Network monitoring method, apparatus, device, medium, and program product
By dynamically updating the weighted average and target threshold judgment through the EMA algorithm and combining it with the operational business priority, the problem of network traffic processing difficulties in the banking information system is solved, adaptive monitoring of the network and efficient resource allocation are achieved, and network stability and security are improved.
Patent Information
- Application Number
- CN202411837996.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-12-13
AI Technical Summary
The network structure of the banking information system is complex, and network traffic processing is difficult, resulting in high pressure on operation and maintenance. Existing monitoring methods are prone to false positives or omissions in dynamic environments, affecting network stability and security.
The exponentially weighted moving average algorithm (EMA) is used to dynamically update the weighted average value. Combined with target parameters and threshold judgments, real-time monitoring prompt information is generated, and traffic is dynamically allocated according to the priority of the running business.
It implements adaptive traffic analysis, provides more accurate and sensitive network status monitoring and alarm mechanisms, enhances network stability and security, optimizes resource allocation, and ensures the efficient operation of key businesses.
Smart Images

Figure CN119603182B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network management, and more specifically to a network monitoring method, apparatus, device, medium, and program product. Background Art
[0002] With the rapid development of informatization in the financial industry, bank information systems, as representative of financial information systems, have developed relatively complex network structures. In a network, a port is a virtual location on a machine that is open to connections from other machines. Every networked computer / server has a standard number of ports, each reserved for certain types of communication. This complex network traffic is extremely difficult to handle during communication, resulting in significant pressure on subsequent operations and maintenance, making system operations and maintenance a cumbersome task. Summary of the Invention
[0003] In view of the above problems, the present disclosure provides a network monitoring method, apparatus, device, medium and program product.
[0004] According to a first aspect of the present disclosure, a network monitoring method is provided, the method comprising: obtaining first network traffic information and second network traffic information of a network device port, the first network traffic information representing traffic data of the port at a current moment, and the second network traffic information representing traffic data of the port at a historical moment; obtaining a target parameter corresponding to the current moment, the target parameter representing the degree of influence of network traffic data at a historical moment on traffic data at the current moment; determining a weighted average value corresponding to the traffic data of the port at the current moment based on the first network traffic information, the second network traffic information and the target parameter; and generating prompt information based on the first network traffic information and the weighted average value.
[0005] According to an embodiment of the present disclosure, obtaining a target parameter corresponding to the current moment includes: obtaining historical network traffic information of a network device port at multiple historical moments within a historical period; determining a first intermediate value based on the historical network traffic information, the first intermediate value representing the variance of the historical network traffic information; and determining the target parameter based on the first intermediate value.
[0006] According to an embodiment of the present disclosure, prompt information is generated based on the second network traffic information and the weighted average value, including: determining the fluctuation value based on the second network traffic information and the weighted average value; obtaining the target threshold corresponding to the current moment; and generating an early warning prompt when the fluctuation value is greater than the target threshold.
[0007] According to an embodiment of the present disclosure, obtaining a target threshold corresponding to the current moment includes: obtaining historical network traffic information of a network device port at multiple historical moments within a historical period; determining a second intermediate value and a third intermediate value based on the historical network traffic information, the second intermediate value representing the standard deviation of the historical network traffic information, and the third intermediate value representing the average value of the historical network traffic information; determining the target threshold based on the second intermediate value and the third intermediate value.
[0008] According to an embodiment of the present disclosure, the method also includes: when the fluctuation value is less than the target threshold, obtaining identification information of multiple running services in the network device; generating priorities corresponding to the multiple running services respectively based on the identification information; and allocating traffic to the multiple running services in order from low to high priority of the multiple running services.
[0009] According to an embodiment of the present disclosure, the method further includes: when the fluctuation value is greater than the target threshold, allocating traffic to the multiple running services in descending order of priority of the multiple running services.
[0010] According to an embodiment of the present disclosure, when the first business traffic allocated to the first operating business is greater than the second business traffic consumed by the first operating business at the current moment, the remaining traffic is allocated to the second operating business. The remaining traffic represents the difference between the first business traffic and the second business traffic. The priority of the first operating business is greater than the priority of the second operating business.
[0011] According to an embodiment of the present disclosure, a weighted average value corresponding to the traffic data of the port at the current moment is determined based on the first network traffic information, the second network traffic information and the target parameter, including: determining a first comprehensive value based on the target parameter and the first network traffic information; determining a second comprehensive value based on the target parameter and the second network traffic information; and determining a weighted average value based on the first comprehensive value and the second comprehensive value.
[0012] The second aspect of the present disclosure provides a network monitoring device, which includes: a first acquisition module, used to obtain first network traffic information and second network traffic information of a network device port, the first network traffic information represents the traffic data of the port at the current moment, and the second network traffic information represents the traffic data of the port at a historical moment; a second acquisition module, used to obtain a target parameter corresponding to the current moment, the target parameter represents the degree of influence of the network traffic data at the historical moment on the traffic data at the current moment; a determination module, used to determine a weighted average value corresponding to the traffic data of the port at the current moment based on the first network traffic information, the second network traffic information and the target parameter; and a generation module, used to generate prompt information based on the first network traffic information and the weighted average value.
[0013] A third aspect of the present disclosure provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0014] The fourth aspect of the present disclosure further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.
[0015] The fifth aspect of the present disclosure further provides a computer program product, comprising a computer program or instructions, which implement the steps of the above method when executed by a processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0017] Figure 1 Schematically illustrates an application scenario diagram of a network monitoring method, apparatus, device, medium, and program product according to an embodiment of the present disclosure;
[0018] Figure 2 The flowchart of the network monitoring method according to the embodiment of the present disclosure is schematically shown;
[0019] Figure 3 Schematically shows a flow chart of a method for determining target parameters according to an embodiment of the present disclosure;
[0020] Figure 4 Schematically shows a flow chart of determination based on the second network traffic information and the weighted average according to an embodiment of the present disclosure;
[0021] Figure 5 Schematically shows a flow chart of a method for determining a target threshold according to an embodiment of the present disclosure;
[0022] Figure 6 Schematically shows a flow chart of a network monitoring method according to another embodiment of the present disclosure;
[0023] Figure 7 The flowchart of the method for determining the weighted average value according to an embodiment of the present disclosure is schematically shown;
[0024] Figure 8 A schematic diagram of a network monitoring device according to an embodiment of the present disclosure is shown; and
[0025] Figure 9 A block diagram of an electronic device suitable for implementing a network monitoring method according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0027] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0029] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0030] It should be noted that the network monitoring determination method and device disclosed herein can be used in the field of financial technology and network management, and can also be used in any field other than the field of financial technology. The application field of the network monitoring method and device disclosed herein is not limited.
[0031] In the technical solutions disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0032] In scenarios where personal information is used for automated decision-making, the methods, devices, and systems provided by the embodiments of the present disclosure all provide users with corresponding operation portals for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered. The expression "automated decision-making" here refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests and hobbies, or economic, health, credit status, etc. through computer programs and making decisions. The expression "expert decision-making" here refers to the activity of making decisions by people who specialize in a certain field, have specialized experience, knowledge, and skills, and have reached a certain level of professionalism.
[0033] The embodiments of the present disclosure provide a network monitoring method, apparatus, device, medium, and program product. Before introducing the technical solutions provided by the embodiments of the present disclosure, the related technologies involved in the present disclosure are first described.
[0034] In related technologies, with the development of informatization in the financial industry, bank information systems, as representative of financial information systems, have a relatively complex network structure. In a network, a port is a virtual location on a machine that is open to connections from other machines. Every networked computer / server has a standard number of ports, each reserved for certain types of communication. This complex network traffic is very difficult to handle during the communication process, resulting in high pressure and heavy system operation and maintenance.
[0035] For example, as enterprise networks expand, the management and optimization of network traffic becomes increasingly complex. Real-time monitoring of network traffic, identifying abnormal traffic, and responding promptly have become core requirements for ensuring network stability and security. Conventional network traffic monitoring methods rely primarily on simple thresholds or static rules. These methods are prone to false positives or false negatives in dynamically changing network environments, impacting network stability.
[0036] Before further describing the embodiments of the present disclosure in detail, the nouns and terms involved in the embodiments of the present disclosure are explained. The nouns and terms involved in the embodiments of the present disclosure are subject to the following interpretations.
[0037] The Exponential Moving Average (EMA) algorithm is widely used to smooth time series data. It assigns different weights to historical data to reflect trends over time. An EMA value (weighted average) represents the weighted average of historical data within a specific time window.
[0038] The embodiment of the present disclosure provides a network monitoring method, which includes: obtaining first network traffic information and second network traffic information of a network device port, the first network traffic information representing the traffic data of the port at the current moment, and the second network traffic information representing the traffic data of the port at a historical moment; obtaining a target parameter corresponding to the current moment, the target parameter representing the degree of influence of the network traffic data at a historical moment on the traffic data at the current moment; determining a weighted average value corresponding to the traffic data of the port at the current moment based on the first network traffic information, the second network traffic information and the target parameter; generating prompt information based on the second network traffic information and the weighted average value. By dynamically updating the target parameters in the weighted average value algorithm based on the historical traffic data within the historical period, and then analyzing the changes in network traffic in real time based on the dynamic target parameters. In this way, an adaptive traffic analysis method is realized, a more accurate and sensitive network status monitoring and alarm mechanism is provided, and the stability and security of the network are enhanced.
[0039] Figure 1 The application scenario diagram of the network monitoring method, apparatus, device, medium and program product according to the embodiments of the present disclosure is schematically shown.
[0040] like Figure 1 As shown, the application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or optical fiber cables.
[0041] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0042] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0043] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.
[0044] It should be noted that the network monitoring method provided in the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the network monitoring device provided in the embodiment of the present disclosure can generally be set in the server 105. The network monitoring method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the network monitoring device provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0045] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0046] The following will be based on Figure 1 The scene described by Figures 2 to 7 The network monitoring method of the disclosed embodiment is described in detail.
[0047] Figure 2 The flowchart of the network monitoring method according to the embodiment of the present disclosure is schematically shown.
[0048] like Figure 2 As shown, the network monitoring method of this embodiment includes operations S210 to S240.
[0049] In operation S210, first network traffic information and second network traffic information of a network device port are acquired, where the first network traffic information represents traffic data of the port at a current moment, and the second network traffic information represents traffic data of the port at a historical moment.
[0050] For example, a real-time monitoring tool in the network system can be used to monitor multiple network devices in the network system in real time. For example, a port traffic monitoring module in the real-time monitoring tool can be used to monitor the inflow and outflow of port traffic in real time.
[0051] Network devices are hardware devices responsible for data transmission, processing, or management in a computer network, such as routers, network cards, and switches.
[0052] A port is a physical or virtual interface that connects to other devices or systems. It facilitates data communication between network devices and external devices. Examples include Ethernet ports, fiber optic interfaces, and serial ports. For example, a router or switch typically has multiple Ethernet ports.
[0053] The first network traffic information may be the network traffic situation of the network device port at the current moment, that is, at this moment.
[0054] The second network traffic information can be the traffic data of the network device port at a certain historical moment in the past. Unlike the "first network traffic information", this part of the information is not the traffic at the current moment, but data related to a known past moment.
[0055] In operation S220 , a target parameter corresponding to the current moment is acquired, where the target parameter represents the degree of influence of the network traffic data at the historical moment on the traffic data at the current moment.
[0056] For example, when calculating the weighted average of traffic data using the EMA algorithm, the EMA value corresponding to the current moment can be calculated based on the current moment's traffic data and historical network traffic data. The target parameter can be a smoothing factor in the EMA value calculation formula, i.e., the weight α of the current moment's traffic data. The historical network traffic data can be represented by 1-α.
[0057] In another embodiment, the target parameter may further include a first target parameter and a second target parameter, wherein the first target parameter represents the weight of the traffic data at the current moment, and the second target parameter represents the weight of the traffic data at the historical moment.
[0058] In operation S230 , a weighted average value corresponding to the traffic data of the port at the current moment is determined according to the first network traffic information, the second network traffic information, and the target parameter.
[0059] Exemplarily, the weighted average value corresponding to the traffic data of the port at the current moment can be calculated according to the following calculation formula.
[0060]
[0061] Among them, EMA t is the EMA value at the current time t, EMA t-1 is the EMA value at the historical moment t-1, X tis the traffic data at the current time t (i.e., the first network traffic information), α is the smoothing factor (i.e., the target parameter), and α takes a value between 0 and 1.
[0062] The larger the value of the target parameter α, the greater the weight of the new data.
[0063] In operation S240 , prompt information is generated according to the first network traffic information and the weighted average value.
[0064] For example, changes in EMA values can be used to assess network health. A rapid increase or decrease in the EMA value of traffic data may indicate a network anomaly requiring prompt action. For example, a sudden increase or decrease in the current EMA value compared to the previous value could indicate a network anomaly (e.g., an attack, a large influx of data, or a network failure). Based on EMA fluctuations, the system can generate timely alerts, notifying administrators to address the situation.
[0065] For example, traffic anomalies can be identified by comparing the deviation between the current EMA value and the current traffic value. Any deviation exceeding a set threshold is considered an anomaly (e.g., an attack, a large influx of data, a network failure, etc.). The system can then generate a timely alert and notify the administrator to address the issue.
[0066] It can be understood that by dynamically updating the target parameters in the weighted average algorithm based on historical traffic data within a historical period, and then analyzing network traffic changes in real time based on the dynamic target parameters, an adaptive traffic analysis method is implemented, providing a more accurate and sensitive network status monitoring and alarm mechanism, and enhancing network stability and security.
[0067] Figure 3 The flowchart of the method for determining target parameters according to an embodiment of the present disclosure is schematically shown.
[0068] As described above, in operation S220, the target parameters corresponding to the current moment are obtained. In one possible implementation, Figure 3 As shown, the operation may further include operations S221 to S223.
[0069] In operation S221 , historical network traffic information of a network device port at multiple historical moments within a historical period is obtained.
[0070] In operation S222 , a first intermediate value is determined based on the historical network traffic information, where the first intermediate value represents a variance of the historical network traffic information.
[0071] In operation S223 , a target parameter is determined based on the first intermediate value.
[0072] Exemplarily, the target parameter (smoothing factor) can be calculated based on network traffic information at multiple historical moments (historical network traffic information). For example, the historical period can be set to the traffic data per minute within 10 minutes before the current moment. If the current moment is 10:00, the historical period can be the traffic data per minute between 9:50 and 10:00. For example, traffic data at 9:50, traffic data at 9:51, traffic data at 9:52, etc. Traffic data at ten historical moments is obtained as historical network traffic information. Whenever the current moment changes, the multiple historical moments can change based on the change in the current moment. For example, if the current moment is 10:10, the historical period can be the traffic data per minute between 10:00 and 10:10, for example, traffic data at 10:00, traffic data at 10:01, traffic data at 10:02, etc.
[0073] The variance of the historical network traffic information in the historical period is calculated based on the port traffic data at multiple historical moments obtained in the historical period to obtain a first intermediate value.
[0074] The target parameters are calculated according to the following formula:
[0075]
[0076] Among them, α t is the target parameter at the current time t, μ is the first adjustment coefficient, They represent the traffic data of multiple historical moments with a time interval of k before the current moment t, and Var represents the variance.
[0077] The first adjustment coefficient μ can be adjusted according to the actual working conditions of the network system. For example, the first adjustment coefficient μ can be 3 or 2.
[0078] It should be noted that the embodiments of the present disclosure do not impose specific restrictions on the historical period, the number and interval of historical moments (for example, historical moments are taken at intervals of 1 minute), and the setting of the first adjustment coefficient, and can be set according to the actual application scenario of the network system.
[0079] As you can understand, target parameters change as the current moment changes. By analyzing network traffic changes in real time, target parameters are dynamically updated. This enables an adaptive traffic analysis method, providing more accurate and sensitive network status monitoring and alerting mechanisms, and enhancing network stability and security.
[0080] Figure 4 The figure schematically shows a flow chart of judgment based on the second network traffic information and the weighted average value according to an embodiment of the present disclosure.
[0081] As described above, in operation S240, prompt information is generated based on the second network traffic information and the weighted average value. Figure 4 As shown, the operation may further include operations S241 to S245.
[0082] In operation S241 , a fluctuation value is determined according to the second network traffic information and the weighted average value.
[0083] In operation S242 , a target threshold corresponding to the current moment is acquired.
[0084] In operation S243 , it is determined whether the fluctuation value is greater than a target threshold.
[0085] In operation S244 , when the fluctuation value is greater than the target threshold, a warning prompt is generated.
[0086] In operation S245 , when the fluctuation value is less than the target threshold, traffic is allocated to the multiple running services in sequence according to their priorities.
[0087] Exemplarily, the difference between the network traffic information (first network traffic information) at the current moment and the EMA value (weighted average) is calculated to obtain the fluctuation value. Obtain the target threshold corresponding to the current moment. The target threshold is continuously updated with changes in time, and the target threshold at different moments may be different. Compare the calculated fluctuation values of each port with the target threshold. When the fluctuation value of the first port is greater than the target threshold, it can be considered that the traffic of the first port at the current moment is abnormal, and an early warning can be formed to notify the management personnel to deal with it in time. In the case that the fluctuation value of the first port is continuously less than the target threshold for multiple moments, it means that the traffic of the first port is gradually decreasing, and traffic can be allocated to multiple running services in turn according to the priority of the multiple running services currently running on the network device. The allocation of traffic to multiple running services in turn according to priority can be specifically described as follows. Figure 6 The description is not repeated here.
[0088] Figure 5 The flowchart of the method for determining the target threshold according to an embodiment of the present disclosure is schematically shown.
[0089] As described above, in operation S242, prompt information is generated based on the second network traffic information and the weighted average value. In one possible implementation, Figure 5 As shown, the operation may further include operations S2421 to S2423.
[0090] In operation S2421 , historical network traffic information of a network device port at multiple historical moments within a historical period is obtained.
[0091] In operation S2422 , a second intermediate value and a third intermediate value are determined based on the historical network traffic information, where the second intermediate value represents a standard deviation of the historical network traffic information, and the third intermediate value represents an average value of the historical network traffic information.
[0092] In operation S2423, a target threshold is determined based on the second intermediate value and the third intermediate value.
[0093] For example, the target threshold value can be calculated based on network traffic information at multiple historical moments (historical network traffic information). For example, the historical period can be the same as the historical period set by the target parameter.
[0094] According to the port traffic data at multiple historical moments obtained in the historical period, an average value of the historical network traffic information in the historical period is calculated to obtain a second intermediate value (X0).
[0095] Based on the port traffic data at multiple historical moments obtained within the historical period, the standard deviation of the historical network traffic information within the historical period is calculated to obtain a third median value (σ).
[0096] The target parameters are calculated according to the following formula:
[0097]
[0098] Where T is the target threshold at the current time t, X0 represents the average value of the flow data of multiple historical moments with a time interval of k before the current time t, β represents the second adjustment coefficient, and σ represents the standard deviation of the flow data of multiple historical moments with a time interval of k before the current time t.
[0099] The first adjustment coefficient β can be adjusted based on the actual operating conditions of the network system. For example, the first adjustment coefficient β can be 5 or 2. A larger β makes the target threshold more lenient, allowing for larger fluctuations; a smaller β makes the threshold more stringent, making it more sensitive to smaller fluctuations. By adjusting β, the sensitivity of traffic anomaly detection can be controlled.
[0100] As you can understand, the target threshold changes as the current time changes. By analyzing network traffic changes in real time, the target threshold is dynamically updated. This enables an adaptive traffic analysis method, providing more accurate and sensitive network status monitoring and alerting mechanisms, and enhancing network stability and security.
[0101] Figure 6 The flowchart of a network monitoring method according to another embodiment of the present disclosure is schematically shown.
[0102] As mentioned above, the network monitoring method, such as Figure 6 As shown, the method may further include operations S310 to S350.
[0103] In operation S310 , it is determined whether the fluctuation value is greater than a target threshold.
[0104] In operation S320 , when the fluctuation value is less than the target threshold, identification information of multiple running services in the network device is obtained.
[0105] In operation S330 , priorities corresponding to the plurality of running services are generated according to the identification information.
[0106] In operation S340 , traffic is allocated to the multiple running services in sequence according to the priority of the multiple running services from low to high.
[0107] In operation S350 , when the fluctuation value is greater than the target threshold, traffic is allocated to the multiple running services in descending order of priority.
[0108] Exemplarily, for example, the protocol information of each running service can be obtained as identification information. When the identification information of the running service is a voice protocol, it is set to the first priority; when the identification information of the running service is a video protocol, it is set to the second priority; when the identification information of the running service is a data protocol (for example, file download, web browsing, etc.), it is set to the third priority. The first priority is greater than the second priority, which is greater than the third priority. In other embodiments, the priority can also be set according to the size of the traffic consumed by the running service. When the traffic consumed by the running service is greater than 2G, it is set to the first priority. When the traffic consumed by the running service is less than 2G, it is set to the second priority. The first priority is greater than the second priority. The embodiment of the present disclosure does not specifically limit the setting of the priority, and it can be set according to the actual application situation.
[0109] The difference between the current network traffic information (second network traffic information) of the first port and the EMA value (weighted average) is calculated to obtain the fluctuation value. If the fluctuation value of the first port is consistently below the target threshold, it indicates that the traffic on the first port is gradually decreasing and showing a downward trend. This indicates that the current traffic is low and the system may have idle resources. At this time, the identification information of multiple running services on the network device is obtained. The priority of each running service is determined. If the fluctuation value of the first port is consistently below the target threshold, a check is performed to determine whether there is a backlog of low-priority requests. An attempt is made to process some low-priority tasks when traffic decreases. This ensures that the system can efficiently process backlogged low-priority requests even when traffic is low, ensuring efficient system operation.
[0110] If the fluctuation value of the first port remains above the target threshold, it indicates that the traffic on the first port is gradually increasing. This indicates that the current traffic is high and the system may be overloaded. In this case, the identification information of multiple currently running services on the network device is obtained. The priority of each running service is determined.
[0111] Traffic is allocated based on priority, ensuring that high-priority services receive more or better network resources (e.g., traffic). When network resources are limited or fluctuating, the system allocates bandwidth based on a predetermined priority order. High-priority services are allocated more bandwidth first, followed by lower-priority services with the remaining resources. Critical or high-priority requests are prioritized, while lower-priority requests are deferred or delayed to avoid system crashes.
[0112] In some embodiments, when the first business traffic allocated to the first operating business is greater than the second business traffic consumed by the first operating business at the current moment, the remaining traffic is allocated to the second operating business. The remaining traffic represents the difference between the first business traffic and the second business traffic. The priority of the first operating business is greater than the priority of the second operating business.
[0113] For example, the first service traffic may refer to the traffic allocated to the first running service. This can be understood as the traffic allocated by the system to the first service. The second service traffic may refer to the traffic actually consumed by the first running service at the current moment. The remaining traffic may be the difference between the first service traffic and the second service traffic at the current moment, i.e., the portion of the allocated traffic not consumed by the first running service.
[0114] Excess traffic from the primary service will be reallocated to the secondary service to help it meet its shortfall. The primary service has higher priority in resource allocation. If a conflict or resource shortage occurs, the system prioritizes the primary service. In this case, even if excess traffic is allocated to the secondary service, if any traffic contention occurs, the primary service will receive priority resources, ensuring its services remain unaffected.
[0115] It is understandable that by distributing the remaining traffic at multiple levels, the system can ensure that the traffic needs of important businesses are met first under multi-task or multi-business loads, avoiding traffic waste. At the same time, it can also reasonably allocate resources to optimize the performance of the overall network or system.
[0116] Figure 7 The flowchart of the method for determining the weighted average value according to an embodiment of the present disclosure is schematically shown.
[0117] As described above, in operation S230, a weighted average value corresponding to the traffic data of the port at the current moment is determined based on the first network traffic information, the second network traffic information and the target parameter. Figure 7 As shown, the operation may further include operations S231 to S233.
[0118] In operation S231 , a first comprehensive value is determined based on the target parameter and the first network traffic information.
[0119] In operation S232 , a second comprehensive value is determined based on the target parameter and the second network traffic information.
[0120] In operation S233, a weighted average value is determined based on the first integrated value and the second integrated value.
[0121] For example, the weighted average is calculated as follows:
[0122]
[0123] Among them, EMA t is the EMA value at the current time t, EMA t-1 is the EMA value at the historical moment t-1, X t is the traffic data at the current time t (i.e., the first network traffic information), α is the smoothing factor (i.e., the target parameter), and α takes a value between 0 and 1.
[0124] According to the product between the target parameter α and the first network traffic information at the current moment, the first comprehensive value α*X is obtained. t According to the target parameter α and the weighted average of historical moments (EMA t-1 ) to obtain the first comprehensive value, namely (1-α)*X t , add the first comprehensive value and the second comprehensive value to get the EMA value at the current time t, that is, EMA t .
[0125] Based on the above network monitoring method, the present disclosure also provides a network monitoring device. Figure 8 The device is described in detail.
[0126] Figure 8 The structural block diagram of the network monitoring device according to an embodiment of the present disclosure is schematically shown.
[0127] like Figure 8 As shown, the network monitoring device 400 of this embodiment includes a first acquisition module 410 , a second acquisition module 420 , a determination module 430 and a generation module 440 .
[0128] The first acquisition module 410 is configured to acquire first network traffic information and second network traffic information of a network device port, wherein the first network traffic information represents traffic data of the port at the current moment, and the second network traffic information represents traffic data of the port at a historical moment. In one embodiment, the first acquisition module 410 may be configured to perform operation S210 described above, which will not be further described herein.
[0129] The second acquisition module 420 is used to obtain a target parameter corresponding to the current moment, where the target parameter represents the degree of influence of network traffic data at a historical moment on traffic data at the current moment. In one embodiment, the second acquisition module 420 can be used to perform the operation S220 described above, which will not be repeated here.
[0130] The determination module 430 is used to determine the weighted average value corresponding to the traffic data of the port at the current moment based on the first network traffic information, the second network traffic information and the target parameter. In one embodiment, the determination module 430 can be used to perform the operation S230 described above, which will not be repeated here.
[0131] The generating module 440 is used to generate prompt information according to the first network traffic information and the weighted average value. In one embodiment, the generating module 440 can be used to perform the operation S240 described above, which will not be described in detail here.
[0132] According to embodiments of the present disclosure, any multiple modules among the first acquisition module 410, the second acquisition module 420, the determination module 430, and the generation module 440 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the first acquisition module 410, the second acquisition module 420, the determination module 430, and the generation module 440 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of the three implementation methods of software, hardware, and firmware, or any appropriate combination of any of these. Alternatively, at least one of the first acquisition module 410 , the second acquisition module 420 , the determination module 430 and the generation module 440 may be at least partially implemented as a computer program module, which may perform corresponding functions when executed.
[0133] Figure 9 A block diagram of an electronic device suitable for implementing a network monitoring method according to an embodiment of the present disclosure is schematically shown.
[0134] like Figure 9 As shown, the electronic device 500 according to an embodiment of the present disclosure includes a processor 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage unit 508 into a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiment of the present disclosure.
[0135] Various programs and data required for the operation of the electronic device 500 are stored in the RAM 503. The processor 501, ROM 502, and RAM 503 are connected to each other via a bus 504. The processor 501 executes the various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 502 and / or RAM 503. It should be noted that the programs may also be stored in one or more memories other than the ROM 502 and RAM 503. The processor 501 may also execute the various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in one or more memories.
[0136] According to an embodiment of the present disclosure, electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to bus 504. Electronic device 500 may also include one or more of the following components connected to I / O interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 508 including a hard disk; and a communication section 509 including a network interface card such as a LAN card or modem. Communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to I / O interface 505 as needed. Removable media 511, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 510 as needed, so that computer programs read from the removable media can be installed into storage section 508 as needed.
[0137] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.
[0138] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include the ROM 502 and / or RAM 503 described above, and / or one or more memories other than ROM 502 and RAM 503.
[0139] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to enable the computer system to implement the network monitoring method provided by the embodiments of the present disclosure.
[0140] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the computer program is executed by the processor 501. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0141] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 509, and / or installed from a removable medium 511. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0142] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 509, and / or installed from a removable medium 511. When the computer program is executed by the processor 501, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.
[0143] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).
[0144] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0145] Those skilled in the art will appreciate that the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present disclosure. In particular, the features described in the various embodiments of the present disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of the present disclosure. All such combinations and / or couplings fall within the scope of the present disclosure.
[0146] The above describes the embodiments of the present disclosure. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. A network monitoring method, characterized in that: The method comprises: Acquire first network traffic information and second network traffic information of a port of a network device, wherein the first network traffic information represents traffic data of the port at a current moment, and the second network traffic information represents traffic data of the port at a historical moment; Obtaining a target parameter corresponding to the current moment, the target parameter representing the degree of influence of network traffic data at a historical moment on traffic data at the current moment; Determining a weighted average value corresponding to the traffic data of the port at a current moment according to the first network traffic information, the second network traffic information and the target parameter; generating prompt information according to the first network traffic information and the weighted average value; Among them, the method also includes: determining a fluctuation value based on the first network traffic information and the weighted average value, and when the fluctuation value is less than the target threshold, obtaining identification information of multiple running services in the network device; generating priorities corresponding to the multiple running services respectively based on the identification information; and allocating traffic to the multiple running services in order from low to high priority of the multiple running services.
2. The method according to claim 1, characterized in that The acquiring of the target parameter corresponding to the current moment includes: Obtain historical network traffic information of network device ports at multiple historical moments within a historical period; Determining a first intermediate value based on the historical network traffic information, where the first intermediate value represents a variance of the historical network traffic information; The target parameter is determined according to the first intermediate value.
3. The method according to claim 1, characterized in that The generating of prompt information according to the second network traffic information and the weighted average value includes: Obtaining a target threshold corresponding to the current moment; When the fluctuation value is greater than the target threshold, an early warning prompt is generated.
4. The method according to claim 3, characterized in that The acquiring of the target threshold corresponding to the current moment includes: Obtain historical network traffic information of network device ports at multiple historical moments within a historical period; Determining a second intermediate value and a third intermediate value based on the historical network traffic information, wherein the second intermediate value represents a standard deviation of the historical network traffic information, and the third intermediate value represents an average value of the historical network traffic information; The target threshold is determined according to the second intermediate value and the third intermediate value.
5. The method according to claim 1, wherein The method further comprises: When the fluctuation value is greater than the target threshold, traffic is allocated to the multiple running services in descending order of priority of the multiple running services.
6. The method according to claim 5, characterized in that When the first service traffic allocated to the first operating service is greater than the second service traffic consumed by the first operating service at the current moment, the remaining traffic is allocated to the second operating service. The remaining traffic represents the difference between the first service traffic and the second service traffic. The priority of the first operating service is greater than the priority of the second operating service.
7. The method according to claim 1, characterized in that Determining a weighted average value corresponding to the traffic data of the port at the current moment based on the first network traffic information, the second network traffic information, and the target parameter includes: determining a first comprehensive value according to the target parameter and the first network traffic information; determining a second comprehensive value according to the target parameter and the second network traffic information; The weighted average value is determined according to the first comprehensive value and the second comprehensive value.
8. A network monitoring device, characterized in that: The device comprises: A first acquisition module is configured to acquire first network traffic information and second network traffic information of a port of a network device, wherein the first network traffic information represents traffic data of the port at a current moment, and the second network traffic information represents traffic data of the port at a historical moment; A second acquisition module is used to acquire a target parameter corresponding to the current moment, wherein the target parameter represents the degree of influence of network traffic data at a historical moment on traffic data at the current moment; a determining module, configured to determine a weighted average value corresponding to the traffic data of the port at a current moment based on the first network traffic information, the second network traffic information, and the target parameter; and a generating module, configured to generate prompt information according to the first network traffic information and the weighted average value; The device is further used to: determine a fluctuation value based on the first network traffic information and the weighted average value, and when the fluctuation value is less than a target threshold, obtain identification information of multiple running services in the network device; generate priorities corresponding to the multiple running services respectively based on the identification information; and allocate traffic to the multiple running services in order from low to high priority of the multiple running services.
9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
11. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Method and device for real-time flux prediction and real-time flux monitoring and early warning
CN101155085A
Network traffic monitoring method and device, equipment and storage medium
CN117221154A