A method and device for analyzing traffic of active PCDN users based on Flink

By combining operator call detail record data and the Flink engine with Netflow data analysis to assess PCDN user activity, this approach solves the accuracy problem in identifying PCDN violators in traditional methods, achieving more efficient user screening and protection of business interests.

CN119697072BActive Publication Date: 2025-11-25CHINA UNITECHS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411476372.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-22
Publication Date
2025-11-25
Estimated Expiration
2044-10-22

AI Technical Summary

Technical Problem

Existing technologies are insufficient to accurately identify PCDN users who violate regulations, leading to difficulties in tracing traffic and impacting operators' commercial interests. Traditional judgment methods also contain numerous errors.

Method used

Suspected PCDN users are initially screened using operator call detail records (CDRs). Activity analysis is then performed using the Flink computing engine and Netflow data to calculate the activity level of PCDN users and output an inverted list of activity levels, thereby improving the accuracy of the judgment.

Benefits of technology

It improves the accuracy and precision of PCDN users' judgments, reduces misjudgments, provides freedom for multi-dimensional analysis, and has good scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119697072B_ABST
    Figure CN119697072B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on Flink's active PCDN user's traffic analysis method and device, wherein, the method comprises: from the aaa phone bill data provided by operator, the user list meeting PCDN feature and PCDN platform domain name is filtered, and PCDN illegal user list is obtained;Flink computing engine loads the PCDN illegal user list, is matched based on user access ip and port with the Netflow traffic data of access, then carries out flow light summary, obtains the Netflow traffic data associated with PCDN illegal user;Select the Netflow traffic data associated with PCDN illegal user in the PCDN illegal user on-line time range of PCDN illegal user and carry out the analysis of activity degree, calculate the active proportion of Flow in the PCDN illegal user on-line time range, obtain the activity degree of the PCDN illegal user, finally output the PCDN illegal user list of activity degree reverse order.The method and device discover suspected PCDN user, according to activity degree sorting, so as to subsequent operation, reduce the burden of traffic settlement, and increase the income of broadband service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of PCDN violation user analysis, and in particular to a method and apparatus for analyzing the traffic of active PCDN users based on Flink. Background Technology

[0002] PCDN (Personal Content Delivery Network) users are individuals or organizations that participate in a PCDN network, typically by sharing their idle bandwidth, storage space, and computing resources to help distribute network content. PCDN is a decentralized content delivery network model; unlike traditional CDNs, PCDN relies on ordinary user devices distributed globally, rather than dedicated data centers or servers.

[0003] In simple terms, PCDN users are those who use their operator's broadband accounts to provide internet access to others. This can lead to errors in the operator's traffic billing and compete with the operator's existing traditional CDN (broadband) services. Because PCDN has advantages such as lower costs and wider coverage, it may impact the operator's CDN revenue. Although PCDN may reduce some of the operator's content distribution costs, its profit model remains unclear. Because it relies on user devices for content distribution, operators cannot directly obtain revenue from each node, thus affecting their commercial interests. Overall, this will lead to a decrease in the operator's customers, as customers use PCDN services provided by others instead of the operator's traditional CDN services, making it difficult to trace traffic and charge these PCDN users.

[0004] Current technical solutions mostly identify PCDN violators from the perspective of the PCDN domain platform, the ratio of upstream to downstream traffic, or the upstream traffic threshold. However, in actual investigations, it has been found that simply meeting these conditions is not enough to determine whether someone is a PCDN violator. Many errors have been found in actual investigations. Therefore, it is necessary to further compare the activity of a large number of suspected users from the perspective of real-time traffic. Finally, the degree of suspicion of an account should be judged based on the activity level. This approach is more effective and accurate. Summary of the Invention

[0005] To address the aforementioned problems with current technical solutions, this invention provides a Flink-based method and apparatus for analyzing the traffic of active PCDN users. It initially identifies users with abnormal traffic based on call detail record (CDR) data (which operators have statistical data on). Then, it combines real-time Netflow data to perform traffic analysis on active PCDN users. The user with the highest overall activity level is identified as a PCDN violator. Operators then take further action against these violators based on the PCDN violator list.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] In one embodiment of the present invention, a traffic analysis method for active PCDN users based on Flink is proposed, the method comprising:

[0008] From the AAA call detail records provided by the operators, a list of users who match the characteristics of PCDN and the PCDN platform domain name is obtained, thus creating a list of PCDN violators.

[0009] The Flink computing engine loads the list of PCDN violators, matches the user's access IP and port with the accessed Netflow traffic data, and then performs a light traffic aggregation to obtain the Netflow traffic data associated with the PCDN violators.

[0010] The activity level of Netflow traffic associated with PCDN violators within the time range of their online / offline activity is analyzed. The active percentage of Flow within the time range of the PCDN violator's online / offline activity is calculated to obtain the activity level of the PCDN violator. Finally, a list of PCDN violators in descending order of activity level is output.

[0011] Furthermore, PCDN is characterized by: uplink traffic greater than 50GB and uplink / downlink traffic ratio greater than 2.

[0012] Furthermore, the activity level of PCDN users who violate regulations is calculated as follows:

[0013] Summarize Netflow traffic data associated with PCDN users who violated regulations by different time points;

[0014] The online / offline times of PCDN violators are selected and associated with the Netflow traffic data of PCDN violators. The Netflow traffic data associated with PCDN violators within the online / offline time range of PCDN violators is retained.

[0015] Calculate the average upload rate of user AAA, the average upload rate of Flow at each time point, and the total number of time points between online and offline times.

[0016] Compare the average upload rate of Flow at each time point with the average upload rate of user aaa. If the average upload rate of Flow at a certain time point is greater than the average upload rate of user aaa, then the status at that time point is recorded as active. Divide the number of active time points by the total number of time points between online and offline time points to obtain the activity level of the PCDN violator.

[0017] In one embodiment of the present invention, a traffic analysis device for active PCDN users based on Flink is also proposed, the device comprising:

[0018] The preliminary screening module for call detail record (CDR) data is used to filter the list of users that match the characteristics of PCDN and the PCDN platform domain name from the AAA CDR data provided by the operator, thereby obtaining a list of PCDN violators.

[0019] The Flink-Netflow integration module is used by the Flink computing engine to access Netflow traffic data. It matches the user's access IP and port with the loaded PCDN violation user list, and then performs a light traffic aggregation to obtain the Netflow traffic data associated with the PCDN violation users.

[0020] The Flink activity calculation module is used to select Netflow traffic data associated with PCDN violators within the time range of their online / offline time to analyze their activity. It calculates the percentage of active Flow within the time range of the PCDN violator's online / offline time, obtains the activity level of the PCDN violator, and finally outputs a list of PCDN violators in reverse order of activity level.

[0021] Furthermore, PCDN is characterized by: uplink traffic greater than 50GB and uplink / downlink traffic ratio greater than 2.

[0022] Furthermore, the activity level of PCDN users who violate regulations is calculated as follows:

[0023] Summarize Netflow traffic data associated with PCDN users who violated regulations by different time points;

[0024] The online / offline times of PCDN violators are selected and associated with the Netflow traffic data of PCDN violators. The Netflow traffic data associated with PCDN violators within the online / offline time range of PCDN violators is retained.

[0025] Calculate the average upload rate of user AAA, the average upload rate of Flow at each time point, and the total number of time points between online and offline times.

[0026] Compare the average upload rate of Flow at each time point with the average upload rate of user aaa. If the average upload rate of Flow at a certain time point is greater than the average upload rate of user aaa, then the status at that time point is recorded as active. Divide the number of active time points by the total number of time points between online and offline time points to obtain the activity level of the PCDN violator.

[0027] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it designs the aforementioned traffic analysis method for active PCDN users based on Flink.

[0028] In one embodiment of the present invention, a computer-readable storage medium is also provided, which stores a computer program that executes a Flink-based traffic analysis method for active PCDN users.

[0029] Beneficial effects:

[0030] 1. This invention mainly combines the traditional method of judging PCDN users with the Flink computing engine. It combines the analysis results of the original call detail record data with network traffic to analyze activity, and screens PCDN users from multiple dimensions. It removes the data that meets the characteristics of PCDN but is not actually a PCDN user, thereby improving the accuracy of judging PCDN users.

[0031] 2. This invention provides a new solution. Previously, users could only check hundreds of thousands of suspected PCDN violators every day. However, with these different dimensions of analysis, users can arbitrarily filter PCDN users with high scores in a certain dimension or several dimensions for screening, providing a certain degree of freedom while maintaining accuracy.

[0032] 3. This invention uses the Flink computing engine for dimensional analysis, which has good scalability. If more dimensions need to be analyzed in the future, only the configuration needs to be changed, demonstrating good scalability. Attached Figure Description

[0033] Figure 1 This is a schematic diagram of a traffic analysis method for active PCDN users based on Flink according to an embodiment of the present invention;

[0034] Figure 2 This is a trend chart of average flow changes for selected PCDN users whose online time is 20:00 and offline time is 22:15, according to an embodiment of the present invention.

[0035] Figure 3This is a list of time points in an embodiment of the present invention where the average uplink rate of Flow is greater than the average uplink rate of aaa users after the PCDN user's online time of 20:00.

[0036] Figure 4 This is a schematic diagram of the traffic analysis device for active PCDN users based on Flink according to the present invention.

[0037] Figure 5 This is a schematic diagram of the computer device structure of the present invention. Detailed Implementation

[0038] The principles and spirit of the present invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and design the present invention, and are not intended to limit the scope of the invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of the disclosure to those skilled in the art.

[0039] Those skilled in the art will recognize that embodiments of the present invention can be designed as an apparatus, device, device, method, or computer program product. Therefore, this disclosure can be specifically designed as: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0040] According to an embodiment of the present invention, a traffic analysis method for active PCDN users based on Flink is proposed. Since the scale of PCDN user data after initial screening is too large, at least 80% of PCDN users are not actually PCDN violators. Therefore, the abnormal traffic users are first identified through preliminary analysis using AAA call detail record data (which the operator has statistical data for). Then, the traffic analysis of active PCDN users is performed by combining real-time Netflow traffic data. The user with the highest overall activity level is identified as a PCDN violator. The operator then performs subsequent operations on the user account based on the list of PCDN violators.

[0041] The principles and spirit of the present invention will be explained in detail below with reference to several representative embodiments.

[0042] The present invention provides a Flink-based method for analyzing the traffic of active PCDN users, comprising:

[0043] 1. From the AAA call detail record (CDR) data provided by the operator, filter out the list of users who match the characteristics of PCDN and the PCDN platform domain name, i.e., the PCDN violation user list, along with specific user IP addresses, port ranges, online / offline times, and other information. PCDN platform domain names are some common websites that provide P2P services.

[0044] 2. The Flink computing engine loads the list of PCDN violators, matches the user's access IP and port with the incoming Netflow traffic data, and then performs a light aggregation of the traffic to obtain the Netflow traffic data associated with the PCDN violators, which is then stored. Light aggregation: Netflow traffic data with the same characteristics are aggregated once, typically in a 15-second rolling window, to reduce data size and improve performance.

[0045] 3. Analyze the activity of Netflow traffic data associated with PCDN violators within the time range of their online / offline time. Calculate the percentage of active Flow within the time range of the PCDN violator's online / offline time to obtain the activity level of the PCDN violator. Finally, output a list of PCDN violators in descending order of activity level. The higher the activity level, the closer the user is to the PCDN violator.

[0046] It should be noted that although the operation of the method of the present invention has been described in a specific order in the above embodiments and figures, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0047] To provide a clearer explanation of the above-described method for analyzing the traffic of active PCDN users based on Flink, a specific embodiment will be used for illustration below. However, it is worth noting that this embodiment is only for better illustrating the present invention and does not constitute an improper limitation of the present invention.

[0048] Example:

[0049] like Figure 1 As shown, the activity level of PCDN user traffic is analyzed by cross-analyzing the results of Flink access to Netflow traffic data and collected AAA call detail record (CDR) data. The specific implementation steps are as follows:

[0050] 1. Analyze the accessed AAA call detail record (CDR) data to initially identify and store a list of users that match the characteristics of PCDN.

[0051] Example of AAA call detail record data is as follows:

[0052] user1272635|61.178.255.117|ads-J092182278010096a8d95158669|10800|2024-07-17 21:00:02|2024-07-1800:00:02|125.75.49.181|54272|58367|100.118.41.51| 39402|0|21560|0|240e:0334:0018:069a:0000:0000:0000:0000 / 64|0|0|0|0|up date

[0053] user1828104|61.178.255.120|ads-X0821922700102274ebbf153320|10752|2024-07-17 21:00:50|2024-07-1800:00:02|118.181.161.87|25600|29695|100.71.5.105|3171262291|0|761733420|1||0|0|0|0|stop

[0054] Valid information is extracted and analyzed from AAA call detail record (CDR) data. This valid information includes user, IP address, start port, end port, event time (fields carried in AAA CDR data), session ID, uplink byte count, downlink byte count, user status, and uplink speed. PCDN characteristics are as follows: entries with uplink traffic greater than 50GB and an uplink-to-downlink traffic ratio greater than 2 are marked as suspected PCDN violation users. The filtered suspected PCDN violation users are then stored.

[0055] 2. Netflow traffic within the metropolitan area network boundary is sent to the Flink UDP data receiving port. The Flink computing engine loads the previously saved list of suspected PCDN violation users into the cache. The Flink computing engine filters the source IP, destination IP, and port that meet the criteria for PCDN violation users, establishes a 60-second rolling window, and performs a light aggregation of Netflow traffic data that meets the conditions (the source IP of the flow is equal to the IP in the AAA call detail record data, and the source IP port of the flow is within the range of that IP and port in the AAA call detail record data), and stores it in the Doris database. The stored flow information includes: source IP, destination IP, source port, destination port, protocol, number of bytes, number of packets, start time, end time, and associated PCDN user name.

[0056] 3. Remove PCDN users who are not associated with Netflow traffic data from the list. Then, associate the lightly aggregated Netflow traffic data with the information of the removed PCDN users. Group and aggregate the data according to source port, destination port, protocol and time interval. Save the aggregated information into the Doris database.

[0057] 4. Query the Doris database to analyze and filter suspected PCDN violators by PCDN platform. Common PCDN platforms include Wangxin Cloud, JD Wireless Treasure, Chaodian Cloud, Fengdong CDN, and Xingyu CDN. Based on the accessed DNS domain information, check if it belongs to the following subdomains (combining DNS domain information, which must include the domain name field; using the PCDN user's IP as the PCDN source IP to match DNS records, then obtaining the domain name of the DNS record; and using the domain name conversion mechanism to determine if it belongs to the PCDN platform domain). Subdomains: For example, if the PCDN platform domain is onethingcloud.com (Wangxin Cloud), then onethingcloud.com.cn, www.onethingcloud.com.cn, and xxx.onethingcloud.com.cn are all subdomains. When comparing domain names, they will be converted to top-level domains for matching. The conversion method is to only retain keywords for comparison, such as removing characters like http: / / , com, cn, and www. This will not be discussed in detail here, as it is not the main focus of this invention.

[0058] 5. Use the Flink computing engine in conjunction with the PCDN list of users who violated regulations to calculate Flow activity.

[0059] (1) First, obtain the lightly summarized Netflow traffic data (step 3), match the PCDN violation user list (after filtering in step 4), output all Netflow traffic data of PCDN violation users, and summarize the Netflow traffic data point by point, one point every five minutes.

[0060] (2) Take the Netflow traffic data associated with the online and offline time of PCDN violators, and only retain the Netflow traffic data within the online and offline time range of PCDN violators.

[0061] The specific database logic is as follows:

[0062] pcdn_aaa_ip_min AS(

[0063] SELECT

[0064] src_aaa_user_name,

[0065] src_address,

[0066] SECOND_CEIL(time, 300)time,

[0067] SUM(IFNULL(octets,0))octets

[0068] FROM dws_analyzer_pcdn_5_min

[0069] WHERE

[0070] src_aaa_user_name is not null

[0071]

[0072] (3) Calculate the uplink rate of the AAA call detail record data. Divide the total number of uplink bytes of the AAA data by the total session duration to obtain the average uplink rate of the AAA user.

[0073] (4) Calculate the uplink rate of the Flow. Using the summary information of Netflow traffic in (1), divide the total traffic over five minutes by the duration (300s) to obtain the average uplink rate of the Flow at each five-minute point.

[0074] (5) Calculate the duration, take the online and offline time of PCDN violators, get the number of minutes between the online and offline time, divide the number of minutes by 5 and take the integer part to get the total number of time points of activity duration.

[0075] The specific SQL logic is as follows:

[0076]

[0077]

[0078] (6) Finally, compare the average uplink rate of Flow with the average uplink rate of user aaa. If the average uplink rate of Flow is greater than the average uplink rate of user aaa (allowing an error of 10%), then the status at that time point is recorded as 1, i.e. active. Divide the number of active time points by the total number of time points to obtain the activity level of the PCDN violator.

[0079] The specific SQL processing logic is as follows:

[0080] )

[0082] (7) Select the PCDN violation user's online time as 20:00 and offline time as 22:15, for example... Figure 2 and 3 As shown:

[0083] Figure 2 The dashed line represents the average uplink speed of AAA users, which is... Figure 2 It can be seen that the PCDN user's traffic was active between 20:00 and 22:00, indicating that the PCDN user was highly likely to be providing PCDN services to others.

[0084] Based on the same inventive concept, this invention also proposes a Flink-based traffic analysis device for active PCDN users. The implementation of this device can refer to the implementation of the methods described above, and repeated details will not be repeated. The term "module" used below can refer to a combination of software and / or hardware designed with predetermined functions. Although the device described in the following embodiments is preferably designed in software, hardware designs, or combinations of software and hardware, are also possible and contemplated.

[0085] Figure 4 This is a schematic diagram of the traffic analysis device for active PCDN users based on Flink, as described in this invention. Figure 4 As shown, the device includes:

[0086] The preliminary screening module 101 for call detail record (CDR) data is used to filter the list of users that meet the PCDN characteristics and PCDN platform domain name from the AAA CDR data provided by the operator, and obtain the list of PCDN violation users; the PCDN characteristics are: uplink traffic greater than 50GB and uplink-to-downlink traffic ratio greater than 2.

[0087] The Flink Netflow access module 102 is used for the Flink computing engine to access Netflow traffic data. It matches the user's access IP and port with the loaded PCDN violation user list, and then performs a light traffic aggregation to obtain the Netflow traffic data associated with the PCDN violation users.

[0088] The Flink activity calculation module 103 is used to analyze the Netflow traffic data associated with PCDN violators within their online / offline time range, calculate the percentage of active Flow within that PCDN violator's online / offline time range, obtain the activity level of that PCDN violator, and finally output a list of PCDN violators in descending order of activity level. The calculation of the PCDN violator's activity level is as follows:

[0089] Summarize Netflow traffic data associated with PCDN users who violated regulations by different time points;

[0090] The online / offline times of PCDN violators are selected and associated with the Netflow traffic data of PCDN violators. The Netflow traffic data associated with PCDN violators within the online / offline time range of PCDN violators is retained.

[0091] Calculate the average upload rate of user AAA, the average upload rate of Flow at each time point, and the total number of time points between online and offline times.

[0092] Compare the average upload rate of Flow at each time point with the average upload rate of user aaa. If the average upload rate of Flow at a certain time point is greater than the average upload rate of user aaa, then the status at that time point is recorded as active. Divide the number of active time points by the total number of time points between online and offline time points to obtain the activity level of the PCDN violator.

[0093] It should be noted that although several modules of the Flink-based traffic analysis device for active PCDN users are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in a single module. Conversely, the features and functions of a single module described above can be further divided and embodied by multiple modules.

[0094] Based on the aforementioned inventive concept, such as Figure 5 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, it designs the aforementioned traffic analysis method for active PCDN users based on Flink.

[0095] Based on the aforementioned inventive concept, the present invention also proposes a computer-readable storage medium storing a computer program that executes the aforementioned Flink-based traffic analysis method for active PCDN users.

[0096] The traffic analysis method and apparatus for active PCDN users based on Flink proposed in this invention have the following highlights:

[0097] 1. The new technical solution of this invention mainly combines the traditional PCDN user identification with the Flink computing engine. It combines the analysis results of the original call detail record data with network traffic to analyze activity, and screens PCDN users from multiple dimensions. It removes the part of the data that meets the characteristics of PCDN but is not actually a PCDN user, thereby improving the accuracy of PCDN user identification.

[0098] 2. This invention provides a new solution. Previously, users could only check hundreds of thousands of suspected PCDN violators every day. However, with these different dimensions of analysis, users can arbitrarily filter PCDN users with high scores in a certain dimension or several dimensions for screening, providing a certain degree of freedom while maintaining accuracy.

[0099] 3. This invention uses the Flink computing engine for dimensional analysis, which has good scalability. If more dimensions need to be analyzed in the future, only the configuration needs to be changed, demonstrating good scalability.

[0100] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0101] Regarding the limitation of the scope of protection of this invention, those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solution of this invention are still within the scope of protection of this invention.

Claims

1. A method for analyzing the traffic of active PCDN users based on Flink, characterized in that, The method includes: From the AAA call detail records provided by the operators, a list of users who match the characteristics of PCDN and the PCDN platform domain name is obtained, thus creating a list of PCDN violators. The Flink computing engine loads the list of PCDN violators, matches the user's access IP and port with the accessed Netflow traffic data, and then performs a light traffic aggregation to obtain the Netflow traffic data associated with the PCDN violators. The activity of Netflow traffic data associated with PCDN violators within the time range of their online and offline activities is analyzed. The active percentage of Flow within the time range of the PCDN violators is calculated to obtain the activity level of the PCDN violators. Finally, a list of PCDN violators in descending order of activity level is output. The activity level of PCDN users who violated regulations is calculated as follows: Summarize Netflow traffic data associated with PCDN users who violated regulations by different time points; The online / offline times of PCDN violators are selected and associated with the Netflow traffic data of PCDN violators. The Netflow traffic data associated with PCDN violators within the online / offline time range of PCDN violators is retained. Calculate the average upload rate of user AAA, the average upload rate of Flow at each time point, and the total number of time points between online and offline times. Compare the average upload rate of Flow at each time point with the average upload rate of user aaa. If the average upload rate of Flow at a certain time point is greater than the average upload rate of user aaa, then the status at that time point is recorded as active. Divide the number of active time points by the total number of time points between online and offline time points to obtain the activity level of the PCDN violator.

2. The method for analyzing the traffic of active PCDN users based on Flink according to claim 1, characterized in that, The PCDN characteristics are: uplink traffic greater than 50GB and uplink / downlink traffic ratio greater than 2.

3. A traffic analysis device for active PCDN users based on Flink, characterized in that, The device includes: The preliminary screening module for call detail record (CDR) data is used to filter the list of users that match the characteristics of PCDN and the PCDN platform domain name from the AAA CDR data provided by the operator, thereby obtaining a list of PCDN violators. The Flink-Netflow integration module is used by the Flink computing engine to access Netflow traffic data. It matches the user's access IP and port with the loaded PCDN violation user list, and then performs a light traffic aggregation to obtain the Netflow traffic data associated with the PCDN violation users. The Flink activity calculation module is used to select Netflow traffic data associated with PCDN violators within the time range of their online / offline time to analyze their activity, calculate the percentage of active Flow within the time range of the PCDN violator's online / offline time, obtain the activity level of the PCDN violator, and finally output a list of PCDN violators in reverse order of activity level. The activity level of PCDN users who violated regulations is calculated as follows: Summarize Netflow traffic data associated with PCDN users who violated regulations by different time points; The online / offline times of PCDN violators are selected and associated with the Netflow traffic data of PCDN violators. The Netflow traffic data associated with PCDN violators within the online / offline time range of PCDN violators is retained. Calculate the average upload rate of user AAA, the average upload rate of Flow at each time point, and the total number of time points between online and offline times. Compare the average upload rate of Flow at each time point with the average upload rate of user aaa. If the average upload rate of Flow at a certain time point is greater than the average upload rate of user aaa, then the status at that time point is recorded as active. Divide the number of active time points by the total number of time points between online and offline time points to obtain the activity level of the PCDN violator.

4. The Flink-based traffic analysis device for active PCDN users according to claim 3, characterized in that, The PCDN characteristics are: uplink traffic greater than 50GB and uplink / downlink traffic ratio greater than 2.

5. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it designs the method according to any one of claims 1-2.

6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the method according to any one of claims 1-2.

Citation Information

Patent Citations

  • Illegal service prediction method and device, electronic equipment and readable storage medium

    CN116432805A

  • PCDN service discovery method

    CN116566853A