An abnormal traffic management method and device, electronic equipment and storage medium

By identifying and predicting the adaptive bandwidth usage requirements of abnormal traffic, and utilizing autoencoders and clustering algorithms to manage abnormal traffic in a refined manner, the problem of insufficient flexibility in existing technologies is solved, and precise and differentiated traffic control is achieved.

CN119854165BActive Publication Date: 2025-11-25CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510006024.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-11-25
Estimated Expiration
2045-01-02

AI Technical Summary

Technical Problem

Existing technologies cannot adequately adapt to highly volatile network demands, lack flexible bandwidth optimization capabilities, and struggle to provide differentiated real-time optimization measures. In particular, they are unable to finely manage abnormal traffic when faced with complex traffic types and fluctuations in intensity.

Method used

By using network traffic characteristic data, anomaly traffic and its types are identified using autoencoders and clustering algorithms. Combined with service type and load conditions, the adaptive bandwidth usage requirements of theomaly traffic are predicted, and the aomaly traffic is finely managed by adjusting the module.

Benefits of technology

It enables accurate and effective prediction of bandwidth usage demand for abnormal traffic, improves the flexibility and adaptability of the abnormal traffic optimization mechanism, and achieves refined and differentiated management of different types of abnormal traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119854165B_ABST
    Figure CN119854165B_ABST
Patent Text Reader

Abstract

The application provides an abnormal traffic management method and device, electronic equipment and computer readable storage medium, and relates to the technical field of traffic processing. The management method comprises: identifying abnormal traffic, its abnormal type and the service type of network traffic based on the traffic feature data of network traffic, wherein the network traffic comprises abnormal traffic and normal traffic; predicting the adaptive bandwidth occupation demand of abnormal traffic based on the traffic feature data of network traffic, the service type of network traffic and the abnormal type of abnormal traffic; and adjusting the current bandwidth occupation of abnormal traffic based on the adaptive bandwidth occupation demand of abnormal traffic to manage and control abnormal traffic. At least, the problems that the related art cannot fully adapt to high fluctuation network demand, lacks flexible bandwidth optimization capability, and is still insufficient in detailed traffic management are solved. The application is suitable for abnormal traffic identification and control scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of traffic processing technology, and in particular to a method, apparatus, electronic device, and computer-readable storage medium for controlling abnormal traffic. Background Technology

[0002] Current network bandwidth optimization and abnormal traffic management technologies are relatively mature and widely used in data centers, enterprise networks, and internet service providers to improve network performance and stability, and ensure the stable transmission of critical business traffic under different network loads and abnormal conditions.

[0003] Existing technologies primarily achieve stable transmission of service traffic through the following methods:

[0004] 1. A traffic control scheme based on fixed bandwidth limits mainly uses QoS (Quality of Service) policies to classify different types of traffic and set fixed bandwidth quotas to ensure the transmission stability of critical traffic. In the event of abnormal traffic in the network, QoS policies can implement traffic restrictions on low-priority traffic.

[0005] 2. A dynamic adjustment scheme based on traffic anomaly detection and early warning mainly combines the abnormal traffic detection and real-time early warning mechanisms of the intrusion detection system (IDS) and the bandwidth management system. It monitors network traffic in real time to identify abnormal traffic, triggers alarms when traffic fluctuations are abnormal, and takes temporary measures to prevent the spread of abnormal traffic.

[0006] 3. The intelligent traffic routing solution based on SD-WAN (software-defined networking in a wide area network) technology mainly utilizes a software-defined network (SDN) controller to monitor network traffic and network load in real time. It dynamically adjusts the transmission path of traffic according to the priority of different traffic and the current network status. In the event of abnormal traffic, SD-WAN prioritizes the transmission of critical business traffic and avoids high-load paths to mitigate the impact of network congestion on critical traffic.

[0007] However, traffic control schemes based on fixed bandwidth limits lack flexibility and struggle to dynamically adjust in real time according to network traffic fluctuations, exhibiting significant limitations, especially in responding to sudden abnormal traffic or network congestion. Dynamic adjustment schemes based on traffic anomaly detection and early warning are limited by the accuracy of the detection system and the adaptability of bandwidth management, often failing to provide targeted optimization for different types of abnormal traffic; especially when multiple traffic anomalies occur simultaneously, the lack of fine-grained traffic adjustment strategies can impact critical traffic. Traffic intelligent routing schemes based on SD-WAN technology lack fine-grained control mechanisms when dealing with different types of abnormal traffic, particularly when facing complex traffic types and fluctuating intensity, failing to provide differentiated optimization measures.

[0008] In summary, existing technologies cannot fully adapt to highly volatile network demands, lack flexible bandwidth optimization capabilities, and are still insufficient in terms of refined traffic management. They cannot provide differentiated real-time optimization measures when faced with complex traffic types and fluctuations in intensity. Summary of the Invention

[0009] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a method, device, electronic device and computer-readable storage medium for abnormal traffic control. The method can achieve accurate and effective prediction of the bandwidth usage requirements of abnormal traffic, thereby improving the flexibility and adaptability of the abnormal traffic optimization mechanism and realizing refined and differentiated control of different types of abnormal traffic.

[0010] In a first aspect, the present invention provides a method for controlling abnormal traffic, comprising: identifying abnormal traffic and its abnormal type and the service type of network traffic based on network traffic characteristic data, wherein network traffic includes abnormal traffic and normal traffic; predicting the adaptive bandwidth usage requirement of abnormal traffic based on network traffic characteristic data, the service type of network traffic and the abnormal type of abnormal traffic; and adjusting the current bandwidth usage of abnormal traffic based on the adaptive bandwidth usage requirement of abnormal traffic to control abnormal traffic.

[0011] Preferably, the identification of abnormal traffic and its abnormality type and the service type of network traffic based on network traffic traffic characteristic data specifically includes: identifying abnormal traffic based on network traffic traffic characteristic data, autoencoder and clustering algorithm; classifying abnormal traffic to obtain the abnormality type of abnormal traffic, wherein the abnormality type includes DDoS attack traffic, overload traffic, abnormal traffic, scanning traffic and protocol abuse traffic; and classifying network traffic by service to obtain the service type of network traffic.

[0012] Preferably, the identification of abnormal traffic based on network traffic feature data, autoencoder, and clustering algorithm specifically includes: evaluating the network traffic feature data based on the autoencoder to obtain the degree of deviation of the network traffic; performing cluster analysis on the network traffic feature data based on the clustering algorithm to identify the network traffic patterns, wherein the traffic patterns include normal traffic patterns, peak traffic patterns, abnormal traffic patterns, periodic traffic patterns, burst traffic patterns, long-term traffic patterns, and session traffic patterns; and identifying abnormal traffic based on the degree of deviation and traffic patterns of the network traffic.

[0013] Preferably, the traffic characteristic data includes current bandwidth usage. The prediction of adaptive bandwidth usage requirements for abnormal traffic based on network traffic characteristic data, network traffic service type, and abnormal traffic anomaly type specifically includes: determining a weighting factor for abnormal traffic based on the anomaly type; calculating a traffic intensity threshold for abnormal traffic based on the weighting factor; classifying network traffic into critical service traffic and non-critical service traffic based on the service type, and calculating the current bandwidth usage of all critical service traffic; determining whether abnormal traffic is critical service traffic; and, in response to abnormal traffic being critical service traffic, predicting adaptive bandwidth usage requirements for abnormal traffic based on network traffic characteristic data, the current bandwidth usage of all critical service traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold.

[0014] Preferably, the traffic characteristic data further includes current traffic throughput, maximum physical link transmission capacity, and maximum bandwidth capacity. The prediction of adaptive bandwidth demand for abnormal traffic based on network traffic characteristic data, current bandwidth usage of all critical service traffic, weighting factors for abnormal traffic, and traffic intensity thresholds specifically includes: calculating the actual utilization rate of network traffic based on current network traffic throughput and maximum physical link transmission capacity; calculating the load factor of network traffic based on actual network traffic utilization and maximum bandwidth capacity; calculating the adaptive adjustment coefficient of abnormal traffic based on the load factor of network traffic, current bandwidth usage of all critical service traffic, weighting factors for abnormal traffic, and traffic intensity thresholds; and calculating the adaptive bandwidth demand for abnormal traffic based on current bandwidth usage and the adaptive adjustment coefficient.

[0015] Preferably, the calculation of the adaptive adjustment coefficient for abnormal traffic based on the network traffic load factor, the current bandwidth usage of all critical service traffic, and the weighting factor and traffic intensity threshold of abnormal traffic specifically includes: calculating the adaptive adjustment coefficient for abnormal traffic according to formula (1):

[0016]

[0017] Where, ΔB critical The adaptive adjustment coefficient for abnormal traffic is represented by α, where α represents the current bandwidth usage of all critical business traffic. traffic The weighting factor for abnormal traffic is represented by Traffic Limit, which represents the traffic intensity threshold for abnormal traffic, and Network Load Factor, which represents the network traffic load factor.

[0018] Preferably, after determining whether the abnormal traffic is critical business traffic, the abnormal traffic control method further includes: calculating the total bandwidth usage of network traffic and the current bandwidth usage of all non-critical business traffic; in response to the abnormal traffic being non-critical business traffic, predicting the adaptive bandwidth usage requirement of the abnormal traffic based on the total bandwidth usage of network traffic, the current bandwidth usage of all critical business traffic and all non-critical business traffic, as well as the weighting factor and traffic intensity threshold of the abnormal traffic.

[0019] Secondly, the present invention also provides an abnormal traffic control device, comprising an identification module, a prediction module, and an adjustment module. The identification module is used to identify abnormal traffic and its abnormal type and the service type of the network traffic based on network traffic characteristic data, wherein the network traffic includes abnormal traffic and normal traffic. The prediction module, connected to the identification module, is used to predict the adaptive bandwidth usage requirement of the abnormal traffic based on the network traffic characteristic data, the abnormal type of the abnormal traffic, and the service type of the network traffic. The adjustment module, connected to the determination module, is used to adjust the current bandwidth usage of the abnormal traffic based on the adaptive bandwidth usage requirement of the abnormal traffic, so as to control the abnormal traffic.

[0020] Thirdly, the present invention also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the abnormal traffic control method provided in the first aspect above.

[0021] Fourthly, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the abnormal traffic control method provided in the first aspect above.

[0022] This invention provides a method, apparatus, electronic device, and computer-readable storage medium for managing abnormal traffic. By utilizing network traffic characteristic data, it can accurately identify abnormal traffic and its anomaly type, as well as the service type and load status of the network traffic. Using abnormal traffic and its anomaly type, service type, and load status as the basis for predicting adaptive bandwidth usage requirements for abnormal traffic, it achieves accurate and effective prediction of bandwidth usage requirements for different types (including anomaly types and service types) and different load conditions. Furthermore, based on the adaptive bandwidth usage requirements of abnormal traffic, it enables refined and differentiated management of abnormal traffic. Therefore, this invention can achieve accurate and effective prediction of bandwidth usage requirements for abnormal traffic, thereby improving the flexibility and adaptability of the abnormal traffic optimization mechanism and achieving refined and differentiated management of different types of abnormal traffic. Attached Figure Description

[0023] Figure 1 This is a flowchart of an abnormal traffic control method according to Embodiment 1 of the present invention;

[0024] Figure 2 This is a schematic diagram of the structure of an abnormal traffic control system according to Embodiment 1 of the present invention;

[0025] Figure 3 This is a schematic diagram of the structure of an abnormal traffic control device according to Embodiment 2 of the present invention. Detailed Implementation

[0026] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0027] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.

[0028] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.

[0029] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.

[0030] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.

[0031] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.

[0032] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.

[0033] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.

[0034] Example 1:

[0035] like Figure 1 As shown, this embodiment provides a method for controlling abnormal traffic.

[0036] In this embodiment, the abnormal traffic control method is applied to an abnormal traffic control system, such as... Figure 2 As shown, the abnormal traffic control system includes a data collection and preprocessing module 1, a dual-level abnormal traffic detection module 2, an abnormal parameter calculation module 3, a traffic classification module 4, and a bandwidth optimization module 5.

[0037] Methods for controlling abnormal traffic include:

[0038] S101, based on network traffic characteristic data, identifies abnormal traffic and its abnormal type, as well as the service type of network traffic, where network traffic includes abnormal traffic and normal traffic.

[0039] In this embodiment, a dual-level abnormal traffic detection module is used to detect abnormal traffic based on the traffic characteristic data of network traffic. As shown in Table 1, potential problems in network traffic (such as network congestion, packet loss, and attacks) can be detected in a timely manner, and normal and abnormal traffic, as well as their service types and abnormal types of abnormal traffic, can be identified.

[0040] Table 1 shows the abnormal traffic detection based on network traffic characteristics data.

[0041]

[0042] It should be noted that before performing abnormal traffic detection on the network traffic characteristic data through the dual-level abnormal traffic detection module, this embodiment also collects network traffic data through a data collection and preprocessing module, and performs data preprocessing and feature extraction on the network traffic data to obtain network traffic characteristic data. The data collection and preprocessing module includes, but is not limited to, the traffic monitoring tool NetFlow and the signal analysis tool Wireshark deployed on key nodes of core routers, switches, and data centers. Network traffic data includes, but is not limited to, bandwidth usage, transmission rate, packet loss, latency, IP address, port number, packet size, traffic direction, timestamp, and RTT (Round Trip Time). Networks include, but are not limited to, communication networks, mobile networks, and Wi-Fi. Data preprocessing includes, but is not limited to, noise reduction and normalization. As shown in Table 1, traffic characteristic data includes, but is not limited to, traffic volume, request frequency, bandwidth usage, latency and packet loss rate, traffic patterns, protocol, and port.

[0043] After preprocessing the network traffic data to obtain the network traffic characteristic data, this embodiment also uses the distributed data storage platform Apache Kafka to store the network traffic data and network traffic characteristic data in real time.

[0044] Specifically, S101: Based on network traffic characteristic data, identify abnormal traffic and its abnormality type, as well as the service type of the network traffic, including steps S1011-S1013:

[0045] S1011 identifies abnormal traffic based on network traffic feature data, autoencoders, and clustering algorithms.

[0046] Specifically, S1011: Identifying abnormal traffic based on network traffic characteristic data, autoencoders, and clustering algorithms, including: evaluating network traffic characteristic data based on autoencoders to obtain the degree of deviation of network traffic; performing cluster analysis on network traffic characteristic data based on clustering algorithms to identify network traffic patterns, wherein traffic patterns include normal traffic patterns, peak traffic patterns, abnormal traffic patterns, periodic traffic patterns, burst traffic patterns, long-term traffic patterns, and session traffic patterns; and identifying abnormal traffic based on the degree of deviation and traffic patterns of network traffic.

[0047] In this embodiment, based on an autoencoder, the traffic characteristic data of network traffic is evaluated to obtain the degree of deviation of network traffic. Specifically, this includes: ① a loss function formula based on the autoencoder. Reconstruct all traffic feature data points using Autoencoder to obtain the reconstruction error for each traffic feature data point. Where x is each traffic feature data point, It is the output of the Autoencoder reconstruction for each traffic feature data point, x1, x2, ..., x n These are the features of traffic characteristic data point x in various dimensions. This is the corresponding feature output reconstructed by the Autoencoder. ② According to the formula... Calculate the mean μ of the reconstruction errors of all training traffic feature data points. reconstruction Then, according to the formula Reconstruction Error(x i )-μ reconstruction Calculate the bias level for each traffic feature data point, where N represents the total number of training traffic feature data points, and Reconstruction Error(x) i ) represents the i-th training traffic feature data point x i Reconstruction error.

[0048] Clustering algorithms include, but are not limited to, the k-means algorithm. Taking the k-means algorithm as an example, based on this algorithm, network traffic characteristic data is clustered to identify network traffic patterns. Specifically, this includes: ① k clusters from the k-means algorithm, each cluster representing a traffic pattern, with the cluster center (centroid) representing typical traffic characteristic data of the pattern. ② According to the formula d(x j ,μ i )=||x j -μ i ||, calculate each flow characteristic data point x j With cluster center μ i The distance d(x) between j ,μ i ) ) Based on each flow characteristic data point x j With cluster center μ i The distance d(x) between j ,μ i ) Assign each traffic feature data point to the nearest cluster, and calculate the mean of all traffic feature data points in each cluster as the new cluster center. ④ Repeat steps ② and ③ until the cluster center no longer changes or the predetermined number of iterations is reached.

[0049] Based on the degree of deviation and traffic patterns of network traffic, abnormal traffic is identified, specifically including: ① based on the degree of deviation of each traffic feature data point and the reconstruction error threshold E. threshold ① Determine whether each traffic feature data point is abnormal. ② Since normal traffic tends to cluster, while abnormal traffic appears at the edge of clusters or far from any cluster center, the more distinct the traffic pattern of normal traffic, the more ambiguous the traffic pattern of abnormal traffic. Therefore, traffic feature data point x j With cluster center μ i The greater the distance, the more likely the traffic feature data point is to be an anomaly. This embodiment sets a distance threshold and determines whether a traffic feature data point is abnormal based on the threshold and the distance between the traffic feature data point and the cluster center. ③ Combining the judgment results of steps ① and ② (anomaly label (yes / no)), the final anomaly identification result is formed. Specifically: if the traffic feature data point is marked as anomaly in both steps ① and ②, it can be determined that the traffic feature data point is abnormal traffic; if the traffic feature data point is marked as anomaly in either step ① or ②, it will be listed as potential abnormal traffic for subsequent manual or further processing. This embodiment uses Autoencoder and clustering algorithms to collaboratively identify abnormal traffic, improving the accuracy of abnormal traffic identification.

[0050] Based on the degree of deviation of each traffic characteristic data point and the reconstruction error threshold E threshold To determine whether each traffic feature data point is abnormal, specifically, this includes determining whether the deviation of each traffic feature data point exceeds the reconstruction error threshold E. threshold If the deviation of each traffic feature data point is greater than the reconstruction error threshold E threshold That is, Reconstruction Error(x) i E threshold If so, the current traffic feature data point is determined to be abnormal traffic, and the current traffic feature data point will be marked as abnormal.

[0051] Based on the distance threshold and the distance between the traffic feature data point and the cluster center, it is determined whether the traffic feature data point is abnormal traffic. Specifically, this includes determining d(x) j ,μ i Is it greater than μ? distince +α·σ distince , where μ distince σ represents the average distance between all training traffic feature data points and the cluster center. distince The standard deviation of the distance between all training traffic feature data points and the cluster center is represented by d(x), and α is the adjustment parameter, which takes a value of 2; if d(x j ,μ i (Exceeding μ)distince +α·σ distince Then we consider x j This is abnormal traffic.

[0052] It should be noted that E threshold This is the threshold value set for abnormal traffic, used to determine whether a data point belongs to abnormal traffic. This embodiment is based on formula E. threshold =μ reconstruction +β·σ reconstruction Calculate the reconstruction error threshold E threshold , where σ reconstruction This represents the standard deviation of the reconstruction error for all training traffic feature data points. β represents the sensitivity adjustment coefficient, with a value of 2. β indicates the leniency of the reconstruction error threshold. Adjusting β controls the sensitivity of the reconstruction error threshold. If β increases, the reconstruction error threshold also increases, thereby reducing false alarms (misclassifying normal data as abnormal data). If β is small, the reconstruction error threshold is low, and more abnormal data will be captured.

[0053] S1012 classifies abnormal traffic to obtain the abnormal types of abnormal traffic. The abnormal types include DDoS attack traffic, overload traffic, abnormal traffic, scanning traffic, and protocol abuse traffic.

[0054] In this embodiment, after accurately identifying abnormal traffic, the traffic feature data of abnormal traffic is clustered again using the k-means algorithm. After clustering, cluster labels of the traffic feature data of abnormal traffic are obtained. Similarly, just as k clusters in the k-means algorithm represent k traffic patterns, the cluster labels of the traffic feature data of abnormal traffic can represent the abnormal type of abnormal traffic. As shown in Table 2, different abnormal types (such as DDoS attacks, overload traffic, abnormal traffic, scanning traffic, and protocol abuse traffic) have different characteristics.

[0055] Table 2 Characteristics of different abnormal types

[0056]

[0057]

[0058] It should be noted that after the re-clustering is completed, the distribution and size of the clusters can be used to determine the abnormal type and severity of the abnormal traffic. For example, DDoS attack traffic usually forms a very large cluster, while overload traffic is distributed in multiple clusters.

[0059] S1013, classify network traffic by service to obtain the service type of network traffic.

[0060] In this embodiment, the network traffic is classified into service types by the traffic classification module to obtain the service types of the network traffic. The service types include, but are not limited to, real-time traffic (such as voice and video calls), file downloads, high-priority application traffic (such as financial transactions and telemedicine), network backup, applications with strict requirements on latency and bandwidth, and some application traffic that tolerates latency (such as batch data transmission).

[0061] Specifically, traffic characteristic data includes current bandwidth usage.

[0062] S102, based on network traffic characteristic data, network traffic service type, and abnormal type of abnormal traffic, predicts adaptive bandwidth usage requirements for abnormal traffic.

[0063] Specifically, S102: Based on network traffic characteristic data, network traffic service type, and abnormal traffic anomaly type, predict the adaptive bandwidth usage demand of abnormal traffic, including steps S1021-S1025:

[0064] S1021, Determine the weighting factor of abnormal traffic based on the abnormality type of abnormal traffic.

[0065] In this embodiment, based on the varying degrees of impact on bandwidth (including severity, network congestion level, and attack scale) of each anomaly type, a weighting factor corresponding to each anomaly type needs to be pre-defined, for example: α DDos α Overload α Scan These represent the weighting factors corresponding to DDoS attacks, overload traffic, and abnormal traffic, respectively. Therefore, the anomaly parameter calculation module can match the weighting factor of abnormal traffic based on the anomaly type.

[0066] S1022, Calculate the flow intensity threshold of abnormal flow based on the weighting factor of abnormal flow.

[0067] In this embodiment, the Traffic Limit is typically used as a proportional factor for dynamically adjusting bandwidth usage. It is primarily calculated based on the traffic intensity of abnormal traffic. Its purpose is to ensure that when abnormal traffic occurs, its impact on network performance can be controlled through reasonable bandwidth adjustments. Traffic intensity refers to the proportion of current traffic to total traffic at a given moment. The higher the traffic intensity of abnormal traffic, the smaller the Traffic Limit should be to avoid a large amount of abnormal traffic affecting the overall network performance. Different types of abnormal traffic have different Traffic Limits. For example, DDoS attack traffic can cause a sharp drop in network bandwidth; therefore, the Traffic Limit for DDoS attack traffic should be set to a very small value, while the Traffic Limit for traffic deviating from normal traffic should be relatively large. The abnormal parameter calculation module can also calculate the threshold based on the formula... Calculate the Traffic Limit, the threshold for abnormal traffic flow, where... This indicates the flow intensity of abnormal flow.

[0068] S1023, based on the service type of network traffic, divides network traffic into critical service traffic and non-critical service traffic, and calculates the current bandwidth usage of all critical service traffic.

[0069] In this embodiment, critical service traffic generally refers to traffic that is essential for the normal operation of the system, while non-critical service traffic is relatively less sensitive. Therefore, critical service types and non-critical service types can be predefined based on the nature of the traffic and service quality requirements, as shown in Table 3. Then, based on the predefined critical and non-critical service types and the service type of network traffic, network traffic is divided into critical service traffic and non-critical service traffic. Network traffic includes abnormal traffic and normal traffic, both of which can be further divided into critical service traffic and non-critical service traffic, i.e., abnormal critical service traffic, abnormal non-critical service traffic, normal critical service traffic, and normal non-critical service traffic. The current bandwidth usage of all critical service traffic is the sum of the current bandwidth usage of abnormal critical service traffic and normal critical service traffic. For example, if network traffic includes four types of traffic: service A, B, C, and D, where service A and service B are critical service types, and services C and D are non-critical service types, then the current bandwidth usage of all critical service traffic is the sum of the current bandwidth usage of service A and service B.

[0070] Table 3 Key Business Types and Non-Key Business Types

[0071]

[0072] S1024, determine whether abnormal traffic is critical business traffic.

[0073] In this embodiment, based on Table 3 and the service type of the abnormal traffic, it can be determined whether the abnormal traffic is critical service traffic. If service A traffic is abnormal traffic, then the abnormal traffic is determined to be critical service traffic.

[0074] S1025, in response to abnormal traffic being critical business traffic, predicts adaptive bandwidth usage requirements for abnormal traffic based on network traffic characteristic data, current bandwidth usage of all critical business traffic, weighting factors of abnormal traffic, and traffic intensity thresholds.

[0075] Optionally, traffic characteristic data may also include current traffic throughput, maximum physical link transmission capacity, and maximum bandwidth capacity.

[0076] Specifically, based on network traffic characteristic data, the current bandwidth usage of all critical service traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold, the adaptive bandwidth usage demand of abnormal traffic is predicted. This includes: calculating the actual utilization rate of network traffic based on the current throughput of network traffic and the maximum transmission capacity of physical links; calculating the load factor of network traffic based on the actual utilization rate of network traffic and the maximum bandwidth capacity; calculating the adaptive adjustment coefficient of abnormal traffic based on the load factor of network traffic, the current bandwidth usage of all critical service traffic, and the weighting factor and traffic intensity threshold of abnormal traffic; and calculating the adaptive bandwidth usage demand of abnormal traffic based on the current bandwidth usage and the adaptive adjustment coefficient.

[0077] In this embodiment, the load factor is used to characterize the impact of the current network state on bandwidth demand, reflecting the current network load. If the current network load is high, more bandwidth is needed to ensure critical traffic, therefore, the load factor is high; if the current network load is low, the bandwidth adjustment is smaller, and the load factor is low. A higher load factor indicates that the network is under full load, and if abnormal traffic occurs, it will have a greater impact on normal service traffic, therefore, a larger bandwidth adjustment is needed to ensure the transmission of critical service traffic. Therefore, based on the traffic characteristic data of network traffic, the current bandwidth usage of all critical service traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold, the adaptive bandwidth usage demand of abnormal traffic is predicted, specifically including: ① Calculating the actual utilization rate and load factor of network traffic through the abnormal parameter calculation module, which can usually be done using the formula The calculation is performed where Network Load Factor represents the load factor of network traffic, Current Network Utilization represents the actual utilization rate of network traffic, and Maximum Networkcapacity represents the maximum bandwidth capacity of network traffic.

[0078] Specifically, based on the network traffic load factor, the current bandwidth usage of all critical business traffic, and the weighting factor and traffic intensity threshold of abnormal traffic, the adaptive adjustment coefficient of abnormal traffic is calculated, including: calculating the adaptive adjustment coefficient of abnormal traffic according to formula (1):

[0079]

[0080] Where, ΔB critical The adaptive adjustment factor represents abnormal traffic; Critical Traffic Bandwidth represents the current bandwidth usage of all critical business traffic; α traffic The weighting factor for abnormal traffic is represented by Traffic Limit, which represents the traffic intensity threshold for abnormal traffic, and Network Load Factor, which represents the network traffic load factor.

[0081] In this embodiment, based on network traffic characteristic data, the current bandwidth usage of all key business traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold, the adaptive bandwidth usage requirement of abnormal traffic is predicted. The method further includes: ② calculating the adaptive adjustment coefficient ΔB of abnormal traffic according to formula (1). critical ③ According to the formula Bandwidth ajuested =Current Traffic Bandwidth+ΔB critical Calculate the adaptive bandwidth usage requirement for abnormal traffic (Bandwidth) ajuested Where Current Traffic Bandwidth represents the current bandwidth usage of abnormal traffic.

[0082] Optionally, after determining whether abnormal traffic is critical business traffic in S1024, the methods for controlling abnormal traffic also include:

[0083] S1026, calculate the total bandwidth usage of network traffic and the current bandwidth usage of all non-critical business traffic.

[0084] In this embodiment, similarly, the current bandwidth usage of all critical service traffic is the sum of the current bandwidth usage of abnormal critical service traffic and normal critical service traffic, and the current bandwidth usage of all non-critical service traffic is the sum of the current bandwidth usage of abnormal non-critical service traffic and normal non-critical service traffic.

[0085] S1027, in response to abnormal traffic being non-critical business traffic, predicts adaptive bandwidth usage requirements for abnormal traffic based on the total bandwidth usage of network traffic, the current bandwidth usage of all critical business traffic and all non-critical business traffic, and the traffic intensity threshold of abnormal traffic.

[0086] In this embodiment, based on the total bandwidth usage of network traffic, the current bandwidth usage of all critical service traffic and all non-critical service traffic, and the traffic intensity threshold of abnormal traffic, the adaptive bandwidth usage requirement of abnormal traffic is predicted. Specifically, this includes: according to the formula Bandwidth adjusted =min(Total Available Bandwidth, CriticalTraffic Bandwidth + (Nom - Critical Traffic Bandwidth × Traffic Limit)), calculates the adaptive bandwidth requirement for abnormal traffic. adjusted Wherein, Total Available Bandwidth represents the total bandwidth usage of network traffic, Critical Traffic Bandwidth represents the current bandwidth usage of all critical service traffic, and Non-Critical Traffic Bandwidth represents the current bandwidth usage of all non-critical service traffic. This embodiment employs different bandwidth calculation methods for abnormal traffic of critical service types and abnormal traffic of non-critical service types. For abnormal traffic of critical service types, the adaptive bandwidth usage calculation is more refined and accurate, while for abnormal traffic of non-critical service types, the calculation efficiency is high. This achieves accurate and effective prediction of bandwidth usage requirements for abnormal traffic, thereby improving the flexibility and adaptability of the abnormal traffic optimization mechanism and enabling refined and differentiated management of different types of abnormal traffic.

[0087] S103 adjusts the current bandwidth usage of abnormal traffic based on the adaptive bandwidth usage requirements of abnormal traffic in order to manage abnormal traffic.

[0088] In this embodiment, the bandwidth optimization module adjusts the current bandwidth usage of abnormal traffic to the adaptive bandwidth usage requirement of abnormal traffic in order to manage abnormal traffic.

[0089] This embodiment provides a method for managing abnormal traffic. By utilizing network traffic characteristic data, it can accurately identify abnormal traffic and its anomaly type, as well as the service type and load status of the network traffic. Using these factors, it predicts the adaptive bandwidth usage requirements of abnormal traffic, enabling precise and effective prediction of bandwidth usage requirements for different types (including anomaly types and service types) and under different load conditions. Based on this adaptive bandwidth usage requirement, it allows for refined and differentiated management of abnormal traffic. Therefore, this invention achieves accurate and effective prediction of bandwidth usage requirements for abnormal traffic, thereby improving the flexibility and adaptability of the abnormal traffic optimization mechanism and enabling refined and differentiated management of different types of abnormal traffic.

[0090] Example 2:

[0091] like Figure 3 As shown, this embodiment provides an abnormal traffic management device, including an identification module 31, a prediction module 32, and an adjustment module 33. The identification module 31 is used to identify abnormal traffic and its abnormal type and the service type of network traffic based on network traffic characteristic data, wherein network traffic includes abnormal traffic and normal traffic. The prediction module 32 is connected to the identification module 31 and is used to predict the adaptive bandwidth usage requirement of abnormal traffic based on network traffic characteristic data, abnormal traffic abnormal type, and network traffic service type. The adjustment module 33 is connected to the determination module 32 and is used to adjust the current bandwidth usage of abnormal traffic based on the adaptive bandwidth usage requirement of abnormal traffic to manage abnormal traffic.

[0092] Specifically, the identification module 31 includes: an identification unit 311, an anomaly classification unit 312, and a service classification unit 313. The identification unit 311 is used to identify abnormal traffic based on network traffic feature data, autoencoders, and clustering algorithms. The anomaly classification unit 312 is used to classify abnormal traffic to obtain the anomaly type of the abnormal traffic. The anomaly type includes DDoS attack traffic, overload traffic, abnormal traffic, scanning traffic, and protocol abuse traffic. The service classification unit 313 is used to classify network traffic to obtain the service type of the network traffic.

[0093] Specifically, the identification unit 311 includes: an evaluation subunit, a clustering subunit, and an identification subunit. The evaluation subunit is used to evaluate the traffic characteristic data of network traffic based on an autoencoder to obtain the degree of deviation of network traffic. The clustering subunit is used to perform cluster analysis on the traffic characteristic data of network traffic based on a clustering algorithm to identify the traffic patterns of network traffic. The traffic patterns include normal traffic patterns, peak traffic patterns, abnormal traffic patterns, periodic traffic patterns, burst traffic patterns, long-term traffic patterns, and session traffic patterns. The identification subunit is used to identify abnormal traffic based on the degree of deviation and traffic patterns of network traffic.

[0094] Specifically, the prediction module 32 includes: a determination unit 321, a first calculation unit 322, a partitioning unit 323, a judgment unit 324, and a second calculation unit 325. The determination unit 321 is used to determine the weighting factor of abnormal traffic based on the abnormality type of the abnormal traffic. The first calculation unit 322 is used to calculate the traffic intensity threshold of abnormal traffic based on the weighting factor of abnormal traffic. The partitioning unit 323 is used to partition network traffic into critical service traffic and non-critical service traffic based on the service type of network traffic, and calculate the current bandwidth usage of all critical service traffic. The judgment unit 324 is used to determine whether the abnormal traffic is critical service traffic. The second calculation unit 324 is used to predict the adaptive bandwidth usage requirement of abnormal traffic based on the traffic characteristic data of network traffic, the current bandwidth usage of all critical service traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold in response to the abnormal traffic being critical service traffic.

[0095] Specifically, the second calculation unit 324 includes: a first calculation subunit, a second calculation subunit, a third calculation subunit, and a fourth calculation subunit. The first calculation subunit is used to calculate the actual utilization rate of network traffic based on the current traffic throughput and the maximum transmission capacity of the physical link. The second calculation subunit is used to calculate the load factor of network traffic based on the actual utilization rate of network traffic and the maximum bandwidth capacity. The third calculation subunit is used to calculate the adaptive adjustment coefficient of abnormal traffic based on the load factor of network traffic, the current bandwidth occupancy of all critical business traffic, and the weight factor and traffic intensity threshold of abnormal traffic. The fourth calculation subunit is used to calculate the adaptive bandwidth occupancy requirement of abnormal traffic based on the current bandwidth occupancy of abnormal traffic and the adaptive adjustment coefficient.

[0096] Specifically, the third calculation subunit includes: a first minimum calculation unit, used to calculate the adaptive adjustment coefficient of abnormal flow according to formula (1):

[0097]

[0098] Where, ΔB criticalThe adaptive adjustment factor represents abnormal traffic; Critical Traffic Bandwidth represents the current bandwidth usage of all critical business traffic; α traffic The weighting factor for abnormal traffic is represented by Traffic Limit, which represents the traffic intensity threshold for abnormal traffic, and Network Load Factor, which represents the network traffic load factor.

[0099] Specifically, the prediction module 32 further includes a third calculation unit 326 and a fourth calculation unit 327. The third calculation unit 326 is used to calculate the total bandwidth usage of network traffic and the current bandwidth usage of all non-critical business traffic. The fourth calculation unit 327 is used to predict the adaptive bandwidth usage requirement of abnormal traffic in response to the abnormal traffic being non-critical business traffic, based on the total bandwidth usage of network traffic, the current bandwidth usage of all critical business traffic and all non-critical business traffic, as well as the weighting factor and traffic intensity threshold of the abnormal traffic.

[0100] Understandably, the abnormal traffic control device provided above implements the abnormal traffic control method corresponding to Embodiment 1 provided above. Therefore, the beneficial effects it can achieve can be referred to the beneficial effects of the scheme corresponding to the abnormal traffic control method of Embodiment 1 above, which will not be repeated here.

[0101] Example 3:

[0102] This embodiment also provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to implement the abnormal traffic control method in Embodiment 1 above.

[0103] Example 4:

[0104] This embodiment also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the abnormal traffic control method in Embodiment 1 above.

[0105] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.

Claims

1. A method for controlling abnormal traffic, characterized in that, include: Based on network traffic characteristic data, abnormal traffic and its abnormality type and network traffic service type are identified, wherein the traffic characteristic data includes current bandwidth usage, and network traffic includes abnormal traffic and normal traffic. Based on the anomaly type of abnormal traffic, determine the weighting factor for abnormal traffic; Calculate the flow intensity threshold of abnormal flow based on the weighting factor of abnormal flow; Based on the service type of network traffic, network traffic is divided into critical service traffic and non-critical service traffic, and the current bandwidth usage of all critical service traffic is calculated. Determine whether abnormal traffic is critical business traffic; In response to abnormal traffic being critical business traffic, based on network traffic characteristic data, the current bandwidth usage of all critical business traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold, the adaptive bandwidth usage requirement of abnormal traffic is predicted. Based on the adaptive bandwidth usage demand of abnormal traffic, the current bandwidth usage of abnormal traffic is adjusted to manage abnormal traffic.

2. The method for controlling abnormal traffic according to claim 1, characterized in that, The network traffic characteristic data, which identifies abnormal traffic and its abnormality type, as well as the service type of the network traffic, specifically includes: Based on network traffic feature data, autoencoders, and clustering algorithms, abnormal traffic is identified. Abnormal traffic is classified into abnormal types, including DDoS attack traffic, overload traffic, abnormal traffic, scanning traffic, and protocol abuse traffic. Classify network traffic by service to obtain the service type of network traffic.

3. The method for controlling abnormal traffic according to claim 2, characterized in that, The network traffic-based traffic feature data, autoencoder, and clustering algorithm for identifying abnormal traffic specifically include: Based on an autoencoder, the traffic characteristic data of network traffic is evaluated to obtain the degree of deviation of network traffic; Based on clustering algorithms, cluster analysis is performed on network traffic characteristic data to identify network traffic patterns, including normal traffic patterns, peak traffic patterns, abnormal traffic patterns, periodic traffic patterns, burst traffic patterns, long-term traffic patterns, and session traffic patterns. Identify abnormal traffic based on the degree of deviation and traffic pattern of network traffic.

4. The method for controlling abnormal traffic according to claim 1, characterized in that, The traffic characteristic data also includes current traffic throughput, maximum physical link transmission capacity, and maximum bandwidth capacity. The method for predicting adaptive bandwidth usage requirements for abnormal traffic, based on network traffic characteristic data, current bandwidth usage of all key business traffic, weighting factors for abnormal traffic, and traffic intensity thresholds, specifically includes: Calculate the actual utilization rate of network traffic based on the current network traffic throughput and the maximum transmission capacity of physical links; Calculate the load factor of network traffic based on the actual utilization rate and maximum bandwidth capacity of network traffic; Based on the load factor of network traffic, the current bandwidth usage of all critical business traffic, and the weight factor and traffic intensity threshold of abnormal traffic, calculate the adaptive adjustment coefficient of abnormal traffic. Based on the current bandwidth usage and adaptive adjustment coefficient of abnormal traffic, calculate the adaptive bandwidth usage requirement of abnormal traffic.

5. The method for controlling abnormal traffic according to claim 4, characterized in that, The adaptive adjustment coefficient for abnormal traffic is calculated based on the network traffic load factor, the current bandwidth usage of all critical service traffic, and the weighting factor and traffic intensity threshold of abnormal traffic. Specifically, this includes: Calculate the adaptive adjustment coefficient for abnormal flow based on formula (1): (1), in, This represents the adaptive adjustment coefficient for abnormal traffic. This indicates the current bandwidth usage for all critical business traffic. Weighting factors representing abnormal traffic The flow intensity threshold represents the abnormal flow. The load factor represents network traffic.

6. The method for controlling abnormal traffic according to claim 1, characterized in that, After determining whether the abnormal traffic is critical business traffic, the process also includes: Calculate the total bandwidth usage of network traffic and the current bandwidth usage of all non-critical business traffic; In response to the fact that abnormal traffic is non-critical business traffic, the system predicts the adaptive bandwidth usage requirements of abnormal traffic based on the total bandwidth usage of network traffic, the current bandwidth usage of all critical business traffic and all non-critical business traffic, as well as the weighting factor and traffic intensity threshold of abnormal traffic.

7. A device for controlling abnormal flow, characterized in that, It includes an identification module, a prediction module, and an adjustment module. The identification module is used to identify abnormal traffic and its abnormality type, as well as the service type of the network traffic, based on network traffic characteristic data. The traffic characteristic data includes current bandwidth usage, and the network traffic includes both abnormal and normal traffic. The prediction module, connected to the identification module, is used to determine the weighting factor of abnormal traffic based on its anomaly type; calculate the traffic intensity threshold of abnormal traffic based on the weighting factor; classify network traffic into critical service traffic and non-critical service traffic based on the service type of network traffic, and calculate the current bandwidth usage of all critical service traffic; determine whether abnormal traffic is critical service traffic; and, in response to abnormal traffic being critical service traffic, predict the adaptive bandwidth usage requirement of abnormal traffic based on network traffic characteristic data, the current bandwidth usage of all critical service traffic, the weighting factor of abnormal traffic, and the traffic intensity threshold. The adjustment module, connected to the determination module, is used to adjust the current bandwidth usage of abnormal traffic based on the adaptive bandwidth usage requirements of abnormal traffic, in order to manage abnormal traffic.

8. An electronic device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to implement an abnormal traffic control method as described in any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements a method for controlling abnormal traffic as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method for dynamically adjusting Qos (Quality of Service) based on data stream

    CN117336249A

  • Traffic monitoring method and device, equipment, storage medium and program product

    CN118713868A