Method for generating network traffic test model and method for detecting network traffic anomaly
By generating a network traffic test model calculated using optical arrays, the lag and inefficiency problems of traditional algorithm models when processing complex network traffic is solved, and smoother and more efficient data processing is achieved.
Patent Information
- Application Number
- CN202510380142.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-28
AI Technical Summary
Traditional algorithm models are prone to lag and low data processing efficiency when dealing with complex network traffic.
By receiving network traffic data sent by the cloud server, integrating it into a training set, and using preset optical arrays to calculate the mean and variance to generate a network traffic test model. This model utilizes the high speed and parallelism of optical arrays to process instead of traditional algorithm models.
When dealing with complex network traffic, the new method not only ensures the smoothness of model operation, but also improves data processing efficiency, solving the problems of lag and low efficiency in traditional methods.
Smart Images

Figure CN119892521B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of anomaly detection technology, and in particular to a method for generating a network traffic test model and a network traffic anomaly detection method. Background Art
[0002] Network traffic refers to the amount of data transmitted in a computer network, usually packets passing through the network over a period of time, where each packet contains transmission data and control information for collaboration between different devices and applications. Therefore, in order to meet the requirements of network security and performance during data packet transmission, network traffic anomaly detection is particularly important.
[0003] In the related art, the traditional algorithm model is mainly used to detect and calculate the network traffic within a certain period of time to complete the subsequent abnormal detection of network traffic. However, in the related art, the traditional algorithm model is prone to problems such as jamming and low data processing efficiency when processing complex network traffic. Summary of the invention
[0004] The present application provides a method for generating a network traffic test model and a method for detecting network traffic anomalies, so as to at least solve the problem that traditional algorithm models in related technologies are prone to lag and low data processing efficiency when processing complex network traffic.
[0005] The present application provides a method for generating a network traffic test model, comprising:
[0006] Receive network traffic data within a preset time sent by any cloud server;
[0007] Integrate network traffic data into a network traffic training set;
[0008] Calculate the corresponding mean value according to the preset optical array and network traffic training set;
[0009] Calculate the corresponding variance based on the preset optical array and network traffic training set;
[0010] Generate a network traffic test model based on the mean, variance and network traffic training set.
[0011] The present application also provides a network traffic anomaly detection method, comprising:
[0012] Receive any network traffic test data point sent by the cloud server;
[0013] Inputting the network traffic test data points into the network traffic test model of any one of claims 1 to 9 for processing to obtain a test result;
[0014] Compare the test result with the preset traffic anomaly threshold to obtain a comparison result;
[0015] Output the comparison results to the cloud server.
[0016] The present application also provides an electronic device, comprising: a memory for storing a computer program; a processor for implementing the steps of any of the above-mentioned methods for generating a network traffic test model, or the steps of any of the methods for detecting anomalies in network traffic when executing the computer program.
[0017] The present application also provides a computer-readable storage medium, in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of any of the above-mentioned methods for generating a network traffic test model or the steps of any of the network traffic anomaly detection methods are implemented.
[0018] The present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of any of the above-mentioned methods for generating a network traffic test model, or the steps of any of the methods for detecting anomalies in network traffic.
[0019] The network traffic test model generation method and network traffic anomaly detection method provided in the embodiments of the present application receive network traffic data within a preset time sent by any cloud service end; integrate the network traffic data into a network traffic training set; calculate the corresponding mean according to the preset optical array and the network traffic training set; calculate the corresponding variance according to the preset optical array and the network traffic training set; generate a network traffic test model according to the mean, variance and the network traffic training set. Due to the high speed and parallelism of light, by using the network traffic test model trained with the optical array instead of the traditional algorithm model, when processing complex network traffic, not only the smoothness of the model operation is guaranteed, but also the data processing efficiency is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0021] Figure 1 A schematic diagram of an application scenario of a method for generating a network traffic test model provided in an embodiment of the present application;
[0022] Figure 2 Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 1 ;
[0023] Figure 3Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 2 ;
[0024] Figure 4 Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 3 ;
[0025] Figure 5 A flowchart of a method for detecting anomalies in network traffic provided by an embodiment of the present application;
[0026] Figure 6 A schematic diagram of the structure of a device for generating a network traffic test model provided in an embodiment of the present application;
[0027] Figure 7 A schematic diagram of the structure of a network traffic anomaly detection device provided in an embodiment of the present application;
[0028] Figure 8 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0029] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0030] It should be noted that, in the description of this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence.
[0031] Network traffic refers to the amount of data transmitted in a computer network, usually the number or size of data packets passing through the network within a period of time. Network traffic can be broken down into data packets and sent through the network before being reassembled by the sending device or computer. Each data packet contains transmission data and control information, which is used for collaboration between different devices and applications. Therefore, in order to meet the requirements of network security and performance during data packet transmission, network traffic anomaly detection is particularly important. In the related art, the network traffic within a certain period of time is mainly detected and calculated through traditional algorithm models to complete the subsequent network traffic anomaly detection. However, in the related art, the traditional algorithm model is prone to jamming and low data processing efficiency when processing complex network traffic.
[0032] In order to solve the above technical problems, the embodiments of the present application propose the following technical concepts: the inventor considers the received network traffic training set, calculates the corresponding mean and variance based on the preset optical array and the network traffic training set, and generates a network traffic test model based on the mean, variance and the network traffic training set. Compared with the traditional algorithm model, the network traffic test model is not only smooth when processing complex network traffic, but also improves data processing efficiency.
[0033] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0034] In combination with the specific application environment architecture or specific hardware architecture on which the network traffic test model generation method and the network traffic anomaly detection method are executed, the specific application environment architecture or specific hardware architecture is described herein. Figure 1 , Figure 1 The diagram is a schematic diagram of an application scenario of a method for generating a network traffic test model and a method for detecting anomalies in network traffic.
[0035] like Figure 1 As shown, the scenario includes: a cloud service end 101 and an electronic device 102.
[0036] The cloud server 101 may be a single server or a cluster of multiple servers.
[0037] The electronic device 102 may be a single device or a cluster of multiple devices.
[0038] The electronic device 102 receives the network traffic data sent by the cloud server 101; integrates the network traffic data into a network traffic training set, and calculates the corresponding mean according to the preset optical array and the network traffic training set; calculates the corresponding variance according to the preset optical array and the network traffic training set, and generates a network traffic test model according to the mean, variance and the network traffic training set.
[0039] Figure 2 Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 1 ,like Figure 2 As shown, the embodiment of the present application provides a method for generating a network traffic test model, and the method is described in detail as follows:
[0040] S201: Receive network traffic data within a preset time sent by any cloud server.
[0041] In this embodiment, the preset time may be any one of one week, two weeks, or three weeks, or may be other time.
[0042] In this embodiment, network traffic data refers to the total amount of data transmitted through the network within a certain period of time.
[0043] S202: Integrate the network traffic data into a network traffic training set.
[0044] In this embodiment, the network traffic training set includes one or more network traffic data points, and any network traffic data point has one or more network traffic features; accordingly, the network traffic training set includes:
[0045]
[0046] In the formula, is the network traffic training set; any network traffic data point , , d is the number of network traffic features.
[0047] Among them, the network traffic characteristics may be the number of packets per second, the number of bytes per second, the connection frequency, and other traffic characteristics.
[0048] S203: Calculate the corresponding mean value according to the preset optical array and network traffic training set.
[0049] In this embodiment, the preset optical array refers to an optical matrix obtained after encoding the input optical signal. The preset optical array can naturally complete the matrix-vector multiplication operation by utilizing the interference effect of light, and present the corresponding result in the form of an output optical signal.
[0050] The preset optical array may be an array composed of a Mach-Zehnder interferometer network, or may be other arrays used for optical operations.
[0051] Among them, the Mach-Zehnder interferometer is an optical instrument that uses the interference phenomenon of light for precision measurement. It is an indispensable tool in modern optical research and engineering. Its core function is that it can accurately control the amplitude and phase of optical signals to complete complex mathematical operations. Specifically, the Mach-Zehnder interferometer can be used to implement matrix-vector multiplication, which is the basic operation of many computing tasks.
[0052] The specific structure of the Mach-Zehnder interferometer is as follows: the Mach-Zehnder interferometer unit consists of two couplers and two phase shift arms, wherein the input end coupler acts as a beam splitter and the output end coupler acts as a beam combiner, both of which can be called 2×2 couplers.
[0053] The principle of Mach-Zehnder interferometer is as follows: First, the beam splitter splits the light from a single light source into two beams, each of which passes through two different phase shift arms to produce a certain phase difference. Secondly, the two beams are combined into one beam through a beam combiner to form an interference signal. Finally, according to the phase difference, constructive or destructive interference of the light amplitude can be achieved.
[0054] For example, the second-order equivalent matrix of a two-port input and two-port output Mach-Zehnder interferometer unit can be mathematically expressed as:
[0055]
[0056] In this embodiment, the mean, also called the average, is a quantity that represents the trend of a set of data. It is calculated by adding up all the values in a set of data and dividing by the number of values, reflecting the average level of the data.
[0057] S204: Calculate the corresponding variance according to the preset optical array and the network traffic training set.
[0058] In this embodiment, the variance is a mathematical characteristic that describes the degree of dispersion of a random variable near its center position, and reflects the degree of discreteness of the values of the random variable.
[0059] S205: Generate a network traffic test model according to the mean, variance and network traffic training set.
[0060] In this embodiment, the network traffic training set includes one or more network traffic data points; accordingly, step S205 is specifically: according to the joint density function, a network traffic test model is generated according to the mean, variance and each network traffic data point.
[0061] Among them, the joint density function is a function that describes the joint distribution of two or more random variables.
[0062] In this embodiment, the network traffic test model is based on an optical anomaly detection algorithm of density estimation.
[0063] In this embodiment, according to the joint density function, the network traffic test model is generated according to the mean, variance and each network traffic data point, and the calculation formula includes:
[0064]
[0065] In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
[0066] In summary, the method for generating a network traffic test model provided in this embodiment receives network traffic data within a preset time sent by any cloud service end; integrates the network traffic data into a network traffic training set; calculates the corresponding mean according to the preset optical array and the network traffic training set; calculates the corresponding variance according to the preset optical array and the network traffic training set; generates a network traffic test model according to the mean, variance and the network traffic training set. Due to the high speed and parallelism of light, by using the network traffic test model trained by the optical array instead of the traditional algorithm model, when processing complex network traffic, not only the smoothness of the model operation is guaranteed, but also the data processing efficiency is improved.
[0067] In addition, the method for generating a network traffic test model provided in this embodiment can save equipment resources and improve computing power because the network traffic test model is based on an optical anomaly detection algorithm based on density estimation.
[0068] Figure 3 Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 2 In the embodiment of the present application, Figure 2 Based on the embodiment provided, a specific implementation method for calculating the corresponding mean value according to the preset optical array and the network traffic training set in step S203 is described in detail. Figure 3 As shown, the method includes:
[0069] S301: Convert the network traffic training set into a network traffic matrix.
[0070] For example, ,in The corresponding network traffic matrix is converted into:
[0071]
[0072] S302: Decomposing the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix.
[0073] Specifically, step S302 includes:
[0074] S3021: Perform singular value decomposition on the network traffic matrix according to the preset optical array to obtain a unitary matrix, a rectangular diagonal matrix, and a complex conjugate of the unitary matrix.
[0075] In this embodiment, the preset optical array is a matrix composed of a Mach-Zehnder interferometer network; accordingly, the network traffic matrix is subjected to singular value decomposition according to the preset optical array to obtain a unitary matrix, a rectangular diagonal matrix, and a complex conjugate of the unitary matrix, and the calculation formula includes:
[0076]
[0077] In the formula, is the network traffic matrix; for The unitary matrix of for A rectangular diagonal matrix of ; for The unitary matrix The complex conjugate of .
[0078] S3022: Obtain a structural unit corresponding to a preset optical array, where the structural unit at least includes an attenuator.
[0079] In this embodiment, the structural unit further includes a tuning phase shifter.
[0080] In addition, based on step S3021, the transmission coefficient of each transmission unit is changed by tuning the phase shifter and the attenuator to achieve and , and finally realize arbitrary matrix-vector multiplication operations.
[0081] S3023: Convert the unitary matrix, the rectangular diagonal matrix, and the complex conjugate of the unitary matrix into a first unitary matrix, an attenuator array, and a second unitary matrix according to the attenuator.
[0082] S3024: Integrate the first unitary matrix, the attenuator array, and the second unitary matrix into a decomposed network traffic matrix.
[0083] S303: According to a preset mean formula, a preset normalized vector is input into the decomposed network traffic matrix for processing to obtain a mean, wherein the preset mean formula is obtained by expanding the initial mean formula according to the network traffic training set.
[0084] Specifically, according to the operation logic corresponding to the preset mean formula, the preset normalized vector is input into the decomposed network traffic matrix for measurement processing to obtain the mean.
[0085] In this embodiment, the initial mean value formula includes:
[0086]
[0087] In the formula, is the mean; M is the number of network traffic data points; is the jth network traffic feature of the ith network traffic data point, .
[0088] In this embodiment, the preset mean formula includes:
[0089]
[0090] In the formula, is the mean vector, The elements in are the mean , ; is the preset normalized vector; is the network traffic matrix.
[0091] in, Set to a normalized all-one vector.
[0092] In summary, the method for generating a network traffic test model provided in this embodiment converts a network traffic training set into a network traffic matrix; decomposes the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix; and inputs a preset normalized vector into the decomposed network traffic matrix for processing according to a preset mean formula to obtain a mean, wherein the preset mean formula is an initial mean formula expanded according to the network traffic training set, and the optical array is used to perform mean calculation, thereby improving the data processing efficiency of the subsequent network traffic test model.
[0093] Figure 4 Schematic diagram of the process of generating a network traffic test model provided in the embodiment of the present application Figure 3 In the embodiment of the present application, Figure 2 Based on the provided embodiment, the specific implementation method for calculating the corresponding variance according to the preset optical array and the network traffic training set in step S204 is described in detail. Figure 4 As shown, the method includes:
[0094] S401: Convert the network traffic training set into a network traffic matrix.
[0095] In this embodiment, the discussion on converting the network traffic training set into the network traffic matrix has been described in detail in step S301 and will not be repeated here.
[0096] S402: Decomposing the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix.
[0097] In this embodiment, the discussion on the preset optical array and the decomposition process has been described in detail in step S302, and will not be repeated here.
[0098] S403: According to the initial variance formula, each column vector of the preset centralization matrix is input into the decomposed network traffic matrix for processing to obtain the variance.
[0099] Specifically, step S403 includes:
[0100] S4031: Input each column vector of the preset centering matrix into the decomposed network traffic matrix for processing to obtain a variance information matrix.
[0101] In this embodiment, each column vector of the preset centering matrix is input into the decomposed network traffic matrix for processing to obtain the calculation formula of the variance information matrix, including:
[0102]
[0103] In the formula, is the variance information matrix, and the elements in the variance information matrix are: , ; is the preset centering matrix; is the network traffic matrix.
[0104] In this embodiment, the initial variance formula includes:
[0105]
[0106] In the formula, is the variance; M is the number of network traffic data points; is the jth network traffic feature of the ith network traffic data point, ; is the mean.
[0107] S4032: Calculate the variance according to the initial variance formula and the variance information matrix.
[0108] Specifically, step S4032 includes:
[0109] According to the operation logic of the initial variance formula, the average value of the sum of the squares of each element in each row vector in the variance information matrix is determined as the corresponding variance ,in .
[0110] In summary, the method for generating a network traffic test model provided in this embodiment converts a network traffic training set into a network traffic matrix; decomposes the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix; and inputs each column vector of the preset centering matrix into the decomposed network traffic matrix for processing according to an initial variance formula to obtain a variance. By using an optical array to perform variance calculation, the data processing efficiency of subsequent network traffic test models is improved.
[0111] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.
[0112] Figure 5 A flow chart of a method for detecting abnormal network traffic provided by an embodiment of the present application is shown in FIG. Figure 5 As shown, the embodiment of the present application provides a method for detecting network traffic anomalies, and the method is described in detail as follows:
[0113] S501: Receive any network traffic test data point sent by the cloud server.
[0114] For example, the network traffic test data points are .
[0115] S502: Input the network traffic test data points into the network traffic test model for processing to obtain test results.
[0116] Exemplarily, the network traffic test data points are input into the network traffic test model for processing to obtain the test results as follows:
[0117]
[0118] S503: Compare the test result with the preset traffic anomaly threshold to obtain a comparison result.
[0119] Specifically, step S503 includes:
[0120] S5031: Perform logarithmic transformation on the test result to obtain a transformed test result.
[0121] In this embodiment, the test result is logarithmically transformed to obtain the transformed test result, and the calculation formula includes:
[0122]
[0123] In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
[0124] Exemplarily, the test result is logarithmically transformed to obtain the transformed test result:
[0125]
[0126] S5032: Perform logarithmic transformation on the preset traffic anomaly threshold to obtain a transformed threshold.
[0127] In this embodiment, the preset flow abnormality threshold is set to , You need to set the corresponding value according to actual needs.
[0128] Specifically, the preset traffic anomaly threshold is logarithmically transformed to obtain the transformed threshold: .
[0129] S5033: Compare the converted test result with the converted abnormal threshold to obtain a comparison result.
[0130] In this embodiment, the comparison result is a normal result or an abnormal result; specifically, step S5033 specifically includes steps a to c:
[0131] Step a: Compare the converted test result with the converted abnormal threshold to determine the size of the converted test result and the converted abnormal threshold.
[0132] Step b: If the converted test result is less than the converted abnormal threshold, an abnormal result is generated.
[0133] For example, if , an abnormal result is generated.
[0134] Step c: If the converted test result is greater than or equal to the converted abnormal threshold, a normal result is generated.
[0135] For example, if , an abnormal result is generated.
[0136] S504: Output the comparison result to the cloud server.
[0137] Specifically, the normal result or the abnormal result is output to the cloud service end to complete the abnormal detection of network traffic.
[0138] In summary, the network traffic anomaly detection method provided in this embodiment receives any network traffic test data point sent by the cloud service end; inputs the network traffic test data point into the network traffic test model for processing to obtain a test result; compares the test result with a preset traffic anomaly threshold to obtain a comparison result; and outputs the comparison result to the cloud service end. Due to the high speed and parallelism of light, the corresponding network traffic data is calculated by using the network traffic test model trained by the optical array, thereby improving the efficiency of network traffic anomaly detection.
[0139] In addition, the network traffic anomaly detection method provided in this embodiment determines the test results by using a network traffic test model containing an optical array, and performs data calculation of the comparison results through classical computing based on the test results, so that optical computing and classical computing can work together and give full play to their respective advantages to achieve the purpose of saving equipment resources and improving computing power.
[0140] Figure 6 This is a schematic diagram of the structure of a device for generating a network traffic test model provided in an embodiment of the present application. Figure 6 As shown, an embodiment of the present application also provides a device for generating a network traffic test model, including: a first receiving module 601, an integration module 602, a first calculation module 603, a second calculation module 604 and a generation module 605.
[0141] The first receiving module 601 is used to receive network traffic data within a preset time sent by any cloud service end;
[0142] An integration module 602, for integrating network traffic data into a network traffic training set;
[0143] A first calculation module 603, used to calculate the corresponding mean value according to the preset optical array and the network traffic training set;
[0144] A second calculation module 604 is used to calculate the corresponding variance according to the preset optical array and the network traffic training set;
[0145] The generation module 605 is used to generate a network traffic test model according to the mean, variance and network traffic training set.
[0146] In a possible implementation, the first calculation module 603 specifically includes:
[0147] A conversion unit, used for converting a network traffic training set into a network traffic matrix;
[0148] A decomposition unit, used for decomposing the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix;
[0149] The input unit is used to input the preset normalized vector into the decomposed network traffic matrix for processing according to the preset mean formula to obtain the mean, wherein the preset mean formula is obtained by expanding the initial mean formula according to the network traffic training set.
[0150] In a possible implementation, the decomposition unit specifically includes:
[0151] A decomposition unit, used for performing singular value decomposition on the network traffic matrix according to a preset optical array to obtain a unitary matrix, a rectangular diagonal matrix and a complex conjugate of the unitary matrix;
[0152] An acquisition unit, used for acquiring a structural unit corresponding to a preset optical array, wherein the structural unit at least includes an attenuator;
[0153] a conversion unit, for converting the unitary matrix, the rectangular diagonal matrix and the complex conjugate of the unitary matrix into a first unitary matrix, an attenuator array and a second unitary matrix according to the attenuator;
[0154] The integration unit is used for integrating the first unitary matrix, the attenuator array and the second unitary matrix into a decomposed network traffic matrix.
[0155] In a possible implementation, the preset mean value formula includes:
[0156]
[0157] In the formula, is the mean vector, The elements in are the mean , ; is the preset normalized vector; is the network traffic matrix.
[0158] In a possible implementation, the second calculation module 604 specifically includes:
[0159] A conversion unit, used for converting a network traffic training set into a network traffic matrix;
[0160] A decomposition unit, used for decomposing the network traffic matrix according to a preset optical array to obtain a decomposed network traffic matrix;
[0161] The input unit is used to input each column vector of the preset centering matrix into the decomposed network traffic matrix for processing according to the initial variance formula to obtain the variance.
[0162] In a possible implementation, the input unit specifically includes:
[0163] An input unit, used for inputting each column vector of the preset centering matrix into the decomposed network traffic matrix for processing to obtain a variance information matrix;
[0164] The calculation unit is used to calculate the variance according to the initial variance formula and the variance information matrix.
[0165] In a possible implementation, each column vector of the preset centering matrix is input into the decomposed network traffic matrix for processing to obtain the calculation formula of the variance information matrix, including:
[0166]
[0167] In the formula, is the variance information matrix, and the elements in the variance information matrix are: , , ; is the preset centering matrix; is the network traffic matrix.
[0168] In one possible implementation, the network traffic training set includes one or more network traffic data points;
[0169] Accordingly, the generation module 605 is specifically used to generate a network traffic test model according to the joint density function, the mean, the variance and each network traffic data point.
[0170] In a possible implementation, according to the joint density function, the network traffic test model is generated according to the mean, variance and each network traffic data point, and the calculation formula includes:
[0171]
[0172] In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
[0173] For the description of the features in the embodiment corresponding to the device for generating a network traffic test model, please refer to the relevant description of the embodiment corresponding to the method for generating a network traffic test model, which will not be repeated here.
[0174] Figure 7 This is a schematic diagram of the structure of the network traffic anomaly detection device provided in the embodiment of the present application. Figure 7 As shown, an embodiment of the present application further provides a network traffic anomaly detection device, including: a second receiving module 701 , an input module 702 , a comparison module 703 and an output module 704 .
[0175] The second receiving module 701 is used to receive any network traffic test data point sent by the cloud service end;
[0176] An input module 702, for inputting network traffic test data points into a network traffic test model according to any one of claims 1 to 9 for processing to obtain a test result;
[0177] The comparison module 703 is used to compare the test result with the preset flow abnormality threshold to obtain a comparison result;
[0178] The output module 704 is used to output the comparison result to the cloud service end.
[0179] In a possible implementation, the comparison module 703 specifically includes:
[0180] A first conversion unit, used for performing logarithmic conversion on the test result to obtain a converted test result;
[0181] A second conversion unit, used for performing logarithmic conversion on the preset flow abnormality threshold to obtain a converted threshold;
[0182] The comparison unit is used to compare the converted test result with the converted abnormal threshold value to obtain a comparison result.
[0183] In a possible implementation, the test result is logarithmically transformed to obtain the transformed test result, and the calculation formula includes:
[0184]
[0185] In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
[0186] For the description of the features in the embodiment corresponding to the network traffic anomaly detection device, reference can be made to the relevant description of the embodiment corresponding to the network traffic anomaly detection method, which will not be repeated here.
[0187] Figure 8 This is a schematic diagram of the structure of the electronic device provided in this application. Figure 8 As shown, the electronic device provided in this embodiment includes: at least one processor 801 and a memory 802. Optionally, the electronic device further includes a communication component 803. The processor 801, the memory 802 and the communication component 803 are connected via a bus.
[0188] In the specific implementation process, at least one processor 801 executes the computer execution instructions stored in the memory 802, so that at least one processor 801 executes the steps of any of the above-mentioned network traffic test model generation methods, or any of the steps of the network traffic anomaly detection method.
[0189] The specific implementation process of the processor 801 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.
[0190] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in the application may be directly implemented as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0191] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage.
[0192] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.
[0193] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program, wherein the computer program is configured to execute the steps in any of the above-mentioned network traffic test model generation method embodiments, or the steps in any of the network traffic anomaly detection method embodiments when running.
[0194] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0195] An embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps in any of the above-mentioned network traffic test model generation method embodiments, or the steps in any of the network traffic anomaly detection method embodiments.
[0196] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, implementing the steps in any of the above-mentioned network traffic test model generation method embodiments, or the steps in any of the network traffic anomaly detection method embodiments.
[0197] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0198] The above is a detailed introduction to a method for generating a network traffic test model and a method for detecting network traffic anomalies provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.
Claims
1. A method for generating a network traffic test model, characterized in that: include: Receive network traffic data within a preset time sent by any cloud server; Integrating the network traffic data into a network traffic training set; Calculate the corresponding mean value according to the preset optical array and the network traffic training set; Calculating the corresponding variance according to the preset optical array and the network traffic training set; Generate a network traffic test model according to the mean, the variance and the network traffic training set; The network traffic training set includes one or more network traffic data points; Accordingly, generating a network traffic test model according to the mean, the variance and the network traffic training set includes: Generate a network traffic test model according to the mean, the variance and each network traffic data point according to the joint density function; The calculation formula for generating the network traffic test model according to the joint density function, the mean, the variance and each network traffic data point includes: In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
2. The method for generating a network traffic test model according to claim 1, characterized in that: The calculating the corresponding mean value according to the preset optical array and the network traffic training set includes: Converting the network traffic training set into a network traffic matrix; Decomposing the network traffic matrix according to the preset optical array to obtain a decomposed network traffic matrix; According to a preset mean formula, a preset normalized vector is input into the decomposed network traffic matrix for processing to obtain the mean, wherein the preset mean formula is an initial mean formula expanded according to the network traffic training set.
3. The method for generating a network traffic test model according to claim 2, characterized in that: Decomposing the network traffic matrix according to the preset optical array to obtain a decomposed network traffic matrix includes: Performing singular value decomposition on the network traffic matrix according to the preset optical array to obtain a unitary matrix, a rectangular diagonal matrix, and a complex conjugate of the unitary matrix; Acquire a structural unit corresponding to the preset optical array, wherein the structural unit at least includes an attenuator; converting the unitary matrix, the rectangular diagonal matrix, and the complex conjugate of the unitary matrix into a first unitary matrix, an attenuator array, and a second unitary matrix according to the attenuator; The first unitary matrix, the attenuator array and the second unitary matrix are integrated into a decomposed network traffic matrix.
4. The method for generating a network traffic test model according to claim 2, characterized in that: The preset mean value formula includes: In the formula, is the mean vector, The elements in are the mean , ; is the preset normalized vector; is the network traffic matrix.
5. The method for generating a network traffic test model according to claim 1, characterized in that: The calculating the corresponding variance according to the preset optical array and the network traffic training set includes: Converting the network traffic training set into a network traffic matrix; Decomposing the network traffic matrix according to the preset optical array to obtain a decomposed network traffic matrix; According to the initial variance formula, each column vector of the preset central matrix is input into the decomposed network traffic matrix for processing to obtain the variance.
6. The method for generating a network traffic test model according to claim 5, characterized in that: According to the initial variance formula, each column vector of the preset central matrix is input into the decomposed network traffic matrix for processing to obtain the variance, including: Input each column vector of the preset centering matrix into the decomposed network traffic matrix for processing to obtain the variance information matrix; The variance is calculated according to the variance information matrix according to an initial variance formula.
7. The method for generating a network traffic test model according to claim 6, characterized in that: The calculation formula of inputting each column vector of the preset centering matrix into the decomposed network traffic matrix for processing to obtain the variance information matrix includes: In the formula, is the variance information matrix, and the elements in the variance information matrix are: , , ; is the preset centering matrix; is the network traffic matrix.
8. A method for detecting network traffic anomaly, characterized in that: include: Receive any network traffic test data point sent by the cloud server; Inputting the network traffic test data points into the network traffic test model according to any one of claims 1 to 7 for processing to obtain a test result; Comparing the test result with a preset flow abnormality threshold to obtain a comparison result; The comparison result is output to the cloud service end.
9. The network traffic anomaly detection method according to claim 8, characterized in that: The comparing the test result with a preset flow abnormality threshold to obtain a comparison result includes: Performing logarithmic transformation on the test result to obtain a transformed test result; Performing logarithmic transformation on the preset flow abnormality threshold to obtain a transformed threshold; The converted test result is compared with the converted abnormal threshold value to obtain a comparison result.
10. The network traffic anomaly detection method according to claim 9, characterized in that: The calculation formula for performing logarithmic transformation on the test result to obtain the transformed test result includes: In the formula, is the test result corresponding to the ith network traffic test point in the network traffic test model; d is the number of network traffic features; is the jth network traffic feature of the ith network traffic data point, ; is the mean; is the standard deviation; is the variance.
11. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the method for generating a network traffic test model as described in any one of claims 1 to 7, or the method for detecting anomalies in network traffic as described in any one of claims 8 to 10, when executing the computer program.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the method for generating a network traffic test model as described in any one of claims 1 to 7, or the method for detecting anomalies in network traffic as described in any one of claims 8 to 10.
13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for generating a network traffic test model as described in any one of claims 1 to 7 or the method for detecting anomalies in network traffic as described in any one of claims 8 to 10 is implemented.
Citation Information
Patent Citations
Method for determining wireless mesh network traffic
CN110839253A
Network traffic prediction method and device, equipment and medium
CN116489038A