A Real-time Tracking and Precise Billing Method for Cloud Printing Information
By capturing and analyzing printing task data in the cloud printing environment, identifying abnormal behaviors and tracking user IDs, the problem of malicious resource occupation in the cloud printing environment is solved, and fair resource allocation and stability improvement of cloud printing services are achieved.
Patent Information
- Application Number
- CN202510387332.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-03-31
AI Technical Summary
In a cloud printing environment, users may use system features to maliciously occupy printing resources, which will affect the printing experience of normal users, and it is difficult to identify and prevent such behaviors based on page billing.
By capturing the original data information of the cloud printing task at the network transport layer, dividing it into independent data blocks, calculating the entropy value distribution of each data block, identifying abnormal behavior, generating an abnormal event notification signal, and tracking the periodic characteristics of the data flow based on the user ID, adjusting the printing task execution order and billing strategy.
Real-time identification and tracking of malicious occupation behavior is realized, ensuring fair distribution of resources, and improving the stability and commercial sustainability of cloud printing services.
Smart Images

Figure CN119902727B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of print tracking and billing, and more specifically, to a method for real-time tracking and accurate billing of cloud print information. Background Art
[0002] In a cloud printing environment, users can share efficient printing resources by remotely submitting print tasks. However, this convenience also brings potential abuse risks. For example, some users may use the characteristics of the cloud printing system to maliciously occupy the print queue and computing resources by forging print tasks, repeatedly submitting blank pages, filling with low-entropy data, etc., thus affecting the printing experience of other normal users and increasing the operating costs of cloud printing service providers. The conventional per-page billing method is difficult to effectively identify such fraudulent behaviors, resulting in some users being able to avoid normal charging rules by constructing low-information tasks, or maliciously occupying the resources of cloud printing devices by submitting periodic tasks, reducing the resource utilization rate of cloud printing.
[0003] Therefore, how to identify and track users with abnormal printing through data analysis, and establish a targeted intelligent billing strategy in combination with the resource occupation situation of abnormal users to prevent users from maliciously occupying printing resources and ensure resource fairness in the cloud printing environment is an urgent problem to be solved.
[0004] To solve the above problems, a technical solution is provided now. Summary of the Invention
[0005] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a method for real-time tracking and accurate billing of cloud print information to solve the problems proposed in the above background art.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] S1: Capture the original print data information of the print tasks to be executed in the cloud print space at the network transport layer, and divide it into continuous and equally long independent data blocks;
[0008] S2: Calculate the byte probability distribution of each data block in the memory buffer and convert it into a normalized entropy value. When it is detected that the entropy value difference between three consecutive pairs of adjacent data blocks is less than a preset abnormal entropy value difference threshold, generate an abnormal event notification signal;
[0009] S3: Add the data block information corresponding to the abnormal event notification signal to the abnormal print task processing queue;
[0010] S4: Analyze the content of the data blocks in the abnormal print task processing queue, reorganize the original data stream in chronological order with the user ID as the analysis dimension, and segmentally calculate the sequence of data stream similarity coefficients at different offsets;
[0011] S5: Perform interval consistency verification on the local peaks of the similarity coefficient sequence, determine whether the current time-ordered data stream segment has periodic characteristics, and mark the user IDs and time-ordered data stream segments with periodicity as abnormal;
[0012] S6: Monitor the user IDs and data stream segments with abnormal marks, adjust the execution order of the printing tasks based on the number of abnormal marks of the user IDs, and calculate the weight occupied by the abnormal printing time of the user IDs;
[0013] S7: Calculate the dynamic penalty coefficient for non-linear penalty billing based on the number of abnormal marks and the time weight of abnormal occupation, and generate an accurate billing statement for the user in combination with the set basic printing billing rules.
[0014] In a preferred embodiment, in S1, capturing the print raw data information of the print tasks to be executed in the cloud printing space at the network transport layer and splitting it into continuous and equally long independent data blocks specifically includes:
[0015] Set the gateway to capture the print raw data information of the print tasks to be executed in the cloud printing space at the network transport layer. The print raw data information includes the upload timestamp of the print task, the submitting user ID, and the original data stream for printing;
[0016] Split the original data stream into continuous and equally long independent data blocks according to a preset fixed length, temporarily store the split data blocks in the memory buffer, and attach the timestamp and user ID.
[0017] In a preferred embodiment, in S2, calculating the byte probability distribution of each data block in the memory buffer and converting it into a normalized entropy value, and generating an abnormal event notification signal when it is detected that the entropy value difference between three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold specifically includes:
[0018] Perform byte frequency statistics on each data block in the memory buffer, and calculate the probability distribution of the occurrence of each byte value within the data block;
[0019] Convert the probability distribution of the byte values into a normalized entropy value based on the Shannon entropy algorithm, generate an entropy value sequence with the user ID, and write it into the temporary storage area;
[0020] Preset the abnormal entropy value difference threshold, compare the entropy values of adjacent data blocks in the memory buffer, and generate an abnormal event notification signal carrying the corresponding data block information when it is detected that the entropy value difference between three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold.
[0021] In a preferred embodiment, in S3, adding the data block information corresponding to the abnormal event notification signal to the abnormal print task processing queue specifically includes:
[0022] An abnormal printing task processing queue is established. When an abnormal event notification signal is received, the corresponding data block, its upload timestamp, and user ID are encapsulated into an encrypted verification task package and added to the abnormal printing task processing queue. Meanwhile, the data block information in the memory buffer is cleared.
[0023] In a preferred embodiment, in S4, the content of the data block in the abnormal printing task processing queue is parsed, and the original data stream in chronological order is reorganized with the user ID as the analysis dimension. Calculating the sequence of data stream similarity coefficients at different offsets by segments specifically includes:
[0024] Parse the content of the encrypted verification task package in the abnormal printing task processing queue in real time, and reorganize the original data stream according to the timestamp and user ID corresponding to the data block to form a chronological data stream based on the user ID dimension;
[0025] Based on the initialized sliding window with preset window length and sliding step parameters, load the chronological data stream into the sliding window by segments according to the window length;
[0026] In the sliding window, obtain the data stream similarity coefficients at different offsets through autocorrelation calculation, generate a sequence of similarity coefficients with offset marks, and identify local peak points. The calculation formula for the data stream similarity coefficient is:
[0027]
[0028] In the formula, is the value of the i-th byte within the window length segment, is the preset window length, k is the preset offset, is the average value of all bytes in the window, is the autocorrelation similarity coefficient when the offset is k, and the value range of k is from 1 to n / 2.
[0029] In a preferred embodiment, in S5, perform interval consistency verification on the local peaks of the similarity coefficient sequence, determine whether the current chronological data stream segment has periodic characteristics, and mark the user ID and chronological data stream segment with periodicity as abnormal. Specifically includes:
[0030] Perform interval consistency verification on the local peak points in the similarity coefficient sequence at different offsets. When there is a similarity coefficient sequence at a certain offset, and the interval standard deviation between its local peak points is less than the set tolerance threshold, it is determined that the chronological data stream has periodicity, and the data stream segment within the window and the corresponding user ID are marked as abnormal.
[0031] In a preferred embodiment, in S6, monitor the user IDs and data stream segments carrying abnormal marks, adjust the execution order of print tasks based on the number of abnormal marks of the user IDs, and calculate the weight of the abnormal occupation of the print time of the user IDs. Specifically, it includes:
[0032] Set the length of the abnormal print monitoring period, extract all user IDs carrying abnormal marks and the corresponding data stream segments in the previous period of the current monitoring period, and record them as abnormal user IDs and abnormal data stream segments respectively;
[0033] Based on the ascending order of the number of abnormal marks of the abnormal user IDs, adjust the execution order of the print tasks to be executed in the cloud printing space during the current monitoring period;
[0034] Obtain the total execution duration of the print tasks corresponding to the abnormal data stream segments of each abnormal user ID, and calculate the weight of the abnormal occupation of the print time of all abnormal user IDs based on the proportion of the total execution duration of the print tasks to the length of the monitoring period.
[0035] In a preferred embodiment, in S7, calculate the dynamic penalty coefficient for non-linear penalty charging based on the number of abnormal marks and the time weight of abnormal occupation, and generate an accurate charging bill for the user in combination with the set basic print charging rule. Specifically, it includes:
[0036] Set the basic print charging rule, obtain the print tasks to be executed in the cloud printing space, and charge the print tasks submitted by the user IDs without abnormal marks according to the basic print charging rule;
[0037] For the print tasks submitted by the user IDs carrying abnormal marks, calculate the dynamic penalty coefficient for non-linear penalty charging based on the number of abnormal marks of the user ID and the weight of the abnormal occupation of the print time. The specific calculation method is:
[0038]
[0039] In the formula, is the dynamic penalty coefficient for the w-th user ID, 、 are the number of abnormal marks and the weight of the abnormal occupation of the print time corresponding to the w-th user ID respectively, is the set growth control parameter;
[0040] Multiply the dynamic penalty coefficient corresponding to each user ID carrying an abnormal mark by the basic print charging rule as the final print charge for the abnormal user ID, and generate a final charging bill.
[0041] The technical effects and advantages of a real-time tracking and accurate charging method for cloud printing information of the present invention:
[0042] By capturing and analyzing the entropy value distribution of cloud printing data streams in real time, malicious occupancy behaviors such as low-entropy forgery tasks and repeated submission tasks are accurately identified to ensure the reasonable allocation of printing resources. Tracking the periodic characteristics of data streams based on user IDs can detect abnormal submission patterns of specific users and improve the ability to identify long-term fraud behaviors. Using abnormal markers and occupancy time weights to calculate non-linear penalty coefficients, the billing strategy can be dynamically adjusted to make malicious users bear higher printing costs and prevent the abuse of resources at low costs. At the same time, combined with intelligent scheduling strategies, the execution order of printing tasks is optimized to reduce queue blocking caused by malicious tasks and improve the overall throughput efficiency of printing tasks. Fair resource allocation is achieved, avoiding unfair impacts on normal users due to malicious occupancy, and enhancing the stability and commercial sustainability of cloud printing services. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 It is a schematic diagram of a method for real-time tracking and accurate billing of cloud printing information according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0045] Embodiment 1
[0046] Figure 1 A method for real-time tracking and accurate billing of cloud printing information according to the present invention is provided, which includes the following steps:
[0047] S1: Capture the original printing data information of the printing tasks to be executed in the cloud printing space at the network transmission layer and divide it into continuous and equally long independent data blocks;
[0048] S2: Calculate the byte probability distribution of each data block in the memory buffer and convert it into a normalized entropy value. When it is detected that the entropy value difference between three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold, an abnormal event notification signal is generated;
[0049] S3: Add the data block information corresponding to the abnormal event notification signal to the abnormal printing task processing queue;
[0050] S4: Analyze the content of the data blocks in the abnormal printing task processing queue, reorganize the original data stream in chronological order with the user ID as the analysis dimension, and calculate the sequence of data stream similarity coefficients at different offsets in segments;
[0051] S5: Perform interval consistency verification on the local peaks of the similarity coefficient sequence, determine whether the current time-ordered data stream segment has periodic characteristics, and mark the user IDs and time-ordered data stream segments with periodicity as abnormal;
[0052] S6: Monitor the user IDs and data stream segments with abnormal marks, adjust the execution order of the printing tasks based on the number of abnormal marks of the user IDs, and calculate the weight of the abnormal occupation of the printing time of the user IDs at the same time;
[0053] S7: Calculate the dynamic penalty coefficient for non-linear penalty billing based on the number of abnormal marks and the time weight of abnormal occupation, and generate an accurate billing statement for the user in combination with the set basic printing billing rules.
[0054] In S1, capture the original printing data information of the printing tasks to be executed in the cloud printing space at the network transport layer, and divide it into continuous and equally long independent data blocks.
[0055] In the network transport layer (L4, Transport Layer) of the cloud printing space, set up a dedicated data capture gateway, and adopt the bypass listening mode (Mirroring Mode) to perform real-time data stream collection on all printing tasks to be executed. When capturing data, only capture the information related to the printing tasks and filter out the background data unrelated to printing.
[0056] Record the arrival time of the printing task data, the ID (identification information) of the submitting user of the printing task, and the data stream. Set a fixed block length (specifically set based on the file size limit that the cloud printing resources can handle, with a default setting of 16KB) to divide the original data stream of the printing into continuous and equally long independent data blocks. If the length of the data stream is not an integer multiple of the block length, fill zeros after the last data block to ensure block alignment.
[0057] The divided data blocks are temporarily stored in an efficient circular buffer. At the same time, in addition to storing the original printing data, each divided data block also needs to be attached with metadata (the user ID and arrival timestamp) to ensure the traceability of the data blocks.
[0058] In S2, calculate the byte probability distribution of each data block in the memory buffer and convert it into a normalized entropy value. When it is detected that the entropy value difference between three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold, generate an abnormal event notification signal.
[0059] In the memory buffer, each data block of the printing task contains the original printing data with a length of L. Calculate the byte frequency distribution of each data block, that is, count the number of times each byte value appears in the data block, and calculate its probability distribution specifically as:
[0060] First, perform statistics in units of bytes (8-bit). The maximum unsigned integer that can be represented is 255, and the byte representation value range is 0 - 255.
[0061] The total number of bytes contained in each data block is 1024*L bytes. Define the byte statistics vector V[j] to represent the number of occurrences of byte value j (0 ≤ j ≤ 255) within the data block. The finally defined probability distribution expression is .
[0062] Based on the Shannon entropy algorithm, convert the probability distribution of byte values into a normalized entropy value, generate an entropy value sequence with user IDs, and write it into the temporary storage area. The Shannon entropy calculation formula is:
[0063]
[0064] In the formula, is the entropy value, is the occurrence probability of byte j in the data block. When all bytes are evenly distributed, the maximum entropy value is 8. When only a small number of bytes appear, the entropy value is close to 0.
[0065] By calculating the ratio of the actual entropy value to 8 as the entropy value after normalization processing (the value range is 0 - 1).
[0066] Preset an abnormal entropy value difference threshold, compare the entropy values of adjacent data blocks in the memory buffer. When it is detected that the entropy value difference of 3 consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold (flexibly set according to the required recognition accuracy requirements, the default setting is 0.125), then it is considered that this data block belongs to abnormal and repeated suspicious data, generate an abnormal event notification signal carrying the corresponding data block information, and mark the task as possibly a forged printing task.
[0067] In S3, add the data block information corresponding to the abnormal event notification signal to the abnormal printing task processing queue.
[0068] Set up an abnormal printing task processing queue to store and manage the data blocks of printing tasks detected as abnormal. Set the specific size based on the data block length. The maximum capacity of the queue is 1000 data block sizes, and at the same time, adopt a first-in, first-out structure to ensure that abnormal tasks are processed in the detection order.
[0069] When receiving the abnormal event notification signal, in order to ensure the integrity and anti-tampering of data block transmission, use SHA-256 hash + RSA digital signature for encryption and signature to generate an encrypted verification task package.
[0070] Encapsulate the corresponding data block, its upload timestamp, and user ID into an encrypted verification task package and add it to the exception printing task processing queue. After writing to the exception printing task queue, immediately clear the corresponding data block in the memory buffer to ensure that memory resources are not occupied by exception tasks and cause memory overflow.
[0071] In S4, parse the content of the data block in the exception printing task processing queue, reorganize the original data stream in chronological order with the user ID as the analysis dimension, and segmentally calculate the similarity coefficient sequence of the data stream at different offsets.
[0072] Real-time parse the content of the data block in the encrypted verification task package in the exception printing task processing queue, reorganize the original data stream according to the timestamp and user ID corresponding to the data block, and form a chronological data stream based on the user ID dimension.
[0073] Based on the initialization of the sliding window with preset window length and sliding step parameters (set as an integer multiple according to the length of the data block), in this embodiment, they are default set to 64KB and 16KB respectively, and load the data stream into the sliding window in segments according to the window length.
[0074] In the sliding window, obtain the similarity coefficient sequence of the data stream at different offsets through autocorrelation calculation, generate a similarity coefficient sequence with offset marks, and identify local peak points. The calculation formula for the data stream similarity coefficient is:
[0075]
[0076] In the formula, is the value of the i-th byte within the window length segment, is the preset window length, k is the preset offset, is the mean value of all bytes within the window, is the autocorrelation similarity coefficient at offset k, and the value range of k is from 1 to n / 2.
[0077] When there is a periodic repetition pattern in the data stream, its autocorrelation similarity coefficient will have a significant peak when the offset k is equal to the repetition period length RT. Because when k = RT, the data segment is exactly the same (or highly similar) to the data pattern at the corresponding position after offset of , resulting in the product term to be fully positively accumulated, there is a maximum value. For non-periodic random data, due to the cancellation of positive and negative product terms, is significantly smaller or close to 0.
[0078] In S5, perform an interval consistency check on the local peaks of the similarity coefficient sequence, determine whether the current time-ordered data stream segment has periodic characteristics, and mark the user IDs and time-ordered data stream segments with periodicity as abnormal.
[0079] Perform an interval consistency check on the local peak points in the similarity coefficient sequence at different offsets. When there exists a similarity coefficient sequence at a certain offset, and the standard deviation of the intervals between its local peak points is less than the set tolerance threshold (specifically set according to the average peak size, and it is required not to exceed 5% of the true value of the standard deviation of the intervals between local peak points), it is determined that the original data stream has periodicity, and the data stream segment within the window and the corresponding user ID are marked as abnormal.
[0080] In S6, monitor the user IDs and data stream segments with abnormal marks, adjust the execution order of the printing tasks based on the number of abnormal marks of the user IDs, and at the same time calculate the weight of the abnormal occupation of the printing time of the user IDs.
[0081] Define an abnormal printing monitoring period , which is used to periodically monitor the abnormal behaviors of the printing tasks. The length of the monitoring period can be configured according to the system load and business requirements, such as 5 minutes, 10 minutes, or 1 hour, continuously monitor all printing tasks, and each task is monitored by the abnormal detection mechanism during the execution process.
[0082] When a new monitoring period starts, extract all the user IDs marked as abnormal and their corresponding data stream segments from the abnormal detection records in the previous monitoring period , and record them as the abnormal user ID set and the abnormal data stream segment set respectively.
[0083] Sort all the abnormal user IDs in ascending order according to the number of abnormal marks (that is, the ones with fewer abnormal times are executed first, and the ones with more abnormal times are ranked later), and adjust the execution order of the printing tasks to be executed in the cloud printing space within the current monitoring period to avoid abnormal users continuously occupying the cloud printing resources.
[0084] Obtain the total execution duration of the printing tasks corresponding to the abnormal data stream segments of each abnormal user ID, and calculate the weight of the abnormal occupation of the printing time of all abnormal user IDs based on the ratio of the total execution duration of the printing tasks to the length of the monitoring period. The calculation method of the abnormal occupation weight is:
[0085]
[0086] In the formula, is the abnormal occupation weight corresponding to the user with the abnormal user ID of , is the execution duration of the printing task corresponding to the l-th abnormal data stream segment, and m is the m-th monitoring period. Among them, when cross-cycle execution occurs, it is necessary to ensure that is not truncated in terms of integrity.
[0087] In S7, based on the number of abnormal marks and the time weight occupied by the abnormality, a dynamic penalty coefficient for non-linear penalty charging is calculated, and an accurate charging bill for the user is generated by combining the set basic printing charging rules.
[0088] Set the basic printing charging rules , obtain the printing tasks to be executed in the cloud printing space, and charge the printing tasks submitted by the user IDs without abnormal marks according to the basic printing charging rules.
[0089] For the printing tasks submitted by the user IDs with abnormal marks, based on the number of times the user ID is abnormally marked and the abnormal occupation weight of the printing time, calculate the dynamic penalty coefficient for non-linear penalty charging. The specific calculation method is as follows:
[0090]
[0091] In the formula, is the dynamic penalty coefficient for the w-th user ID, , are respectively the number of abnormal marks and the abnormal occupation weight of the printing time corresponding to the w-th user ID, is the set growth control parameter, which is specifically set according to the required charging penalty intensity, and the default setting is 0.5. The control of the
[0092] item is up to 1, that is, when cross-cycle task execution occurs, only the weight within this single monitoring period is counted. Take the product of the dynamic penalty coefficient corresponding to each user ID with an abnormal mark and the basic printing charging rules as the final printing charge for the abnormal user ID, and generate the final charging bill. For example, when the number of abnormal marks of user w is 2 times, and the abnormal occupation weight of its printing time is 0.75, the calculation result of the penalty coefficient is times the basic rate.
[0093] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.
[0094] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0095] Those of ordinary skill in the art will realize that the modules and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0096] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0097] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there can be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or modules can be in electrical, mechanical, or other forms.
[0098] The module described as a separation component may or may not be physically separated. The component shown as a module may or may not be a physical module. It may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0099] In addition, in each embodiment of the present application, each functional module can be integrated into a processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.
[0100] If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs and other various media that can store program codes.
[0101] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all of them should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0102] Finally: The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A real-time tracking and accurate billing method for cloud printing information, characterized in that: The steps include: S1: Capture the original printing data information of the printing task to be executed in the cloud printing space at the network transmission layer, and divide it into continuous independent data blocks of equal length; S2: Calculate the byte probability distribution of each data block in the memory buffer and convert it into a normalized entropy value. When it is detected that the entropy value difference of three consecutive pairs of adjacent data blocks is less than a preset abnormal entropy value difference threshold, generate an abnormal event notification signal; S3: adding the data block information corresponding to the abnormal event notification signal to the abnormal printing task processing queue; S4: parsing the data block content in the abnormal printing task processing queue, reorganizing the original data stream in time order with user ID as the analysis dimension, and calculating the data stream similarity coefficient sequence under different offsets in segments; S5: Perform interval consistency check on the local peak value of the similarity coefficient sequence to determine whether the current time sequence data stream segment has periodic characteristics, and mark the user ID and time sequence data stream segment with periodicity as abnormal; S6: Monitor the user IDs and data stream segments that carry abnormal marks, adjust the execution order of the printing tasks based on the number of abnormal marks of the user IDs, and calculate the weight of the abnormal printing time occupied by the user IDs; S7: Calculate the dynamic penalty coefficient of nonlinear penalty billing based on the number of abnormal markings and the time weight of abnormal occupancy, and generate an accurate billing bill for the user in combination with the set basic printing billing rules; In S2, the byte probability distribution of each data block in the memory buffer is calculated and converted into a normalized entropy value. When it is detected that the entropy value difference of three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold, an abnormal event notification signal is generated, specifically including: Perform byte frequency statistics on each data block in the memory buffer and calculate the probability distribution of each byte value appearing in the data block; Based on the Shannon entropy algorithm, the probability distribution of the byte value is converted into a normalized entropy value, and an entropy value sequence with a user ID is generated and written into a temporary storage area; Preset an abnormal entropy value difference threshold, compare the entropy values of adjacent data blocks in the memory buffer, and generate an abnormal event notification signal carrying the corresponding data block information when it is detected that the entropy value difference of three consecutive pairs of adjacent data blocks is less than the preset abnormal entropy value difference threshold; In S7, the dynamic penalty coefficient of nonlinear penalty billing is calculated based on the number of abnormal markings and the time weight occupied by the abnormality, and an accurate billing bill is generated for the user in combination with the set basic printing billing rules, including: Set basic printing billing rules, obtain the print tasks to be executed in the cloud printing space, and charge the print tasks submitted by user IDs without abnormal marks according to the basic printing billing rules; For the print tasks submitted by the user ID with an abnormal mark, the dynamic penalty coefficient of nonlinear penalty billing is calculated based on the number of times the user ID is marked with an abnormal mark and the weight of the abnormal printing time. The specific calculation method is: In the formula, is the dynamic penalty coefficient for the w-th user ID, , are the number of abnormal markings and the abnormal occupancy weight of printing time corresponding to the w-th user ID, To set growth control parameters; The product of the dynamic penalty coefficient corresponding to each user ID carrying the abnormal mark and the basic printing charging rule is used as the final printing charging of the abnormal user ID to generate a final charging bill.
2. A method for real-time tracking and accurate billing of cloud printing information according to claim 1, characterized in that: In S1, the original printing data information of the printing task to be executed in the cloud printing space is captured at the network transmission layer and divided into continuous independent data blocks of equal length, specifically including: The gateway is set to capture the original printing data information of the printing task to be executed in the cloud printing space at the network transmission layer. The original printing data information includes the upload timestamp of the printing task, the submitting user ID and the original printing data stream; The original data stream is divided into continuous independent data blocks of equal length according to the preset fixed length, and the divided data blocks are temporarily stored in the memory buffer and attached with timestamps and user IDs.
3. A method for real-time tracking and accurate billing of cloud printing information according to claim 2, characterized in that: In S3, adding the data block information corresponding to the abnormal event notification signal to the abnormal printing task processing queue specifically includes: Establish an abnormal printing task processing queue. When an abnormal event notification signal is received, the corresponding data block and its upload timestamp and user ID are encapsulated as an encrypted verification task package and added to the abnormal printing task processing queue, and the data block information in the memory buffer is cleared at the same time.
4. A method for real-time tracking and accurate billing of cloud printing information according to claim 3, characterized in that: In S4, the data block content in the abnormal printing task processing queue is parsed, the original data stream in time sequence is reorganized with the user ID as the analysis dimension, and the data stream similarity coefficient sequence under different offsets is calculated in segments, specifically including: Parse the data block content of the encrypted verification task package in the abnormal printing task processing queue in real time, reorganize the original data stream according to the timestamp and user ID corresponding to the data block, and form a time-sequential data stream based on the user ID dimension; Based on the initialization sliding window of the preset window length and sliding step parameters, the time-sequential data stream is segmented into the sliding window according to the window length; In the sliding window, the similarity coefficient of the time sequence data stream under different offsets is obtained by autocorrelation calculation, a similarity coefficient sequence with offset marks is generated and the local peak points are identified. The calculation formula of the data stream similarity coefficient is: In the formula, is the value of the i-th byte in the window length segment, is the preset window length, k is the preset offset, is the mean of all bytes in the window, is the autocorrelation similarity coefficient when the offset is k, and the value range of k is 1 to n / 2.
5. A method for real-time tracking and accurate billing of cloud printing information according to claim 4, characterized in that: In S5, the local peak values of the similarity coefficient sequence are checked for interval consistency to determine whether the current time sequence data stream segment has periodic characteristics, and abnormal marking is performed on the user ID and time sequence data stream segment with periodicity. Specifically, the following steps are performed: The local peak points in the similarity coefficient sequence under different offsets are checked for interval consistency. When there is a similarity coefficient sequence under a certain offset whose interval standard deviation between local peak points is less than the set tolerance threshold, it is determined that the time sequence data stream has periodicity, and the data stream segments in the window and the corresponding user IDs are marked as abnormal.
6. A method for real-time tracking and accurate billing of cloud printing information according to claim 5, characterized in that: In S6, the user IDs and data stream segments carrying abnormal marks are monitored, and the execution order of the printing tasks is adjusted based on the number of abnormal marks of the user IDs. At the same time, the weight of the abnormal printing time occupied by the user ID is calculated, which specifically includes: Set the length of the abnormal printing monitoring cycle, extract all user IDs carrying abnormal marks and corresponding data stream segments in the cycle before the current monitoring cycle, and record them as abnormal user IDs and abnormal data stream segments respectively; Adjust the execution order of the print tasks to be executed in the cloud printing space within the current monitoring period based on the ascending order of the number of times the abnormal user ID is marked abnormally; The total execution time of the printing task corresponding to the abnormal data flow segment corresponding to each abnormal user ID is obtained, and the weight of the abnormal printing time occupancy of all abnormal user IDs is calculated based on the proportion of the total execution time of the printing task to the length of the monitoring cycle.
Citation Information
Patent Citations
Method for dynamically screening aperiodic anomalies
CN112862019A
Security risk evaluation system for cloud printing data transmission
CN119311234A