Resource Object Dimension Traffic Analysis Method Based on Genetic Algorithm and Related Devices

Through the resource object dimensional traffic analysis method based on genetic algorithm, the problem of difficulty in accurately inferring IP flow-level traffic information in the prior art is solved, and network performance and security are improved. Especially in a large-scale distributed network environment, traffic load balancing can be better optimized and potential threats can be identified.

CN119583371BActive Publication Date: 2025-07-22BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411469659.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2025-07-22
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

Existing traffic monitoring and analysis methods are difficult to accurately infer traffic information at the IP flow level, resulting in difficulty in ensuring network performance, reliability and security.

Method used

The resource object dimension traffic analysis method based on genetic algorithm is adopted, and the port data packets and routing matrix of the network topology system are obtained, and the target traffic matrix is decomposed, dimensionality reduction, scaling and shaping are performed. The target traffic matrix is determined in combination with the genetic algorithm, and the IP-level traffic information is accurately inferred.

Benefits of technology

It has achieved in-depth understanding of network nodes and port traffic, optimized bandwidth control, reduced network congestion, improved data transmission efficiency, identified abnormal traffic patterns, and improved network security and attack resistance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583371B_ABST
    Figure CN119583371B_ABST
Patent Text Reader

Abstract

The present application provides a method for analyzing the traffic of resource object dimensions of a genetic algorithm, which is applied to a network topology system. The network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The method includes: obtaining a routing matrix in the network topology system and the uplink and downlink data packets of each port; decomposing the uplink and downlink data packets to determine a real traffic array; performing dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix; determining a first traffic matrix through operations according to the real traffic array and the dimensionality reduction matrix; randomly generating multiple load factors, and performing scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices; performing shaping and expansion on each of the multiple second traffic matrices to obtain multiple third traffic matrices; and determining a target traffic matrix related to the multiple resource objects by using a genetic algorithm based on the multiple third traffic matrices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network traffic analysis, and in particular, to a resource object dimension traffic analysis method based on genetic algorithm and related devices. Background Art

[0002] With the rapid development of cloud computing and network technologies, building an efficient and intelligent cloud network system has become an important topic in the field of information technology. As an innovative solution, digital twin network provides new ideas for network management and optimization by integrating spatial dimension and temporal dimension. Digital twin network creates a virtual model synchronized with the actual network using real-time data and advanced analysis technologies, making network monitoring, analysis, and prediction more accurate and efficient.

[0003] In the research and practice in this field, the research on traffic super-resolution of resource object dimension in spatial dimension is crucial. Traffic information at port level and tunnel level is essential for understanding network performance, reliability, and security. However, existing traffic monitoring and analysis methods often have difficulty accurately inferring traffic information at IP flow level. Summary of the Invention

[0004] In view of this, the purpose of the present application is to propose a resource object dimension traffic analysis method based on genetic algorithm and related devices to solve the problem that existing traffic monitoring and analysis methods have difficulty accurately inferring traffic information at IP flow level.

[0005] Based on the above purpose, the first aspect of the present application provides a resource object dimension traffic analysis method based on genetic algorithm, which is applied to a network topology system. The network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The method includes:

[0006] Obtain the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system;

[0007] Decompose the uplink and downlink data packets to obtain uplink input traffic and uplink output traffic, and determine a real traffic array based on the uplink input traffic and the uplink output traffic;

[0008] Perform dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix;

[0009] Determine a first traffic matrix through calculation according to the real traffic array and the dimensionality reduction matrix;

[0010] Randomly generate multiple load factors, and perform scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices;

[0011] Shape and expand each of the multiple second traffic matrices to obtain multiple third traffic matrices;

[0012] Based on the multiple third traffic matrices, use a genetic algorithm to determine the target traffic matrix related to the multiple resource objects.

[0013] Based on the same inventive concept, the present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable by the processor. When the processor executes the computer program, the method described in the first aspect is implemented.

[0014] Based on the same inventive concept, the present application also provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions for causing a computer to execute the method described in the first aspect.

[0015] As can be seen from the above, the method for analyzing traffic in resource object dimensions based on a genetic algorithm provided by this application is applied to a network topology system. The network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The method includes: obtaining the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system, providing a data basis for subsequent traffic analysis. Decompose the uplink and downlink data packets to obtain the uplink input traffic and the uplink output traffic, and determine the real traffic array based on the uplink input traffic and the uplink output traffic. Perform dimensionality reduction processing on the routing matrix to obtain a dimensionality-reduced matrix. The routing matrix after dimensionality reduction changes from sparse to full rank, making the accuracy of the finally solved traffic matrix higher. According to the real traffic array and the dimensionality-reduced matrix, determine the first traffic matrix through calculation. Randomly generate multiple load factors, and perform scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices. Perform shaping and expansion on each of the multiple second traffic matrices to obtain multiple third traffic matrices. Based on the multiple third traffic matrices, use the genetic algorithm to determine the target traffic matrix related to the multiple resource objects. The genetic algorithm improves the convergence speed of the solution and obtains the optimal solution, that is, the target traffic matrix. Through the method of this application, traffic information at the IP level can be inferred, the traffic conditions of each network node and port can be deeply understood, and more fine-grained control and optimization of the bandwidth can be achieved. Based on the obtained IP-level traffic data, the traffic load balance can be adjusted in a timely manner to avoid overloading of individual paths, thereby reducing network congestion, improving data transmission efficiency and response speed. Through an accurate traffic management method, network resources can be more reasonably allocated, resources can be allocated on demand, and waste of resources can be reduced, thereby improving the overall performance of the network, especially important in a large-scale distributed network environment. In addition, by deeply analyzing the traffic information at the IP flow level, abnormal traffic patterns and potential security threats can be more easily identified. This fine-grained traffic analysis and detection ability helps to build a more perfect network security system and improve the anti-attack ability of the entire network. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in this application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 It is a schematic structural diagram of the network topology system according to the embodiment of this application;

[0018] Figure 2Schematic flowchart of the resource object dimension traffic analysis method based on genetic algorithm according to an embodiment of the present application;

[0019] Figure 3 Schematic diagram of the routing matrix according to an embodiment of the present application;

[0020] Figure 4 Schematic structural diagram of the resource object dimension traffic analysis device based on genetic algorithm according to an embodiment of the present application;

[0021] Figure 5 Schematic diagram of the hardware structure of the electronic device according to an embodiment of the present application. Detailed implementation manners

[0022] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the following further details the present application in conjunction with specific embodiments and with reference to the accompanying drawings.

[0023] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meanings understood by those of ordinary skill in the art to which the present application belongs. The "first", "second" and similar terms used in the embodiments of the present application do not denote any order, quantity or importance, but are only used to distinguish different components. The terms such as "include" or "comprise" mean that the elements or objects appearing before this term cover the elements or objects listed after this term and their equivalents, without excluding other elements or objects. The terms such as "connect" or "couple" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left" and "right" are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0024] As described in the background art, existing traffic monitoring and analysis methods often have difficulty in accurately inferring traffic information at the IP flow level. In view of this, the present application proposes a resource object dimension traffic analysis method based on genetic algorithm, which can more effectively utilize data such as port traffic information, topological structure and forwarding routing table, so as to generate high-resolution traffic data at the service flow level and provide data sources for constructing digital twin networks for various network service models.

[0025] The following details the embodiments of the present application in conjunction with the accompanying drawings.

[0026] Figure 1 Shows the structural diagram of the network topology system according to an embodiment of the present application. As Figure 1As shown in the figure, the network topology system includes multiple resource objects, namely Pod1 to PodM. Among them, a Pod is the smallest resource management component in kubemetes and is also the resource object for running containerized applications in a minimized manner. Each Pod includes a spine switch, a top-of-rack switch (ToR) connected to the spine, and servers connected to the ToR. The spine is respectively connected to each logical super spine switch, and the above devices together constitute the network topology system. Figure 1 The quantities of Pods, spine switches, top-of-rack switches, servers, and logical super spine switches in Figure 1 are only for illustrative purposes and do not limit the method of this application.

[0027] Figure 2 The figure shows a schematic flowchart of the resource object dimension traffic analysis method based on the genetic algorithm according to an embodiment of this application. The resource object dimension traffic analysis method based on the genetic algorithm is applied to the network topology system, which includes multiple resource objects, and any two resource objects are communicatively connected. The method includes the following steps:

[0028] Step 102: Obtain the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system.

[0029] Specifically, the uplink and downlink data packets include uplink input traffic and downlink output traffic. The uplink input traffic is denoted as UI, representing the traffic from the spine switch to the ToR. The downlink output traffic is denoted as UO, representing the traffic from the ToR to the spine switch. Assuming the number of resource objects in this embodiment is M, the routing matrix is obtained according to the topology and forwarding routing table. Each row in the routing matrix represents the traffic from or to a Pod, and the M 2 columns represent the total number of all Pod pairs in the network. Figure 3 The figure shows a schematic diagram of the routing matrix according to an embodiment of this application. The routing matrix has 2M rows, including UI1 to UI M , UO1 to UO M . Figure 1Each Pod contains two spines. For Pod1, UI1 represents the uplink input traffic from the first spine in Pod1 to all ToRs in Pod1, and UO1 represents the uplink output traffic from all ToRs in Pod1 to the first spine in Pod1. UI2 represents the uplink input traffic from the second spine in Pod1 to all ToRs in Pod1, and UO2 represents the uplink output traffic from all ToRs in Pod1 to the second spine in Pod1. UI3 represents the uplink input traffic from the first spine in Pod1 to all ToRs in Pod2, and UO3 represents the uplink output traffic from all ToRs in Pod2 to the first spine in Pod1. UI4 represents the uplink input traffic from the second spine in Pod1 to all ToRs in Pod2, and UO4 represents the uplink output traffic from all ToRs in Pod2 to the second spine in Pod1, and so on.

[0030] For Pod2, UI1 represents the uplink input traffic from the first spine in Pod2 to all ToRs in Pod1, and UO1 represents the uplink output traffic from all ToRs in Pod1 to the first spine in Pod2. UI2 represents the uplink input traffic from the second spine in Pod2 to all ToRs in Pod1, and UO2 represents the uplink output traffic from all ToRs in Pod1 to the second spine in Pod2. UI3 represents the uplink input traffic from the first spine in Pod2 to all ToRs in Pod2, and UO3 represents the uplink output traffic from all ToRs in Pod2 to the first spine in Pod2. UI4 represents the uplink input traffic from the second spine in Pod2 to all ToRs in Pod2, and UO4 represents the uplink output traffic from all ToRs in Pod2 to the second spine in Pod2, and so on.

[0031] Routing matrix In it, the number of columns is M 2 , including M groups of Pod1 to PodM. In Figure 3 the shown routing matrix, for the row of UI1, the value of the column corresponding to Pod1 in the Pod1 column is 1, indicating that the traffic of Pod1 itself passes through UI1. The value of the column corresponding to Pod3 is 0, indicating that the traffic from Pod1 to Pod3 does not pass through UI1.

[0032] Step 104: Decompose the uplink and downlink data packets to obtain uplink input traffic and uplink output traffic, and determine a real traffic array based on the uplink input traffic and the uplink output traffic.

[0033] Specifically, the uplink and downlink data packets can be decomposed into uplink input traffic and uplink output traffic. The uplink input traffic and uplink output traffic in each Pod constitute a link traffic data Y with a size of 2M 2M×1 , that is, the real traffic array. Y 2M×1 = [UI1 + UI2, UI3 + UI4,..., UI 2M-1 + UI 2M , UO1 + UO2, UO3 + UO4,..., UO 2M-1 + UO 2M . Exemplarily, when the specific value of M is 60, Y 120×1 = [UI1 + UI2, UI3 + UI4,..., UI1 19 + UI 120 , UO1 + UO2, UO3 + UO4,..., UO 119 + UO 120 = [0.03365 0.03146 0.03355 0.03126 0.00942 …… 0.0155 0.0173 0.01574]. Correspondingly, the routing matrix Exemplarily,

[0034] R 120×3600 = [[1.1.1....0.0.0.] [0.0.0....0.0.0.] [0.0.0....0.0.0.] ... [0.0.0....1.0.0.] [0.0.0....0.1.0.]

[0040] [0.0.0....0.0.1.]].

[0041] Step 106: Perform dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix.

[0042] Further, step 106 includes:

[0043] Determine the target dimension according to the number of resource objects;

[0044] Based on the target dimension, randomly select the target dimension number of column data from the routing matrix and combine them to obtain the dimensionality reduction matrix; or

[0045] Based on the target dimension, according to the elephant flow information in the network topology system, randomly select the target dimension number of column data from the routing matrix and combine them to obtain the dimensionality reduction matrix.

[0046] Specifically, continuing the previous example, the routing matrix R 120×3600 is a sparse matrix, and the solution of the target traffic matrix calculated based on the sparse matrix is not unique. Therefore, it is necessary to perform dimensionality reduction processing on the routing matrix so that the routing matrix is transformed from a sparse matrix to a full-rank matrix. When the number of resource objects is M = 60, the target dimension is determined to be 2 * M = 120. Randomly select 120 columns of data from the routing matrix to form a dimensionality reduction matrix. There are two methods for selecting 120 columns of data. One is to randomly select 120 columns of data from the 3600 columns of data in the routing matrix to form a dimensionality reduction matrix. The other is to select 120 columns of data from the 3600 columns of data in the routing matrix according to the elephant flow information in the network topology system to form a dimensionality reduction matrix. The selected column data is the column data related to the elephant flow. Elephant flow refers to the network traffic with a long duration and a large amount of data in the network. The dimensionality reduction matrix obtained by selecting according to the elephant flow information is more accurate. Through the above two methods, the dimensionality reduction processing of the routing matrix is realized to ensure that a unique target traffic matrix is obtained subsequently.

[0047] Step 108: Determine the first traffic matrix through operations according to the real traffic array and the dimensionality reduction matrix.

[0048] Specifically, the first traffic matrix is determined by the following formula:

[0049] Y = R * X

[0050] where Y is the real traffic array, R represents the dimensionality reduction matrix, and X represents the IP-level traffic matrix. The first traffic matrix is the IP-level traffic matrix. X = R -1 Y. Exemplarily, when M = 60,

[0051] Step 110: Randomly generate multiple load factors, and perform scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices.

[0052] Further, step 110 includes:

[0053] For each load factor, perform a multiplication operation on each value in the first traffic matrix with the load factor to obtain the second traffic matrix.

[0054] Specifically, the number of load factors is the same as the number of samples for the subsequent genetic algorithm. Exemplarily, if the number of samples used in the genetic algorithm is 1000, then the number of load factors is 1000. The values of the load factors are randomly generated, and the values of each load factor are different. The value range of the load factors is [0.65, 0.95] so that the values of the scaled second traffic matrix fluctuate within a small range. Multiply each load factor by the first traffic matrix to obtain the second traffic matrix. Exemplarily, if the load factor is 0.74490, then the corresponding second traffic matrix X′ 120×1 = 0.74490 * X 120×1 = [1.91559013e-02 2.56096404e-03 2.44188571e-03 1.31952891e-02 9.33212167e-03 2.32022605e-02 -1 …… 2.05398076e-02]. After scaling by 1000 load factors, 1000 second traffic matrices are formed. By introducing the load factors in this step, the second traffic matrix can be shaped into the initial value of the subsequent genetic algorithm. The initial number of samples for the subsequent genetic algorithm is determined by the load factors, which improves the convergence speed of the subsequent genetic algorithm to obtain the optimal solution.

[0055] Step 112: Shape and expand each of the multiple second traffic matrices to obtain multiple third traffic matrices.

[0056] Further, step 112 includes:

[0057] For each second traffic matrix, determine the total magnitude interval using a logarithmic algorithm according to the maximum and minimum values in the second traffic matrix;

[0058] Divide the total magnitude interval to obtain multiple sub-magnitude intervals;

[0059] Process all the values in the second traffic matrix using a logarithmic algorithm, and divide each processed value into the corresponding sub-magnitude interval;

[0060] For each sub-magnitude interval, determine the first quantity of data to be expanded according to the column information of the values corresponding to the sub-magnitude interval, randomly generate the first quantity of expansion data, and fill the first quantity of expansion data into the second traffic matrix to obtain the third traffic matrix; wherein, the column information is determined according to the routing matrix, and the values of the expansion data are within the sub-magnitude interval.

[0061] Specifically, before determining the total magnitude range, it is also necessary to perform anomaly detection on the second traffic matrix, which specifically includes: detecting whether there are anomalies in the values in each second traffic matrix, and if there are anomalies, performing correction processing on the abnormal data. In the foregoing calculation process, the values in the calculated second traffic matrix may be negative numbers, and negative numbers are abnormal values. Perform correction processing on the abnormal values and set the abnormal values to 0.

[0062] For each second traffic matrix, determine the maximum value max and the minimum value min in the second traffic matrix, perform logarithmic processing on the maximum value and the minimum value, and determine the total magnitude range [logmin, logmax]. Divide the total magnitude range [logmin, logmax] into multiple sub-magnitude ranges. The number of sub-magnitude ranges can be determined according to the actual situation. Exemplarily, the number of sub-magnitude ranges is 10, and the 10 sub-magnitude ranges are specifically denoted as [logmin, a1), [a1, a2),... [a9, logmax). For each value X in the second traffic matrix i perform logarithmic processing, and according to the result of the logarithmic processing divide each value X i into the corresponding sub-magnitude range.

[0063] The first traffic matrix is obtained by operating on the real traffic array and the dimensionality reduction matrix. The first traffic matrix carries the column information in the dimensionality reduction matrix, that is, it carries the column information in the routing matrix. The second traffic matrix is obtained by scaling the first traffic matrix. Therefore, the second traffic matrix also carries the column information in the routing matrix. Each value in the second traffic matrix corresponds to a certain column in the routing matrix and thus has a corresponding column identifier. When performing an expansion operation on the values corresponding to each sub-magnitude interval, first determine the column identifier of each value, then determine the column difference between this column identifier and the forward column identifier adjacent to this column identifier in the second traffic matrix, and determine the number of data to be expanded according to the column difference. Exemplarily, if the column identifier of a value in the sub-magnitude interval is 5, it means that the value is associated with the 5th column in the routing matrix. Among the column identifiers corresponding to all the values in the second traffic matrix, determine the column identifier that is adjacent to and less than 5 as 3. There is a difference of one column between column identifier 3 and column identifier 5. Therefore, the first number of data to be expanded is 1, and 1 expansion data is randomly generated, and the magnitude range of this expansion data is within this sub-magnitude interval. Another example, if the column identifier of a value in the sub-magnitude interval is 200, it means that the value is associated with the 200th column in the routing matrix. Among the column identifiers corresponding to all the values in the second traffic matrix, determine the column identifier that is adjacent to and less than 200 as 180. There is a difference of 19 columns between column identifier 180 and column identifier 200. Therefore, the first number of data to be expanded is 19, and 19 expansion data are randomly generated, and the magnitude range of this expansion data is within this sub-magnitude interval. Complement the expanded data into the second traffic matrix to obtain the second traffic matrix. Continuing the foregoing example, the second traffic matrix X′ 120×1 After expansion, the third traffic matrix X′ is obtained 3600×1 =[6.26858961e-04 9.96811741e-05 2.70170781e-04...3.73887484e-04 1.17732451e-04 1.82967979e-02]. Correspondingly, the number of second traffic matrices is 1000, and the number of third traffic matrices obtained after expansion is also 1000.

[0064] Step 114: Based on multiple third traffic matrices, use the genetic algorithm to determine the target traffic matrix related to the multiple resource objects.

[0065] Further, step 114 includes:

[0066] Perform multiple rounds of iterative operations. For each round of iterative operation:

[0067] According to multiple third traffic matrices, use the multi-point crossover method to obtain multiple fourth traffic matrices;

[0068] Generate a matrix set based on multiple third traffic matrices and multiple fourth traffic matrices;

[0069] For each matrix in the matrix set, perform an operation based on the matrix and the routing matrix to obtain a predicted traffic array;

[0070] Calculate the deviation between the predicted traffic array and the actual traffic array,

[0071] In response to the deviation obtained from the current round of iterative calculation not converging, sort all the deviations obtained from the current round of iterative calculation in ascending order, and use the matrices corresponding to the first N deviations in the sequence as the multiple third traffic matrices in the next round of iteration, where N is equal to the number of multiple third traffic matrices;

[0072] In response to the deviation obtained from the current round of iterative calculation converging, use the matrix corresponding to the minimum deviation obtained from the current round of iterative calculation as the target traffic matrix.

[0073] Specifically, in this embodiment, a genetic algorithm is used to determine the target traffic matrix. Specifically, when implementing, a multi-round iterative method is used to determine the target traffic matrix. During each round of iterative operation, first perform a selection and crossover operation on multiple third traffic matrices, combine multiple third traffic matrices in pairs for multi-point crossover to generate new traffic matrices, that is, fourth traffic matrices. In this embodiment, the multi-point crossover method is selected, and three crossover points are randomly selected for crossover. After the crossover is completed, the fourth traffic matrices are obtained. It should be noted that the multi-point crossover method in this embodiment is a conventional method in the genetic algorithm and will not be described in detail here. Exemplarily, the number of third traffic matrices is 1000. After the crossover operation of this embodiment, 1000 fourth traffic matrices are obtained. After combining the third traffic matrices and the fourth traffic matrices, a matrix set is obtained, and the matrix set contains 2000 matrices.

[0074] In addition, before combining to obtain the matrix set, the fourth traffic matrices can also be mutated. Specifically, it includes: randomly generating a mutation amount in a preset numerical interval, and mutating the fourth traffic matrices according to the mutation amount; combining multiple third traffic matrices and multiple mutated fourth traffic matrices to obtain a matrix set.

[0075] The preset numerical region in this embodiment can be (-0.001, 0.001). Randomly generate a mutation amount within the preset numerical interval, and add the mutation amount to each value in the fourth traffic matrix to obtain the mutated fourth traffic matrix.

[0076] For each matrix in the matrix set, according to the formula Y′ = R * X, each matrix is taken as X, and the routing matrix is taken as R, and the product operation is performed to obtain the predicted traffic array Y′. The deviation between each calculated predicted traffic array Y′ and the true traffic array Y is calculated. In this embodiment, the deviation between the predicted traffic array Y′ and the true traffic array Y is determined by calculating the Euclidean norm. The calculation process is represented by the following formula, Exemplarily, the number of matrices in the matrix set is 2000, so the number of calculated deviations is also 2000. If the 2000 deviations calculated in this round of iteration reach the minimum value and tend to be stable, that is, the deviations calculated in this round of iteration converge, then the matrix corresponding to the minimum deviation calculated in this round of iteration can be used as the target traffic matrix. On the contrary, if the deviation calculated in this round of iteration does not converge, it means that the deviation calculated in this round of iteration is not stable and needs to continue the iteration. Then, 1000 matrices corresponding to the smaller deviations are selected from the 2000 deviations as the 1000 third traffic matrices required for the next round of iteration. By setting the sample number of the 1000 third traffic matrices, the optimal solution, that is, the target traffic matrix, is obtained through iterative calculation.

[0077] In the specific implementation process, multiple groups of samples can be set. For example, the first group includes 1000 third traffic matrices, the second group includes 2000 third traffic matrices, the third group includes 3000 third traffic matrices, the fourth group includes 4000 third traffic matrices, and the fifth group includes 5000 third traffic matrices. Correspondingly, the number of load factors in the foregoing embodiment is determined to be 1000, 2000, 3000, 4000, and 5000. After multiple groups of tests, it is determined that when the sample number is 5000, the convergence effect of the deviation calculated in multiple rounds of iteration is the best.

[0078] Based on the above steps 102 to 114, the resource object dimension traffic analysis method provided in this embodiment based on a genetic algorithm is applied to a network topology system. The network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The method includes: obtaining the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system, providing a data basis for subsequent traffic analysis. Decompose the uplink and downlink data packets to obtain uplink input traffic and uplink output traffic, and determine a real traffic array based on the uplink input traffic and the uplink output traffic. Perform dimensionality reduction processing on the routing matrix to obtain a reduced-dimensional matrix. After dimensionality reduction, the routing matrix changes from sparse to full rank, making the accuracy of the finally solved traffic matrix higher. According to the real traffic array and the reduced-dimensional matrix, determine the first traffic matrix through calculation. Randomly generate multiple load factors, and perform scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices. Perform shaping and expansion on each of the multiple second traffic matrices to obtain multiple third traffic matrices. Based on the multiple third traffic matrices, use a genetic algorithm to determine the target traffic matrix related to the multiple resource objects. By using the genetic algorithm, the convergence speed of the solution is improved, and the optimal solution, that is, the target traffic matrix, is obtained. Through the method of this application, traffic information at the IP level can be inferred, the traffic conditions of each network node and port can be deeply understood, and more fine-grained control and optimization of the bandwidth can be achieved. Based on the obtained IP-level traffic data, the traffic load balance can be adjusted in a timely manner to avoid overloading of individual paths, thereby reducing network congestion, improving data transmission efficiency and response speed. Through an accurate traffic management method, network resources can be more reasonably allocated, resources can be allocated on demand, and waste of resources can be reduced, thereby improving the overall performance of the network, especially important in a large-scale distributed network environment. After knowing the traffic information at the IP flow level, network managers can understand the usage of resources in more detail. By understanding the traffic patterns of each IP flow and allocating resources on demand, waste of resources can be reduced. For example, frequently used ports and links can be supported with more bandwidth and computing resources, while idle or low-usage parts can temporarily reduce resource allocation. By optimizing the management of resources, the network operation cost can be significantly reduced and the overall efficiency can be improved. In addition, by deeply analyzing the traffic information at the IP flow level, abnormal traffic patterns and potential security threats can be more easily identified. Network attacks often generate abnormal traffic behaviors, such as DDoS attacks, IP spoofing, etc. With the data perspective at the IP flow level, the system can more accurately detect these abnormal behaviors, quickly identify the sources and targets of malicious traffic, and then take effective security protection measures. This fine-grained traffic analysis and detection ability helps to build a more perfect network security system and improve the anti-attack ability of the entire network.

[0079] In some embodiments, it further includes: shaping the target traffic matrix according to the number of the multiple resource objects.

[0080] Specifically, the target traffic matrix obtained through the foregoing embodiments is X 3600×1 , and the target traffic matrix is shaped according to the number of multiple resources to obtain the shaped target traffic matrix X 60×60 . In the target traffic matrix X 60×60 , each row represents a source Pod, and each column represents a target Pod. Through the target traffic matrix X 60×60 , the speculated traffic data between any two Pods can be obtained, realizing the speculation of traffic information at the IP level.

[0081] It should be noted that the method of the embodiments of the present application can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In such a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present application, and these multiple devices will interact with each other to complete the described method.

[0082] It should be noted that some embodiments of the present application are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the above embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0083] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides a resource object dimension traffic analysis device based on a genetic algorithm.

[0084] Referring to Figure 4 , the resource object dimension traffic analysis device based on a genetic algorithm is applied to a network topology system, the network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The device includes:

[0085] An acquisition module 402, configured to acquire the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system;

[0086] A decomposition module 404, configured to decompose the uplink and downlink data packets to obtain uplink input traffic and uplink output traffic, and determine a real traffic array based on the uplink input traffic and the uplink output traffic;

[0087] The dimensionality reduction module 406 is configured to perform dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix;

[0088] The determination module 408 is configured to determine a first traffic matrix through operations according to the real traffic array and the dimensionality reduction matrix;

[0089] The scaling module 410 is configured to randomly generate a plurality of load factors, and perform scaling processing on the first traffic matrix based on the plurality of load factors to obtain a plurality of second traffic matrices;

[0090] The expansion module 412 is configured to perform shaping and expansion on each of the plurality of second traffic matrices to obtain a plurality of third traffic matrices;

[0091] The operation module 414 is configured to determine a target traffic matrix related to the plurality of resource objects by using a genetic algorithm based on the plurality of third traffic matrices.

[0092] In some embodiments, the dimensionality reduction module 406 is configured to determine a target dimension according to the number of resource objects; based on the target dimension, randomly select target dimension column data from the routing matrix and combine them to obtain the dimensionality reduction matrix; or, based on the target dimension, according to the elephant flow information in the network topology system, randomly select target dimension column data from the routing matrix and combine them to obtain the dimensionality reduction matrix.

[0093] In some embodiments, the scaling module 410 is configured to perform a multiplication operation on each value in the first traffic matrix with each load factor for each load factor to obtain the second traffic matrix.

[0094] In some embodiments, the expansion module 412 is configured to, for each second traffic matrix, determine a total magnitude interval by using a logarithmic algorithm according to the maximum value and the minimum value in the second traffic matrix;

[0095] Divide the total magnitude interval to obtain a plurality of sub-magnitude intervals;

[0096] Use a logarithmic algorithm to process all the values in the second traffic matrix, and divide each processed value into the corresponding sub-magnitude interval;

[0097] For each sub - magnitude interval, determine the first quantity of data to be augmented according to the column information of the values corresponding to the sub - magnitude interval, randomly generate the first quantity of augmented data, and fill the first quantity of augmented data into the second traffic matrix to obtain the third traffic matrix; wherein, the column information is determined according to the routing matrix, and the values of the augmented data are within the sub - magnitude interval.

[0098] In some embodiments, the operation module 414 is configured to perform multiple rounds of iterative operations. For each round of iterative operation:

[0099] Obtain multiple fourth traffic matrices by using a multi - point crossover method according to multiple third traffic matrices;

[0100] Generate a matrix set according to multiple third traffic matrices and multiple fourth traffic matrices;

[0101] For each matrix in the matrix set, perform an operation based on the matrix and the routing matrix to obtain a predicted traffic array;

[0102] Calculate the deviation between the predicted traffic array and the actual traffic array,

[0103] In response to the deviation obtained from the current round of iterative calculation not converging, sort all the deviations obtained from the current round of iterative calculation in ascending order, and use the matrices corresponding to the first N deviations in the sequence as the multiple third traffic matrices in the next round of iteration, where N is equal to the number of multiple third traffic matrices;

[0104] In response to the deviation obtained from the current round of iterative calculation converging, use the matrix corresponding to the minimum deviation obtained from the current round of iterative calculation as the target traffic matrix.

[0105] In some embodiments, the operation module 414 is configured to randomly generate a variation amount within a preset numerical interval, and perform a variation process on the fourth traffic matrix according to the variation amount;

[0106] Combine multiple third traffic matrices and multiple fourth traffic matrices that have undergone the variation process to obtain a matrix set.

[0107] In some embodiments, it further includes an exception handling module, which is configured to detect whether there are any abnormalities in the values of each second traffic matrix. If there are abnormalities, perform a correction process on the abnormal data.

[0108] In some embodiments, it further includes a shaping module, which is configured to shape the target traffic matrix according to the number of the multiple resource objects.

[0109] For the convenience of description, when describing the above device, it is divided into various modules according to functions for separate description. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0110] The device in the above embodiment is used to implement the corresponding resource object dimension traffic analysis method based on the genetic algorithm in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0111] Based on the same inventive concept, corresponding to the method in any of the above embodiments, the present application further provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the resource object dimension traffic analysis method based on the genetic algorithm described in any of the above embodiments.

[0112] Figure 5 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.

[0113] The processor 1010 can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0114] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.

[0115] The input / output interface 1030 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure), or can be externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0116] The communication interface 1040 is used to connect to the communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can achieve communication through wired means (such as USB, network cable, etc.), or can also achieve communication through wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0117] The bus 1050 includes a path to transmit information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0118] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and do not have to include all the components shown in the figure.

[0119] The electronic device of the above embodiment is used to implement the corresponding resource object dimension traffic analysis method based on the genetic algorithm in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0120] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the resource object dimension traffic analysis method based on the genetic algorithm described in any of the above embodiments.

[0121] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0122] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the resource object dimension traffic analysis method based on the genetic algorithm as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0123] Based on the same concept, corresponding to the method of any of the above embodiments, the present application also provides a computer program product, including computer program instructions, which when running on a computer, cause the computer to execute the method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0124] Those of ordinary skill in the art should understand that: the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present application is limited to these examples; under the idea of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and they are not provided in detail for the sake of brevity.

[0125] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present application difficult to understand, well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that details regarding the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be entirely within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application may be practiced without these specific details or with variations of these specific details. Accordingly, these descriptions should be considered illustrative rather than restrictive.

[0126] Although the present application has been described in connection with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art in light of the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0127] Embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the present application. Accordingly, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the embodiments of the present application shall be included within the protection scope of the present application.

Claims

1. A resource object dimension traffic analysis method based on genetic algorithm, characterized in that Applied to a network topology system, the network topology system includes multiple resource objects, and any two resource objects are communicatively connected. The method includes: Obtain the uplink and downlink data packets of each port in the network topology system, and the routing matrix in the network topology system; Decompose the uplink and downlink data packets to obtain uplink input traffic and uplink output traffic, and determine a real traffic array based on the uplink input traffic and the uplink output traffic; Perform dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix; Determine a first traffic matrix through operations according to the real traffic array and the dimensionality reduction matrix; Randomly generate multiple load factors, and perform scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices; Perform shaping and expansion on each of the multiple second traffic matrices to obtain multiple third traffic matrices; Based on the multiple third traffic matrices, use a genetic algorithm to determine a target traffic matrix related to the multiple resource objects, including: Perform multiple rounds of iterative operations. For each round of iterative operation: According to the multiple third traffic matrices, use a multi-point crossover method to obtain multiple fourth traffic matrices; Generate a matrix set according to the multiple third traffic matrices and the multiple fourth traffic matrices; For each matrix in the matrix set, perform operations based on the matrix and the routing matrix to obtain a predicted traffic array; Calculate the deviation between the predicted traffic array and the real traffic array; In response to the deviation calculated in this round of iteration not converging, sort all the deviations calculated in this round of iteration in ascending order, and use the matrices corresponding to the first N deviations in the sequence as the multiple third traffic matrices in the next round of iteration, where N is equal to the number of the multiple third traffic matrices; In response to the deviation calculated in this round of iteration converging, use the matrix corresponding to the minimum deviation calculated in this round of iteration as the target traffic matrix.

2. The method according to claim 1, wherein The performing dimensionality reduction processing on the routing matrix to obtain a dimensionality reduction matrix includes: Determine a target dimension according to the number of resource objects; Based on the target dimension, randomly select target dimension column data from the routing matrix and combine them to obtain the dimensionality reduction matrix; or, Based on the target dimension, according to the elephant flow information in the network topology system, randomly select target dimension column data from the routing matrix and combine them to obtain the dimensionality reduction matrix.

3. The method according to claim 1, wherein The performing scaling processing on the first traffic matrix based on the multiple load factors to obtain multiple second traffic matrices includes: For each load factor, perform a multiplication operation on each value in the first traffic matrix and the load factor to obtain the second traffic matrix.

4. The method according to claim 1, wherein The performing shaping and expansion on each of the multiple second traffic matrices to obtain multiple third traffic matrices includes: For each second traffic matrix, determine a total magnitude interval using a logarithmic algorithm according to the maximum value and the minimum value in the second traffic matrix; Divide the total magnitude interval to obtain multiple sub-magnitude intervals; Process all the values in the second traffic matrix using a logarithmic algorithm, and divide each processed value into the corresponding sub-magnitude interval; For each sub-magnitude interval, determine the first quantity of data to be augmented according to the column information of the values corresponding to the sub-magnitude interval, randomly generate the first quantity of augmented data, and fill the first quantity of augmented data into the second traffic matrix to obtain the third traffic matrix; wherein, the column information is determined according to the routing matrix, and the values of the augmented data are within the sub-magnitude interval.

5. The method according to claim 1, characterized in that Said generating a matrix set according to a plurality of third traffic matrices and a plurality of fourth traffic matrices includes: Randomly generate a variation amount in a preset value interval, and perform a variation process on the fourth traffic matrix according to the variation amount; Combine a plurality of third traffic matrices and a plurality of fourth traffic matrices that have been subjected to the variation process to obtain a matrix set.

6. The method according to claim 4, wherein Before determining the total magnitude interval using a logarithmic algorithm based on the maximum and minimum values in the second traffic matrix, it includes: Detect whether there are any abnormal values in each second traffic matrix, and if there are any abnormal values, perform correction processing on the abnormal data.

7. The method according to claim 1, wherein It further includes: Shape the target traffic matrix according to the number of the plurality of resource objects.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 7.

9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Network-key-node self-similar-traffic generation simplification method based on genetic algorithm

    CN103944748A

  • Network topology updating method and device and communication equipment

    CN116094927A