PCDN user management methods, devices, and computer equipment
By redirecting traffic from PCDN user management to the tunnel router and performing feature value matching, suspected PCDN users are automatically identified and processed, solving the problem of low efficiency in existing technologies and achieving highly efficient automated processing.
Patent Information
- Application Number
- CN202411655918.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-18
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-11-18
AI Technical Summary
In existing technologies, the identification and handling of PCDN users mainly rely on manual analysis, which is inefficient and has a long response time, lacking an automated and efficient information feedback and handling mechanism.
By identifying suspected PCDN users from multiple users to be identified, their traffic is diverted to a preset tunnel router, feature values are obtained and matched with a preset PCDN user feature database, suspected PCDN users are confirmed and processed, and their traffic is processed using a predetermined strategy.
It has enabled automated identification and handling of PCDN users, improved processing efficiency, and solved the problem of low efficiency in manual identification and handling.
Smart Images

Figure CN119363472B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the network technical field, in particular to a PCDN user management method and device and computer equipment. BACKGROUND
[0002] With the rapid development of Internet technology, network traffic management and network security control become increasingly complex. Under this background, PCDN (Partial Content Delivery Network) as a special application mode, the traffic characteristics it brings and the regular network usage mode exist significant differences, especially in the uplink traffic. PCDN users often produce far beyond the normal range of uplink data transmission, which not only occupies a large amount of network bandwidth resources, but also may cause network congestion, reduce network service quality, and even pose a potential threat to network security. When facing PCDN problems, the traditional processing method mainly relies on manual analysis and manual intervention, which is low in efficiency and long in response time. When the fixed network AAA (Authentication, Authorization, Accounting) system identifies suspected PCDN users, it often lacks an automatic, efficient information feedback and disposal mechanism.
[0003] In view of the above problems, no effective solution has been proposed so far. SUMMARY
[0004] The embodiments of the present application provide a PCDN user management method, device and computer equipment to at least solve the technical problem of low PCDN disposal efficiency caused by manual identification and disposal.
[0005] According to an aspect of the embodiments of the present application, a PCDN user management method is provided, comprising: identifying suspected PCDN users from a plurality of to-be-identified users; diverting the traffic of the suspected PCDN users to a preset tunnel router, and obtaining a feature value corresponding to the traffic of the suspected PCDN users, the feature value being used to represent the traffic characteristics of the user; matching the feature value corresponding to the traffic of the suspected PCDN users with the feature values in a preset PCDN user feature library by using the preset tunnel router, wherein in the case that the feature value corresponding to the traffic of the suspected PCDN users matches the feature values in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; and processing the traffic of the PCDN user according to a predetermined processing strategy.
[0006] Optionally, the tunneling the traffic of the suspected PCDN user to the preset tunneling router comprises: performing a kick-off operation on the suspected PCDN user; in a case where the suspected PCDN user re-accesses, performing VPDN authentication on the suspected PCDN user to establish a tunnel between the suspected PCDN user and the tunneling router; and obtaining traffic data of the suspected PCDN user through the tunnel.
[0007] Optionally, the comparison of the feature value corresponding to the traffic of the suspected PCDN user with the feature value in the preset PCDN user feature library comprises: obtaining the feature value corresponding to the traffic of the suspected PCDN user, the feature value corresponding to the traffic of the suspected PCDN user comprising at least one of the following: a MAC address device type of the suspected PCDN user, a destination address of the suspected PCDN user, a divergence degree of a source address to a destination address of the suspected PCDN user, and a destination address proportion of uplink traffic of the suspected PCDN user; and evaluating a similarity between the feature value corresponding to the traffic of the suspected PCDN user and the feature value in the preset PCDN user feature library, and in a case where the similarity is higher than a first threshold, determining that the feature value corresponding to the traffic of the suspected PCDN user matches the feature value in the preset PCDN user feature library.
[0008] Optionally, the processing of the traffic of the PCDN user according to the predetermined processing strategy comprises: issuing a preset domain name to the PCDN user, the preset domain name being used to direct the traffic of the PCDN user to a preset environment; and in the preset environment, performing traffic limiting processing on each session of the PCDN user.
[0009] Optionally, after the processing of the traffic of the PCDN user according to the predetermined processing strategy, the method further comprises: in a case where a quantity of reduced uplink traffic of the PCDN user is greater than a preset quantity threshold, determining that the PCDN user is effectively controlled, and marking a destination link of the traffic of the PCDN user after the processing; in a case where the uplink traffic of the PCDN user is not reduced, determining that the PCDN user will mark the PCDN user as an observation period user; in a case where the uplink traffic of the observation period user is always not reduced, determining that the observation period user is a white list user, and determining a feature of the white list user as a white list feature.
[0010] Optionally, the method of comparing the feature value corresponding to the traffic of the suspected PCDN user with the feature value in the preset PCDN user feature library further comprises: performing feature value extraction on the suspected PCDN user in multiple ways, wherein the multiple ways at least include: obtaining a divergence score of the suspected PCDN user, obtaining a server to which the suspected PCDN user belongs, and classifying a protocol of the suspected PCDN user; comparing the extracted feature value with a historical feature value of the PCDN user, and in a case of matching the historical feature value, processing the traffic of the suspected PCDN user according to a predetermined processing strategy.
[0011] According to another aspect of the embodiments of the present application, a PCDN user management apparatus is further provided, comprising: an identification module, configured to identify a suspected PCDN user from a plurality of to-be-identified users; a diversion module, configured to divert traffic of the suspected PCDN user to a preset tunnel router, and obtain a feature value corresponding to the traffic of the suspected PCDN user, the feature value being used to represent a traffic feature of the user; a matching module, configured to match the feature value corresponding to the traffic of the suspected PCDN user with a feature value in a preset PCDN user feature library by using the preset tunnel router, wherein in a case that the feature value corresponding to the traffic of the suspected PCDN user matches the feature value in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; and a processing module, configured to process the traffic of the PCDN user according to a predetermined processing strategy.
[0012] According to still another aspect of the embodiments of the present application, a computer program product is further provided, comprising: computer instructions, which are executed by a processor to implement the PCDN user management method.
[0013] According to still another aspect of the embodiments of the present application, a computer program product is further provided, comprising: computer instructions, which are executed by a processor to implement the PCDN user management method.
[0014] In the embodiment of the present application, a suspected PCDN user is identified from a plurality of to-be-identified users; traffic of the suspected PCDN user is diverted to a preset tunnel router, and a feature value corresponding to the traffic of the suspected PCDN user is obtained, the feature value being used to represent a traffic feature of the user; the preset tunnel router is used to match the feature value corresponding to the traffic of the suspected PCDN user with feature values in a preset PCDN user feature library, wherein in a case where the feature value corresponding to the traffic of the suspected PCDN user matches the feature values in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; and a traffic of the PCDN user is processed according to a predetermined processing strategy, thereby achieving the purpose of automatic feedback in PCDN identification and disposal, and further solving the technical problem of low PCDN disposal efficiency caused by manual identification and disposal. BRIEF DESCRIPTION OF DRAWINGS
[0015] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application and illustrate the illustrative embodiments of the present application and their description serve to explain the present application, and do not constitute improper limitations on the present application. In the drawings:
[0016] Figure 1 is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a method for identifying risk data according to an embodiment of the present application;
[0017] Figure 2 is a schematic diagram of a PCDN user management method flow according to an embodiment of the present application;
[0018] Figure 3 is a schematic diagram of a tunnel-based PCDN prevention and control method flow according to an embodiment of the present application;
[0019] Figure 4 is a schematic diagram of a user feature value output flow when a fault reporting user and a tunnel router belong to the same AS number according to an embodiment of the present application;
[0020] Figure 5 is a schematic diagram of a user feature value output flow when a fault reporting user and a tunnel router do not belong to the same AS number according to an embodiment of the present application;
[0021] Figure 6 is a schematic diagram of a NAT4 construction flow according to an embodiment of the present application;
[0022] Figure 7 is a schematic diagram of a feature value processing flow according to an embodiment of the present application;
[0023] Figure 8 is a structural schematic diagram of a PCDN user management device according to an embodiment of the present application. DETAILED DESCRIPTION
[0024] In order to make the personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of the present application.
[0025] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.
[0026] In order to facilitate those skilled in the art to better understand the embodiments of the present application, some technical terms or nouns related to the embodiments of the present application are explained as follows:
[0027] VPDN: VPDN stands for Virtual Private Dialup Networks, which refers to dial-up access to the Internet, transmitting private data on public networks by packetizing and encrypting network data, achieving the security level of private networks, and using the architecture of the public switched telephone network (PSTN) to build private networks for enterprises and institutions.
[0028] PCDN: (Partial Content Delivery Network) is a technology for accelerating network transmission, which distributes content to multiple edge nodes.
[0029] NAT4: Symmetric NAT, Symmetric NAT has the limited feature of port-restricted cone, and each request for an internal address to a specific external address may be bound to a new port number. That is, the port number mapped by the request for different external addresses may be different.
[0030] With the development of the tunnel, an internal layer 2 tunnel based on a wide area network becomes a popular means for implementing business construction across a wide area network. In this way, we can process PCDN users identified from tunnel flow concentration and use the NAT4 technology to automatically issue policies to realize a complete automatic information chain from discovery to disposal and from disposal to evaluation, greatly improving the disposal efficiency of PCDN.
[0031] The PCDN user management method embodiment provided by the embodiment of the application can be executed in a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal for implementing a PCDN user management method is shown. As shown in the figure, Figure 1 The computer terminal 10 can include one or more processors (the processor can include but is not limited to a microprocessor MCU or a programmable logic device FPGA processing device), a memory 104 for storing data, and a transmission module 106 for communication functions connected through a wired and / or wireless network. In addition, it can also include a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the I / O interface), a network interface, a BUS bus. Those skilled in the art can understand, Figure 1 The structure shown is only a schematic, which does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 can include more or fewer components than those shown in Figure 1 or have a different configuration than Figure 1 shown.
[0032] It should be noted that the one or more processors and / or other data processing circuits described above can be referred to herein as "data processing circuits" in general. The data processing circuit can be embodied in whole or in part as software, hardware, firmware, or any other combination. In addition, the data processing circuit can be a single independent processing module, or any one of the other elements combined into the computer terminal 10 in whole or in part. As referred to in the embodiments of the present application, the data processing circuit controls as a processor (for example, the selection of the variable resistance terminal path connected to the interface).
[0033] The memory 104 can be used to store software programs of application software and modules, such as program instructions / data storage means corresponding to the PCDN user management method of the embodiments of the present application, and the processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, i.e. implements the above-mentioned PCDN user management method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor, which can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0034] The transmission module 106 is used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the computer terminal 10. In one example, the transmission module 106 includes a network adapter (NIC) which can be connected to other network devices through a base station so as to be able to communicate with the Internet. In one example, the transmission module 106 can be a radio frequency (RF) module which is used to communicate with the Internet in a wireless manner.
[0035] The display can be, for example, a touch screen type liquid crystal display (LCD) which can enable a user to interact with the user interface of the computer terminal 10.
[0036] It should be noted that, in some optional embodiments, the above-mentioned Figure 1 The computer terminal shown can include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that, Figure 1 is merely one example of a particular implementation, and is intended to illustrate the types of components that can be present in the above-mentioned computer terminal.
[0037] Under the above-mentioned operating environment, the embodiments of the present application provide a PCDN user management method embodiment. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown.
[0038] Figure 2 is a flowchart of a PCDN user management method according to the embodiments of the present application, asFigure 2 As shown, the method comprises the following steps:
[0039] Step S202, identifying a suspected partial content distribution network PCDN user from a plurality of to-be-identified users;
[0040] In step S202, there are various ways to identify a suspected partial content distribution network PCDN user from a plurality of to-be-identified users, one of which is to determine a user whose weekly uplink peak is much greater than the weekly downlink peak as a suspected PCDN user.
[0041] It can be understood that much greater means that the difference between the weekly uplink peak and the weekly downlink peak is greater than a preset threshold, and the week is a preset period, which can be set according to the actual scene, for example, one week.
[0042] It needs to be explained that the IP address and MAC address of the suspected PCDN user can be collected through the fixed network AAA system.
[0043] Step S204, diverting the traffic of the suspected PCDN user to a preset tunnel router, and obtaining a feature value corresponding to the traffic of the suspected PCDN user, the feature value being used to represent the traffic characteristics of the user;
[0044] Step S206, matching the feature value corresponding to the traffic of the suspected PCDN user with the feature values in the preset PCDN user feature library by using the preset tunnel router, wherein in the case that the feature value corresponding to the traffic of the suspected PCDN user matches the feature values in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user.
[0045] In step S206, if the feature value in the preset PCDN user feature library is matched, it directly enters the processing queue of the PCDN for PCDN processing, and if the feature value in the preset PCDN user feature library is not matched, it enters the suspected processing queue of the PCDN for PCDN processing plus PCDN feature recognition.
[0046] Through the above steps, the suspected PCDN user is diverted to the preset tunnel router for identification, and the traffic of the PCDN user is processed by using the predetermined processing strategy, so as to achieve the purpose of automatic feedback in the identification and disposal of the PCDN, and further solve the technical problem of low PCDN disposal efficiency caused by manual identification and disposal.
[0047] The management method of the PCDN user in steps S202 to S206 of the embodiment of the present application is further introduced below.
[0048] In step S204, the specific steps of attracting the traffic of the suspected PCDN user to the preset tunnel router include: performing a kick-off operation on the suspected PCDN user; in the case that the suspected PCDN user re-accesses, performing VPDN authentication on the suspected PCDN user to establish a tunnel between the suspected PCDN user and the tunnel router; and obtaining the traffic data of the suspected PCDN user through the tunnel.
[0049] In an optional manner, a user is kicked off, and when the user dials in again, VPDN authentication is started, the user dialing forms an L2TP tunnel, and the user enters the tunnel router. At this time, the tunnel router captures the uplink traffic and the downlink traffic according to the user IP address, including the IPv4 address, transmitted by the fixed network AAA, and the network state of the user when the suspected PCDN is restored.
[0050] In another optional manner, as Figure 3 , Figure 4 and Figure 5As shown, through the fixed network AAA authentication system, the real-time IP address and MAC address of the user are collected. The tunnel is started for user traction. The tunnel router is constructed, and the centralized PCDN processing point is set. The PCDN processing point constructs a tunnel router, and the server has LNS termination function, NAT agent setting, port mirroring packet capture function, BGP establishment function, etc. It is used for user tunnel access, address allocation, IP release, traffic traction, mirror packet capture analysis and NAT4 construction. When the suspected user and the tunnel router belong to the same AS (Autonomous System, Autonomous System) number, first, when the user reports a fault, the user dialing mode is modified, a two-layer tunnel from the user's uplink MSE to the tunnel router is constructed, the tunnel router allocates according to the user's original IP information, and at the same time, the tunnel router releases the detailed route and tractions the user's traffic with the uplink CR (Core Router, Core Router) where it is located. The tunnel router simultaneously guides the traffic into the planned mirror port, the mirror port is connected to the log server, the log server unpacks and labels the user for warehousing after unpacking; when the user reports a fault and the tunnel router does not belong to the same AS number, the user dialing mode is modified, a two-layer tunnel from the user's uplink MSE to the tunnel router is constructed, the tunnel router allocates according to the user's original IP information, and at the same time, the tunnel router releases the detailed route, and the CR and the user's CR establish a three-layer tunnel such as a GRE channel, and the user's CR measures the route into the tunnel to complete the user's online traffic traction to the remote. The log server and the remote workstation are interconnected, and the remote workstation calls the user packet capture information to provide output. The remote workstation performs embedded packet capture analysis according to the user information, and desensitizes part of the user information. For user faults, an integrated analysis tool is provided to output user characteristic values.
[0051] In step S206, the specific process of comparing the characteristic value corresponding to the traffic of the suspected PCDN user with the characteristic value in the preset PCDN user characteristic library is as follows: obtaining the characteristic value corresponding to the traffic of the suspected PCDN user, the characteristic value corresponding to the traffic of the suspected PCDN user includes at least one of the MAC address device type of the suspected PCDN user, the destination address of the suspected PCDN user, the divergence degree of the source address to the destination address of the suspected PCDN user, and the destination address proportion of the uplink traffic of the suspected PCDN user; evaluating the similarity between the characteristic value corresponding to the traffic of the suspected PCDN user and the characteristic value in the preset PCDN user characteristic library, and in the case where the similarity is higher than a first threshold, it is determined that the characteristic value corresponding to the traffic of the suspected PCDN user matches the characteristic value in the preset PCDN user characteristic library.
[0052] Specifically, the tunnel router and the upper route establish a BGP relationship, and a 32-bit v4 host route is sent to the neighbor according to the IPv4 of the suspected PCDN user, forming the route traction within the network. Then, the single user packet is captured for the mirror of the uplink port to the observation port. The feature comparison of the PCDN is performed, including but not limited to: MAC address device type, destination address matching, and source address to destination address divergence, and the proportion of the destination address of the uplink traffic, etc. to identify the suspected PCDN user.
[0053] In a case where the feature value corresponding to the traffic of the suspected PCDN user matches the feature value in the historical PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user. In the process of matching the feature value corresponding to the traffic of the suspected PCDN user with the feature value in the preset PCDN user feature library, the PCDN needs to be identified, and the feature value is captured, which is specifically as follows:
[0054] In the embodiments of the present application, the suspected PCDN user is captured by multiple ways, wherein the multiple ways at least include: obtaining the divergence score of the suspected PCDN user, obtaining the server to which the suspected PCDN user belongs, and classifying the protocol of the suspected PCDN user;
[0055] Specifically, as shown in Figure 6 The PCDN user enters the packet capture analysis through traction, and the traction process is as described above. For the captured packet, the source address, destination address, traffic, and source MAC are two-dimensionally tabulated. The analysis is formed with a preset time length as a period. The divergence of the user as the source to the external service as the destination is calculated from the above two-dimensional table. The following is a complex algorithm formula:
[0056]
[0057] Wherein, D represents the divergence score, I represents the number of different destination addresses, A(i) represents the traffic score of the i-th destination address (between 0 and 1), S(i) represents the repetition score of the i-th destination address (measuring the repetition of the destination address, between 0 and 1), P(i) represents the next period score of the i-th destination address (evaluating the influence on the future, between 0 and 1), E(i) represents the scalability score of the i-th destination address (the ability to derive other addresses, between 0 and 1), and α, β, γ, δ are weight coefficients.
[0058] It should be noted that the traffic score is used to represent the size of the traffic, the repetition score is used to represent the probability of the repetition of the destination address, the next period score is used to represent the influence degree of the destination address on the network traffic in the next period, and the scalability score of the destination address is used to represent the possibility evaluation index of the behavior of the destination address extending to other destination addresses.
[0059] This formula evaluates the quality and divergence of the destination address through multiple dimensions and considers the impact of thinking time, but the specific weight coefficients and evaluation criteria need to be further determined and calibrated according to actual situations and needs. In this way, the average divergence of each destination address is calculated.
[0060] The protocol distribution of suspected PCDN users can be determined in the following way:
[0061] We construct a protocol data point set P with the center coordinates (cx, cy).
[0062] We define a distance measurement formula to determine the distance between the data point and the center:
[0063]
[0064] Where p(p x , p y ) represents the protocol data point, and d represents the distance between the data point and the center.
[0065] In the case of inner circle radius r1 and outer circle radius r2 (r2 > r1), when d is not greater than r1, the data point belongs to the inner circle clustering. When d is between r1 and r2, the data point belongs to the intermediate circular ring clustering. When d is greater than r2, the data point does not belong to the two clusters, and the protocol can be divided into three categories based on the above method.
[0066] User class attribute classification: According to the device type of the user MAC, the MAC of the suspected user can be classified as a device type class label such as large enterprise, network company, small enterprise, personal user multiple address user. According to the type of the user, it can be determined whether the suspected PCDN user is a PCDN user.
[0067] In another optional way, a two-dimensional table is used to calculate the home server of the user terminal as the destination address and the external server as the source address, and the external server to the user terminal as the destination traffic is determined according to the traffic size and the number of repetitions of the multiple servers with the largest traffic and the most times as the servers to which the suspected PCDN user belongs.
[0068] According to the predetermined processing strategy, the traffic of the PCDN user is processed, including: issuing a preset domain name to the PCDN user, the preset domain name is used to direct the traffic of the PCDN user to a preset environment; in the preset environment, the traffic of each session of the PCDN user is limited and processed.
[0069] After the traffic of the PCDN user is processed according to the predetermined processing strategy, in a case where the number of the uplink traffic reduction of the PCDN user is greater than a preset number threshold, it is determined that the PCDN user is effectively controlled, and a link to which the traffic of the PCDN user disappears after processing is marked; in a case where the uplink traffic of the PCDN user does not reduce, the PCDN user is marked as an observation period user; in a case where the uplink traffic of the observation period user always does not reduce, the observation period user is determined as a whitelist user, and a feature of the whitelist user is determined as a whitelist feature. All feature values of the PCDN user are added to the preset PCDN user feature library to obtain an adjusted feature library; for unmatched features in all feature values that do not match the features in the preset PCDN user feature library, the feature weight is continuously increased, until the feature weight is higher than a first weight threshold, the unmatched features are deleted from the adjusted feature library; the whitelist feature is added to a whitelist feature library, and the weight of the whitelist feature in the whitelist feature library is continuously increased, until the weight of the whitelist feature is higher than a second weight threshold, the whitelist feature is removed from the whitelist feature library. In the embodiment of the application, a preset domain name is issued to the PCDN user, and the preset domain name is used to direct the traffic of the PCDN user to a preset environment; in the preset environment, traffic limiting processing is performed on each session of the PCDN user. In a case where the number of the uplink traffic reduction of the PCDN user is greater than a preset number threshold, it is determined that the PCDN user is effectively controlled, and a link to which the traffic of the PCDN user disappears after processing is marked; in a case where the uplink traffic of the PCDN user does not reduce, the PCDN user is marked as an observation period user; in a case where the uplink traffic of the observation period user always does not reduce, the observation period user is determined as a whitelist user, and a feature of the whitelist user is determined as a whitelist feature.
[0070] Specifically, the system captures the characteristic values of PCDN users and compares them with historical characteristic values. When a whitelisted characteristic value is matched, the user is immediately removed and their service restored. When a historical characteristic value is matched, NAT4 is constructed for handling. If traffic decreases, the handling is effective, the lifecycle of the matched historical characteristic value is reset, and other characteristic values are added. If the handling is ineffective, this characteristic value is marked as unmanageable by NAT, requiring further manual intervention. If no handling is found, the system enters the suspected PCDN handling stage. NAT4 is a symmetric NAT. Symmetric NAT maps all requests from the same internal network address and port to the same destination address and port to the same public network address and port. If the same internal network host sends packets to a different destination address using the same internal network address and port, different mappings will be used. This differs from port-restricted NAT, which maps all requests to the same public IP address and port, while symmetric NAT uses different mappings for different requests.
[0071] This application provides a prevention and control method based on tunnel PCDN, such as... Figure 7 As shown, suspected PCDN users are identified and their characteristics are matched. If a match is found, the user is confirmed as a PCDN user and processed accordingly. The characteristics of PCDN users are managed throughout their entire lifecycle. For suspected PCDN users that do not match, a NAT4 strategy is applied, and their characteristics are evaluated. This aims to improve the efficiency of automated handling of PCDN users. When the fixed network AAA identifies a PCDN user, automated redirection is implemented. A NAT4 strategy is deployed centrally on a single MSE (Mobile Service Provider), forming an automated control method covering the entire process from discovery to redirection, from redirection to handling, from handling to feedback, and flexible user recovery.
[0072] According to an embodiment of this application, an embodiment of a PCDN user management device is also provided. Figure 8 This is a schematic diagram of a PCDN user management device provided according to an embodiment of this application. Figure 8 As shown, the device includes:
[0073] Identification module 80 is used to identify suspected partial content delivery network (PCDN) users from multiple users to be identified;
[0074] The towing module 82 is used to divert the traffic of suspected PCDN users to a preset tunnel router and obtain the feature value corresponding to the traffic of the suspected PCDN users. The feature value is used to represent the traffic characteristics of the user.
[0075] The matching module 84 is configured to match the characteristic value corresponding to the traffic of the suspected PCDN user with the characteristic value in the preset PCDN user characteristic library by using the preset tunnel router, and in a case where the characteristic value corresponding to the traffic of the suspected PCDN user matches the characteristic value in the preset PCDN user characteristic library, the suspected PCDN user is confirmed as a PCDN user.
[0076] The processing module 86 is configured to process the traffic of the PCDN user according to a predetermined processing strategy.
[0077] The pulling module 82 includes a pulling sub-module configured to perform a kicking-off operation on the suspected PCDN user, and in a case where the suspected PCDN user re-accesses, performing VPDN authentication on the suspected PCDN user to establish a tunnel between the suspected PCDN user and the tunnel router, and obtaining traffic data of the suspected PCDN user through the tunnel.
[0078] The matching module 84 includes a comparison sub-module configured to compare the characteristic value corresponding to the traffic of the suspected PCDN user with the characteristic value in the preset PCDN user characteristic library, obtain the characteristic value corresponding to the traffic of the suspected PCDN user, and the characteristic value corresponding to the traffic of the suspected PCDN user includes at least one of a MAC address of the suspected PCDN user, a device type of the suspected PCDN user, a destination address of the suspected PCDN user, a divergence degree of a source address to a destination address of the suspected PCDN user, and a destination address proportion of uplink traffic of the suspected PCDN user, evaluate a similarity between the characteristic value corresponding to the traffic of the suspected PCDN user and the characteristic value in the preset PCDN user characteristic library, and in a case where the similarity is higher than a first threshold, determine that the characteristic value corresponding to the traffic of the suspected PCDN user matches the characteristic value in the preset PCDN user characteristic library.
[0079] The comparison sub-module includes a first processing unit configured to compare the characteristic value corresponding to the traffic of the suspected PCDN user with the characteristic value in the preset PCDN user characteristic library, further including: performing characteristic value grabbing on the suspected PCDN user in multiple ways, wherein the multiple ways include at least: obtaining a divergence score of the suspected PCDN user, obtaining a server to which the suspected PCDN user belongs, and classifying a protocol of the suspected PCDN user; comparing the grabbed characteristic value with a historical characteristic value of the PCDN user, and in a case where the historical characteristic value is matched, processing the traffic of the suspected PCDN user according to a predetermined processing strategy.
[0080] The processing module 86 includes a second processing unit configured to issue a preset domain name to a PCDN user, the preset domain name being used to direct traffic of the PCDN user to a preset environment; and perform traffic limiting processing on each session of the PCDN user in the preset environment. In a case where a number of reduced uplink traffic of the PCDN user is greater than a preset number threshold, it is determined that the PCDN user is effectively controlled, and a destination link of the PCDN user after traffic processing is marked as disappeared; in a case where the uplink traffic of the PCDN user is not reduced, the PCDN user is marked as an observation period user; in a case where the uplink traffic of the observation period user is always not reduced, the observation period user is determined as a whitelist user, and a feature of the whitelist user is determined as a whitelist feature. All feature values of the PCDN user are added to the preset PCDN user feature library to obtain an adjusted feature library; for unmatched features in all feature values that do not match features in the preset PCDN user feature library, a feature weight is continuously increased until the feature weight is higher than a first weight threshold, and the unmatched features are deleted from the adjusted feature library; and the whitelist feature is added to a whitelist feature library, and a weight of the whitelist feature in the whitelist feature library is continuously increased until the weight of the whitelist feature is higher than a second weight threshold, and the whitelist feature is removed from the whitelist feature library.
[0081] It can be understood that the whitelist feature is used to represent that the user has a feature of not being a PCDN user.
[0082] It should be noted that each module in the PCDN user management apparatus described above can be a program module (for example, a set of program instructions for implementing a certain specific function) or a hardware module. For the latter, it can be in the following form, but is not limited thereto: each of the modules is in the form of a processor, or the functions of each of the modules are implemented by a processor.
[0083] It should be noted that the PCDN user management apparatus provided in the present embodiment can be used to execute the PCDN user management method shown in Figure 2 Therefore, the related explanations and descriptions of the PCDN user management method described above are also applicable to the present embodiment, and will not be repeated here.
[0084] The embodiment of the present application further provides a computer program product comprising computer instructions, which, when executed by a processor, implement the steps of the management method of a PCDN user in various embodiments of the present application: identifying a suspected partial content distribution network (PCDN) user from a plurality of to-be-identified users; diverting traffic of the suspected PCDN user to a preset tunnel router, and obtaining a feature value corresponding to the traffic of the suspected PCDN user, the feature value being used to represent traffic characteristics of the user; and matching the feature value corresponding to the traffic of the suspected PCDN user with feature values in a preset PCDN user feature library by using the preset tunnel router, wherein in a case where the feature value corresponding to the traffic of the suspected PCDN user matches a feature value in a historical PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; and processing the traffic of the PCDN user according to a pre-determined processing strategy.
[0085] The above sequence numbers of the embodiments of the present application are only for description, and do not represent advantages or disadvantages of the embodiments.
[0086] In the above embodiments of the present application, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0087] In the several embodiments of the present application, it should be understood that the disclosed technology can be implemented in other ways. Of course, the unit described as the division is only a logical function division, and there can be other division manners in actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, units or modules, and can be electrical or other forms.
[0088] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0089] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware, or in the form of a software functional unit.
[0090] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.
[0091] The above is only the preferred embodiment of the present application, and it should be pointed out that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, which should be considered as the protection scope of the present application.
Claims
1. A method of managing PCDN users, characterized by, The method comprises: identifying a suspected PCDN user from a plurality of to-be-identified users; diverting the traffic of the suspected PCDN user to a preset tunnel router and obtaining a feature value corresponding to the traffic of the suspected PCDN user, the feature value being used to represent the traffic characteristics of the user; matching the feature value corresponding to the traffic of the suspected PCDN user with a feature value in a preset PCDN user feature library using the preset tunnel router, wherein in the case that the feature value corresponding to the traffic of the suspected PCDN user matches the feature value in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; processing the traffic of the PCDN user according to a predetermined processing strategy; diverting the traffic of the suspected PCDN user to a preset tunnel router, comprising: performing a kick-off-line operation on the suspected PCDN user; in the case that the suspected PCDN user re-connects, performing VPDN authentication on the suspected PCDN user to establish a tunnel between the suspected PCDN user and the tunnel router; and obtaining traffic data of the suspected PCDN user through the tunnel; comparing the feature value corresponding to the traffic of the suspected PCDN user with the feature value in the preset PCDN user feature library, comprising: obtaining the feature value corresponding to the traffic of the suspected PCDN user, the feature value corresponding to the traffic of the suspected PCDN user comprising at least one of the following: MAC address device type of the suspected PCDN user, destination address of the suspected PCDN user, divergence degree of source address to destination address of the suspected PCDN user, and destination address proportion of uplink traffic of the suspected PCDN user; and evaluating the similarity between the feature value corresponding to the traffic of the suspected PCDN user and the feature value in the preset PCDN user feature library, in the case that the similarity is higher than a first threshold, determining that the feature value corresponding to the traffic of the suspected PCDN user matches the feature value in the preset PCDN user feature library; processing the traffic of the PCDN user according to a predetermined processing strategy, comprising: issuing a preset domain name to the PCDN user, the preset domain name being used to direct the traffic of the PCDN user to a preset environment; and performing traffic limiting processing on each session of the PCDN user in the preset environment; after processing the traffic of the PCDN user according to the predetermined processing strategy, the method further comprises: in the case that the number of uplink traffic reduction of the PCDN user is greater than a preset number threshold, determining that the PCDN user is effectively controlled, and marking the destination link of the PCDN user after traffic processing disappears; in the case that the uplink traffic of the PCDN user does not decrease, determining that the PCDN user marks the PCDN user as an observation period user; in the case that the uplink traffic of the observation period user always does not decrease, determining that the observation period user is a white list user, and determining the feature of the white list user as a white list feature.
2. The method of claim 1, wherein, After processing the traffic of the PCDN user according to the predetermined processing strategy, the method further comprises: adding all the feature values of the PCDN user into the preset PCDN user feature library to obtain an adjusted feature library; for unmatched features in all the feature values that do not match the features in the preset PCDN user feature library, continuously increasing the feature weight until the feature weight is higher than a first weight threshold, and then deleting the unmatched features from the adjusted feature library; adding the whitelist features into a whitelist feature library, continuously increasing the weight of the whitelist features in the whitelist feature library until the weight of the whitelist features is higher than a second weight threshold, and then removing the whitelist features from the whitelist feature library.
3. The method of claim 1, wherein, The method further comprises: performing feature value extraction on the suspected PCDN user in multiple ways, wherein the multiple ways at least include obtaining a divergence score of the suspected PCDN user, obtaining a server to which the suspected PCDN user belongs, and classifying a protocol of the suspected PCDN user; comparing the extracted feature values with historical feature values of the PCDN user, and processing the traffic of the suspected PCDN user according to a predetermined processing strategy in the case of matching the historical feature values.
4. A PCDN user management device, characterized in that, an identification module is configured to identify a suspected PCDN user from a plurality of to-be-identified users; a traction module is configured to divert the traffic of the suspected PCDN user to a preset tunnel router, and obtain feature values corresponding to the traffic of the suspected PCDN user, wherein the feature values are used to represent the traffic characteristics of the user; a matching module is configured to match the feature values corresponding to the traffic of the suspected PCDN user with feature values in a preset PCDN user feature library using the preset tunnel router, wherein in the case that the feature values corresponding to the traffic of the suspected PCDN user match the feature values in the preset PCDN user feature library, the suspected PCDN user is confirmed as a PCDN user; a processing module is configured to process the traffic of the PCDN user according to a predetermined processing strategy; diverting the traffic of the suspected PCDN user to the preset tunnel router comprises: performing a kick-off-line operation on the suspected PCDN user; in the case that the suspected PCDN user re-connects, performing VPDN authentication on the suspected PCDN user to establish a tunnel between the suspected PCDN user and the tunnel router; and obtaining traffic data of the suspected PCDN user through the tunnel. The characteristic value corresponding to the traffic of the suspected PCDN user is compared with the characteristic values in the preset PCDN user characteristic library, including: obtaining the characteristic value corresponding to the traffic of the suspected PCDN user, the characteristic value corresponding to the traffic of the suspected PCDN user including at least one of the MAC address device type of the suspected PCDN user, the destination address of the suspected PCDN user, the divergence degree of the source address to the destination address of the suspected PCDN user, and the destination address proportion of the uplink traffic of the suspected PCDN user; evaluating the similarity between the characteristic value corresponding to the traffic of the suspected PCDN user and the characteristic values in the preset PCDN user characteristic library, and in the case that the similarity is higher than a first threshold, determining that the characteristic value corresponding to the traffic of the suspected PCDN user matches the characteristic values in the preset PCDN user characteristic library; The traffic of the PCDN user is processed according to a predetermined processing strategy, including: issuing a preset domain name to the PCDN user, the preset domain name being used to direct the traffic of the PCDN user to a preset environment; in the preset environment, performing traffic limiting processing on each session of the PCDN user; After the traffic of the PCDN user is processed according to the predetermined processing strategy, further including: in the case that the number of uplink traffic reduction of the PCDN user is greater than a preset number threshold, determining that the PCDN user is effectively controlled, and marking the destination link of the PCDN user after the traffic processing disappears; in the case that the uplink traffic of the PCDN user does not reduce, determining that the PCDN user marks the PCDN user as an observation period user; in the case that the uplink traffic of the observation period user always does not drop, determining that the observation period user is a white list user, and determining the characteristic of the white list user as a white list characteristic.
5. A computer device, comprising: including: a memory and a processor, wherein the memory is used to store program instructions; the processor, connected with the memory, is used to execute the PCDN user management method in any one of claims 1 to 3.
6. A computer program product comprising computer instructions, characterized in that, The computer instructions are executed by the processor to implement the PCDN user management method in any one of claims 1 to 3.
Citation Information
Patent Citations
Method, system and device for controlling traffic
CN101715182A
Network mobility management processing method and instrument
CN105308928A