Abnormal node determination method and device, electronic equipment, chip and storage medium

By constructing a node attribute information matrix and generating a hash code matrix using a hash learning method, combined with entropy analysis, the problem of low accuracy in abnormal node detection in existing technologies is solved, achieving efficient identification and real-time early warning of abnormal network nodes and reducing the false judgment rate.

CN119382941BActive Publication Date: 2026-04-07CHINA MOBILE COMM CORP TIANJIN +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-09
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies suffer from low detection accuracy and an inability to effectively respond to spoofing attacks and the flooding of critical paths by legitimate low-speed flows when detecting abnormal network nodes, leading to network performance degradation and paralysis.

Method used

By constructing a node attribute information matrix and generating a node hash code matrix using a hash learning method, combined with entropy analysis, abnormal nodes in the network are identified, and the entropy values ​​of multiple time slices are used to sort and identify abnormal nodes.

Benefits of technology

It improves the accuracy of abnormal node identification, reduces the false positive rate, and can identify abnormal nodes in real time, thereby reducing network losses and avoiding network congestion and paralysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382941B_ABST
    Figure CN119382941B_ABST
Patent Text Reader

Abstract

The present disclosure provides an abnormal node determination method, device, electronic equipment, chip and medium, the method comprises: determining a node attribute information matrix of a network corresponding to a current time slice, the node attribute information matrix being generated according to data flow characteristics of a plurality of nodes contained in the network; using a hash learning method to perform hash representation on the node attribute information matrix to generate a node hash code matrix of the network in the current time slice; determining entropy values of the plurality of nodes contained in the network in the current time slice based on the node hash code matrix; and determining an abnormal node in the network according to the entropy values of the plurality of nodes contained in the network in the current time slice and a plurality of adjacent time slices. The method can realize aggregated analysis of the nodes in the network and aggregated analysis of the node states of a plurality of time slices, can detect the abnormal node before the node is congested, and reduces the misjudgment rate of the abnormal node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security, and in particular to a method, apparatus, electronic device, chip, and storage medium for identifying abnormal nodes. Background Technology

[0002] When a network is attacked, abnormal nodes will appear. These abnormal nodes are generally concentrated in routing nodes and target hosts. The appearance of abnormal nodes can cause network congestion or network paralysis, affecting network performance and related service quality indicators. The detection of abnormal nodes suffers from problems such as post-event reflection and low detection accuracy. Summary of the Invention

[0003] This disclosure provides a method, apparatus, electronic device, chip, and storage medium for determining abnormal nodes.

[0004] The first aspect of this disclosure proposes a method for determining abnormal nodes. The method includes: determining a node attribute information matrix corresponding to a network in the current time slice, the node attribute information matrix being generated based on the data flow characteristics of multiple nodes contained in the network; performing a hash representation on the node attribute information matrix using a hash learning method to generate a node hash code matrix for the network in the current time slice; determining the entropy values ​​of multiple nodes contained in the network in the current time slice based on the node hash code matrix; and determining abnormal nodes in the network based on the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices.

[0005] In some embodiments of this disclosure, data flow characteristics of multiple nodes in the network corresponding to the current time slice are determined. The data flow characteristics include at least one of the following: the number of data packets received by the node in the current time slice, the amount of traffic received by the node in the current time slice, the number of data packets sent by the node in the current time slice, the amount of traffic sent by the node in the current time slice, and the average latency of the node in the current time slice. Based on the data flow characteristics of multiple nodes corresponding to the current time slice, a node attribute information matrix of the network corresponding to the current time slice is generated.

[0006] In some embodiments of this disclosure, the hash learning method is used to hash the node attribute information matrix to generate the node hash code matrix of the network in the current time slice. This includes: transforming the node attribute information matrix of the network in the current time slice to obtain a linear transformation matrix; reconstructing the network based on the node attribute information matrix and the linear transformation matrix to obtain a reconstructed information matrix; establishing a residual function based on the linear transformation matrix and the reconstructed information matrix; and determining the node hash code matrix when the residual function meets a preset condition.

[0007] In some embodiments of this disclosure, determining the entropy value of multiple nodes in the network in the current time slice based on the node hash code matrix includes: for each node, performing a similarity function to analyze the similarity between the node's hash code and the hash codes of its neighboring nodes to determine the comprehensive similarity between the node and its neighboring nodes; determining the anomaly coefficient between the node and its neighboring nodes based on the comprehensive similarity between the node and its neighboring nodes; and determining the entropy value of the node in the current time slice based on the anomaly coefficient between the node and its neighboring nodes using an entropy function.

[0008] In some embodiments of this disclosure, determining abnormal nodes in the network based on the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices includes: sorting the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices respectively; determining the sorting result of the entropy values ​​of multiple nodes in the current time slice and multiple adjacent time slices; and determining the node as an abnormal node when the sorting result of the entropy values ​​of the node in the current time slice and multiple adjacent time slices meets a preset condition.

[0009] In some embodiments of this disclosure, the preset condition is that the number of time slices in which the entropy ranking of a node is within a preset range is greater than or equal to a preset threshold.

[0010] A second aspect of this disclosure provides an anomalous node determination apparatus, comprising: a first processing unit for determining a node attribute information matrix corresponding to the current time slice of the network, the node attribute information matrix being generated based on the data flow characteristics of multiple nodes contained in the network; a second processing unit for performing hash representation on the node attribute information matrix using a hash learning method to generate a node hash code matrix of the network in the current time slice; a third processing unit for determining the entropy values ​​of multiple nodes contained in the network in the current time slice based on the node hash code matrix; and a fourth processing unit for determining anomalous nodes in the network based on the entropy values ​​of multiple nodes contained in the network in the current time slice and multiple adjacent time slices.

[0011] A third aspect of this disclosure provides an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor to enable the at least one processor to perform the methods described in the first aspect of this disclosure.

[0012] A fourth aspect of this disclosure provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the methods described in the first aspect of this disclosure.

[0013] A fifth aspect of this disclosure provides a computer program product including a computer program that is executed by a processor using the methods described in the first aspect of this disclosure.

[0014] A sixth aspect of this disclosure provides a chip including one or more interfaces and one or more processors; the interfaces are configured to receive signals from the memory of an electronic device and send signals to the processors, the signals including computer instructions stored in the memory, which, when executed by the processors, cause the electronic device to perform the methods described in the first aspect of this disclosure.

[0015] In summary, the abnormal node identification method, apparatus, electronic device, chip, and storage medium proposed in this disclosure can improve the identification accuracy of abnormal nodes by aggregating and analyzing the data flow characteristics of nodes in the network and by aggregating and analyzing the data flow characteristics of nodes across multiple time slices. By comprehensively analyzing the nodes in the entire network and by comprehensively analyzing the entropy values ​​of nodes across multiple time slices, abnormal nodes can be identified by distinguishing between isolated and generalized phenomena, reducing the false positive rate of abnormal nodes, and improving the identification accuracy of abnormal nodes. Through comprehensive node analysis, the behavior of false attacks or legitimate low-speed flows flooding critical paths can be identified, enabling the identification of abnormal nodes before they cause alarms or congestion, thereby reducing the losses caused by abnormal nodes.

[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.

[0018] Figure 1 A flowchart of an abnormal node determination method provided in this embodiment of the disclosure;

[0019] Figure 2 A flowchart of an abnormal node determination method provided in this embodiment of the disclosure;

[0020] Figure 3 A flowchart of an abnormal node determination method provided in this embodiment of the disclosure;

[0021] Figure 4 A flowchart illustrating node communication behavior provided in an embodiment of this disclosure;

[0022] Figure 5 A schematic diagram illustrating a hash code conversion process provided in an embodiment of this disclosure;

[0023] Figure 6 This is a schematic diagram illustrating the original attribute information reconstruction process provided in an embodiment of this disclosure;

[0024] Figure 7 This is a schematic diagram of the structure of an abnormal node determination device provided in an embodiment of the present disclosure;

[0025] Figure 8 This is a schematic diagram of the electronic device structure provided in the embodiments of this disclosure;

[0026] Figure 9 This is a schematic diagram of the chip structure provided in an embodiment of this disclosure. Detailed Implementation

[0027] Embodiments of this disclosure are described in detail below. Examples of these embodiments are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0028] Network attacks lead to the emergence of anomalous nodes, typically concentrated around routing nodes and target hosts. However, due to firmware backdoors and vulnerabilities in routing nodes, attackers can often gain administrative privileges within minutes through phishing and brute-force attacks. Routing nodes function as data forwarders and transmitters in the network topology; therefore, once an attacker gains access, they can exploit packet loss, packet tampering, or the injection of invalid packets to compromise target hosts. These network security behaviors severely impact network performance and related Quality of Service (QoS) metrics. While existing research employs path-based and neighbor-based detection techniques to locate anomalous routing nodes, the computational burden on path-based detection increases exponentially with network size. Neighbor-based anomalous node detection uses aggregated data streams to identify anomalous nodes; however, all data stream information is reported to a globally unique node. If this node is compromised, or if the network becomes too large, network congestion or paralysis can occur.

[0029] To address the above issues, some researchers have proposed the following methods for detecting anomalous nodes.

[0030] For example, a machine learning-based network fault location method trains an artificial intelligence model by feeding historical alarm data into it, and generates a fault root cause inference relationship based on the existing network topology and alarm relationships, thus obtaining a tree diagram of alarm relationships, thereby using artificial intelligence to perform root cause inference on faults.

[0031] However, this method cannot effectively deal with attackers' fake attacks or the behavior of legitimate low-speed flows overwhelming the critical path. Sometimes attackers do not continuously send a large number of route probe packets, so they will not affect the performance of the target server or be detected by the detection system. In this case, this method cannot achieve fault location of network nodes.

[0032] For example, in the method, device, storage medium, and electronic equipment for locating each type of network fault, the method, upon detecting an alarm message, determines the starting node information of at least one starting node in a knowledge graph set based on the alarm message; queries the subtree of at least one starting node in the knowledge graph set to obtain a subtree set; traverses the nodes of each subtree in the subtree set and detects abnormal nodes with anomalies to obtain an abnormal node set; sorts the nodes in the abnormal node set according to the relationships between nodes in the knowledge graph set, and locates the root cause of the alarm message based on the node at the end of the sorted queue.

[0033] This method is also ineffective against attackers’ fake attacks or legitimate low-speed flows flooding critical paths. If the detection system does not detect them, then faulty network nodes cannot be identified, and real-time network security detection cannot be achieved.

[0034] For example, a fault detection method, apparatus, and computer device based on the Internet Control Message Protocol (ICMP) protocol. This method involves: capturing ICMP packets in real time; comparing the sending and receiving times of ICMP echo request messages and ICMP echo reply messages to measure network latency and monitor latency fluctuations; analyzing ICMP destination unreachable messages to identify the IP packets causing the errors and refining the fault type based on the ICMP code values ​​in the ICMP packets; tracing the network path based on ICMP timeout messages to obtain the transmission path of ICMP packets, thereby locating faulty nodes on the network path; and dynamically adjusting the threshold used for anomaly detection by continuously monitoring ICMP interaction patterns, and generating a network fault report when an anomaly is detected.

[0035] While this method can track data packets in real time and refine fault types, the computational burden becomes extremely high as network size increases, rendering it impractical. Furthermore, this method typically identifies attacks based on the latency of individual data streams; however, in flood attack scenarios, the differences between individual attack streams and normal streams are minimal, making it difficult to improve detection accuracy.

[0036] Therefore, in order to solve the above-mentioned technical problems, this invention proposes an abnormal node determination method. This method can be executed by electronic devices, such as servers. This method greatly reduces the computational complexity of abnormal nodes in the entire network system through hash codes. In addition, by ranking the entropy of the abnormal node data stream in descending order through multiple time slices, it is possible to avoid misjudgment due to the suddenness of the data stream.

[0037] Figure 1 This is a flowchart illustrating a method for determining abnormal nodes provided in an embodiment of this disclosure. Figure 1 As shown, the method may include the following steps.

[0038] Step 101: Determine the node attribute information matrix corresponding to the current time slice of the network.

[0039] In some embodiments, a network may include multiple nodes, and the node attribute information matrix is ​​generated based on the data flow characteristics of the multiple nodes contained in the network. That is, the node attribute information matrix can be generated based on the data flow characteristics of all or some of the nodes contained in the network.

[0040] In some embodiments, the data flow characteristics of nodes in the network over multiple time periods can be analyzed to identify abnormal nodes. For example, multiple time periods can be divided into multiple time slices, and the data flow characteristics of nodes in the network in each time slice can be analyzed separately. For example, the current time slice can be the time slice in which analysis and processing is being performed, such as time slice t.

[0041] In other words, it can perform comprehensive analysis on all nodes in the network, as well as comprehensive analysis on data from nodes across multiple time slices, to identify anomalous nodes, thereby improving the accuracy of anomalous node identification and reducing the false positive rate of anomalous nodes.

[0042] In some embodiments, for example, determining the node attribute information matrix corresponding to the current time slice of the network includes: determining the data flow characteristics of multiple nodes in the network corresponding to the current time slice, wherein the data flow characteristics include at least one of the following: the number of data packets received by the node in the current time slice, the amount of traffic received by the node in the current time slice, the number of data packets sent by the node in the current time slice, the amount of traffic sent by the node in the current time slice, and the average latency of the node in the current time slice; and generating the node attribute information matrix corresponding to the current time slice of the network based on the data flow characteristics of multiple nodes corresponding to the current time slice.

[0043] In other words, a node attribute information matrix can be generated based on the data flow characteristics of nodes within the current time slice. For example, a network can generate a node attribute information matrix in one time slice. For instance, if the data of a network is analyzed over n time slices, the network can generate node attribute information in each of the n time slices, meaning the network has n node attribute information matrices.

[0044] In some embodiments, the data flow characteristics may optionally include the five dimensions mentioned above. For example, based on the data flow characteristics of a node in the current time slice, multidimensional attribute information of a node in the current time slice can be generated, which may be represented as follows: in, This represents the multidimensional attribute information of the routing node with the identifier 1 in time slice t. This indicates the number of data packets received by the routing node with the identifier 1 as the receiver in time slice t. This indicates the amount of traffic received by the routing node with the identifier 1 as the receiver in time slice t. This indicates the number of data packets sent by the routing node with the identifier 1 as the sender in time slice t. This indicates the amount of traffic sent by the routing node with the identifier 1 as the sender in time slice t. This represents the average delay for the routing node with the identifier 1 to process and forward data in time slice t.

[0045] In some embodiments, optionally, the data stream characteristics of each node in the current time slice can generate multidimensional attribute information. Based on the multidimensional attribute information of all or some of the nodes in the network, a node attribute information matrix corresponding to the network in the current time slice can be generated, which can be represented as, for example, by the following formula 1:

[0046]

[0047] In some embodiments, the data flow features used to generate the node attribute information matrix may optionally include other dimensions. In practical scenarios, dimensions can be added as needed, such as adding fields to measure traffic attributes, such as average traffic value, instantaneous maximum traffic value, etc. This disclosure does not limit this. By selecting data flow features of different dimensions, it is possible to avoid calculating useless data, reduce the amount of calculation, and improve the calculation efficiency while ensuring that the node status is determined.

[0048] Step 102: Use the hash learning method to hash the node attribute information matrix to generate the node hash code matrix of the network in the current time slice.

[0049] In some embodiments, a hash learning method can be used to hash the node attribute information matrix to obtain the corresponding node hash code matrix, so that abnormal nodes can be identified based on the hash code matrix. This can reduce the amount of computation and lower the computational complexity.

[0050] In some embodiments, the method of hash learning is used to hash the node attribute information matrix to generate the node hash code matrix of the network in the current time slice. This includes: transforming the node attribute information matrix of the network in the current time slice to obtain a linear transformation matrix; reconstructing the network based on the node attribute information matrix and the linear transformation matrix to obtain a reconstructed information matrix; establishing a residual function based on the linear transformation matrix and the reconstructed information matrix; and determining the node hash code matrix when the residual function meets a preset condition.

[0051] In other words, hash learning methods can be used to represent the node attribute information matrix using hashing, thereby reducing the dimensionality of the data. For example, hashing can represent the node attribute information using a specific binary string, which can reduce computational complexity and improve computational efficiency. That is, a node in the current time slice can correspond to a hash code, which is a binary string of a specific length. A node hash code matrix can be generated based on the hash codes of all or some of the nodes in the network. A network can generate a node hash code matrix in one time slice.

[0052] In some embodiments, optionally, a sparse representation can be used to hash the node attribute information matrix. For example, a sparse representation can refer to setting the vector of unimportant positions to 0 in order to reduce the amount of computation. For example, a vector [1 5 5 6] can be represented as [1 0 0 0] if it is sparsified. Sparse representation can reduce the amount of computation when performing related operations.

[0053] In some embodiments, when using sparse representation, greater attention needs to be paid to the feature loss before and after the reconstruction data transformation to avoid excessive feature loss caused by sparse representation. Therefore, when performing hash representation on the node attribute information matrix, the loss before and after hash code representation can be constrained to ensure that the loss is minimized. The specific process is as follows:

[0054] (1) Transfer node attribute information f t The matrix is ​​transformed to obtain the linear transformation matrix U.

[0055] (2) Reconstruct the information matrix by reconstructing the node attribute information matrix and the linear transformation matrix.

[0056] Specifically, it can be applied to the multidimensional attribute information of each node in the node attribute matrix. And the linear transformation matrix U, to reconstruct the original information for each node, the reconstructed original information can be represented as: For example, a reconstruction information matrix can be generated based on the original reconstruction information of all or some of the nodes contained in the network.

[0057] (3) Establish the residual function based on the linear transformation matrix and the reconstructed information matrix.

[0058] Specifically, a residual function can be established for each node. For example, a residual function for each node can be established based on the linear transformation matrix and the reconstruction information of each node. This can be expressed as the following formula 2:

[0059]

[0060] Among them, It is the F-norm. It is a 2-norm. It is the hash code corresponding to the multidimensional attribute information of the i-th node, representing the hash code sequence corresponding to the i-th node; λ1 is the attribute similarity matrix, representing the attribute similarity matrix of the i-th node at time t, with λ2 being the balancing parameter and λ2 being the non-negative penalty parameter.

[0061] In the above formula, the attribute similarity matrix is ​​trained using a corpus from a specific domain. For example, a corpus can be constructed from the semantic information of similar traffic, such as the semantic information of normal traffic. The local semantics of this corpus can be trained isomorphically. For instance, the five attributes mentioned above can be trained using this corpus to determine the similarity between the five attributes of normal traffic. It can be guaranteed that similar attribute information has similar hash codes, and similar hash codes have similar residual structures.

[0062] In the above formula, This residual function can be used to represent the feature loss between the semantic representations before and after reconstruction. Minimization guarantee and Approximation is used to minimize the feature loss between the semantic representations before and after reconstruction; Constraint terms are regularization terms that prevent the residual function from overfitting and improve the generalization ability of the residual function.

[0063] (4) When the residual function satisfies the preset conditions, determine the node hash code matrix.

[0064] Specifically, the preset condition can be that the residual function value is minimized, that is, to determine the b corresponding to the minimum residual function value. it Using the hash codes of nodes and generating a hash code matrix based on the hash codes of all or some of the nodes in the network, the feature loss can be minimized when the node attribute information matrix is ​​converted into a hash code matrix.

[0065] Alternatively, the preset condition may be that the residual function value is less than or equal to a preset threshold, etc. The preset condition can be determined according to the actual scenario, and this disclosure does not limit it.

[0066] Step 103: Based on the node hash code matrix, determine the entropy value of multiple nodes in the network in the current time slice.

[0067] In some embodiments, entropy can be used to indicate the uncertainty of the traffic distribution of a node in the current time slice. Since the traffic of a node is usually periodic and trend-based, if the traffic of a node fluctuates greatly and is unstable in the current time slice, the node may be an abnormal node. Therefore, entropy can be used to identify abnormal nodes.

[0068] In some embodiments, the entropy value of a node in a time slice can be determined based on the hash code of the node in a time slice, that is, a node can have a corresponding entropy value in a time slice.

[0069] In some embodiments, determining the entropy value of multiple nodes in the network in the current time slice based on the node hash code matrix includes: for each of the multiple nodes, performing a similarity function to analyze the similarity between the node's hash code and the hash codes of its neighboring nodes to determine the comprehensive similarity between the node and its neighboring nodes; determining the anomaly coefficient between the node and its neighboring nodes based on the comprehensive similarity between the node and its neighboring nodes; and determining the entropy value of the node in the current time slice based on the anomaly coefficient between the node and its neighboring nodes using an entropy function.

[0070] Specifically, neighboring nodes can be nodes whose hop count from the current node is less than a preset threshold. For example, neighboring nodes can be nodes within a 2-hop range from the current node. For instance, if node 0's neighboring nodes are 1 and 2, 1's neighboring node is 3, and 2's neighboring node is 4, then node 0's neighboring nodes within a 2-hop range are node 1, node 2, node 3, and node 4. The preset threshold for the number of hops can be limited according to the actual usage scenario, but this disclosure does not impose any restrictions on it.

[0071] Step 104: Based on the entropy values ​​of multiple nodes in the network at the current time slice and multiple adjacent time slices, determine the abnormal nodes in the network.

[0072] In some embodiments, adjacent time slices can be time periods adjacent to the current time slice. For example, when the current time slice is t, the adjacent time slices can be t-1, t+1, t+2, etc. The number of adjacent time slices can be determined according to the actual scenario, and this disclosure does not limit it.

[0073] In other words, we can comprehensively analyze the entropy values ​​of nodes at different time slices, as well as the entropy values ​​of different nodes in the network, to identify abnormal nodes. By analyzing how attacking a node affects the characteristics of surrounding nodes, we can comprehensively identify abnormal nodes, distinguish between random data and attack behavior, reduce the false positive rate of abnormal nodes, and improve the identification accuracy of abnormal nodes.

[0074] In some embodiments, determining an abnormal node in the network based on the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices includes: sorting the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices respectively; determining the sorting result of the entropy values ​​of multiple nodes in the current time slice and multiple adjacent time slices; and determining the node as an abnormal node when the sorting result of the entropy values ​​of the node in the current time slice and multiple adjacent time slices meets a preset condition.

[0075] In summary, the embodiments of this application, by comprehensively analyzing the data flow characteristics of multiple nodes in the network and the data flow characteristics of nodes in multiple time slices, and by measuring the abnormal distribution of nodes in the entire network using entropy values, can determine the communication behavior of nodes in the entire network from a global perspective and identify abnormal nodes. By identifying abnormal nodes based on the entropy values ​​of multiple time slices, it is possible to distinguish between general anomalies caused by data randomness and individual anomalies caused by attacks, thereby reducing the false positive rate of abnormal node identification and improving the identification accuracy of abnormal nodes.

[0076] Figure 2 This is a flowchart illustrating a method for determining abnormal nodes provided in an embodiment of this disclosure. Figure 2 As shown, the method may include the following steps.

[0077] Step 201: For each of the multiple nodes, a similarity function is used to analyze the similarity between the node's hash code and the hash codes of its neighboring nodes to determine the overall similarity between the node and its neighboring nodes.

[0078] In some embodiments, for multiple nodes included in the network, a similarity analysis can be performed on each of the multiple nodes to determine the comprehensive similarity between the node and its neighboring nodes. For example, the comprehensive similarity between a node and its neighboring nodes can be determined based on the similarity of their hash codes. For instance, the similarity function can be a cosine function, that is, the cosine function can be used to perform similarity analysis on the hash codes of a node and its neighboring nodes to determine the comprehensive similarity between the node and its neighboring nodes. For example, the similarity function can be expressed as the following formula 3:

[0079]

[0080] in, The hash code of the k-th node indicates that the k-th node and the i-th node are neighboring nodes. The above k∈Γ(i) means that the number of hops between the k-th node and the i-th node is less than or equal to a preset threshold, for example, the number of hops between the k-th node and the i-th node is less than or equal to 2.

[0081] In some embodiments, for each of the multiple nodes, the comprehensive similarity between that node and its multiple neighboring nodes can be determined separately. For example, when a node has 5 neighboring nodes, the corresponding node and each of the 5 neighboring nodes has a comprehensive similarity value.

[0082] In some embodiments, nodes in different time-slice networks can be processed separately to determine the overall similarity between a node and its neighboring nodes in each time-slice.

[0083] Step 202: Determine the anomaly coefficients of the node and its neighboring nodes based on the comprehensive similarity between the node and its neighboring nodes.

[0084] In some embodiments, based on the comprehensive similarity between the node and its neighboring nodes, an anomaly coefficient can be determined between the node and multiple neighboring nodes. That is, a node has an anomaly coefficient with a neighboring node. For example, the anomaly coefficient... This can be expressed as the following formula 4:

[0085]

[0086] In some embodiments, nodes in different time-slice networks can be processed separately to determine the anomaly coefficients between nodes and their neighboring nodes in each time slice.

[0087] Step 203: Based on the anomaly coefficients of the node and its neighboring nodes, the entropy value of the node in the current time slice is determined using the entropy function.

[0088] In some embodiments, the entropy value of a node can be determined based on the anomaly coefficients of the node and all its neighboring nodes. For example, different time slices can be processed separately to determine the entropy values ​​of multiple nodes in the network at different time slices. For example, the entropy function can be expressed as the following formula 5:

[0089]

[0090] Where K is a constant value greater than zero. Let be the entropy value of the i-th node at time slice t. For example, When the flow distribution at a node is within time slice t, it indicates that there is no uncertainty in the flow distribution at that node; conversely... When the uncertainty is high, it indicates that the flow distribution of the node in time slice t has great uncertainty. Generally speaking, the flow of a node has periodic and trend characteristics. When the flow distribution of a node has high uncertainty, it is very likely to be an abnormal node. Therefore, the entropy value can be used to detect abnormal nodes.

[0091] In summary, the above embodiments of this application can determine the anomaly coefficient between a node and its neighboring nodes by determining the comprehensive similarity between the node and its neighboring nodes, and determine the entropy value of the node based on the anomaly coefficient between the node and its neighboring nodes, so as to identify abnormal nodes based on the entropy value. This can realize the identification of abnormal nodes based on the communication behavior between nodes, and can distinguish between general anomalies caused by the randomness of data and individual anomalies caused by attacks, thereby reducing the false judgment rate of abnormal node identification and improving the identification accuracy of abnormal nodes.

[0092] Figure 3 This is a flowchart illustrating a method for determining abnormal nodes provided in an embodiment of this disclosure. Figure 3 As shown, the method may include the following steps.

[0093] Step 301: Sort the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices respectively.

[0094] In some embodiments, for one of multiple time slices, such as the current time slice, the entropy values ​​of the nodes contained in the network in the current time slice can be sorted. For example, if the network contains 5 nodes, the entropy values ​​of the 5 nodes in the current time slice can be sorted. For instance, they can be sorted in descending order according to the size of the entropy value. For example, in the current time slice, the entropy value of node 1 is 0.8, the entropy value of node 2 is 0.5, the entropy value of node 3 is 0.9, the entropy value of node 4 is 0.6, and the entropy value of node 5 is 0.3. Then the sorting result of the current time slice is: node 3-node 1-node 4-node 2-node 5. When using descending order sorting, the higher the ranking of the node, the higher the uncertainty.

[0095] Step 302: Determine the entropy ranking results of multiple nodes in the current time slice and multiple adjacent time slices.

[0096] In some embodiments, the entropy values ​​of nodes can be sorted in multiple time slices, that is, one time slice can correspond to one sorting result, which is the sorting of the entropy values ​​of multiple nodes contained in the network.

[0097] For example, the entropy ranking result of a node in the current time slice and multiple adjacent time slices can refer to the ranking of the node in the current time slice and multiple adjacent time slices. For example, for the i-th node, it can be determined that the node ranks 2nd in time slice t, 5th in time slice t+1, 2nd in time slice t+2, 1st in time slice t+3, and 2nd in time slice t+4.

[0098] In other words, for each node, its ranking across multiple time slices can be determined.

[0099] Step 303: When the entropy value sorting result of a node in the current time slice and multiple adjacent time slices meets the preset conditions, the node is determined to be an abnormal node.

[0100] In some embodiments, the preset condition is that the number of time slices in which the entropy ranking of a node is within a preset range is greater than or equal to a preset threshold.

[0101] In other words, the number of time slices in which the entropy value of a node ranks within a preset range can be determined. For example, in the example of step 302 above, the preset range can be the top 2. At this time, it can be determined that the number of time slices in which the node ranks in the top 2 in entropy value across multiple time slices is 4, namely time slice t, time slice t+2, time slice t+3, and time slice t+4. Then, the number of time slices that meet the above requirements is 4. When the preset threshold is 3, it is determined that the node meets the preset conditions, and the node is an abnormal node.

[0102] In the above embodiments, when the entropy values ​​are sorted in descending order, the higher the uncertainty of the traffic distribution of the nodes ranked higher, the higher the probability that they are abnormal nodes. At this time, the preset range in the preset conditions can be the range of the top-ranked nodes, that is, nodes with relatively high uncertainty in multiple time slices are preferentially identified as abnormal nodes. Optionally, the entropy values ​​can also be sorted in ascending order. At this time, the preset range in the preset conditions can be the range of the bottom-ranked nodes, etc. This disclosure does not limit this.

[0103] In the above embodiments, the preset range can be set according to the actual scenario, and this disclosure does not limit it. For example, if the preset range is determined to be the top 5, then when a node is in the top 5 in the uncertain descending order ranking for all 5 time slices, it indicates that the node is an abnormal node.

[0104] In summary, the above embodiments of this application can sort the entropy values ​​of multiple nodes in the network, conduct comprehensive comparative analysis of nodes in the entire network to identify abnormal nodes, and determine an abnormal node only when the number of time slices that meet the conditions is greater than or equal to a threshold by analyzing the entropy values ​​of nodes in multiple time slices. This can distinguish between general anomalies caused by the randomness of data and individual anomalies caused by attacks, avoid misjudgments caused by the randomness and suddenness of data, reduce the misjudgment rate of abnormal node identification, and improve the identification accuracy of abnormal nodes.

[0105] For the foregoing method embodiments, in order to simplify the description, they are all described as a series of actions. However, those skilled in the art should know that this disclosure is not limited to the described order of actions, because according to this disclosure, some steps may be performed in other orders or simultaneously.

[0106] Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by this disclosure.

[0107] The technical solutions of this disclosure will be further described in detail below with reference to specific application embodiments.

[0108] This disclosure provides a method for detecting and locating abnormal network nodes oriented towards SDN.

[0109] This example method leverages the advantages of a global view in Software Defined Network (SDN) controllers, combining the states of all nodes in the network to detect abnormal nodes before congestion occurs. It characterizes node communication behavior by aggregating data streams and constructs a node attribute information matrix. A hash learning method is used to represent this matrix with hash codes, significantly reducing computational complexity. Furthermore, nodes are categorized based on hash code differences. Entropy is used to measure the abnormal distribution of nodes across the network. The entropy of multiple consecutive time slices (e.g., five slices) is used to rank nodes in descending order. If five consecutive descending entropy rankings fall within a specified range (e.g., the top five), the node is considered abnormal; otherwise, it is considered normal.

[0110] The specific details of this method are as follows.

[0111] Step 1: Characterize the communication behavior of nodes by aggregating data streams and construct a node spatial feature matrix.

[0112] like Figure 4As shown, data stream f1 originates from source node A, passes through B, C, D, E, and F, and flows to the target node. Data stream f2 originates from source node G, passes through D and F, and flows to the target node. Therefore, tracing individual data streams would be extremely costly to detect abnormal nodes. This example method strikes a trade-off between cost and accuracy by using node-aggregated data streams to characterize node communication behavior and constructing a node space matrix based on the characteristics of the node data streams.

[0113] Generally, the characteristics of a data stream include the number of data packets sent and received, the size of the data transmission and reception, and the average latency of data packet forwarding. Therefore, the communication behavior of a node represented by the aggregated data stream over time slice t can be expressed as:

[0114]

[0115] Formula (1) presents a sequence of attribute information for the number of data packets sent and received, and the average delay for data packet forwarding for the n routes in the entire network. This represents the multidimensional attribute information of the routing node with the identifier 1 in time slice t. This indicates the number of data packets received by the routing node with the identifier 1 as the receiver in time slice t. This indicates the amount of traffic received by the routing node with the identifier 1 as the receiver in time slice t. This indicates the number of data packets sent by the routing node with the identifier 1 as the sender in time slice t. This indicates the amount of traffic sent by the routing node with the identifier 1 as the sender in time slice t. This represents the average latency for the routing node with the identifier 1 to process and forward data in time slice t. The node attribute information in this scheme includes, but is not limited to, the five dimensions mentioned above. Additional dimensions can be added as needed. In practice, many fields are used to measure traffic attributes, and some fields can be added based on the specific scenario, such as average traffic value and instantaneous maximum traffic value. The above attribute information sequence is input into the hash model to obtain the corresponding hash code.

[0116] Step 2: The node attribute information matrix is ​​represented by hash codes using the hash learning method, which greatly reduces the amount of computation required for the attribute information matrix.

[0117] The node attribute information matrix representation based on hash learning maps the different attribute data of a node to a Hamming space (i.e., a common latent space), and then transforms it into a binary string of "0" and "1" of a specific length. The hash-based algorithm can then directly use binary encoding operations to calculate similarity, which significantly reduces computational complexity and improves efficiency. Furthermore, since a corresponding binary sequence is generated for each node's communication behavior in a time slice t (assuming 5 attribute information points, this corresponds to a binary sequence like "01100"), significant memory savings are achieved when storing node attribute information. If n is 100, then there are 100 binary sequences. The specific transformation process is as follows... Figure 5 As shown.

[0118] Figure 5 The common latent space (CLS) is used to reduce the dimensionality of the original data, representing the attributes of a node with fewer hash codes. However, using sparse representation of the CLS requires greater attention to the feature loss before and after the data transformation. Since the attribute information of each network is very different, different networks cannot use the same CLS for hash code transformation. Sparse representation involves setting vectors at unimportant positions to 0 to reduce computation. For example, a vector [1 5 5 6] might be reduced to [1 0 0 0] by sparsification, thus reducing computational cost during related operations.

[0119] The basic idea of ​​the common latent space is to minimize the feature loss before and after reconstruction by combining the residual values ​​of the original attribute information before and after transformation with the information after reconstruction. That is, the purpose of constructing the common latent space is to map high dimensions to low dimensions. Moreover, during the mapping process, it is hoped that the information of the original attributes will not be lost too much, otherwise this dimensionality reduction is meaningless. Therefore, it is hoped that the feature loss before and after reconstruction will be minimized. This represents the residual between the original attribute information after linear matrix transformation and the hash code, specifically expressed as:

[0120]

[0121] Among them, It is the F-norm. It is a 2-norm, and matrix U is a linear transformation matrix obtained by transforming the original information.

[0122] It is the hash code corresponding to the original attribute information, representing the hash code sequence corresponding to the i-th node; This is the attribute similarity matrix, representing the attribute similarity matrix of the i-th node at time t, along with its j-th dimension. The attribute similarity matrix is ​​trained using a domain-specific corpus. This corpus comprises semantic information from similar traffic flows; for example, it contains semantic information from normal traffic flows. The local semantics of this corpus are trained isomorphically. For instance, the five attributes mentioned above can be trained using this corpus to determine the similarity between the five attributes of normal traffic flows.

[0123] λ1 is the balancing parameter, and λ2 is the non-negativity penalty parameter. The reconstructed residuals are added... It can be guaranteed that similar attribute information has similar hash codes, and similar hash codes have similar residual structures. It is a process of hash code reconstruction, the purpose of which is to minimize the feature loss between the semantic representation before and after reconstruction, and to make the value as close to 0 as possible, through the reconstruction of the original attribute information. It is a binary hash code A nearest neighbor sample in the sample.

[0124] Specifically, such as Figure 6 As shown, the original attribute information is reconstructed using hash codes and dictionary information. The hash code is actually calculated by multiplying the original attribute information (which has already been transformed into a linear matrix) by the dictionary itself. Generally, the original attribute information is multiplied by the inverse matrix of the dictionary. Therefore, linearly transforming the dictionary into its inverse matrix is ​​how the hash code reconstruction formula is written.

[0125] Because the dictionary generation process cannot be achieved from a single sample, but requires a corpus of a certain domain. The construction of the corpus requires neighboring samples, that is, similar samples, to ensure that the generated dictionary has the characteristics of that domain.

[0126] In formula 2 above, By minimization, thus ensuring and Approximation is used to achieve the minimum feature loss. The constraint term is a regularization term that avoids overfitting. Based on this, we can obtain the hash code of the original attribute information. matrix.

[0127] Alternatively, to reduce computational cost, besides hashing algorithms, other dimensionality reduction methods can be used, such as Linear Discriminant Analysis (LDA), Locally Linear Embedding (LLE), and Singular Value Decomposition (SVD). However, these methods do not have the advantages of the hashing algorithm used in this solution because binary feature representation is the simplest and requires the least computation. Furthermore, this patent uses a regularization term to avoid overfitting when calculating the latent space, which prevents the loss of too many data features in order to reduce computational cost, thus better preserving the data's features during dimensionality reduction.

[0128] (3) Nodes are classified according to the differences in hash codes, and entropy is used to measure the abnormal distribution of nodes in the entire network.

[0129] The similarity of the binary hash codes of different nodes is measured using a cosine function. Therefore, the comprehensive similarity between node i and its neighbors within a 2-hop range can be expressed as:

[0130]

[0131] in, This represents the hash code of the k-th node.

[0132] Because different nodes have different characteristics, it's not possible to compare a single node with other nodes. Therefore, this example uses 2-hop neighbor nodes for comparison, meaning the range of node k cannot exceed the 2-hop range of node i. The 2-hop range is interpreted as follows: node 0's neighbors are 1 and 2, 1's neighbor is 3, and 2's neighbor is 4. Therefore, node 0's 2-hop range includes 1, 2, 3, and 4, representing the combined similarity of all 2-hop neighbors. Furthermore, 3-hop or 4-hop ranges can be used depending on the specific needs. However, the computational complexity of 3-hop and 4-hop ranges is higher; generally, 2-hop ranges are sufficient to measure the traffic characteristics of neighbor nodes.

[0133] The anomaly coefficient between node i and its neighbors within a 2-hop range can be calculated based on the comprehensive similarity between node i and its neighbors within a 2-hop range.

[0134]

[0135] Similarly, the anomaly coefficients of other nodes are calculated according to formula (4). Entropy is used to measure the anomaly distribution of the entire network nodes, and anomaly nodes are selected by ranking. The formula for entropy can be expressed as follows.

[0136]

[0137] Where K is a constant value greater than zero. This refers to the uncertainty in the traffic distribution of network node i within time slice t. The reason why the uncertainty in the traffic distribution of network node i can characterize node anomalies is that if a node's traffic fluctuates wildly and is very different from the usual distribution, its traffic characteristics are unpredictable, then the node is a suspected anomaly node. Generally speaking, the traffic of a node has periodic and trend characteristics. If these characteristics are uncertain, then it is very likely an anomaly node.

[0138] if This indicates that its flow distribution is not uncertain; on the contrary... This indicates that its traffic distribution has great uncertainty, enabling the detection of abnormal nodes.

[0139] The method in this example requires multiple time slices. The reason why a single time slice cannot determine whether a node is abnormal is that the traffic of a node has periodicity and trend, while the traffic of a single node may be affected by randomness and show abnormalities within a short period of time. Therefore, a single time slice cannot determine whether a node is abnormal. Multiple time slices are needed to determine whether the node's traffic conforms to periodicity and trend and whether it is different from the normal characteristic distribution before a judgment can be made.

[0140] This example method uses entropy to measure node traffic anomalies, and ranking the entropy of multiple time slices in descending order allows for observation of traffic change patterns over time. Therefore, by ranking uncertainty in descending order, if a node ranks in the top 5 for all 5 time slices *t*, it is considered an anomaly, thus locating the anomaly. This example method uses the length of time to observe traffic change patterns, avoiding misjudgments due to the suddenness of data flow. By comprehensively considering both time (multiple time slices) and space (descending entropy ranking), it reduces the probability of misjudging nodes.

[0141] For example, when using this method to identify abnormal nodes, if node i is ranked 1st in descending order in time slices t, t+1, t+2, and t+3, but ranks 6th or even lower in t+4, is there a possibility of missed detection? The answer is: it is unlikely. This is because once an attacker launches a real attack on a node (rather than a probing attack), there will definitely be continuous alarms within a certain range. If a probing attack occurs, it is not a real attack, but merely a way to find the target host. However, once the host is found, the attacker will definitely use various attack methods to carry out the attack.

[0142] In summary, the above examples disclosed herein characterize the communication behavior of nodes by aggregating data streams, construct a node attribute information matrix, and use a hash learning method to represent the node attribute information matrix with hash codes. Based on the hash code matrix of the nodes, the anomaly coefficients of the nodes and their neighboring nodes are calculated. The anomaly coefficients of the nodes are measured by entropy, and the entropy of multiple time slices is used to rank them in descending order to determine the anomaly distribution of the nodes in the entire network.

[0143] The method described above significantly reduces computational complexity compared to traditional methods. By converting traffic characteristics into hash codes and using the anomaly coefficients of node i and its neighboring nodes within a 2-hop range, it quickly measures abnormal communication behavior of nodes, providing a data foundation for identifying abnormal nodes. The method described above uses entropy to measure the pattern of traffic changes, ranking the entropy of multiple time slices in descending order. On the one hand, it observes the pattern of traffic changes through the length of time; on the other hand, it determines abnormal nodes by their ranking among global network nodes, avoiding misjudgments due to the suddenness of data flow. By comprehensively considering both time and space factors, it reduces the probability of node misjudgment.

[0144] Figure 7 This is a block diagram of an abnormal node determination device 700 provided in an embodiment of this disclosure. Figure 7 As shown, the device 700 includes: a first processing unit 710, used to determine the node attribute information matrix corresponding to the network in the current time slice, wherein the node attribute information matrix is ​​generated based on the data flow characteristics of multiple nodes contained in the network; a second processing unit 720, used to perform hash representation on the node attribute information matrix using a hash learning method to generate a node hash code matrix of the network in the current time slice; a third processing unit 730, used to determine the entropy value of multiple nodes contained in the network in the current time slice based on the node hash code matrix; and a fourth processing unit 740, used to determine abnormal nodes in the network based on the entropy values ​​of multiple nodes contained in the network in the current time slice and multiple adjacent time slices.

[0145] In summary, the device disclosed herein can improve the accuracy of identifying abnormal nodes by aggregating and analyzing the data flow characteristics of nodes in the network and by aggregating and analyzing the data flow characteristics of nodes across multiple time slices. By comprehensively analyzing the nodes in the entire network and by comprehensively analyzing the entropy values ​​of nodes across multiple time slices to identify abnormal nodes, it can distinguish between isolated and common phenomena of nodes, reduce the false positive rate of abnormal nodes, and improve the accuracy of identifying abnormal nodes. Through comprehensive analysis of nodes, it can identify the behavior of false attacks or legitimate low-speed flows flooding critical paths, enabling the identification of abnormal nodes before they cause alarms or congestion, thereby reducing the losses caused by abnormal nodes.

[0146] In some embodiments, the first processing unit is further configured to determine the data flow characteristics of multiple nodes in the network corresponding to the current time slice, wherein the data flow characteristics include at least one of the following: the number of data packets received by the node in the current time slice, the amount of traffic received by the node in the current time slice, the number of data packets sent by the node in the current time slice, the amount of traffic sent by the node in the current time slice, and the average latency of the node in the current time slice; and generate a node attribute information matrix of the network corresponding to the current time slice based on the data flow characteristics of multiple nodes in the current time slice.

[0147] In some embodiments, the second processing unit is further configured to transform the node attribute information matrix corresponding to the current time slice of the network to obtain a linear transformation matrix; reconstruct the network according to the node attribute information matrix and the linear transformation matrix corresponding to the current time slice to obtain a reconstructed information matrix; establish a residual function based on the linear transformation matrix and the reconstructed information matrix; and determine the node hash code matrix when the residual function satisfies a preset condition.

[0148] In some embodiments, the third processing unit is further configured to, for each of the multiple nodes, perform a similarity function to analyze the similarity between the hash code of the node and the hash codes of its neighboring nodes, and determine the comprehensive similarity between the node and its neighboring nodes; determine the anomaly coefficient between the node and its neighboring nodes based on the comprehensive similarity between the node and its neighboring nodes; and determine the entropy value of the node in the current time slice based on the anomaly coefficient between the node and its neighboring nodes using an entropy function.

[0149] In some embodiments, the fourth processing unit is further configured to sort the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices respectively; determine the entropy value sorting result of multiple nodes in the current time slice and multiple adjacent time slices; and determine the node as an abnormal node when the entropy value sorting result of the node in the current time slice and multiple adjacent time slices meets a preset condition.

[0150] In some embodiments, the preset condition is that the number of time slices in which the entropy ranking of a node is within a preset range is greater than or equal to a preset threshold.

[0151] Figure 8 This is a block diagram of an electronic device 800 for implementing the above-described method, provided as an embodiment of the present disclosure.

[0152] Based on the hardware implementation of the above program modules, and in order to implement the method of this disclosure embodiment, this disclosure embodiment also provides an electronic device, such as... Figure 8 As shown, the electronic device 800 includes:

[0153] The communication interface 801 enables information exchange with other devices;

[0154] The processor 802 is connected to the communication interface 801 to enable information interaction with other devices and to execute the methods provided by one or more of the above-mentioned technical solutions when running computer programs;

[0155] Memory 803, computer programs are stored in memory 803.

[0156] Specifically, the processor 802 can be used to determine the first family to which the first object belongs based on the communication data of the first object; if the first family meets the first preset conditions, the first family is identified as the target family; and the target information is pushed to the target family.

[0157] It should be noted that the specific processing procedure of processor 802 can be understood by referring to the above method.

[0158] Of course, in practical applications, the various components in electronic device 800 are coupled together through bus system 804. It can be understood that bus system 804 is used to realize the connection and communication between these components. In addition to a data bus, bus system 804 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 8 The general labeled all buses as Bus System 804.

[0159] The memory 803 in this embodiment is used to store various types of data to support the operation of the electronic device 800. Examples of such data include any computer program used to operate on the electronic device 800.

[0160] The methods disclosed in the embodiments of this application can be applied to or implemented by processor 802. Processor 802 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 802 or by instructions in the form of software. The first processor 802 mentioned above may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 802 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 803. Processor 802 reads the information in memory 803 and combines its hardware to complete the steps of the aforementioned method.

[0161] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0162] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of an electronic device 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0163] Embodiments of this disclosure also provide a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to perform the methods described in the above embodiments of this disclosure.

[0164] Embodiments of this disclosure also propose a chip, such as Figure 9 As shown, the chip includes a processor 910 and an interface 920. The number of processors 910 can be one or more, and the number of interfaces 920 can be multiple. The interface circuitry is used to receive signals from the electronic device's memory and send signals to the processor. The signals include computer instructions stored in the memory. When the processor executes the computer instructions, it causes the electronic device to perform the methods described in the above embodiments of this disclosure.

[0165] It should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this application can be combined with each other.

[0166] It should be understood that the terms "system," "apparatus," "unit," and / or "module" used in this application are a method of distinguishing different components, elements, parts, sections, or assemblies at different levels. However, if other terms can achieve the same purpose, they may be replaced by other expressions.

[0167] As indicated in this application and claims, unless the context clearly indicates otherwise, the words "a," "an," "a," and / or "the" are not specifically singular and may include the plural. Generally, the terms "comprising" and "including" only indicate the inclusion of expressly identified steps and elements, which do not constitute an exclusive list, and the method or apparatus may also include other steps or elements. An element defined by the phrase "comprising an..." does not exclude the presence of other identical elements in the process, method, product, or apparatus that includes the element.

[0168] In the description of the embodiments of this application, unless otherwise stated, " / " means "or", for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more.

[0169] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.

[0170] Flowcharts are used in this application to illustrate the operations performed by the system according to embodiments of this application. It should be understood that the preceding or following operations are not necessarily performed precisely in sequence. Instead, the steps can be processed in reverse order or simultaneously. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0171] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with an embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0172] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0173] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processing module, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (control method), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic device, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0174] It should be understood that various parts of the embodiments of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0175] Those skilled in the art will understand that all or part of the steps of the methods described in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0176] Furthermore, the functional units in the various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc.

[0177] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A method for determining abnormal nodes, characterized in that, The method includes: Determine the node attribute information matrix corresponding to the current time slice of the network. The node attribute information matrix is ​​generated based on the data flow characteristics of multiple nodes contained in the network. The node attribute information matrix is ​​hashed using a hash learning method to generate the node hash code matrix of the network in the current time slice; Based on the node hash code matrix, determine the entropy value of multiple nodes in the network in the current time slice; based on the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices, determine the abnormal nodes in the network. The process of determining the entropy value of multiple nodes in the network in the current time slice based on the node hash code matrix includes: For each of the plurality of nodes, a similarity function is used to perform similarity analysis between the hash code of the node and the hash codes of its neighbors to determine the overall similarity between the node and its neighbors. The anomaly coefficient between the node and its neighboring nodes is determined based on the comprehensive similarity between the node and its neighboring nodes. Based on the anomaly coefficients of the node and its neighboring nodes, the entropy value of the node in the current time slice is determined using an entropy function; the entropy value is used to indicate the uncertainty of the traffic distribution of the node in the current time slice. The step of determining abnormal nodes in the network based on the entropy values ​​of multiple nodes in the network at the current time slice and multiple adjacent time slices includes: The entropy values ​​of multiple nodes in the network are sorted in the current time slice and in multiple adjacent time slices, respectively. Determine the entropy ranking of the multiple nodes in the current time slice and multiple adjacent time slices; When the entropy value sorting result of the node in the current time slice and multiple adjacent time slices meets the preset conditions, the node is determined to be an abnormal node.

2. The method according to claim 1, characterized in that, The matrix of node attribute information corresponding to the current time slice of the network includes: Determine the data flow characteristics of multiple nodes in the network corresponding to the current time slice. The data flow characteristics include at least one of the following: the number of data packets received by the node in the current time slice, the amount of traffic received by the node in the current time slice, the number of data packets sent by the node in the current time slice, the amount of traffic sent by the node in the current time slice, and the average latency of the node in the current time slice. Based on the data flow characteristics of the multiple nodes in the current time slice, a node attribute information matrix of the network in the current time slice is generated.

3. The method according to claim 1, characterized in that, The step of using a hash learning method to hash the node attribute information matrix and generate the node hash code matrix of the network in the current time slice includes: The node attribute information matrix of the network at the current time slice is transformed to obtain a linear transformation matrix; the network is then reconstructed based on the node attribute information matrix of the network at the current time slice and the linear transformation matrix to obtain a reconstructed information matrix. A residual function is established based on the linear transformation matrix and the reconstructed information matrix; when the residual function satisfies a preset condition, the node hash code matrix is ​​determined.

4. The method according to claim 1, characterized in that, The preset condition is that the number of time slices in which the entropy ranking of the node is within a preset range is greater than or equal to a preset threshold.

5. An abnormal node determination device, characterized in that, The device includes: The first processing unit is used to determine the node attribute information matrix corresponding to the network in the current time slice. The node attribute information matrix is ​​generated based on the data flow characteristics of multiple nodes contained in the network. The second processing unit is used to perform hash representation on the node attribute information matrix using a hash learning method, and generate the node hash code matrix of the network in the current time slice. The third processing unit is used to determine the entropy value of multiple nodes in the network in the current time slice based on the node hash code matrix. The fourth processing unit is used to determine abnormal nodes in the network based on the entropy values ​​of multiple nodes in the network in the current time slice and multiple adjacent time slices. The process of determining the entropy value of multiple nodes in the network in the current time slice based on the node hash code matrix includes: For each of the plurality of nodes, a similarity function is used to perform similarity analysis between the hash code of the node and the hash codes of its neighbors to determine the overall similarity between the node and its neighbors. The anomaly coefficient between the node and its neighboring nodes is determined based on the comprehensive similarity between the node and its neighboring nodes. Based on the anomaly coefficients of the node and its neighboring nodes, the entropy value of the node in the current time slice is determined using an entropy function; the entropy value is used to indicate the uncertainty of the traffic distribution of the node in the current time slice. The step of determining abnormal nodes in the network based on the entropy values ​​of multiple nodes in the network at the current time slice and multiple adjacent time slices includes: The entropy values ​​of multiple nodes in the network are sorted in the current time slice and in multiple adjacent time slices, respectively. Determine the entropy ranking of the multiple nodes in the current time slice and multiple adjacent time slices; When the entropy value sorting result of the node in the current time slice and multiple adjacent time slices meets the preset conditions, the node is determined to be an abnormal node.

6. An electronic device, characterized in that, include: One or more processors; A storage device communicatively connected to the one or more processors, wherein one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the method as described in any one of claims 1-4.

7. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-4.

8. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Image feature binary coding representing method based on dot pair relation learning and reconstruction

    CN108536750A

  • Elastic distributed parameter estimation method in multi-attack adversarial network

    CN115550931A