A dynamic bandwidth allocation method, system, device and medium
By distinguishing rogue ONUs from normal ONUs in the PON network and limiting the bandwidth allocation of rogue ONUs to the average demand of other ONUs, the problem of unreasonable bandwidth allocation under DDoS attacks is solved, and the rationality of bandwidth allocation and network performance are achieved.
Patent Information
- Application Number
- CN202411633494.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2044-11-15
AI Technical Summary
The existing common dynamic bandwidth allocation (DBA) solution fails to effectively deal with DDoS attacks in PON networks, resulting in the attacked ONU occupying a large amount of bandwidth, reducing the bandwidth share of other normal ONUs, and even significantly degrading the upstream US link performance.
By obtaining the actual load of each ONU in the PON network, a regression model is used to distinguish rogue ONUs from normal ONUs. The bandwidth allocation of the rogue ONU is limited to the average bandwidth demand of other ONUs, ensuring no over-allocation and evenly distributing the remaining bandwidth to normal ONUs.
Effectively mitigate the impact of DDoS attacks, ensure the rationality of bandwidth allocation, improve bandwidth allocation for other ONUs, and reduce the negative impact of attacks on network performance.
Smart Images

Figure CN119497003B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of optical network technology, and in particular to a dynamic bandwidth allocation method, system, device and medium. Background Art
[0002] With the rapid development of information technology, the security situation in cyberspace is becoming increasingly severe, and the number of cyberattacks is on the rise. These attacks are diverse, each with distinct impacts and consequences on networks or network nodes. Among them, DoS (Denial of Service) attacks are particularly noteworthy. DoS attacks attempt to deplete computing resources or bandwidth by sending a large number of invalid or high-volume data requests to a target network node, causing it to crash or significantly reduce the availability of network resources. This attack not only affects the attacked network node but can also degrade network performance or cause service interruptions. A more severe variant of DoS attacks is the Distributed Denial of Service (DDoS) attack. Compared to DoS attacks, DDoS attacks are more difficult to prevent because they are not initiated by a single source. Instead, they target specific optical network units (ONUs) at the application layer, targeting various user sources. Attackers control a large number of infected computers or botnets to flood the target network node with massive packets, creating a network flood that can lead to severe network congestion and even a complete outage of the ONU's services, posing a serious threat to the continuity and stability of network services. Therefore, it is crucial to protect ONUs (Optical Network Units) and reject DDoS attacks.
[0003] Currently, bandwidth allocation in PON networks is primarily achieved through conventional dynamic bandwidth allocation (DBA) schemes. However, these schemes fail to fully address the security requirements faced by PON networks in actual operation. Since PON is an access network technology operating at the MAC layer, DDoS attacks at the network and transport layers can significantly increase the traffic rates on the downstream DS link (from the OLT to the ONUs) and upstream US link (from the ONUs to the OLT). At this point, the attacked ONUs (hereafter referred to as rogue ONUs) send large numbers of invalid or redundant data packets, attempting to exhaust the bandwidth resources of the shared links. Since bandwidth resources in PON networks are limited, when a single ONU occupies a large amount of bandwidth, the bandwidth share available to other functioning ONUs decreases accordingly, potentially leading to a significant degradation in the performance of the upstream US link. Therefore, conventional dynamic bandwidth allocation (DBA) schemes for upstream US link bandwidth management are unable to address this situation.
[0004] Application Contents
[0005] The present application provides a dynamic bandwidth allocation method, system, device, and medium. By limiting the bandwidth allocation of a rogue ONU to the average bandwidth demand of other ONUs, the bandwidth allocation of other ONUs can be increased, ensuring reasonable bandwidth allocation, thereby mitigating the impact of DDoS attacks.
[0006] In a first aspect, the present application provides a dynamic bandwidth allocation method, comprising:
[0007] Obtain each ONU in the current PON network and the corresponding actual load respectively;
[0008] Determining rogue ONUs and normal ONUs in a PON network based on each of the ONUs and the actual load;
[0009] Bandwidth is evenly distributed to the rogue ONU according to an even distribution requirement to obtain remaining bandwidth, and the remaining bandwidth is evenly distributed to the normal ONUs.
[0010] The embodiments of the present application can accurately obtain the actual load of all ONUs in the current PON network by separately obtaining each ONU and the corresponding actual load, facilitating the subsequent differentiation of rogue ONUs from normal ONUs based on the actual load; distinguishing rogue ONUs from normal ONUs in the PON network based on each ONU and the actual load, facilitating the subsequent bandwidth allocation to rogue ONUs and normal ONUs; and by limiting the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs and ensuring that no excess bandwidth is subsequently allocated to rogue ONUs, the bandwidth allocation of other ONUs is increased, ensuring reasonable bandwidth allocation. Compared with the prior art, the present application limits the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs, thereby increasing the bandwidth allocation of other ONUs and ensuring reasonable bandwidth allocation, thereby mitigating the impact of DDoS attacks.
[0011] Furthermore, the ONUs and corresponding actual loads in the current PON network are obtained respectively, specifically:
[0012] Determining an ONU number of ONUs in a PON network and initializing a vector variable based on the ONU number;
[0013] Traversing each of the ONUs in the PON network, and obtaining a buffer occupancy report of each of the ONUs under a traffic category;
[0014] The buffer zone occupancy reports are respectively accumulated into the vector variables to obtain the actual load.
[0015] In this way, by obtaining the buffer occupancy report under the traffic category in the current PON network and accumulating the buffer occupancy report to the vector variable, the actual load is obtained. The actual load of all ONUs in the current PON network can be accurately obtained, which facilitates the subsequent distinction between rogue ONUs and normal ONUs based on the actual load.
[0016] Furthermore, the determining of rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load is specifically as follows:
[0017] Inputting each of the ONUs and the actual load into a preset regression model to obtain a bandwidth demand prediction value corresponding to each of the ONUs;
[0018] Obtaining an error vector corresponding to each of the ONUs based on the bandwidth demand prediction value and the actual load;
[0019] It is determined whether the error vector meets a preset error threshold. If so, the ONU meeting the preset error threshold is determined as a rogue ONU in the PON network; otherwise, it is determined to be a normal ONU.
[0020] In this way, rogue ONUs and normal ONUs in the PON network are distinguished based on each ONU and the actual load, which facilitates subsequent bandwidth allocation to the rogue ONUs and normal ONUs.
[0021] Furthermore, each of the ONUs and the actual load is input into a preset regression model to obtain a bandwidth demand prediction value corresponding to each of the ONUs, specifically:
[0022] Based on each of the ONUs and the actual load, obtaining a slope corresponding to the regression model according to a least squares method, and determining an intercept corresponding to the regression model based on the slope;
[0023] Based on the slope and the intercept, a bandwidth demand prediction value corresponding to each of the ONUs is determined.
[0024] In this way, the bandwidth demand prediction value corresponding to each ONU can be accurately determined by the regression model, which facilitates the subsequent distinction between rogue ONUs and normal ONUs in the PON network.
[0025] Furthermore, the calculation formula for the slope corresponding to the regression model obtained by the least squares method is specifically:
[0026]
[0027] Where m ONUis the slope, ONU(i) is the i-th ONU, Load(i) is the i-th actual load, and N is the number of ONUs.
[0028] Furthermore, the calculation formula for determining the intercept corresponding to the regression model based on the slope is specifically:
[0029]
[0030] Where C ONU is the intercept, Load(i) is the actual load of the ith item, m ONU is the slope, ONU(i) is the i-th ONU, and N is the number of ONUs.
[0031] Furthermore, the bandwidth is evenly distributed to the rogue ONU according to the even distribution requirement to obtain the remaining bandwidth, specifically:
[0032] Obtaining bandwidth requirements of each of the ONUs under traffic categories;
[0033] Determine a corresponding average distribution requirement based on the bandwidth requirement and the number of ONUs;
[0034] Bandwidth is evenly distributed to the rogue ONU according to an even distribution requirement to obtain remaining bandwidth.
[0035] In this way, by limiting the bandwidth allocation of the rogue ONU to the average bandwidth demand of other ONUs and ensuring that excess bandwidth is not allocated to the rogue ONU in the future, the bandwidth allocation of other ONUs is increased, ensuring reasonable bandwidth allocation.
[0036] In a second aspect, the present application provides a dynamic bandwidth allocation system, comprising: an acquisition module, a differentiation module, and an allocation module;
[0037] The acquisition module is used to respectively acquire each ONU in the current PON network and the corresponding actual load;
[0038] The distinguishing module is configured to determine rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load;
[0039] The allocation module is configured to allocate bandwidth to the rogue ONUs on an average basis according to an average allocation requirement, obtain remaining bandwidth, and allocate the remaining bandwidth on an average basis to the normal ONUs.
[0040] The embodiments of the present application can accurately obtain the actual load of all ONUs in the current PON network by separately obtaining each ONU and the corresponding actual load, facilitating the subsequent differentiation of rogue ONUs from normal ONUs based on the actual load; distinguishing rogue ONUs from normal ONUs in the PON network based on each ONU and the actual load, facilitating the subsequent bandwidth allocation to rogue ONUs and normal ONUs; and by limiting the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs and ensuring that no excess bandwidth is subsequently allocated to rogue ONUs, the bandwidth allocation of other ONUs is increased, ensuring reasonable bandwidth allocation. Compared with the prior art, the present application limits the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs, thereby increasing the bandwidth allocation of other ONUs and ensuring reasonable bandwidth allocation, thereby mitigating the impact of DDoS attacks.
[0041] In a third aspect, the present application provides a terminal device comprising: one or more processors; a memory coupled to the processor for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the dynamic bandwidth allocation method as described in the present application.
[0042] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the dynamic bandwidth allocation method as described in the present application is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 This is a schematic diagram of the GONP system provided by this application being attacked by DoS;
[0044] Figure 2 This is a flow chart of an embodiment of the dynamic bandwidth allocation method provided by the present application;
[0045] Figure 3 This application provides Figure 2 Schematic diagram of step S102 in ;
[0046] Figure 4 This is a trend chart of the bandwidth requirements and bandwidth demand forecast values of each ONU under different loads provided by this application;
[0047] Figure 5 This is a structural diagram of an embodiment of the dynamic bandwidth allocation system provided by the present application;
[0048] Figure 6 This is the hardware structure diagram of the terminal device provided by this application. DETAILED DESCRIPTION
[0049] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0050] It should be understood that the step numbers used herein are only for convenience of description and are not intended to limit the order in which the steps are executed.
[0051] It should be understood that the terms used in the present specification are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0052] The terms “include” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0053] The term "and / or" refers to and includes any and all possible combinations of one or more of the associated listed items.
[0054] With the advancement of information technology, the cybersecurity landscape is becoming increasingly challenging. The number of cyberattacks continues to increase, and these attacks are diverse and have varying impacts. Among them, DoS attacks are particularly prominent. They deplete target resources by sending a large number of invalid requests, causing network crashes or reduced availability. A variant of DoS attacks, Distributed Denial of Service (DDoS), is even more severe and difficult to prevent. These attacks, launched from multiple sources targeting a specific ONU, flood the target network node with messages, potentially leading to complete service interruption.
[0055] Currently, PON networks primarily use standard dynamic bandwidth allocation (DBA) solutions, but these solutions don't fully consider security requirements. DDoS attacks can significantly increase PON network traffic, and the attacked ONUs can potentially occupy significant bandwidth. Since bandwidth resources in PON networks are limited, when a single ONU occupies a significant portion of the bandwidth, the bandwidth available to other functioning ONUs decreases, potentially leading to a significant performance degradation of the upstream US link.
[0056] Next, the nouns involved in this application are analyzed:
[0057] An optical network unit (ONU) is a fiber optic access terminal device. It terminates fiber in a fiber access network and provides multiple service interfaces for users. As a fiber optic access terminal, it works in conjunction with an optical line terminal (OLT). The OLT is typically located in the ISP's central equipment room, while the ONU is deployed at the user end.
[0058] A passive optical network (PON) is a new fiber-based access network topology with high bandwidth. It accesses users using a point-to-multipoint tree topology, with the optical fiber terminal (OLT) at the root. A simple optical splitter (OS) connects to the root via optical fiber, splitting the optical signal from a single fiber into multiple fiber points connected to optical network units (ONUs).
[0059] Dynamic Bandwidth Assignment (DBA) is a mechanism that dynamically allocates upstream bandwidth within microsecond or millisecond intervals. It dynamically allocates bandwidth based on service needs, significantly improving bandwidth utilization and enabling service priority settings to achieve communication at different service levels. DBA is primarily used in PON (Passive Optical Network) systems, particularly EPON (Ethernet Passive Optical Network) systems. In PON systems, DBA is a dynamic allocation protocol between the Optical Line Terminal (OLT) and the Optical Network Unit (ONU).
[0060] Based on this, the embodiments of the present application provide a dynamic bandwidth allocation method and system. By limiting the bandwidth allocation of the rogue ONU to the average bandwidth demand of other ONUs, the bandwidth allocation of other ONUs can be increased, ensuring reasonable bandwidth allocation, thereby reducing the impact of DDoS attacks.
[0061] A dynamic bandwidth allocation method and system provided in an embodiment of the present application are specifically described through the following embodiments. First, the dynamic bandwidth allocation method in an embodiment of the present application is described.
[0062] The dynamic bandwidth allocation method provided in the embodiment of the present application relates to the field of power system communications. The dynamic bandwidth allocation method provided in the embodiment of the present application can be applied to a terminal, can be applied to a server side, and can also be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the dynamic bandwidth allocation method, etc., but is not limited to the above forms.
[0063] The present application can also be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0064] Please refer to Figure 1 , Figure 1Figure 1 is a schematic diagram of a GONP system under a DoS attack. In a Gigabit Passive Optical Network (GPON) system, a passive optical network (PON) is a new fiber-based access network topology with high bandwidth. It accesses users in a point-to-multipoint tree topology, with the optical fiber terminal (OLT) at the root of the tree. A simple optical splitter (OS) connects to the OLT via optical fiber. The GPON system splits the optical signal from a single fiber into multiple fiber points and optical network units (ONUs). When a user is attacked, the traffic rate (λ) on the PON's downstream (DS) link (from the OLT to the ONUs) and upstream (US) link (from the ONUs to the OLT) increases significantly. At this point, the attacked ONU (hereafter referred to as a rogue ONU) sends a large number of invalid or redundant data packets, attempting to exhaust the shared link's bandwidth resources. Since bandwidth resources in a PON network are limited, if one ONU occupies a large amount of bandwidth, the bandwidth share available to other functioning ONUs decreases accordingly, potentially significantly degrading the performance of the upstream US link.
[0065] Please refer to Figure 2 , Figure 2 This is a flow chart of an embodiment of the dynamic bandwidth allocation method provided by the present application, including steps S101 to S103;
[0066] Step S101, respectively obtaining each ONU in the current PON network and the corresponding actual load;
[0067] It can be understood that, first, the number of ONUs in the PON network is determined, and a vector variable is initialized based on the number of ONUs. Specifically, it is necessary to create a vector variable with the number of ONUs as the length and initialize all elements to 0; secondly, each of the ONUs in the PON network is traversed to obtain a buffer occupancy report of each ONU under a traffic category, wherein the traffic category includes T-CONT Type2 (T2), T-CONT Type3 (T3) and T-CONT Type 4 (T4) is specifically as follows: a loop is created, traversing from the first ONU to the last ONU, and in each loop process, the buffer occupancy report of the current ONU under the T2, T3, and T4 traffic categories is obtained; finally, the buffer occupancy report of each ONU under the T2, T3, and T4 traffic categories is accumulated to the previously initialized vector variable to obtain the actual load. The relevant formulas are: Load(ONU) + = T2_buffer_usage; Load(ONU) + = T3_buffer_usage; Load(ONU) + = T4_buffer_usage, where T2_buffer_usage, T3_buffer_usage, and T4_buffer_usage represent the buffer occupancy reports of each ONU under the T2, T3, and T4 traffic categories, respectively, and Load is the scale variable.
[0068] It should be noted that T-CONT includes five types: T-CONT Type 1 (T1), which has fixed bandwidth and fixed time slots and is suitable for delay-sensitive services such as voice services; T-CONT Type 2 (T2), which has fixed bandwidth but not fixed time slots and is suitable for services with low jitter requirements such as video on demand; T-CONT Type 3 (T3), which has a minimum bandwidth guarantee and can dynamically share the remaining bandwidth, and has a maximum bandwidth constraint and is suitable for services with service guarantees and large burst traffic, such as download services; T-CONT Type 4 (T4), which has no bandwidth guarantee and is suitable for services with low delay and jitter requirements such as web browsing; T-CONT Type 5 (T5), which is a combination type and allocates additional bandwidth on a best-effort basis after allocating guaranteed and non-guaranteed bandwidth. Among them, T-CONT Type 2 (T2), T-CONT Type 3 (T3) and T-CONT Type 4 (T4) belong to traffic categories.
[0069] In this way, by obtaining the buffer occupancy report under the traffic category in the current PON network and accumulating the buffer occupancy report to the vector variable, the actual load is obtained. The actual load of all ONUs in the current PON network can be accurately obtained, which facilitates the subsequent distinction between rogue ONUs and normal ONUs based on the actual load.
[0070] Step S102, determining rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load;
[0071] After obtaining the actual load of each ONU, we can distinguish between rogue ONUs and normal ONUs in the PON network. Figure 3 In some embodiments, step S102 may include, but is not limited to, steps S301 to S303:
[0072] Step S301: input each of the ONUs and the actual load into a preset regression model to obtain a bandwidth demand prediction value corresponding to each of the ONUs;
[0073] It can be understood that, first, based on each of the ONUs and the actual load Load(i), the slope m corresponding to the regression model is obtained according to the least squares method. ONU , where the slope m is obtained ONU The calculation formula is:
[0074]
[0075] Where m ONU is the slope, ONU(i) is the i-th ONU, Load(i) is the i-th actual load, and N is the number of ONUs.
[0076] When the slope m corresponding to the regression model is obtained ONU After that, it is necessary to calculate the slope m ONU , each of the ONUs and the actual load Load(i), determine the intercept C corresponding to the regression model ONU , determine the intercept C corresponding to the regression model ONU The calculation formula is as follows:
[0077]
[0078] Where C ONU is the intercept, Load(i) is the actual load of the ith item, m ONU is the slope, ONU(i) is the i-th ONU, and N is the number of ONUs.
[0079] Finally, based on the slope m ONU and the intercept C ONU , determine the bandwidth demand prediction value corresponding to each of the ONUs, wherein, when determining the slope m of the regression model ONU and the intercept C ONU After that, we can determine the regression model as Dp (i) = m ONU ★i+C ONU Where, D p (i) is the predicted value of bandwidth demand, m ONU is the slope of the regression model, C ONU The intercept of the regression model is used to determine the bandwidth demand prediction value D corresponding to each ONU based on the regression model. p (i), where the trend graph of the bandwidth demand and bandwidth demand prediction value of each ONU under different loads is shown in Figure 4. The ONUs that suffer from DOS attacks (such as ONU3 and ONU12) have very high bandwidth demands compared to other ONUs, which makes their error vectors always positive and very high.
[0080] In this way, the bandwidth demand prediction value corresponding to each ONU can be accurately determined by the regression model, which facilitates the subsequent distinction between rogue ONUs and normal ONUs in the PON network.
[0081] Step S302: obtaining an error vector corresponding to each ONU based on the bandwidth demand prediction value and the actual load;
[0082] It is understandable that when the bandwidth demand prediction value D is obtained p (i) After that, the bandwidth demand prediction value D can be calculated p (i) and the actual load Load(i) to obtain the error vector Err(i) corresponding to each ONU, wherein the calculation formula of the error vector Err(i) is: Where Err(i) is the error vector, Load(i) is the actual load, and D p (i) is the bandwidth demand prediction value.
[0083] Step S303 , determining whether the error vector meets a preset error threshold; if so, determining the ONU meeting the preset error threshold as a rogue ONU in the PON network; otherwise, determining the ONU as a normal ONU.
[0084] It is understandable that when the bandwidth demand prediction value D is obtained p (i) After that, it is necessary to determine the error vector D p (i) Whether a preset error threshold is met. If so, the ONU meeting the preset error threshold is determined as a rogue ONU in the PON network; otherwise, it is a normal ONU. It should be noted that the preset threshold can be freely set and is not limited in this application.
[0085] In this way, rogue ONUs and normal ONUs in the PON network are distinguished based on each ONU and the actual load, which facilitates subsequent bandwidth allocation to the rogue ONUs and normal ONUs.
[0086] Step S103: Allocate bandwidth to the rogue ONUs on an average basis according to an average allocation requirement to obtain remaining bandwidth, and distribute the remaining bandwidth to the normal ONUs on an average basis.
[0087] It is understandable that when an ONU is under a DDoS attack, bandwidth allocation to the rogue ONU cannot be directly stopped because the ONU user has signed a service level agreement (SLA) with the service provider. Before allocating bandwidth, the rogue ONU can be detected through, but is not limited to, the above steps. Alternatively, a preset rogue ONU list can be traversed using a computer programming language to determine whether the current ONU is a rogue ONU. If it is a rogue ONU, it is necessary to first guarantee allocation to the rogue ONU, and then evenly distribute the remaining bandwidth to normal ONUs. If it is not a rogue ONU, the bandwidth is directly distributed evenly to all ONUs.
[0088] When a rogue ONU exists, first, the bandwidth requirements of each ONU under the traffic category are obtained from the queue report received in the previous service interval, and the bandwidth requirements are summed to obtain the total bandwidth requirement, where the traffic categories include T-CONT Type 2 (T2), T-CONT Type 3 (T3), and T-CONT Type 4 (T4). Second, the corresponding average distribution requirement is determined based on the total bandwidth requirement and the number of ONUs. That is, the total bandwidth requirement is divided by the number of ONUs to obtain the average demand. However, when determining the average distribution requirement, it is necessary to consider emergencies and assign a certain weight, such as 1.2 or 1.3, to the calculated average demand to obtain the average distribution requirement. Finally, the bandwidth is evenly distributed to the rogue ONU according to the average distribution requirement to obtain the remaining bandwidth, where the total bandwidth minus the average distribution bandwidth equals the remaining bandwidth.
[0089] After obtaining the remaining bandwidth, it is necessary to ensure that no excess bandwidth is allocated to the rogue ONU. In other words, the remaining bandwidth needs to be evenly distributed to all normal ONUs. The formula is: Bandwidth allocated to a single normal ONU = Remaining bandwidth / (NN 流氓ONU ); where N is the total number of ONUs, N 流氓ONU is the number of rogue ONUs.
[0090] In this way, by limiting the bandwidth allocation of the rogue ONU to the average bandwidth demand of other ONUs and ensuring that excess bandwidth is not allocated to the rogue ONU in the future, the bandwidth allocation of other ONUs is increased, ensuring reasonable bandwidth allocation.
[0091] The embodiments of the present application can accurately obtain the actual load of all ONUs in the current PON network by separately obtaining each ONU and the corresponding actual load, facilitating the subsequent differentiation of rogue ONUs from normal ONUs based on the actual load; distinguishing rogue ONUs from normal ONUs in the PON network based on each ONU and the actual load, facilitating the subsequent bandwidth allocation to rogue ONUs and normal ONUs; and by limiting the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs and ensuring that no excess bandwidth is subsequently allocated to rogue ONUs, the bandwidth allocation of other ONUs is increased, ensuring reasonable bandwidth allocation. Compared with the prior art, the present application limits the bandwidth allocation of rogue ONUs to the average bandwidth demand of other ONUs, thereby increasing the bandwidth allocation of other ONUs and ensuring reasonable bandwidth allocation, thereby mitigating the impact of DDoS attacks.
[0092] Please refer to Figure 5 , Figure 5 1 is a schematic structural diagram of an embodiment of a dynamic bandwidth allocation system provided by the present application, comprising an acquisition module 100, a differentiation module 200 and an allocation module 300;
[0093] The acquisition module 100 is used to respectively acquire each ONU and the corresponding actual load in the current PON network;
[0094] The distinguishing module 200 is configured to determine rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load;
[0095] The allocation module 300 is configured to allocate bandwidth to the rogue ONUs in average according to an average allocation requirement, obtain remaining bandwidth, and evenly allocate the remaining bandwidth to the normal ONUs.
[0096] The information exchange and execution process between the modules in the above-mentioned dynamic bandwidth allocation system are based on the same concept as the embodiment of the dynamic bandwidth allocation method of the first aspect of the present invention, and the technical effects achieved are basically the same. For specific details, please refer to the description of the embodiment 1 of the method of the present invention, and will not be repeated here.
[0097] See also Figure 6 , Figure 6 The hardware structure of a terminal device according to another embodiment is shown. The terminal device includes:
[0098] The processor 601 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0099] The memory 602 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 602 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 602 and is called by the processor 601 to execute the dynamic bandwidth allocation method of the embodiments of this application.
[0100] Input / output interface 603, used to implement information input and output;
[0101] Communication interface 604, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0102] Bus 605 , which transmits information between various components of the device (e.g., processor 601 , memory 602 , input / output interface 603 , and communication interface 604 );
[0103] The processor 601 , the memory 602 , the input / output interface 603 and the communication interface 604 are connected to each other in communication within the device via a bus 605 .
[0104] The present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the dynamic bandwidth allocation method as described in the first embodiment is implemented.
[0105] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware through a computer program. The program can be stored in a computer-monitorable storage medium, and when executed, the program can include the processes in the above-described method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0106] The specific embodiments described above further illustrate the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of protection of the present application.
[0107] It is particularly pointed out that for those skilled in the art, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this application should be included in the scope of protection of this application.
Claims
1. A dynamic bandwidth allocation method, characterized in that: include: Obtain each ONU in the current PON network and the corresponding actual load respectively; Determining rogue ONUs and normal ONUs in a PON network based on each of the ONUs and the actual load; Allocate bandwidth evenly to the rogue ONU according to the average distribution requirement to obtain remaining bandwidth, and evenly distribute the remaining bandwidth to the normal ONU; The method of determining rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load is as follows: inputting each of the ONUs and the actual load into a preset regression model to obtain a bandwidth demand prediction value corresponding to each of the ONUs; obtaining an error vector corresponding to each of the ONUs based on the bandwidth demand prediction value and the actual load; and judging whether the error vector satisfies a preset error threshold. If so, the ONU that satisfies the preset error threshold is determined as a rogue ONU in the PON network; otherwise, it is determined to be a normal ONU.
2. The dynamic bandwidth allocation method according to claim 1, wherein: The method of respectively obtaining each ONU in the current PON network and the corresponding actual load is specifically as follows: Determining an ONU number of ONUs in a PON network and initializing a vector variable based on the ONU number; Traversing each of the ONUs in the PON network, and obtaining a buffer occupancy report of each of the ONUs under a traffic category; The buffer zone occupancy reports are respectively accumulated into the vector variables to obtain the actual load.
3. The dynamic bandwidth allocation method according to claim 1, wherein: The ONUs and the actual loads are input into a preset regression model to obtain a bandwidth demand prediction value corresponding to each ONU, specifically: Based on each of the ONUs and the actual load, obtaining a slope corresponding to the regression model according to a least squares method, and determining an intercept corresponding to the regression model based on the slope; Based on the slope and the intercept, a bandwidth demand prediction value corresponding to each of the ONUs is determined.
4. The dynamic bandwidth allocation method according to claim 3, wherein: The calculation formula for the slope corresponding to the regression model obtained by the least squares method is specifically: Where m ONU is the slope, ONU(i) is the i-th ONU, Load(i) is the i-th actual load, and N is the number of ONUs.
5. The dynamic bandwidth allocation method according to claim 4, wherein: The calculation formula for determining the intercept corresponding to the regression model based on the slope is specifically: Where C ONU is the intercept, Load(i) is the actual load of the ith item, m ONU is the slope, ONU(i) is the i-th ONU, and N is the number of ONUs.
6. The dynamic bandwidth allocation method according to claim 2, wherein: The method of evenly allocating bandwidth to the rogue ONU according to the even distribution requirement to obtain the remaining bandwidth is specifically as follows: Obtaining bandwidth requirements of each of the ONUs under traffic categories; Determine a corresponding average distribution requirement based on the bandwidth requirement and the number of ONUs; Bandwidth is evenly distributed to the rogue ONU according to an even distribution requirement to obtain remaining bandwidth.
7. A dynamic bandwidth allocation system, characterized in that: include: Acquire modules, distinguish modules, and assign modules; The acquisition module is used to respectively acquire each ONU in the current PON network and the corresponding actual load; The distinguishing module is configured to determine rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load; The allocation module is configured to allocate bandwidth to the rogue ONUs on an average basis according to an average allocation requirement, obtain remaining bandwidth, and allocate the remaining bandwidth on an average basis to the normal ONUs; The method of determining rogue ONUs and normal ONUs in the PON network based on each of the ONUs and the actual load is as follows: inputting each of the ONUs and the actual load into a preset regression model to obtain a bandwidth demand prediction value corresponding to each of the ONUs; obtaining an error vector corresponding to each of the ONUs based on the bandwidth demand prediction value and the actual load; and judging whether the error vector satisfies a preset error threshold. If so, the ONU that satisfies the preset error threshold is determined as a rogue ONU in the PON network; otherwise, it is determined to be a normal ONU.
8. A terminal device, characterized in that: include: one or more processors; a memory, coupled to the processor, for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the dynamic bandwidth allocation method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the dynamic bandwidth allocation method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Method and OLT (optical line terminal) for detecting abnormal-lighting ONUs (optical network units) in PON (passive optical network) system
CN104811240A
Method for identifying rogue ONU in passive optical network and device
CN105743567A