 by h to obtain set List4 (i.e., multiple first fluctuation differences).
[0155] Step D: The detection device performs exponential operations on the elements in set List4 to obtain set List5 (i.e., multiple second fluctuation differences).
[0156] List5 can be represented by Formula 15.
[0157] List5 = {e -x Formula 15, x∈List4}.
[0158] Step E: The detection device performs a weighted average of the elements in set List5 to obtain w. var_i The weight estimate E(w) var_i ).
[0159] In one possible design, E(w) var_i It can be expressed by formula sixteen (i.e. formula ten).
[0160]
[0161] Where xi∈List5, and var_i represents the i-th element in List_var.
[0162] Step F: The detection device applies each estimated weight E(w) var_i The weights w are obtained by performing a normalization operation. var_i .
[0163] Wherein, weight w var_i It can be expressed by Formula 17 (i.e. Formula 11).
[0164]
[0165] In this embodiment of the application, after steps A to F, the detection device can obtain the fluctuation value of each state and the weight of its occurrence, and obtain the distribution characteristics of the fluctuation value (i.e., the preset correspondence), which is represented by List6.
[0166] In one possible design, List6 can be represented by Formula 18 (i.e. Formula 4).
[0167] List6 = {var_i:w var_i Formula 18.
[0168] Where var_i represents the i-th element in List_var, w var_i This represents the weight of var_i.
[0169] S403. The detection device calculates the latest fluctuation value (i.e., the target fluctuation value) of the network performance index.
[0170] In this embodiment of the application, the detection device can extract the most recent 'win' data according to the preset time span 'win' in S401, define it as the current state, denoted by List_latest, and calculate the fluctuation value var_latest of the current state List_latest according to the fluctuation value calculation method in S401.
[0171] S404, The detection device determines whether the latest fluctuation value is abnormal (i.e., S206).
[0172] In this embodiment of the application, the detection device can calculate the fluctuation value score of the current state (i.e., the target fluctuation score), and give a judgment result on whether the fluctuation value of the current state is abnormal based on the predetermined maximum value P (i.e., the preset score threshold).
[0173] In one possible design, the current state fluctuation score can be represented by Equation 19 (i.e. Equation 5).
[0174] score=∑(w var_i |var_i≤var_latest); i=0,1,2,...,N Formula 19.
[0175] Specifically, the judgment logic for determining whether the fluctuation score of the current state of the detection device is abnormal can be expressed by Formula 20.
[0176]
[0177] For example, such as Figure 5 As shown, it illustrates the abnormal fluctuation detection results determined based on the network anomaly detection method provided in this application embodiment. The target network performance indicator is network traffic, and the network under test was in an abnormal operating state during time 568 to 610.
[0178] The foregoing primarily describes the solutions provided in the embodiments of this application from the perspective of computer devices. It is understood that, in order to achieve the above functions, the computer device includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the network anomaly detection method steps described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0179] This application also provides a network anomaly detection device. This network anomaly detection device can be a computer device, a CPU within the aforementioned computer device, a processing module within the aforementioned computer device for detecting network anomalies, or a client within the aforementioned computer device for detecting network anomalies.
[0180] This application embodiment can divide the network anomaly detection device into functional modules or functional units according to the above method examples. For example, each function can be divided into its own functional modules or functional units, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module or functional unit. The module or unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0181] like Figure 6 The diagram shown is a structural schematic of a network anomaly detection device provided in an embodiment of this application. The network anomaly detection device is used to perform... Figure 2 or Figure 3 The network anomaly detection method shown may include an acquisition module 601 and a processing module 602.
[0182] The acquisition module 601 is used to acquire a target indicator value and multiple first historical indicator values. The target indicator value is the indicator value of the target network performance index of the network under test at the current time, and the first historical indicator values are the indicator values of the target network performance index of the network under test at the first historical time. The processing module 602 is used to determine the target fluctuation value of the network under test at the current time based on the target indicator value and the multiple first historical indicator values. The processing module 602 is also used to filter out first fluctuation values less than or equal to the target fluctuation value from multiple preset fluctuation values to obtain multiple first fluctuation values. The processing module 602 is also used to determine the first fluctuation score corresponding to each first fluctuation value according to a preset correspondence between the multiple preset fluctuation values and multiple preset fluctuation scores to obtain multiple first fluctuation scores. The processing module 602 is also used to sum the multiple first fluctuation scores to obtain the target fluctuation score of the network under test at the current time. The processing module 602 is also used to generate target alarm information if the target fluctuation score is greater than or equal to a preset score threshold. The target alarm information is used to indicate that the network under test is in an abnormal operating state at the current time.
[0183] Optionally, the acquisition module 601 is further configured to acquire multiple sets of historical indicator values based on multiple preset historical times. Each preset historical time corresponds to one set of historical indicator values. A second historical time corresponds to a preset historical indicator value that is greater than or equal to any indicator value in the corresponding set of historical indicator values. The indicator values in the set of historical indicator values represent the target network performance indicators of the network under test at the corresponding second historical time. The processing module 602 is further configured to, for each set of historical indicator values, determine a preset fluctuation value of the network under test at the preset historical time based on the indicator values in the set of historical indicator values, thereby obtaining multiple preset fluctuation values. Each preset fluctuation value corresponds to one set of historical indicator values. The processing module 602 is further configured to determine a preset fluctuation score corresponding to each preset fluctuation value, thereby obtaining multiple preset fluctuation scores. The processing module 602 is further configured to generate a preset correspondence relationship based on the multiple preset fluctuation values and the multiple preset fluctuation scores.
[0184] Optionally, the processing module 602 is specifically used to determine a preset fluctuation score corresponding to each preset fluctuation value through a target operation. The target operation includes: calculating the difference between a second fluctuation value and each of the multiple preset fluctuation values to obtain multiple target fluctuation differences, where the second fluctuation value is any fluctuation value among the multiple preset fluctuation values; updating the multiple target fluctuation differences according to a preset fluctuation difference threshold and preset parameters to obtain updated multiple target fluctuation differences, where the updated multiple target fluctuation differences include: fluctuation differences less than or equal to the preset fluctuation difference threshold and multiple preset parameters, and the number of preset parameters in the updated multiple target fluctuation differences is equal to the number of fluctuation differences greater than the preset fluctuation difference threshold; and calculating the weighted average of the updated multiple target fluctuation differences according to preset weight values to obtain the preset fluctuation score corresponding to the second fluctuation value.
[0185] Optionally, the difference between the current time and any two adjacent times among multiple first historical times is equal to a preset time difference, and the difference between any two adjacent second historical times in the set of historical index values is equal to a preset time difference.
[0186] Optionally, the target network performance metrics can be any of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, and data retransmission rate.
[0187] Figure 7 This is a schematic diagram of the hardware structure of a network anomaly detection device according to an exemplary embodiment. The network anomaly detection device may include a processor 702, which executes application code to implement the network anomaly detection method of this application.
[0188] The processor 702 may be a CPU, a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits used to control the execution of the program of the present application.
[0189] like Figure 7 As shown, the network anomaly detection device may further include a memory 703. The memory 703 stores the application code that executes the scheme of this application, and its execution is controlled by the processor 702.
[0190] Memory 703 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 703 may exist independently and be connected to processor 702 via bus 704. Memory 703 may also be integrated with processor 702.
[0191] like Figure 7 As shown, the network anomaly detection device may further include a communication interface 701, wherein the communication interface 701, processor 702, and memory 703 may be coupled to each other, for example, through a bus 704. The communication interface 701 is used for information exchange with other devices, for example, supporting information exchange between the network anomaly detection device and other devices.
[0192] It should be pointed out that, Figure 7 The device structure shown does not constitute a limitation on the network anomaly detection device, except... Figure 7 In addition to the components shown, the network anomaly detection device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.
[0193] In actual implementation, the functions implemented by processing module 602 can be derived by... Figure 7The processor 702 shown calls the program code in memory 703 to implement this.
[0194] This application also provides a computer-readable storage medium storing instructions that, when executed by a processor of a computer device, enable the computer to perform the network anomaly detection provided in the embodiments described above. For example, the computer-readable storage medium may be a memory 703 including instructions, which may be executed by a processor 702 of a computer device to complete the above method. Optionally, the computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a ROM, RAM, CD-ROM, magnetic tape, floppy disk, or optical data storage device.
[0195] Figure 8 A conceptual partial view of a computer program product provided in an embodiment of this application is shown as an example. The computer program product includes a computer program for executing computer processes on a computing device.
[0196] In one embodiment, the computer program product is provided using a signal bearer medium 800. The signal bearer medium 800 may include one or more program instructions that, when executed by one or more processors, can provide the above-mentioned... Figure 2 or Figure 3 The described function or part of the function. Therefore, for example, refer to... Figure 2 In the embodiment shown, one or more features of S201 to S207 can be fulfilled by one or more instructions associated with the signal carrying medium 800. Furthermore, Figure 8 The program instructions in the document also describe example instructions.
[0197] In some examples, the signal carrying medium 800 may include a computer-readable medium 801, such as, but not limited to, a hard disk drive, a compact disc (CD), a digital video disc (DVD), a digital magnetic tape, a memory, a read-only memory (ROM), or a random access memory (RAM), etc.
[0198] In some implementations, the signal carrying medium 800 may include a computer recordable medium 802, such as, but not limited to, a memory, a read / write (R / W) CD, a R / W DVD, etc.
[0199] In some implementations, the signal carrying medium 800 may include a communication medium 803, such as, but not limited to, digital and / or analog communication media (e.g., fiber optic cables, waveguides, wired communication links, wireless communication links, etc.).
[0200] The signal-bearing medium 800 can be transmitted by a wireless communication medium 803. One or more program instructions can be, for example, computer-executable instructions or logical implementation instructions.
[0201] In some examples, such as targeting Figure 6 The described network anomaly detection device can be configured to provide various operations, functions, or actions in response to one or more program instructions in a computer-readable medium 801, a computer-recordable medium 802, and / or a communication medium 803.
[0202] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0203] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another apparatus, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0204] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be in one place or distributed in multiple different locations. Some or all of the constituent units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0205] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0206] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, essentially, or the part that contributes to the prior art, or a complete or partial classification of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0207] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network anomaly detection method, characterized by, The method includes: Obtain a target indicator value and multiple first historical indicator values, wherein the target indicator value is the indicator value of the target network performance indicator of the network to be detected at the current time, and the first historical indicator value is the indicator value of the target network performance indicator of the network to be detected at the first historical time. Based on the target index value and the plurality of first historical index values, the target fluctuation value of the network to be detected at the current moment is determined; From a plurality of preset fluctuation values, a first fluctuation value that is less than or equal to the target fluctuation value is selected to obtain a plurality of first fluctuation values; Based on the preset correspondence between the multiple preset fluctuation values and the multiple preset fluctuation scores, a first fluctuation score corresponding to each first fluctuation value is determined to obtain multiple first fluctuation scores; The target fluctuation score of the network to be detected at the current time is obtained by summing the plurality of the first fluctuation scores. If the target fluctuation score is greater than or equal to a preset score threshold, a target alarm message is generated. The target alarm message is used to indicate that the network under test is in an abnormal operating state at the current time.
2. The method according to claim 1, characterized in that, Before obtaining the target indicator value and multiple first historical indicator values, the method further includes: Based on multiple preset historical moments, multiple sets of historical indicator values are obtained. Each preset historical moment corresponds to one set of historical indicator values. The preset historical moment is greater than or equal to the second historical moment corresponding to any indicator value in the set of historical indicator values. The indicator values in the set of historical indicator values are the indicator values of the target network performance indicators of the network to be detected at the corresponding second historical moment. For each set of historical indicator values, the preset fluctuation value of the network to be detected at the preset historical time is determined based on the indicator values in the set of historical indicator values, so as to obtain the plurality of preset fluctuation values, and one preset fluctuation value corresponds to one set of historical indicator values. Based on the plurality of preset fluctuation values, determine the preset fluctuation score corresponding to each preset fluctuation value to obtain the plurality of preset fluctuation scores; The preset correspondence is generated based on the multiple preset fluctuation values and the multiple preset fluctuation scores.
3. The method according to claim 2, characterized in that, The step of determining the preset fluctuation score corresponding to each preset fluctuation value based on the plurality of preset fluctuation values includes: For each preset fluctuation value, a preset fluctuation score corresponding to each preset fluctuation value is determined through a target operation, wherein the target operation includes: Calculate the difference between the second fluctuation value and each of the plurality of preset fluctuation values to obtain a plurality of target fluctuation differences, wherein the second fluctuation value is any fluctuation value among the plurality of preset fluctuation values; Based on a preset fluctuation difference threshold and preset parameters, the plurality of target fluctuation difference values are updated to obtain the updated plurality of target fluctuation difference values. The updated plurality of target fluctuation difference values include: fluctuation difference values less than or equal to the preset fluctuation difference threshold and a plurality of preset parameters. The number of preset parameters in the updated plurality of target fluctuation difference values is equal to the number of fluctuation difference values greater than the preset fluctuation difference threshold. Based on preset weight values, the weighted average of the updated multiple target fluctuation differences is calculated to obtain the preset fluctuation score corresponding to the second fluctuation value.
4. The method according to claim 3, characterized in that, The difference between the current time and any two adjacent times in the plurality of first historical times is equal to a preset time difference, and the difference between any two adjacent second historical times in the set of historical index values is equal to the preset time difference.
5. The method according to any one of claims 1-4, characterized in that, The target network performance indicators are any one of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, and data retransmission rate.
6. A network anomaly detection device, characterized in that, The device includes: The acquisition module is used to acquire a target indicator value and multiple first historical indicator values. The target indicator value is the indicator value of the target network performance indicator of the network to be detected at the current time, and the first historical indicator value is the indicator value of the target network performance indicator of the network to be detected at the first historical time. The processing module is used to determine the target fluctuation value of the network to be detected at the current moment based on the target indicator value and the plurality of first historical indicator values; The processing module is further configured to filter out a first fluctuation value that is less than or equal to the target fluctuation value from a plurality of preset fluctuation values, so as to obtain a plurality of first fluctuation values; The processing module is further configured to determine the first fluctuation score corresponding to each first fluctuation value according to the preset correspondence between the multiple preset fluctuation values and the multiple preset fluctuation scores, so as to obtain multiple first fluctuation scores; The processing module is further configured to sum the plurality of first fluctuation scores to obtain the target fluctuation score of the network to be detected at the current time; The processing module is further configured to generate target alarm information if the target fluctuation score is greater than or equal to a preset score threshold, and the target alarm information is used to indicate that the network under test is in an abnormal operating state at the current time.
7. The apparatus according to claim 6, characterized in that, The acquisition module is further configured to acquire multiple sets of historical indicator values based on multiple preset historical times, wherein one preset historical time corresponds to one set of historical indicator values, the preset historical time is greater than or equal to the second historical time corresponding to any indicator value in the corresponding set of historical indicator values, and the indicator values in the set of historical indicator values are the indicator values of the target network performance indicators of the network to be detected at the corresponding second historical time. The processing module is further configured to, for each set of historical indicator values, determine the preset fluctuation value of the network to be detected at the preset historical time based on the indicator values in the set of historical indicator values, so as to obtain the plurality of preset fluctuation values, wherein one preset fluctuation value corresponds to one set of historical indicator values. The processing module is further configured to determine the preset fluctuation score corresponding to each preset fluctuation value based on the plurality of preset fluctuation values, so as to obtain the plurality of preset fluctuation scores; The processing module is also used to generate the preset correspondence relationship based on the multiple preset fluctuation values and the multiple preset fluctuation scores.
8. The apparatus according to claim 7, characterized in that, The processing module is specifically used to determine the preset fluctuation score corresponding to each preset fluctuation value through a target operation, wherein the target operation includes: Calculate the difference between the second fluctuation value and each of the plurality of preset fluctuation values to obtain a plurality of target fluctuation differences, wherein the second fluctuation value is any fluctuation value among the plurality of preset fluctuation values; Based on a preset fluctuation difference threshold and preset parameters, the plurality of target fluctuation difference values are updated to obtain the updated plurality of target fluctuation difference values. The updated plurality of target fluctuation difference values include: fluctuation difference values less than or equal to the preset fluctuation difference threshold and a plurality of preset parameters. The number of preset parameters in the updated plurality of target fluctuation difference values is equal to the number of fluctuation difference values greater than the preset fluctuation difference threshold. Based on preset weight values, the weighted average of the updated multiple target fluctuation differences is calculated to obtain the preset fluctuation score corresponding to the second fluctuation value.
9. The apparatus according to claim 8, characterized in that, The difference between the current time and any two adjacent times in the plurality of first historical times is equal to a preset time difference, and the difference between any two adjacent second historical times in the set of historical index values is equal to the preset time difference.
10. The apparatus according to any one of claims 6-9, characterized in that, The target network performance indicators are any one of the following: network latency, latency jitter, throughput, network packet loss rate, channel utilization, and data retransmission rate.
11. A network anomaly detection device, characterized in that, include: Processor and memory; The processor and the memory are coupled; The memory is used to store one or more programs, the one or more programs including computer execution instructions. When the network anomaly detection device is running, the processor executes the computer execution instructions stored in the memory to cause the network anomaly detection device to perform the network anomaly detection method as described in any one of claims 1-5.
12. A computer-readable storage medium storing instructions, characterized in that, When the computer executes the instructions, the computer performs the network anomaly detection method as described in any one of claims 1-5.