Real-time monitoring and early warning method and system for high-speed routing
Through the combination of multi-layer attention network and deep convolutional network, the traffic, hardware performance and routing status data of high-speed routers are analyzed, and the network behavior feature set is generated, which realizes accurate positioning of fault sources and efficient management of routing tables, solving the problem that traditional monitoring methods are difficult to identify abnormal behaviors and locate fault sources, and improving the stability and security of the network.
Patent Information
- Application Number
- CN202510262091.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
AI Technical Summary
Traditional high-speed router monitoring methods are difficult to quickly identify abnormal behaviors and accurately locate fault sources in complex and changeable network environments. They lack the ability to deeply analyze network behavior characteristics, making it difficult to deal with network attacks and security threats.
The method of combining multi-layer attention network and deep convolutional network is adopted to comprehensively collect and analyze the traffic data, hardware performance data and routing status data of high-speed network interfaces, generate network behavior feature sets, and accurately locate fault sources through correlation analysis and feature significance evaluation, and efficient management and dynamic optimization of routing tables are achieved through the two-layer Bloom Filter structure.
Real-time monitoring and early warning of high-speed routers is realized, which can quickly identify abnormal behaviors, accurately locate fault sources, improve network stability and reliability, and ensure reasonable allocation and security of network resources.
Smart Images

Figure CN119766638B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of high-speed routing, and in particular to a real-time monitoring and early warning method and system for high-speed routing. Background Art
[0002] As the scale of networks continues to expand and the complexity of services continues to increase, the performance and reliability of high-speed routers, as core equipment of network infrastructure, directly affect the operation quality of the entire network. Traditional router monitoring methods mainly rely on simple threshold detection and manual experience judgment, which is difficult to cope with complex and changing network environments and diverse fault scenarios. This monitoring method not only has a slow response speed, but is also prone to false alarms and missed alarms, which seriously affects the stability and reliability of the network.
[0003] The main challenge facing high-speed routers is how to quickly identify abnormal behaviors and accurately locate the source of faults in massive amounts of data. Due to the complex dependencies between network interfaces, the abnormality of a single interface may cause a chain reaction, resulting in an overall decline in network performance. Traditional single-point monitoring and static threshold detection methods cannot effectively capture the characteristics of such dynamic changes, and it is also difficult to track the propagation path of the fault. In addition, with the continuous evolution of network attack methods, the security threats faced by high-speed routers are also increasing. Existing monitoring systems lack the ability to deeply analyze network behavior characteristics, making it difficult to detect potential security risks in a timely manner. Summary of the invention
[0004] The present invention provides a real-time monitoring and early warning method and system for high-speed routing. The present invention constructs a fault propagation path tracing mechanism, realizes accurate fault source location, and further realizes efficient management and dynamic optimization of routing tables, ensuring reasonable allocation of network resources.
[0005] In a first aspect, the present invention provides a real-time monitoring and early warning method for high-speed routing, the real-time monitoring and early warning method for high-speed routing comprising:
[0006] Collect data from multiple high-speed network interfaces in the router to generate a multi-dimensional original data sequence for each high-speed network interface;
[0007] Performing flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence to generate a network behavior feature set for each high-speed network interface;
[0008] Input the network behavior feature set into a multi-layer attention network to perform inter-interface correlation analysis, temporal importance calculation, and feature significance evaluation, and output a target feature vector for each high-speed network interface;
[0009] Inputting the target feature vector into a network anomaly analysis model for pattern matching and threshold judgment to generate a network anomaly alarm sequence for each high-speed network interface;
[0010] Based on the network abnormality alarm sequence, time-space state correlation analysis and fault propagation path tracing are performed to output router fault location results.
[0011] In a second aspect, the present invention provides a real-time monitoring and early warning system for high-speed routing, the real-time monitoring and early warning system for high-speed routing comprising:
[0012] A collection module, used for collecting data from multiple high-speed network interfaces in the router, and generating a multi-dimensional original data sequence for each high-speed network interface;
[0013] A statistical module, used to perform flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence, and generate a network behavior feature set for each high-speed network interface;
[0014] An analysis module, used for inputting the network behavior feature set into a multi-layer attention network to perform inter-interface correlation analysis, temporal importance calculation and feature significance evaluation, and outputting a target feature vector for each high-speed network interface;
[0015] A judgment module, used for inputting the target feature vector into a network anomaly analysis model for pattern matching and threshold judgment, and generating a network anomaly alarm sequence for each high-speed network interface;
[0016] The output module is used to perform spatiotemporal state correlation analysis and fault propagation path tracing based on the network abnormality alarm sequence, and output router fault location results.
[0017] The third aspect of the present invention provides a computer device, comprising: a memory and at least one processor, wherein the memory stores instructions; the at least one processor calls the instructions in the memory so that the computer device executes the above-mentioned real-time monitoring and early warning method for high-speed routing.
[0018] A fourth aspect of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, which, when executed on a computer, enable the computer to execute the above-mentioned real-time monitoring and early warning method for high-speed routing.
[0019] In the technical solution provided by the present invention, the flow data, hardware performance data and routing status data of the high-speed network interface are collected in an all-round way, and a standardized multi-dimensional raw data sequence is constructed through time alignment and normalization processing. Fourier transform and wavelet decomposition are used for time-frequency domain analysis, and a comprehensive network behavior feature set is constructed by combining traffic fluctuation statistics and protocol feature analysis. A three-layer attention network architecture is adopted, including spatial attention, temporal attention and cross attention, to realize correlation analysis and feature fusion between interfaces. Combined with deep convolutional networks and residual modules, accurate abnormal behavior identification is achieved through multi-level feature extraction and pattern matching. Based on spatiotemporal state correlation analysis and graph neural networks, a fault propagation path tracking mechanism is constructed to achieve accurate fault source location. A double-layer Bloom Filter structure is adopted to realize efficient management and dynamic optimization of routing tables and ensure the rational allocation of network resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0021] Figure 1 A schematic diagram of the steps of a real-time monitoring and early warning method for high-speed routing in an embodiment of the present invention;
[0022] Figure 2 It is a structural diagram of a real-time monitoring and early warning system for high-speed routing in an embodiment of the present invention;
[0023] Figure 3 It is a schematic block diagram of the structure of a computer device in an embodiment of the present invention. DETAILED DESCRIPTION
[0024] Embodiments of the present invention provide a method and system for real-time monitoring and early warning of high-speed routing. The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" or "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0025] For ease of understanding, the specific process of the embodiment of the present invention is described below. Figure 1 , an embodiment of the real-time monitoring and early warning method of high-speed routing in the embodiment of the present invention includes:
[0026] Step S1, collecting data from multiple high-speed network interfaces in a router to generate a multi-dimensional original data sequence for each high-speed network interface;
[0027] It is understandable that the execution subject of the present invention may be a real-time monitoring and early warning system for high-speed routing, or a terminal or a server, which is not specifically limited here. The embodiment of the present invention is described by taking a server as the execution subject as an example.
[0028] Specifically, the traffic data of each high-speed network interface is periodically sampled to obtain the data packet traffic sequence at the interface level. During the sampling process, the data packet traffic sequence collected from each interface is statistically classified by protocol to obtain the proportion of different protocol types in the network traffic. At the same time, the size of the data packet is analyzed to obtain detailed information on the traffic distribution. These data analysis results are combined to obtain the interface-level traffic feature data, which describes the traffic characteristics of each network interface, including the composition of the protocol and the specific size distribution of the traffic. The hardware performance data of each high-speed network interface is monitored in real time. The CPU occupancy rate and memory usage rate involved in each interface are monitored to evaluate the usage of the hardware resources of the device where the interface is located. High CPU occupancy rate and memory usage rate are often signs of high device load, indicating bottlenecks or hidden dangers in network operation. The routing status of each high-speed network interface is periodically scanned. The number of routing table entries and the update frequency of the routing table of each interface are monitored. The number of entries in the routing table can reflect the routing complexity in the current network, while the update frequency reveals the dynamic changes in the network topology. Frequent updates will have a certain impact on the stability of the network. The interface-level traffic feature data, interface-level hardware performance data, and interface-level routing status data are time-aligned to construct an interface-level multidimensional data set. The interface-level multidimensional data set is normalized to eliminate the dimensional differences between different features and avoid improper amplification or reduction of certain features in the calculation due to dimensional differences. The standardized interface data is sampled by sliding through a preset time window to extract the timing feature data of the interface. Continuous data segments are divided into multiple overlapping time windows at certain time intervals, each containing data within a period of time. In each time window, the change characteristics of the network interface during this period are extracted. These timing feature data help capture the dynamic changes in network behavior, thereby better understanding the operation of the interface. Based on the timing feature data, a multidimensional raw data sequence for each high-speed network interface is constructed.
[0029] Step S2, performing flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence to generate a network behavior feature set for each high-speed network interface;
[0030] Specifically, the multi-dimensional raw data sequence of each high-speed network interface is segmented to obtain the interface traffic sequence. Fourier transform is performed on the interface traffic sequence to convert the original time domain signal into a frequency domain data matrix. Fourier transform can effectively reveal the periodic changes and spectral characteristics in the traffic data. This information is helpful to analyze the regularity and potential periodic behavior of network traffic and generate the frequency domain data matrix of each high-speed network interface. Time-frequency analysis and feature combination are performed on the frequency domain data matrix to obtain the multi-scale traffic characteristics of each high-speed network interface. Time-frequency analysis reveals the change pattern of traffic at different time scales. By combining features at multiple scales, the dynamic behavior and change trend of traffic can be fully described. In order to simplify the model calculation and improve the effectiveness of the features, nonlinear dimensionality reduction is performed on the multi-scale traffic features to obtain the compressed feature vector of each high-speed network interface. Through the dimensionality reduction operation, the most representative traffic features are retained, the dimension of the data is reduced, and the important information describing the traffic behavior is retained. The traffic fluctuation statistics of each high-speed network interface are calculated based on the compressed feature vector to better quantify the fluctuation of traffic. On this basis, five-point smoothing filtering and inflection point detection are applied to the traffic fluctuation statistics to identify the mutation characteristics of traffic. The five-point smoothing filter eliminates short-term fluctuations in traffic data through moving average and extracts more representative trend information, while inflection point detection is used to find drastic change points in traffic, which correspond to abnormal network events or some potential problems. Through smoothing and inflection point detection, the traffic mutation characteristics of each high-speed network interface are obtained. The data packets of each high-speed network interface are statistically analyzed. The data packets are classified and counted according to the TCP, UDP and ICMP protocol types to obtain the protocol feature data of each high-speed network interface. The protocol feature data can reflect the proportion of data packets of different protocol types. The information entropy calculation and cluster analysis are performed on the protocol feature data. The information entropy calculation measures the randomness and complexity of the distribution of protocol types in network traffic. Higher information entropy indicates an increase in the diversity of network behavior, while cluster analysis groups protocol data, identifies similar behavior patterns, and obtains the data packet behavior characteristics of each high-speed network interface. These data packet behavior characteristics reveal the usage and changes of various protocols in the network, and help determine whether there are abnormal activities in the network. The traffic mutation characteristics and data packet behavior characteristics are weighted fused. In the weighted fusion process, different weights are assigned according to the importance of the characteristics to construct the network behavior feature set for each high-speed network interface.
[0031] Step S3, input the network behavior feature set into the multi-layer attention network to perform interface correlation analysis, temporal importance calculation and feature significance evaluation, and output the target feature vector of each high-speed network interface;
[0032] Specifically, the network behavior feature set of each high-speed network interface is input into the first-layer spatial attention network. The first-layer spatial attention network consists of 8 attention heads. Each attention head obtains the interface spatial features of each high-speed network interface by calculating the query matrix, key matrix and value matrix. The query matrix, key matrix and value matrix calculate the similarity between different interfaces through linear transformation and matrix multiplication, and capture the potential correlation between interfaces in the spatial dimension. This mechanism can fully explore the mutual dependence between network interfaces and generate interface spatial features. The interface spatial features are input into the second-layer temporal attention network. The second-layer temporal attention network consists of 4 parallel temporal attention submodules, each of which uses a 512-dimensional hidden layer to calculate the temporal correlation. The purpose of the temporal attention network is to capture the changing trend of each network interface feature in the temporal dimension. By paying attention to the relative importance of the input features at different time points, it can identify the dynamic change characteristics of network behavior over time and generate the temporal correlation features of each high-speed network interface. Multi-head self-attention calculation is performed on the temporal correlation features. The multi-head self-attention contains 6 attention heads, each with an output dimension of 64. Position encoding and scaled dot product attention mechanisms are used to obtain the results of feature interaction. The multi-head self-attention mechanism can capture the diversity of input data and interaction information in different dimensions by processing multiple subspaces of features in parallel. At the same time, position encoding retains the order information of features in the time dimension, while the scaled dot product attention mechanism avoids the gradient vanishing problem caused by excessive values by normalizing the attention scores. The interface space features of each high-speed network interface and the corresponding feature interaction results are input into the feature fusion layer. The feature fusion layer contains two fully connected layers. The output dimension of the first fully connected layer is 256, and the output dimension of the second fully connected layer is 128. ReLU activation function and Dropout operation are used respectively. In this process, the ReLU activation function introduces nonlinearity, so that the fused features can better fit the complex network behavior pattern, while the Dropout operation reduces the risk of overfitting of the model and enhances the generalization ability of the model by randomly discarding some neurons. Through the processing of the feature fusion layer, the fused feature vector of each high-speed network interface is generated. The fused feature vector is input into the cross attention layer. The cross-attention layer contains 8 attention heads, which are used to model the interaction between the features of different interfaces and obtain the inter-interface correlation features. Through the calculation of cross-attention, the relationship between different interfaces is further strengthened, which helps to capture the correlation behavior caused by the mutual influence of network traffic. The inter-interface correlation features are combined with the original features to obtain the enhanced feature matrix. The enhanced feature matrix contains the fused spatiotemporal features and the interaction features between interfaces. The feature importance is calculated for the enhanced feature matrix, and the weight vector of the feature is calculated by the softmax function.The softmax function performs exponential operations and normalization on the input features, maps the feature weights to a probability distribution, and obtains the relative importance of each feature. Based on the feature weight vector, the fused feature vector of each high-speed network interface is mapped to a reduced dimension, and the target feature vector of each high-speed network interface is output. The dimensionality reduction process retains important feature information by weighted summation of the features according to the weights, while compressing the secondary information, thereby simplifying the feature representation while retaining the most important features for the network status. The output target feature vector is used in subsequent anomaly detection and early warning models to help achieve real-time monitoring and fault prediction of high-speed network interfaces.
[0033] Step S4: input the target feature vector into the network anomaly analysis model for pattern matching and threshold judgment to generate a network anomaly alarm sequence for each high-speed network interface;
[0034] Specifically, the target feature vector is input into the feature extraction module of the network anomaly analysis model, which contains three convolutional layers for extracting deep information of the target feature vector. In the feature extraction module, the first convolutional layer uses 32 one-dimensional convolution kernels and cooperates with the ReLU activation function to perform nonlinear transformation on the input features, which can capture lower-level local features. The second convolutional layer uses 64 one-dimensional convolution kernels and also uses the ReLU activation function, so that the model can mine the intermediate patterns in the features. The third convolutional layer uses 128 one-dimensional convolution kernels and uses the ReLU activation function again to enhance the model's recognition ability for complex patterns. After three layers of convolution operations, a primary feature map containing multi-level features is generated. The primary feature map is feature enhanced by the first-level residual module. The first-level residual module contains two one-dimensional convolutional layers and a short-circuit connection structure, which aims to avoid the gradient vanishing problem through jump connections and make the training of deep networks more stable. Each convolutional layer uses 128 convolution kernels in this module, and also includes a BatchNorm normalization layer to normalize the features, thereby accelerating the training process and reducing overfitting. Through the processing of the first-level residual module, the primary feature map is further enhanced to generate the first-level enhanced features. The first-level enhanced features are input into the second-level residual module. The second-level residual module is similar to the first-level, and also contains two one-dimensional convolutional layers and a short-circuit connection, but the number of convolution kernels is increased, and each convolution layer uses 256 convolution kernels. This design enables the second-level residual module to capture higher-dimensional and more complex feature relationships. At the same time, the BatchNorm normalization layer normalizes the features, making the distribution of the features more stable and convenient for subsequent processing. Under the action of the second-level residual module, the features are enhanced to obtain richer and more comprehensive second-level enhanced features. The second-level enhanced features are subjected to the maximum pooling operation to achieve feature dimensionality reduction and information compression while retaining important information in the features. Max pooling reduces the dimension of the feature map by taking the maximum value in the local area, thereby reducing the amount of calculation while retaining the significant part of the feature. The features are fused in the pooling operation to generate a fused feature vector. The fused feature vector is input into a three-layer fully connected network for abnormal pattern matching. The output dimensions of the three-layer fully connected network are 128, 64, and 32, respectively. Each layer uses the ReLU activation function to introduce nonlinear characteristics, and the Dropout operation is introduced in each layer to reduce overfitting and enhance the generalization ability of the model. The first fully connected layer converts the fused feature vector into a 128-dimensional feature representation, enhances the nonlinear expression ability of the feature through the ReLU activation function, and then randomly discards some neurons through the Dropout operation, making the training of the model more robust. The second fully connected layer further compresses the features to 64 dimensions, and processes them again through ReLU and Dropout to extract important patterns in the features.The third fully connected layer maps the features to 32 dimensions and finally generates a network anomaly alarm sequence.
[0035] Step S5: Perform time-space state correlation analysis and fault propagation path tracing based on the network abnormality alarm sequence, and output the router fault location result.
[0036] Specifically, the network abnormality alarm sequence is input into the spatiotemporal state association model, which contains three layers of temporal convolutional networks. Each layer of temporal convolutional networks contains 64 convolution kernels, and the size of the convolution kernel is 3. In this process, the spatiotemporal features in the alarm sequence are effectively extracted through the local receptive field of the temporal convolutional network, and the spatiotemporal state feature matrix is obtained. Through the layer-by-layer processing of the three-layer temporal convolutional network, the trend changes of the network alarm sequence in the time dimension and the association between different network interfaces in the spatial dimension can be captured, forming a spatiotemporal state feature matrix containing rich spatiotemporal information. The spatiotemporal state feature matrix is topologically analyzed based on the graph neural network. The graph neural network performs in-depth association analysis on the spatiotemporal features of the alarm sequence by capturing the topological relationship between network interfaces. The graph neural network contains two layers of graph convolutional layers, each with an output dimension of 128, and interacts and updates the features through the message passing mechanism. In the process of message transmission, nodes share information through the edges of the graph structure, so that the graph convolution layer can comprehensively consider the characteristics of the nodes and the relationship with the adjacent nodes, generate topological association features, reveal the mutual influence caused by alarm events between different network interfaces, and provide necessary structural information for identifying the fault propagation path in the network. Based on the topological association features, a directed graph of fault propagation is constructed. When constructing the directed graph, the correlation strength between different interfaces in the network and the temporal relationship of alarm events are considered to ensure that the constructed directed graph can accurately reflect the direction and path of fault propagation. After obtaining the fault propagation directed graph, the fault propagation paths between interfaces are calculated to obtain the fault propagation path set. These paths describe the specific process of fault propagation from one interface to other interfaces, so as to clarify which interfaces are affected by other interface faults. In order to determine the causal relationship of the fault, the fault propagation path set is input into the causal analysis network for causal reasoning. The causal analysis network can infer the causal chain between fault events based on the characteristics of fault propagation, and output the fault causal chain, so as to help identify the source of the fault and its impact on other interfaces. Based on the fault causal chain, the task of fault location is performed. In this process, the fault probability distribution of each high-speed network interface is calculated to determine which interface is most likely to be the source of the fault. A fault source candidate set is generated through probability calculation, which contains all possible fault sources and is sorted according to their fault probabilities. The fault source candidate set is verified and sorted in multiple dimensions. In the multi-dimensional verification process, information from multiple dimensions such as the historical behavior, current status, and alarm frequency of the interface is considered to ensure that the fault source is accurately identified. Through a multi-dimensional comprehensive analysis of the candidate set, the most likely router fault location result is output.
[0037] The fault location results are analyzed for features and key routing entry information is extracted. This information is used to construct a counting Bloom Filter. The counting Bloom Filter maps the hash value of each routing entry by using a preset number of hash functions, and sets the length of the counting bit array to N bits. Each routing entry is mapped to multiple positions in the counting bit array through these hash functions to generate an inner routing filter structure. In the counting Bloom Filter, each position of the bit array stores an access count value, which is used to record the access status of the corresponding network segment and can effectively capture the access frequency and pattern. The original Bloom Filter is set as the outer filter for the inner routing filter structure. The outer filter performs fast member query and filtering on the routing entries of the inner filter, thereby reducing the query burden on the counting Bloom Filter and improving the processing efficiency of the entire filtering system. The original Bloom Filter also uses multiple hash functions and sets the length of the bit array to M bits. Each routing entry is mapped to a position in the outer bit array through these hash functions to obtain a complete double-layer filtering structure. In this two-layer structure, the original Bloom Filter, as the first layer of fast filter, can effectively exclude entries that do not exist in the routing table, while the counting Bloom Filter is used to further accurately record and manage the access information of the routing entries. Based on the two-layer filtering structure, the routing entry mapping function of the inner filter is set, and the access count value and access mode of each network segment are recorded through the counting Bloom Filter to obtain the inner routing table state matrix. The inner routing table state matrix captures the access behavior of different network segments in the network, including characteristics such as access frequency and access time distribution, which helps to monitor abnormal changes in network traffic and identify hot network segments. By recording and managing these access behaviors, network segments with potential problems in the router can be effectively identified. The network segment retrieval function of the outer filter is set for the inner routing table state matrix, and member query and forwarding judgment are performed through the original Bloom Filter to obtain the filtering results of the outer routing table. The outer filter determines whether the corresponding network segment exists in the routing table by quickly judging the query entry, thereby greatly improving the query efficiency. For entries in the routing table, the inner counting Bloom Filter is used to determine their access counts and pattern characteristics to obtain more accurate routing entry status information. The outer routing table filtering results are matched with the network topology status to understand the adaptability between the routing table entries in the current router and the overall network topology. Based on the matching results, the routing table entries are updated through the dynamic routing protocol to obtain an optimized routing table. Under the action of the dynamic routing protocol, the entries in the routing table are automatically adjusted according to the status changes of different nodes in the network to ensure that the forwarding path of the router is always in the best state.The optimized routing table reduces network congestion to a certain extent and improves the stability and reliability of data transmission. Based on the optimized routing table, a traffic allocation strategy is generated to obtain the link bandwidth allocation result. In this process, the capacity of different links and their load conditions are taken into account to ensure the rational use and fair allocation of bandwidth. Traffic control instructions are output according to the link bandwidth allocation results. These traffic control instructions are used to dynamically adjust the traffic load of different links in the router to achieve global traffic balance and optimal use of network resources.
[0038] In an embodiment of the present invention, the flow data, hardware performance data and routing status data of the high-speed network interface are collected in an all-round manner, and a standardized multi-dimensional raw data sequence is constructed through time alignment and normalization processing. Fourier transform and wavelet decomposition are used for time-frequency domain analysis, and a comprehensive network behavior feature set is constructed in combination with flow fluctuation statistics and protocol feature analysis. A three-layer attention network architecture is adopted, including spatial attention, temporal attention and cross attention, to realize correlation analysis and feature fusion between interfaces. Combined with deep convolutional networks and residual modules, accurate abnormal behavior identification is achieved through multi-level feature extraction and pattern matching. Based on spatiotemporal state correlation analysis and graph neural networks, a fault propagation path tracking mechanism is constructed to achieve accurate fault source location. A double-layer Bloom Filter structure is adopted to realize efficient management and dynamic optimization of routing tables and ensure the rational allocation of network resources.
[0039] In a specific embodiment, the process of executing step S1 may specifically include the following steps:
[0040] The flow data of each high-speed network interface is periodically sampled to obtain an interface-level data packet flow sequence, and protocol classification statistics and data packet size analysis are performed on the interface-level data packet flow sequence to obtain interface-level flow characteristic data;
[0041] Monitor the CPU occupancy rate and memory usage rate of each high-speed network interface in real time to obtain interface-level hardware performance data, and periodically scan the number of routing table entries and update frequency of each high-speed network interface to obtain interface-level routing status data;
[0042] Time-aligning interface-level traffic characteristic data, interface-level hardware performance data, and interface-level routing status data to obtain an interface-level multidimensional data set;
[0043] The interface-level multidimensional data set is normalized to obtain standardized interface data, and the standardized interface data is slidingly sampled through a preset time window to obtain interface timing feature data. Based on the interface timing feature data, a multidimensional original data sequence for each high-speed network interface is constructed.
[0044] Specifically, the traffic data of each high-speed network interface is sampled periodically to generate an interface-level data packet traffic sequence. The sampling frequency determines the accuracy of the traffic changes that can be captured. For example, set the sampling to be performed once per second to record the data packet traffic of each interface within this second. Through periodic sampling, an interface-level data packet traffic sequence is obtained, and these data can reflect the real-time traffic load of the interface. Protocol classification statistics and data packet size analysis are performed on the traffic data. Protocol classification statistics refer to classifying the collected data packets according to the protocol type they use (such as TCP, UDP, ICMP, etc.), and counting the number of data packets and traffic proportion of each protocol. Use the following formula to calculate the traffic share of a certain protocol:
[0045] ;
[0046] in, Indicates the proportion of data packet traffic of a certain protocol. represents the number of packets of this protocol, and Indicates the total number of packets. Through this classification, the data traffic characteristics of different protocols for each interface in a certain period of time are obtained. For example, 80% of the traffic on a certain interface in a certain period of time is TCP, and 20% of the traffic is UDP. This information helps to identify potential abnormal activities in the network. At the same time, packet size analysis is used to calculate the size distribution of packets over a period of time. For example, the traffic characteristics are described by statistical data packets such as the average size, variance, maximum and minimum values. The average packet size is calculated using the following formula:
[0047] ;
[0048] in, Indicates the average value of the packet size, Indicates The size of the data packet, Indicates the total number of data packets. By calculating these characteristics, we can understand the composition of traffic and the characteristics of abnormal behavior. Real-time monitoring of the hardware performance of each high-speed network interface. Including real-time monitoring of CPU usage and memory usage. These hardware performance indicators can reflect the operating status of the interface and the existing bottlenecks. Assuming the use of Indicates at time The CPU usage at each moment is averaged over a period of time to obtain the overall load situation:
[0049] ;
[0050] in, Indicates the average CPU usage. Indicates the length of the monitoring period. Similarly, memory usage is calculated in a similar way. These indicators can be used to evaluate whether the hardware resources of the current interface meet the requirements of its traffic load and whether further optimization is needed. At the same time, the routing status of each high-speed network interface is monitored, including the periodic scanning of the number of routing table entries and the update frequency. Number of routing table entries Indicates at time The number of entries in the routing table of the interface at the moment, and the routing table update frequency is To indicate that at time The number of routing table updates at a certain time. By counting the average number of routing table entries and update frequency over a period of time, the dynamics of the routing table and the stability of the network can be evaluated. For example:
[0051] ;
[0052] Through calculation, we can find out whether the routing table of the current interface is updated too frequently. We can time-align the interface-level traffic feature data, interface-level hardware performance data, and interface-level routing status data to obtain an interface-level multidimensional data set. We can ensure that data from different sources are effectively compared and analyzed at the same time point. Assume that , and Respectively, in time Traffic characteristics, CPU usage, and number of routing table entries at each moment, and constructing a multidimensional dataset through time alignment :
[0053] ;
[0054] in, Indicates at time The multidimensional dataset at the moment contains features of multiple dimensions such as traffic, hardware performance, and routing status. In order to make the data of different dimensions have consistent dimensions and ranges, the interface-level multidimensional dataset is normalized to the maximum and minimum values. The normalization formula is as follows:
[0055] ;
[0056] in, Indicates at time Normalized data at time, and The vectors representing the minimum and maximum values in the multidimensional data set are respectively. Through normalization, all feature values are limited to the range of [0,1], eliminating the scale differences between different features and improving the stability of the model during training. The standardized interface data is sampled by sliding through a preset time window to obtain interface timing feature data. The sliding sampling process is performed by setting a fixed length time window, such as a length of , and then on the data set with a step size Slide and intercept a length of The data of the time period forms a time series feature sample. Assume The data is standardized, and the time series feature data is obtained by sliding window sampling It is expressed as:
[0057] ;
[0058] Through sliding sampling, feature samples containing time series information are constructed. These samples can reflect the dynamic change characteristics of the interface over a period of time, thereby providing input in the time dimension for the model. Based on the interface timing feature data, a multi-dimensional raw data sequence of each high-speed network interface is constructed, which contains the correlation between different features in the time and space dimensions, and can more comprehensively describe the state and behavior of the interface.
[0059] In a specific embodiment, the process of executing step S2 may specifically include the following steps:
[0060] Segmenting the multi-dimensional original data sequence of each high-speed network interface to obtain an interface traffic sequence, and performing Fourier transform on the interface traffic sequence to obtain a frequency domain data matrix of each high-speed network interface;
[0061] Perform time-frequency analysis and feature combination on the frequency domain data matrix to obtain the multi-scale traffic features of each high-speed network interface, and perform nonlinear dimensionality reduction processing on the multi-scale traffic features to obtain the compressed feature vector of each high-speed network interface;
[0062] The traffic fluctuation statistics of each high-speed network interface are calculated based on the compressed feature vector, and five-point smoothing filtering and inflection point detection are performed based on the traffic fluctuation statistics to obtain the traffic mutation characteristics of each high-speed network interface;
[0063] Classify and count the data packets of each high-speed network interface according to the TCP, UDP, and ICMP protocol types to obtain the protocol feature data of each high-speed network interface, and perform information entropy calculation and cluster analysis on the protocol feature data to obtain the data packet behavior characteristics of each high-speed network interface;
[0064] The traffic mutation characteristics and data packet behavior characteristics are weightedly fused to construct a network behavior feature set for each high-speed network interface.
[0065] Specifically, the multi-dimensional raw data of the interface is divided into several time periods to ensure that each data segment has relatively stable characteristics. The length of the time period is set to , by dividing the entire data sequence by time, we get several interface traffic sequences. Each traffic sequence is recorded in the time period The number of packets, transmission rate and other traffic characteristics in the interface are used to form traffic samples in the time domain. The interface traffic sequence is subjected to Fourier transform to convert the time domain signal into the frequency domain. The formula for Fourier transform is as follows:
[0066] ;
[0067] in, represents the amplitude of the frequency domain signal, Indicates time The flow value at the moment, represents the length of the time series, is the frequency, Represents an imaginary unit. Through Fourier transform, the frequency domain data matrix of each high-speed network interface is obtained , where each element of the matrix corresponds to the signal strength at a specific frequency. The frequency domain data matrix can reveal potential periodic characteristics in the traffic, such as high amplitude peaks at a specific frequency means periodic congestion or repeated data in the network traffic. Time-frequency analysis and feature combination are performed on the frequency domain data matrix to capture the frequency characteristics of traffic that change over time. Time-frequency analysis can combine time and frequency to reveal the changes in frequency characteristics in different time periods, which is achieved through time-frequency analysis methods such as wavelet transform. The formula for wavelet transform is as follows:
[0068] ;
[0069] in, Indicates at time and scale The wavelet coefficients under Represents the time signal, is the wavelet function, is a scale parameter, which indicates the frequency range of the analysis. Through time-frequency analysis, traffic characteristics at different time scales are obtained to describe the changing trend of traffic in the short and long term, thereby generating multi-scale traffic characteristics for each interface. Nonlinear dimensionality reduction is performed on the multi-scale traffic characteristics to reduce the feature dimension and retain the main information. The t-SNE method is used to project high-dimensional data into low-dimensional space, and the relative distance between data points is maintained as much as possible. The feature vector after dimensionality reduction is expressed as:
[0070] ;
[0071] in, represents the feature vector after dimensionality reduction, represents the original high-dimensional features, Represents the number of samples. The feature vector after dimensionality reduction is the compressed feature vector , retaining the main information of the original multi-scale features while significantly reducing the dimension of the features. Based on the compressed feature vector, the traffic fluctuation statistics of each high-speed network interface are calculated, such as the mean, variance, and standard deviation, which are used to describe the stability and volatility of the traffic. Assumptions represents the first components, whose mean and variance It is expressed as:
[0072] ;
[0073] The statistical data is subjected to five-point smoothing filtering and inflection point detection to identify the sudden change characteristics of the traffic. The five-point smoothing filter takes the average value of the two points before and after each point to eliminate short-term random fluctuations and make the overall trend of the traffic smoother. The smoothed value It is expressed as:
[0074] ;
[0075] Inflection point detection is used to identify mutation points in traffic by calculating the difference between two adjacent time points. In this way, the traffic mutation characteristics of each high-speed network interface are obtained. These characteristics are used to identify abnormal situations in the network, such as sudden traffic surges or traffic drops. Protocol classification statistics are performed on the data packets of each high-speed network interface. The collected data packets are classified according to TCP, UDP and ICMP protocol types, and the number of data packets of each protocol type is counted. Assume , and Respectively represent the number of packets of TCP, UDP and ICMP protocols, and the total number of packets is The agreement percentage is calculated as:
[0076] ;
[0077] These protocol feature data are used to describe the protocol distribution of the interface within a certain period of time, and further measure the complexity of the protocol distribution through information entropy calculation. The calculation formula of information entropy is as follows:
[0078] ;
[0079] in, represents information entropy, Indicates The higher the information entropy, the more complex the protocol distribution is, which means that there are diverse traffic behaviors in the network. These protocol feature data are grouped through cluster analysis to identify similar packet behavior patterns. For example, using the K-means clustering algorithm, different protocol features are divided into several categories to identify traffic behaviors with similar features. The traffic mutation features and packet behavior features are weighted and fused to construct a network behavior feature set for each high-speed network interface. Weighted fusion is achieved by setting weights for different features. Assume that the weight of the traffic mutation feature is , the weight of the packet behavior feature is , then the fused network behavior feature set It is expressed as:
[0080] ;
[0081] in, Indicates the traffic mutation characteristics. Represents the behavior characteristics of data packets. Through weighted fusion, the dynamic changes of traffic and the behavior patterns of protocols are comprehensively considered to construct a comprehensive set of network behavior characteristics.
[0082] In a specific embodiment, the process of executing step S3 may specifically include the following steps:
[0083] The network behavior feature set of each high-speed network interface is input into the first-layer spatial attention network. The first-layer spatial attention network contains 8 attention heads. Each attention head calculates the interface spatial features of each high-speed network interface through the Query matrix, Key matrix, and Value matrix.
[0084] The interface spatial features are input into the second-layer temporal attention network. The second-layer temporal attention network contains four parallel temporal attention submodules. Each temporal attention submodule uses a 512-dimensional hidden layer to perform temporal correlation calculation to obtain the temporal correlation features of each high-speed network interface.
[0085] Multi-head self-attention is calculated for the time series correlation features. The multi-head self-attention includes 6 attention heads, and the output dimension of each attention head is 64. The feature interaction results are obtained through position encoding and scaled dot product attention mechanism;
[0086] The interface spatial features and corresponding feature interaction results of each high-speed network interface are input into the feature fusion layer. The feature fusion layer includes two fully connected layers. The output dimension of the first fully connected layer is 256, and the output dimension of the second fully connected layer is 128. ReLU activation function and Dropout operation are used respectively to obtain the fused feature vector of each high-speed network interface.
[0087] The fused feature vector is input into the cross attention layer. The cross attention layer uses 8 attention heads to model the interaction between the features of different interfaces, obtains the inter-interface correlation features, and combines the inter-interface correlation features with the original features to obtain the enhanced feature matrix.
[0088] The feature importance of the enhanced feature matrix is calculated, and the feature weight vector is obtained through the softmax function. Based on the feature weight vector, the fusion feature vector of each high-speed network interface is mapped to a dimension reduction mode, and the target feature vector of each high-speed network interface is output.
[0089] Specifically, the network behavior feature set of each high-speed network interface is input into the first-layer spatial attention network. In the first-layer spatial attention network, there are 8 attention heads, and each attention head obtains the interface spatial features of each network interface by calculating the Query matrix, Key matrix and Value matrix. Given a feature set , which is converted into a query matrix through a linear transformation , key matrix Sum Matrix :
[0090] ;
[0091] in, The weight matrices for query, key, and value respectively define how to map the input features. Then, we calculate and The dot product of and scaling is performed to obtain the attention score matrix :
[0092] ;
[0093] in, is the dimension of the key vector, which is used to scale to prevent the dot product value from being too large. The softmax function is used to normalize the attention score to the range of [0,1]. Then the attention score is combined with the value matrix Multiply them together to get the output of each attention head:
[0094] ;
[0095] The output of each attention head represents the correlation of network interface features in the spatial dimension. The output results of the eight attention heads are spliced together and the final interface spatial features are obtained through linear transformation. These features retain the spatial correlation between different network interfaces and can capture the mutual dependence between interfaces. The interface spatial features are input into the second-layer temporal attention network. The second-layer temporal attention network contains four parallel temporal attention submodules, each of which uses a 512-dimensional hidden layer to calculate temporal correlation. In the temporal attention network, the dynamic changes of the network interface are captured by paying attention to the relationship between input features at different time points. For each temporal attention submodule, the input features are linearly transformed and mapped to a 512-dimensional hidden space, and then the attention mechanism is used to calculate the correlation between different time steps. Similar to the spatial attention mechanism, the temporal correlation obtains the attention score by the dot product of the query, key, and value, reflecting the importance of the input features in the temporal dimension. After being processed by four parallel temporal attention submodules, the temporal correlation features of each interface are obtained, which contain the changing rules of the interface at different times. Multi-head self-attention calculation is performed on the temporal correlation features. The multi-head self-attention calculation contains 6 attention heads, each with an output dimension of 64, and uses position encoding and scaled dot product attention mechanism to capture the interaction between features. Position encoding is used to introduce the position information of the input sequence. Position encoding is defined as:
[0096] ;
[0097] in, and Respectively represent The encoding components for even and odd positions of time steps, Represents the dimension of the feature. Position encoding introduces sequence information to the feature, thereby preserving the temporal dependency in the feature interaction. The correlation between features is calculated by the scaled dot product attention mechanism, and the interaction result of the feature is obtained. After obtaining the feature interaction result, the interface space feature of each high-speed network interface and the corresponding feature interaction result are input into the feature fusion layer. The feature fusion layer contains two fully connected layers, the output dimension of the first layer is 256, and the output dimension of the second layer is 128. Each layer uses the ReLU activation function, and the expression of the ReLU function is:
[0098] ;
[0099] The ReLU activation function increases the expressiveness of the model by introducing nonlinearity. At the same time, each layer introduces the Dropout operation to randomly discard some neurons to reduce overfitting. The effect of Dropout is expressed as:
[0100] ;
[0101] in, represents the retention probability of Dropout, Represents the output of the fully connected layer. Through Dropout, the network can effectively prevent overfitting and thus improve generalization ability. After being processed by two fully connected layers, the fused feature vector of each high-speed network interface is obtained. The fused feature vector is input into the cross-attention layer for modeling. The cross-attention layer contains 8 attention heads for interacting the features between different interfaces. Through cross-attention, the mutual influence and dependency between different interfaces are captured. Especially in scenarios such as shared bandwidth and load balancing, the correlation between interfaces is very important. Through the parallel processing of 8 attention heads, these complex interaction patterns can be captured more comprehensively. The output of cross-attention is the correlation feature between interfaces. Next, the correlation feature between interfaces is combined with the original feature to obtain the enhanced feature matrix. The feature importance of the enhanced feature matrix is calculated, and the weight of each feature is calculated by the softmax function. The expression of the softmax function is:
[0102] ;
[0103] in, Indicates The weight of the feature, Indicates The softmax function obtains the relative importance of the features by performing exponential operations and normalizing the feature values. The sum of the weights is 1, which indicates the relative contribution of each feature to the whole. After obtaining the feature weight vector through softmax, the fusion feature vector of each high-speed network interface is reduced in dimension based on these weights to obtain the final target feature vector. The process of dimensionality reduction mapping is achieved by weighted summation of each component in the feature vector:
[0104] ;
[0105] in, Indicates The target feature vector of the network interface, represents the first Quantity, is the weight of this component. Through dimensionality reduction mapping, the most important feature information is retained while reducing feature redundancy, making the final feature vector more compact and effective.
[0106] In a specific embodiment, the process of executing step S4 may specifically include the following steps:
[0107] The target feature vector of each high-speed network interface is input into the feature extraction module of the network anomaly analysis model. The feature extraction module includes three convolutional layers. The first convolutional layer uses 32 one-dimensional convolutional kernels and ReLU activation function, the second convolutional layer uses 64 one-dimensional convolutional kernels and ReLU activation function, and the third convolutional layer uses 128 one-dimensional convolutional kernels and ReLU activation function to obtain a primary feature map.
[0108] The primary feature map is enhanced through the first-level residual module. The first-level residual module contains two one-dimensional convolutional layers and a short-circuit connection. Each convolutional layer uses 128 convolution kernels and a BatchNorm normalization layer to obtain the first-level enhanced features.
[0109] The first-level enhanced features are input into the second-level residual module. The second-level residual module contains two one-dimensional convolutional layers and a short-circuit connection. Each convolutional layer uses 256 convolution kernels and a BatchNorm normalization layer to obtain the second-level enhanced features.
[0110] The second-level enhanced features are subjected to maximum pooling and feature fusion to obtain a fused feature vector, which is then used for abnormal pattern matching through a three-layer fully connected network. The output dimensions of the three-layer fully connected network are 128, 64, and 32, respectively. Each layer uses the ReLU activation function and Dropout operation to obtain a network abnormality alarm sequence.
[0111] Specifically, the target feature vector of each high-speed network interface is input into the feature extraction module of the network anomaly analysis model. The feature extraction module consists of three one-dimensional convolutional layers. The first convolutional layer is used to perform convolution processing on the input target feature vector. The first convolutional layer contains 32 one-dimensional convolutional kernels, each of which has a length of , and the ReLU activation function is used to perform nonlinear processing on the convolution output. The convolution operation is expressed as:
[0112] ;
[0113] in, represents the output of the first convolutional layer, The value of the position, represents the input feature vector, represents the weight of the first convolution kernel, is the bias term, is the length of the convolution kernel. Through the operation of the first convolution layer, the input features are nonlinearly enhanced through the ReLU activation function to obtain the initial extracted features. The second convolution layer uses 64 one-dimensional convolution kernels and uses the ReLU activation function to activate the output. The convolution calculation of the second layer is similar to that of the first layer, and its expression is:
[0114] ;
[0115] in, represents the output of the second convolutional layer, is the weight of the second layer convolution kernel, is the bias term, is the length of the second convolution kernel. Through the processing of the second convolution layer, the features are further extracted and the understanding of the local pattern is deepened. The third convolution layer uses 128 one-dimensional convolution kernels and uses the ReLU activation function to activate the output. The calculation process is similar to the first two layers. The convolution output is expressed as:
[0116] ;
[0117] in, represents the output of the third convolutional layer, is the weight of the third layer convolution kernel, is the bias term, is the length of the third convolution kernel. After the third convolution layer is processed, a higher-order feature representation is obtained to form a primary feature map. The primary feature map is enhanced by the first-level residual module. The first-level residual module contains two one-dimensional convolution layers and a short-circuit connection structure. The jump connection avoids the gradient vanishing problem and increases the stability of the network. Each convolution layer uses 128 convolution kernels and also contains a BatchNorm normalization layer. The expression of BatchNorm is:
[0118] ;
[0119] in, represents the normalized output, and are the mean and variance of the current batch of data, respectively. is a small constant used to avoid the situation where the denominator is zero. The BatchNorm normalization layer is used to standardize the output of the convolutional layer, making it easier for the model to converge during training and reducing overfitting. In the residual module, the input features are processed by two convolutional layers, then added to the input through a short-circuit connection, and finally the first-level enhanced features are output. The formula for the short-circuit connection is expressed as:
[0120] ;
[0121] in, Represents the features after two layers of convolution and BatchNorm. It is a primary feature map. By adding it to the input feature, it retains the original feature information while enhancing the depth and expression ability of the feature. The first-level enhanced feature is input into the second-level residual module for feature enhancement. The second-level residual module contains two one-dimensional convolutional layers and a short-circuit connection. The difference is that each convolutional layer uses 256 convolution kernels. Through the processing of the second-level residual module, the dimension of the feature is further improved, and its internal structure can capture more complex patterns and correlations, and obtain richer second-level enhanced features. Perform a maximum pooling operation on the second-level enhanced features. Reduce the dimension of the feature by taking the maximum value in the local area while retaining the most significant information. Assume is the feature after pooling, The value of the position is expressed as:
[0122] ;
[0123] in, represents the pooling window size, Indicates that from Positions to The maximum pooling can reduce the number of features, thereby reducing the amount of calculation, while retaining key information. After the pooling operation, the features are fused to obtain the fused feature vector . The fused feature vector The input is sent to a three-layer fully connected network for abnormal pattern matching. The output dimensions of the three-layer fully connected network are 128, 64, and 32 respectively. Each layer uses the ReLU activation function to activate the output, and the Dropout operation is used to reduce overfitting. The first layer of the fully connected network is represented as:
[0124] ;
[0125] in, represents the output of the first layer, is the weight matrix, is the bias term. Through the ReLU activation function, the network introduces nonlinearity, thereby improving the model's expressiveness. Then the Dropout operation is performed, and the Dropout probability is set to , then the output after Dropout is:
[0126] ;
[0127] Similarly, the calculations for the second and third layers are expressed as:
[0128] ;
[0129] ;
[0130] After being processed by the three-layer fully connected network, the network output is finally obtained, which is represented as a network anomaly alarm sequence. The network anomaly alarm sequence is used to identify whether there is abnormal behavior in the current network state. By matching the fused feature vector with the known abnormal pattern, the model can identify which interfaces have problems and generate corresponding alarm information.
[0131] In a specific embodiment, the process of executing step S5 may specifically include the following steps:
[0132] The network abnormality alarm sequence is input into the spatiotemporal state association model, which contains three layers of temporal convolutional networks. Each layer of temporal convolutional network contains 64 convolution kernels with a kernel size of 3. The spatiotemporal features are extracted through the local receptive field to obtain the spatiotemporal state feature matrix.
[0133] The topological structure of the spatiotemporal state feature matrix is analyzed based on a graph neural network. The graph neural network contains two layers of graph convolutional layers with an output dimension of 128 per layer. The topological correlation features are obtained through a message passing mechanism.
[0134] Based on the topological association features, a fault propagation directed graph is constructed to calculate the fault propagation paths between interfaces, obtain the fault propagation path set, and input the fault propagation path set into the causal analysis network for causal relationship reasoning, and output the fault causal chain;
[0135] Fault location is performed based on the fault causal chain, the fault probability distribution of each high-speed network interface is calculated, the fault source candidate set is obtained, and the fault source candidate set is combined for multi-dimensional verification and sorting, and the router fault location result is output.
[0136] Specifically, the network abnormal alarm sequence is input into the spatiotemporal state association model for in-depth analysis. The spatiotemporal state association model contains 3 layers of temporal convolutional networks, each layer of which contains 64 convolution kernels, and the size of the convolution kernel is 3. The goal of the temporal convolutional network is to extract spatiotemporal features from the input abnormal alarm sequence. These features can reflect the abnormal state of the network interface that changes over time and the spatial correlation. Indicates at time The first convolutional layer extracts the local time correlation through the convolution operation. The convolution operation is expressed by the following formula:
[0137] ;
[0138] in, represents the output of the first convolutional layer, is the weight of the convolution kernel, is the bias term, and the size of the convolution kernel is 3, which means that at each time step, the convolution will cover the current moment and one time step before and after it. The ReLU activation function is used to introduce nonlinear capabilities, so that it can better fit the abnormal change pattern. Through layer-by-layer convolution operations, the second and third layers of the temporal convolution network extract features in a similar way to obtain deeper spatiotemporal features. Through the processing of these three layers of temporal convolution networks, a feature matrix containing rich spatiotemporal information is extracted. The spatiotemporal state feature matrix S records the correlation between different times and different interfaces. The spatiotemporal state feature matrix is topologically analyzed based on the graph neural network. The graph neural network is suitable for processing data with a graph structure, and the spatiotemporal state feature matrix is represented as a graph, in which each node corresponds to a network interface, and the edges between nodes represent the association between different interfaces. The graph neural network contains two layers of graph convolution layers, and the output dimension of each layer is 128. For each graph convolution layer, the message passing mechanism is used to calculate the features of each node, which updates the state of the current node by aggregating the information of neighboring nodes. The calculation of the graph convolution is expressed as:
[0139] ;
[0140] in, Indicates Node in layer Features, Representation Node The neighbor set of and Node and nodes The degree, For the The weight matrix of the layer, is the bias term, Represents the activation function (e.g. ReLU). The message passing mechanism can capture the complex association relationships between different nodes (i.e. different interfaces) and integrate these relationships into the feature representation of the nodes. Through the calculation of two layers of graph convolutional layers, the topological association feature matrix is obtained. , where the characteristics of each node represent the position and association of the node in the entire network topology. Based on the topological association characteristics, a directed graph of fault propagation is constructed. The nodes of the directed graph represent different interfaces in the network, and the edges represent the direction and intensity of fault propagation. The connection relationship between the nodes is determined according to the weight values in the topological association characteristics, and the weight values are mapped to the probability of fault propagation. After the directed graph is constructed, the fault propagation paths between the interfaces are calculated to obtain a set of fault propagation paths. Each path represents a potential fault propagation path, such as the abnormal state of the adjacent interface caused by a fault on a certain interface. The set of fault propagation paths is input into the causal analysis network for causal reasoning. The goal of the causal analysis network is to infer the causal chain between faults from the fault propagation path and determine which faults are the source and which are caused by other faults. Assume Representation Node The causal analysis is expressed by the following causal relationship formula:
[0141] ;
[0142] in, Representation Node The parent node (that is, the node that caused Failed node), is a noise term, representing a random external factor. Through the causal analysis network, the causal chain of each fault is inferred , that is, the propagation relationship from the fault source to other affected nodes. Based on the obtained fault causal chain, fault location is performed. The goal of fault location is to determine whether each high-speed network interface is a fault source and their failure probability. The failure probability distribution of each node is calculated, assuming that the node The failure probability is , estimated by Bayesian inference:
[0143] ;
[0144] in, Representation Node The conditional probability when the parent node fails, represents the failure probability of the parent node, Represents the evidence probability of all known faults. In this way, the fault probability distribution of each node is obtained, and the candidate set of fault sources is determined based on these probabilities. The candidate set of fault sources is verified and sorted in multiple dimensions to output the final fault location result. Different information sources are combined to verify the rationality of each candidate fault source, such as combining historical data of network traffic, current network topology status, and status of other interfaces. Suppose the verification score of a node is , weighted summation is performed based on the verification results of different dimensions:
[0145] ;
[0146] in, Indicates Verification function in dimensions, represents the corresponding weight, Represents the total number of verification dimensions. Through multi-dimensional verification and weighted sorting, the comprehensive score of each candidate fault source is obtained, and these candidate nodes are sorted according to the score, and finally the fault location result of the router is output.
[0147] In a specific embodiment, the real-time monitoring and early warning method of high-speed routing also includes the following steps:
[0148] The router fault location result is analyzed for features, and a counting Bloom Filter is constructed as an inner filter. The counting Bloom Filter uses a preset number of hash functions and the length of the counting bit array is N bits, thereby obtaining an inner routing filter structure.
[0149] The original Bloom Filter is set as the outer filter for the inner routing filter structure. The original Bloom Filter uses a preset number of hash functions and the bit array length is M bits, so as to obtain a complete double-layer filter structure.
[0150] The routing entry mapping function of the inner filter is set based on the double-layer filtering structure. The access count value and access mode of each network segment are recorded by counting Bloom Filter to obtain the inner routing table state matrix.
[0151] The network segment retrieval function of the outer filter is set for the inner routing table state matrix, and the member query and forwarding judgment are performed through the original Bloom Filter to obtain the outer routing table filtering result;
[0152] Match the outer routing table filtering results with the network topology status, and update the routing table entries through the dynamic routing protocol to obtain an optimized routing table;
[0153] Generate a traffic allocation strategy based on the optimized routing table, obtain the link bandwidth allocation result, and output the traffic control instruction according to the link bandwidth allocation result.
[0154] Specifically, the characteristics of the router fault location results are analyzed, and a suitable filtering mechanism is constructed to improve the efficiency of the router's routing entry management. A counting Bloom Filter is constructed as an inner filter, which can effectively record the access status of each routing entry in the network. The counting Bloom Filter is different from the traditional Bloom Filter. It adds a counting function on the basis of the traditional bit array, thereby counting the hash map of each position, so that not only can entries be inserted, but also deleted under certain conditions. The length of the designed bit array is bit, through A preset hash function is used to map the routing entries, and the status update of the counting Bloom Filter is expressed as:
[0155] ;
[0156] in, Indicates Hash functions The calculated position The count value on Indicates the routing entry that needs to be inserted, maps the routing entry through each hash function and increases the count value of the corresponding position. In this way, the counting Bloom Filter can record the access count of each entry and form an inner routing filter structure for managing and monitoring the access mode of each network segment. In order to improve the query efficiency and reduce the access frequency of the inner filter when constructing the inner routing filter structure, an original Bloom Filter is set as the outer filter in its outer layer. The function of the original Bloom Filter is to perform a quick member query on all routing entries to determine whether an entry may exist, thereby avoiding direct access to the inner counting Bloom Filter. The original Bloom Filter uses There are preset hash functions, each of which maps a routing entry to a When inserting an entry into a bit array of bits, the operation is as follows:
[0157] ;
[0158] in, Indicated by Hash functions Whether the calculated position is set to 1. By inserting the routing entry into the original Bloom Filter, a two-layer filtering structure is obtained: the inner counting Bloom Filter is responsible for recording the access frequency and mode of the entry, while the outer original Bloom Filter is responsible for quickly determining whether an entry may exist. Based on the two-layer filtering structure, the routing entry mapping function of the inner filter is further set to record the routing access status of each network interface. For each new network access request, a member query is performed through the outer original BloomFilter. If all mapping positions in the bit array are set to 1, it is considered that the entry exists in the routing table. At this time, the inner counting Bloom Filter is entered to obtain more detailed information. Suppose For the routing entry that needs to be queried, the query operation is as follows:
[0159] ;
[0160] In the inner counting Bloom Filter, by recording the access count value of each network segment , get the inner routing table state matrix Each element in the inner routing table state matrix Indicates The routing entry is in The access counts at each position can fully reflect the access mode of each interface in the network. After obtaining the state matrix of the inner routing table, set the network segment retrieval function of the outer filter, and use the original Bloom Filter to perform member query to determine whether a request needs to be forwarded. For the entries that need to be forwarded, the state count of the inner routing table is used to determine which entries are hot entries with high frequency access and which are cold entries with low frequency access, and decide whether they need to be optimized in the network topology. For example, if a routing entry has a very high access count value in the inner counting Bloom Filter, it means that the entry is the route of an important node in the network, and its path needs to be further optimized to avoid overload. Match the filtering results of the outer routing table with the topological state of the current network. The network topological state describes the connection status of the current router with other network nodes, link bandwidth and other information. The routing table entries are updated through dynamic routing protocols to obtain the optimized routing table. Dynamic routing protocols (such as OSPF and BGP) adjust the entries in the routing table according to the real-time status of the network to ensure that the forwarding path of the traffic is optimal. For example, if the load of a link is , the link bandwidth is , then the load factor of the link is expressed as:
[0161] ;
[0162] When the load factor Exceeding a certain threshold When the dynamic routing protocol tries to find other available links to share the traffic, in order to reduce the load of the current link. In this way, the entries in the routing table are optimized to make the traffic distribution in the network more balanced, avoiding the situation where some links are overloaded while other link resources are not fully utilized. Based on the optimized routing table, a traffic allocation strategy is generated to reasonably allocate the link bandwidth in the network and obtain the link bandwidth allocation result. Assume that there are a total of links, the bandwidth allocation strategy uses a bandwidth allocation matrix To indicate that Indicates source node to the The bandwidth allocation value of each destination node. The generation of the bandwidth allocation matrix needs to consider factors such as link load, bandwidth, and priority, and is solved through optimization algorithms (such as linear programming). For example, the objective function is set to maximize the minimum bandwidth allocation value in the network to improve the reliability and fairness of the entire network:
[0163] ;
[0164] The constraints include the upper bandwidth limit of the link:
[0165] ;
[0166] By solving this optimization problem, the optimal bandwidth allocation for each link is obtained, thereby ensuring the balanced distribution of traffic in the network. According to the link bandwidth allocation results, traffic control instructions are output. These traffic control instructions are used to guide the router to dynamically adjust the traffic forwarding strategy, thereby realizing link bandwidth management. For example, for a link with insufficient link bandwidth, part of the traffic is redirected to other relatively idle links through traffic control instructions to reduce the load pressure of the link. At the same time, for frequently accessed routing entries, the forwarding performance is improved by increasing the bandwidth allocation to avoid packet loss and delay caused by excessive traffic.
[0167] The above describes the real-time monitoring and early warning method of the high-speed routing in the embodiment of the present invention. The following describes the real-time monitoring and early warning system of the high-speed routing in the embodiment of the present invention. Figure 2 In one embodiment of the present invention, a real-time monitoring and early warning system for high-speed routing includes:
[0168] A collection module, used for collecting data from multiple high-speed network interfaces in the router, and generating a multi-dimensional original data sequence for each high-speed network interface;
[0169] Statistics module, used to perform traffic fluctuation analysis and packet feature statistics on multi-dimensional raw data sequences, and generate a network behavior feature set for each high-speed network interface;
[0170] The analysis module is used to input the network behavior feature set into the multi-layer attention network to perform interface correlation analysis, timing importance calculation and feature significance evaluation, and output the target feature vector of each high-speed network interface;
[0171] A judgment module is used to input the target feature vector into the network anomaly analysis model for pattern matching and threshold judgment, and generate a network anomaly alarm sequence for each high-speed network interface;
[0172] The output module is used to perform spatiotemporal state correlation analysis and fault propagation path tracing based on the network abnormality alarm sequence, and output the router fault location results.
[0173] Through the collaboration of the above components, the traffic data, hardware performance data and routing status data of the high-speed network interface are collected in an all-round way. Through time alignment and normalization processing, a standardized multi-dimensional raw data sequence is constructed. Fourier transform and wavelet decomposition are used for time-frequency domain analysis, and a comprehensive network behavior feature set is constructed by combining traffic fluctuation statistics and protocol feature analysis. A three-layer attention network architecture is adopted, including spatial attention, temporal attention and cross attention, to achieve correlation analysis and feature fusion between interfaces. Combined with deep convolutional networks and residual modules, accurate abnormal behavior identification is achieved through multi-level feature extraction and pattern matching. Based on spatiotemporal state correlation analysis and graph neural networks, a fault propagation path tracking mechanism is constructed to achieve accurate fault source location. A double-layer Bloom Filter structure is adopted to achieve efficient management and dynamic optimization of routing tables and ensure the rational allocation of network resources.
[0174] Reference Figure 3 In an embodiment of the present invention, a computer device is also provided. The computer device may be a server, and its internal structure may be as follows: Figure 3 As shown. The computer device includes a processor, a memory, a display screen, an input device, a network interface and a database connected through a system bus. Among them, the processor designed by the computer is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the corresponding data in this embodiment. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.
[0175] Those skilled in the art will understand that Figure 3 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied.
[0176] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the above method is implemented. It can be understood that the computer-readable storage medium in this embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.
[0177] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided by the present invention and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double-speed data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM.
[0178] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, systems and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0179] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the whole or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0180] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A real-time monitoring and early warning method for high-speed routing, characterized in that: The method comprises: Collect data from multiple high-speed network interfaces in the router to generate a multi-dimensional original data sequence for each high-speed network interface; Performing flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence to generate a network behavior feature set for each high-speed network interface; Input the network behavior feature set into a multi-layer attention network to perform inter-interface correlation analysis, temporal importance calculation, and feature significance evaluation, and output a target feature vector for each high-speed network interface; Inputting the target feature vector into a network anomaly analysis model for pattern matching and threshold judgment to generate a network anomaly alarm sequence for each high-speed network interface; Based on the network abnormality alarm sequence, time-space state correlation analysis and fault propagation path tracing are performed to output router fault location results; The router fault location result is characterized and a counting Bloom Filter is constructed as an inner filter, wherein the counting Bloom Filter uses a preset number of hash functions and the length of the counting bit array is N bits, so as to obtain an inner routing filter structure; the original Bloom Filter is set as an outer filter for the inner routing filter structure, wherein the original Bloom Filter uses a preset number of hash functions and the length of the bit array is M bits, so as to obtain a complete double-layer filtering structure; the routing entry mapping function of the inner filter is set based on the double-layer filtering structure, and the access count value and access mode of each network segment are recorded through the counting Bloom Filter to obtain an inner routing table state matrix; the network segment retrieval function of the outer filter is set for the inner routing table state matrix, and member query and forwarding judgment are performed through the original Bloom Filter to obtain an outer routing table filtering result; the outer routing table filtering result is matched with the network topology state, and the routing table entries are updated through a dynamic routing protocol to obtain an optimized routing table; a traffic allocation strategy is generated based on the optimized routing table to obtain a link bandwidth allocation result, and a traffic control instruction is output according to the link bandwidth allocation result.
2. The real-time monitoring and early warning method for high-speed routing according to claim 1 is characterized in that: The data collection for the multiple high-speed network interfaces in the router to generate a multi-dimensional original data sequence for each high-speed network interface includes: The flow data of each high-speed network interface is periodically sampled to obtain an interface-level data packet flow sequence, and the interface-level data packet flow sequence is subjected to protocol classification statistics and data packet size analysis to obtain interface-level flow characteristic data; Monitor the CPU occupancy rate and memory usage rate of each high-speed network interface in real time to obtain interface-level hardware performance data, and periodically scan the number of routing table entries and update frequency of each high-speed network interface to obtain interface-level routing status data; Time-aligning the interface-level traffic characteristic data, the interface-level hardware performance data, and the interface-level routing status data to obtain an interface-level multidimensional data set; Maximum and minimum value normalization processing is performed on the interface-level multidimensional data set to obtain standardized interface data, and the standardized interface data is slidingly sampled through a preset time window to obtain interface timing feature data, and a multidimensional original data sequence of each high-speed network interface is constructed based on the interface timing feature data.
3. The real-time monitoring and early warning method for high-speed routing according to claim 2 is characterized in that: The performing flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence to generate a network behavior feature set for each high-speed network interface includes: Segmenting the multi-dimensional original data sequence of each high-speed network interface to obtain an interface traffic sequence, and performing Fourier transform on the interface traffic sequence to obtain a frequency domain data matrix of each high-speed network interface; Performing time-frequency analysis and feature combination on the frequency domain data matrix to obtain multi-scale traffic features of each high-speed network interface, and performing nonlinear dimensionality reduction processing on the multi-scale traffic features to obtain a compressed feature vector of each high-speed network interface; Calculating the traffic fluctuation statistics of each high-speed network interface based on the compressed feature vector, and performing five-point smoothing filtering and inflection point detection based on the traffic fluctuation statistics to obtain the traffic mutation characteristics of each high-speed network interface; Classify and count the data packets of each high-speed network interface according to the TCP, UDP, and ICMP protocol types to obtain the protocol feature data of each high-speed network interface, and perform information entropy calculation and cluster analysis on the protocol feature data to obtain the data packet behavior characteristics of each high-speed network interface; The traffic mutation characteristics and the data packet behavior characteristics are weightedly fused to construct a network behavior feature set for each high-speed network interface.
4. The real-time monitoring and early warning method for high-speed routing according to claim 3 is characterized in that: The network behavior feature set is input into a multi-layer attention network to perform inter-interface correlation analysis, temporal importance calculation, and feature significance evaluation, and output a target feature vector for each high-speed network interface, including: The network behavior feature set of each high-speed network interface is respectively input into the first-layer spatial attention network. The first-layer spatial attention network includes 8 attention heads. Each attention head calculates the interface spatial features of each high-speed network interface through the Query matrix, the Key matrix, and the Value matrix. Inputting the interface spatial features into a second-layer temporal attention network, wherein the second-layer temporal attention network comprises four parallel temporal attention submodules, each of which uses a 512-dimensional hidden layer to perform temporal correlation calculations to obtain the temporal correlation features of each high-speed network interface; Perform multi-head self-attention calculation on the temporal correlation features, wherein the multi-head self-attention includes 6 attention heads, and the output dimension of each attention head is 64, and the feature interaction result is obtained through position encoding and scaled dot product attention mechanism; The interface space features and the corresponding feature interaction results of each high-speed network interface are input into the feature fusion layer, wherein the feature fusion layer comprises two fully connected layers, the output dimension of the first fully connected layer is 256, and the output dimension of the second fully connected layer is 128, and the ReLU activation function and Dropout operation are used respectively to obtain the fusion feature vector of each high-speed network interface; The fused feature vector is input into a cross attention layer, and the cross attention layer uses 8 attention heads to interactively model features between different interfaces to obtain inter-interface correlation features, and the inter-interface correlation features are combined with the original features to obtain an enhanced feature matrix; The feature importance of the enhanced feature matrix is calculated, a feature weight vector is obtained through a softmax function, and based on the feature weight vector, a fusion feature vector of each high-speed network interface is mapped to a dimension reduction, and a target feature vector of each high-speed network interface is output.
5. The real-time monitoring and early warning method for high-speed routing according to claim 4 is characterized in that: The step of inputting the target feature vector into a network anomaly analysis model for pattern matching and threshold judgment to generate a network anomaly alarm sequence for each high-speed network interface includes: Input the target feature vector of each high-speed network interface into the feature extraction module of the network anomaly analysis model, wherein the feature extraction module comprises three convolution layers, wherein the first convolution layer uses 32 one-dimensional convolution kernels and ReLU activation function, the second convolution layer uses 64 one-dimensional convolution kernels and ReLU activation function, and the third convolution layer uses 128 one-dimensional convolution kernels and ReLU activation function, to obtain a primary feature map; Performing feature enhancement on the primary feature map through a first-level residual module, wherein the first-level residual module includes two one-dimensional convolutional layers and a short-circuit connection, each convolutional layer uses 128 convolution kernels and a BatchNorm normalization layer to obtain a first-level enhanced feature; The first-level enhanced features are input into the second-level residual module, where the second-level residual module includes two one-dimensional convolutional layers and a short-circuit connection, each convolutional layer uses 256 convolution kernels and a BatchNorm normalization layer to obtain the second-level enhanced features; The second-level enhanced features are subjected to maximum pooling operation and feature fusion to obtain a fused feature vector, and the fused feature vector is subjected to abnormal pattern matching through a three-layer fully connected network. The output dimensions of the three-layer fully connected network are 128, 64, and 32, respectively. Each layer uses a ReLU activation function and a Dropout operation to obtain a network abnormality alarm sequence.
6. The real-time monitoring and early warning method for high-speed routing according to claim 5 is characterized in that: The performing of spatiotemporal state correlation analysis and fault propagation path tracing based on the network abnormality alarm sequence and outputting a router fault location result includes: The network abnormality alarm sequence is input into a spatiotemporal state association model, wherein the spatiotemporal state association model comprises three layers of temporal convolutional networks, each layer of which comprises 64 convolutional kernels with a kernel size of 3, and spatiotemporal features are extracted through a local receptive field to obtain a spatiotemporal state feature matrix; A topological structure analysis is performed on the spatiotemporal state feature matrix based on a graph neural network, wherein the graph neural network includes two graph convolution layers and each layer has an output dimension of 128, and a topological correlation feature is obtained through a message passing mechanism; A fault propagation directed graph is constructed based on the topological association features, fault propagation paths between interfaces are calculated, a fault propagation path set is obtained, and the fault propagation path set is input into a causal analysis network for causal relationship reasoning, and a fault causal chain is output; Fault location is performed based on the fault causal chain, the fault probability distribution of each high-speed network interface is calculated, a fault source candidate set is obtained, and the fault source candidate set is combined for multi-dimensional verification and sorting, and a router fault location result is output.
7. A real-time monitoring and early warning system for high-speed routing, characterized in that: A method for real-time monitoring and early warning of a high-speed route according to any one of claims 1 to 6, wherein the real-time monitoring and early warning system of the high-speed route comprises: A collection module, used for collecting data from multiple high-speed network interfaces in the router, and generating a multi-dimensional original data sequence for each high-speed network interface; A statistical module, used to perform flow fluctuation analysis and data packet feature statistics on the multi-dimensional original data sequence, and generate a network behavior feature set for each high-speed network interface; An analysis module, used for inputting the network behavior feature set into a multi-layer attention network to perform inter-interface correlation analysis, temporal importance calculation and feature significance evaluation, and outputting a target feature vector for each high-speed network interface; A judgment module, used for inputting the target feature vector into a network anomaly analysis model for pattern matching and threshold judgment, and generating a network anomaly alarm sequence for each high-speed network interface; The output module is used to perform spatiotemporal state correlation analysis and fault propagation path tracing based on the network abnormality alarm sequence, and output router fault location results.
8. A computer device, characterized in that: It comprises a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and is characterized in that when the processor executes the computer program, the real-time monitoring and early warning method for high-speed routing described in any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the processor is enabled to execute the real-time monitoring and early warning method for high-speed routing as claimed in any one of claims 1 to 6.
Citation Information
Patent Citations
Communication network operation and maintenance fault positioning and tracking method and system
CN119420639A