Broadcast suppression method, control device and storage medium for flat networking
By monitoring and analyzing broadcast traffic in the flat network, using traffic feature recognition and timing analysis technology, dynamically adjusting broadcast storm parameters, solving the problem of network performance degradation caused by broadcast storms in the flat network, and achieving rational utilization and stability improvement of network resources.
Patent Information
- Application Number
- CN202510087285.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-20
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-01-20
AI Technical Summary
In flat networking, broadcast storms lead to degradation of network performance and impaired stability. The existing technology lacks effective suppression methods, resulting in unreasonable utilization of network resources.
By monitoring the broadcast traffic of the target network, using preset traffic feature recognition models and timing analysis technology, potential broadcast storm characteristics are identified, traffic trends are predicted, broadcast storm parameters are adjusted according to the adjustment strategy, including setting dynamic thresholds and key parameters, and dynamically adjusting the network configuration to suppress broadcast storm.
Effectively suppress broadcast storms, improve network stability and performance, and ensure the rational use of network resources.
Smart Images

Figure CN119906681B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a broadcast suppression method, a control device, and a storage medium for flat networking. Background Art
[0002] Under a flat networking architecture, the broadcast domain range in the network tends to become larger than that in a traditional multi-layer network due to the reduction of the network hierarchy. When there is a large amount of broadcast traffic in the network, broadcast storms are prone to occur, resulting in decreased network performance and damaged stability.
[0003] To effectively suppress broadcast storms, existing technologies typically employ more sophisticated configurations of network devices, such as implementing VLAN division strategies. However, the effectiveness of implementing these strategies is low. Simply put, improper configurations can place a greater burden on the network and fail to ensure the optimal use of network resources. Summary of the Invention
[0004] The present invention provides a broadcast suppression method for flat networking, which is used to solve the defect of the prior art that there is no effective method for suppressing broadcast storms.
[0005] In one aspect, the present invention provides a broadcast suppression method for flat networking, comprising:
[0006] Monitor data related to broadcast traffic in a target network; use a preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm features; use time series analysis technology to predict the traffic trend of the target network and identify potential broadcast storms in the monitored data; and based on the identified presence of potential broadcast storm features in the monitored data, the predicted traffic trend and the identified potential broadcast storms, use a preset adjustment strategy to adjust parameters for suppressing broadcast storms in the target network.
[0007] Preferably, the steps of monitoring data related to broadcast traffic in the target network include: deploying a traffic monitoring system to capture data related to broadcast traffic; creating a database to store the captured data related to broadcast traffic; counting data related to broadcast traffic and storing the results in the database.
[0008] Preferably, the data related to broadcast traffic includes at least: broadcast traffic quantity, forwarding times, broadcast traffic frequency, and source IP address.
[0009] Preferably, before using the preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm characteristics, the broadcast suppression method also includes: obtaining historical data related to broadcast traffic in the target network to construct a training set and a verification set; constructing a long short-term memory network for identifying traffic characteristics, and setting an activation function and a loss function; training the long short-term memory network for identifying traffic characteristics through the training set, and verifying the training of the long short-term memory network for identifying traffic characteristics through the verification set; and using the trained model as the preset traffic feature recognition model.
[0010] Preferably, the use of time series analysis technology to predict the traffic trend of the target network and identify broadcast storms in the monitored data includes: obtaining historical data and real-time data related to the broadcast traffic of the target network in chronological order to obtain time series data; extracting features in the time series data that are helpful for prediction, and constructing a training set and a validation set, which features at least include moving average, seasonal decomposition, and autocorrelation; using a long short-term memory network to construct a time series prediction model; training the time series prediction model through the training set, and verifying the training of the time series prediction model through the validation set; and using the trained time series prediction model to predict the traffic trend of the target network and identify broadcast storms in the monitored data.
[0011] Preferably, the method of using the trained time series prediction model to identify broadcast storms in the monitored data includes: setting a preset threshold for broadcast traffic based on historical data related to broadcast traffic in the monitored target network; and marking the monitored data related to broadcast traffic as a potential broadcast storm when it exceeds the preset threshold.
[0012] Preferably, the parameters for suppressing broadcast storms in the target network are adjusted based on whether the identified monitored data has potential broadcast storm characteristics, the predicted traffic trend and the identified potential broadcast storm, and according to a preset adjustment strategy, including: setting a dynamic threshold based on whether the identified monitored data has potential broadcast storm characteristics, the predicted traffic trend and the identified potential broadcast storm; determining key parameters related to broadcast suppression; when the monitored data related to broadcast traffic is not within the dynamic threshold, adjusting the key parameters related to broadcast suppression; when the monitored data related to broadcast traffic is within the dynamic threshold range, gradually calling back to the initial parameter settings to maintain normal operation of the network.
[0013] Preferably, the key parameters related to broadcast suppression include at least: the maximum number of forwarding times allowed for each broadcast data packet in the network and the broadcast traffic rate.
[0014] Preferably, when the monitored data related to the broadcast traffic is not within the dynamic threshold range, the key parameters related to broadcast suppression are adjusted, including: when the monitored data related to the broadcast traffic continues to be higher than the dynamic threshold, the maximum forwarding times and / or the broadcast traffic rate are gradually reduced.
[0015] Preferably, after adjusting the parameters for suppressing broadcast storms in the target network, the broadcast suppression method further includes: monitoring data related to broadcast traffic in the target network based on a feedback mechanism, and optimizing the preset adjustment strategy based on the monitoring results.
[0016] Preferably, the optimization of the preset adjustment strategy includes: performing data analysis on the stored data related to the broadcast traffic; performing feedback adjustment based on the analysis results; and updating the preset traffic feature recognition model within a preset period based on the data analysis results and the feedback adjustment results.
[0017] On the other hand, the present invention further provides a control device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-mentioned broadcast suppression method.
[0018] On the other hand, the present invention further provides a machine-readable storage medium, on which instructions are stored, and the instructions enable a machine to execute the above-mentioned broadcast suppression method.
[0019] The broadcast suppression method for flat networking provided by the present invention monitors data related to broadcast traffic in a target network, and then uses a preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm features. Based on the potential broadcast storm features, the method uses timing analysis technology to predict the traffic trend of the target network and the degree of the broadcast storm. Then, according to a preset adjustment strategy, the parameters for suppressing broadcast storms in the target network are adjusted. This solves the problem of the lack of effective methods for predicting and suppressing broadcast storms in the prior art, and achieves the beneficial effect of ensuring the rational use of network resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0021] Figure 1This is a flow chart of a broadcast suppression method for flat networking provided by one embodiment of the present invention;
[0022] Figure 2 It is a flowchart of a broadcast suppression method for flat networking provided by another embodiment of the present invention. DETAILED DESCRIPTION
[0023] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0024] As mentioned above, to effectively suppress broadcast storms, existing technologies typically require more sophisticated configuration of network devices, such as implementing VLAN division strategies. However, the effectiveness of implementing such strategies is low. Simply put, improper configuration can place a greater burden on the network and fail to ensure the optimal use of network resources.
[0025] To this end, the present invention provides a broadcast suppression method for flat networking, which uses a preset traffic feature recognition model to identify potential broadcast storm characteristics, and then adjusts the parameters for suppressing broadcast storms according to a preset adjustment strategy, thereby suppressing the occurrence of broadcast storms.
[0026] The following combination Figure 1 、 Figure 2 The present invention will be described in detail.
[0027] Figure 1 The present invention is a flowchart of a broadcast suppression method for flat networking provided by an embodiment of the present invention.
[0028] like Figure 1 As shown, an embodiment of the present invention provides a broadcast suppression method for flat networking, the execution subject of which may be a controller, and the method mainly includes the following steps:
[0029] S101. Monitor data related to broadcast traffic in a target network.
[0030] S102: Using a preset traffic feature recognition model, identify whether the monitored data has potential broadcast storm features.
[0031] S103: Using time series analysis technology, predict the traffic trend of the target network and identify potential broadcast storms in the monitored data.
[0032] S104: Based on whether the identified monitored data has potential broadcast storm characteristics, the predicted traffic trend, and the identified potential broadcast storm, and using a preset adjustment strategy, adjust parameters for suppressing broadcast storms in the target network.
[0033] Based on the above steps, the present invention provides a broadcast suppression method for flat networking, which monitors data related to broadcast traffic in the target network; uses a preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm features, and based on the potential broadcast storm features; uses timing analysis technology to predict the traffic trend of the target network and the degree of the broadcast storm; and then adjusts the parameters for suppressing broadcast storms in the target network according to a preset adjustment strategy. The embodiment of the present invention can suppress broadcast storms by adjusting the broadcast storm suppression parameters, thereby reducing the impact of broadcast traffic on the network, improving the stability and performance of the network, and ensuring the rational use of network resources.
[0034] In order to explain the technical solutions provided by the above embodiments in more detail, the present invention also provides another preferred embodiment, such as Figure 2 As shown, Figure 2 This is a flow chart of a broadcast suppression method for flat networking provided by another embodiment of the present invention. In this figure, the broadcast suppression method can also be executed by a controller.
[0035] like Figure 2 As shown, in another embodiment of the present invention, step S101 can utilize the traffic monitoring and analysis module to monitor the data related to the broadcast traffic in the target network. In step S101, the broadcast suppression method may include, step S1011, deploying a traffic monitoring system, capturing data related to the broadcast traffic, and creating a database; step S1012, storing the captured data related to the broadcast traffic; step S1013, counting the data related to the broadcast traffic, and storing the results in the database.
[0036] For example, a traffic monitoring and analysis module can include real-time data capture and storage capabilities. For example, a network traffic analysis tool (such as Wireshark or custom-developed network monitoring software) can be used to capture all filtered broadcast packets passing through a network device. The tool must be configured to identify and filter broadcast packets, typically targeting a destination MAC address of FF:FF:FF:FF:FF:FF. By configuring filtering rules, the system can focus on collecting data related to broadcast traffic.
[0037] In the embodiment of the present invention, the data related to the broadcast traffic may preferably include at least: the amount of broadcast traffic, the number of forwarding times, the frequency of broadcast traffic, the source IP address, etc.
[0038] The traffic monitoring and analysis module can also have a data statistics function. For example, the system needs to regularly (e.g., every minute) count data related to broadcast traffic in the target network. In another embodiment of the present invention, the data related to broadcast traffic in the target network includes at least: broadcast traffic volume (i.e., calculating the total number of broadcast packets captured within a specified time period), broadcast traffic frequency (i.e., calculating the frequency of broadcast packets sent per unit time), and source IP address (recording the source IP address of each broadcast packet and counting the number of broadcast packets sent by each source IP address to identify potential sources of abnormal traffic).
[0039] The broadcast traffic frequency can be expressed as follows: ,
[0040] In order to achieve the above functions, the traffic monitoring module can use a database (such as MySQL or MongoDB) to store the collected data, and the data table structure can be designed as: timestamp (i.e., recording the time of data collection), source IP address (i.e., storing the source IP that sends the broadcast data packet), number of broadcast data packets (i.e., recording the number of broadcast data packets captured within the time period), frequency (i.e., the calculated broadcast traffic frequency).
[0041] The traffic monitoring and analysis module can also have visualization functions so that network administrators can view traffic data intuitively. Chart tools (such as Grafana or a customized web interface) can be used to display real-time traffic data, including the number and frequency trends of broadcast traffic.
[0042] The traffic monitoring and analysis module can be connected to subsequent pattern recognition and prediction modules to use the collected data for further analysis and decision-making. By passing traffic data to the pattern recognition algorithm, the system can identify normal broadcast traffic patterns and potential broadcast storm characteristics.
[0043] Therefore, through the above steps, the traffic monitoring and analysis module can effectively collect and analyze broadcast traffic data in the network, providing reliable data support for subsequent broadcast suppression strategies.
[0044] In another embodiment of the present invention, before step S102, step S1021 may be further included, obtaining historical data related to broadcast traffic in the target network to construct a training set and a verification set; S1022, constructing a long short-term memory network for identifying traffic characteristics, and setting an activation function and a loss function; S1023, training the long short-term memory network for identifying traffic characteristics through the training set, and verifying the training of the long short-term memory network for identifying traffic characteristics through the verification set; S1024, using the trained model as the preset traffic feature recognition model.
[0045] For example, steps S1021-S1024 further include the following steps:
[0046] Acquire and process historical data related to broadcast traffic in the target network. The steps are as follows: Data cleaning to remove duplicate and invalid data records to ensure data accuracy and completeness. Extract key features from the historical data, such as the number of broadcast traffic packets (i.e., the total number of broadcast packets in a specific time period), source IP address diversity (i.e., the number of different source IP addresses sending broadcast packets in a time period), time interval (i.e., the time interval between broadcast packets, calculating the average and standard deviation), and traffic burstiness (i.e., this indicator can identify abnormal fluctuations in traffic). Traffic burstiness is calculated using the following formula: ,
[0047] A machine learning algorithm is selected to train the model. Considering the temporal characteristics and complexity of broadcast traffic, another embodiment of the present invention uses a Long Short-Term Memory (LSTM) network, a recurrent neural network suitable for processing time series data. LSTM can capture long-term dependencies in time series and is suitable for identifying broadcast traffic patterns.
[0048] Subsequently, the long short-term memory network model is trained using the following steps: The collected historical data related to broadcast traffic on the target network is divided into a training set and a test set (for example, 70% can be used as the training set and 30% as the test set). An LSTM model is then constructed using a deep learning framework (such as TensorFlow or PyTorch). The model structure can be designed as an input layer (i.e., receiving the extracted feature data), an LSTM layer (i.e., setting an appropriate number of LSTM units, such as 64 or 128, to capture time series features), a fully connected layer (i.e., mapping the output of the LSTM layer to the classification result), and an output layer (i.e., using a softmax activation function to output the probabilities of normal traffic and broadcast storms).
[0049] Then, you can choose cross entropy as the loss function, for example, you can use the Adam optimizer for model training. During training, monitor the training loss and validation loss to prevent overfitting, and optimize the above model.
[0050] After training is complete, the model is evaluated based on metrics such as accuracy (i.e., the proportion of samples correctly classified by the model), recall (i.e., the ability of the model to identify positive classes such as broadcast storms), and F1-score (i.e., a metric that takes both accuracy and recall into account).
[0051] The trained model is used as a traffic feature recognition model and deployed in the pattern recognition and prediction module configured according to step S102. The real-time data collected by the traffic monitoring and analysis module is input into the above-mentioned traffic feature recognition model. According to the output result of the traffic feature recognition model, it is judged whether the current traffic belongs to the normal mode or a potential broadcast storm.
[0052] Through the above steps, the pattern recognition and prediction module can effectively train the traffic feature recognition model, identify normal broadcast traffic patterns and potential broadcast storm characteristics, and provide important decision support for subsequent broadcast suppression strategies.
[0053] In another embodiment of the present invention, in step S103, the method of using time series analysis technology to predict the traffic trend of the target network and the degree of broadcast storm may include: step S1031, obtaining historical and real-time data related to the broadcast traffic of the target network in chronological order to obtain time series data; S1032, extracting features that are helpful for prediction in the time series data, and constructing a training set and a validation set, and the features include at least moving average, seasonal decomposition, and autocorrelation; S1033, using a long short-term memory network to construct a time series prediction model; S1034, training the time series prediction model through the training set, and verifying the trained time series prediction model through the validation set; S1035, using the trained time series prediction model to predict the traffic trend and broadcast storm of the target network.
[0054] In step S1035, it can also include S10351: setting a preset threshold for broadcast traffic based on historical data related to broadcast traffic in the monitored target network; S10352: when the monitored data related to broadcast traffic exceeds the preset threshold, marking it as a potential broadcast storm.
[0055] For example, steps S1031-S1035 further include the following steps:
[0056] A broadcast storm prediction module can be deployed and used to collect real-time and historical network traffic data from the traffic monitoring and analysis module. This data, specifically data related to broadcast traffic on the target network, can be cleaned to remove missing values and outliers before constructing a time series. For example, collected traffic data can be organized into a time series format by timestamp for subsequent analysis. Data at each time point should include the timestamp (i.e., the time the data was recorded), the number of broadcast packets (i.e., the total number of broadcast packets at that time point), and the traffic rate (i.e., the broadcast traffic rate per unit time).
[0057] Features that are helpful for prediction are extracted from the above time series. These features can be moving average (i.e., calculating the average number of broadcast data packets at the past N time points to smooth data fluctuations), seasonal decomposition (i.e., analyzing seasonal changes in data and identifying periodic patterns), and autocorrelation (i.e., using autocorrelation function and partial autocorrelation function to analyze the autocorrelation of data to determine appropriate model parameters).
[0058] Select a time series prediction model. Considering the dynamic nature of broadcast traffic, in another embodiment of the present invention, depending on the data characteristics, an LSTM or autoregressive integrated moving average (ARIMA) model can be used. LSTM is suitable for processing complex nonlinear time series data, while ARIMA is suitable for linear time series data.
[0059] The steps for model training are as follows: divide the time series into training and test sets. For example, you can use 80% for training and 20% for testing. Then, use a deep learning framework to build an LSTM network. The model structure can be designed as follows: input layer (receives time series data), LSTM layer (sets an appropriate number of LSTM units, such as 64 or 128, to capture time series characteristics), fully connected layer (maps the output of the LSTM layer to the prediction result), and output layer (outputs the prediction of the number of broadcast packets at a future time point).
[0060] Next, you can select mean squared error (MSE) as the loss function and use the Adam optimizer for model training. During training, monitor the training and validation losses to prevent overfitting. Evaluate the trained model based on mean squared error (average of the squared differences between predicted and actual values), mean absolute error (average of the absolute differences between predicted and actual values), and the R² coefficient of determination (R²), which assesses the model's ability to explain data variation.
[0061] The trained model is used as the preset time series prediction model to predict the input real-time data, so as to set the preset threshold of broadcast traffic based on the monitored data related to broadcast traffic. When the predicted number of broadcast data packets exceeds the preset threshold, it is marked as a potential broadcast storm.
[0062] Through the above steps, the broadcast storm prediction module can effectively apply timing analysis technology to identify possible broadcast storms in advance, providing important decision support for subsequent broadcast suppression strategies.
[0063] In another embodiment of the present invention, step S104 may further include step S1041: setting a dynamic threshold based on the predicted traffic trend, the degree of broadcast storm, and whether the identified monitored data has potential broadcast storm characteristics; step S1042: determining key parameters related to broadcast suppression; step S1043: when the monitored data related to broadcast traffic is not within the dynamic threshold, adjusting the key parameters related to broadcast suppression; step S1044: when the monitored data related to broadcast traffic is within the dynamic threshold range, gradually calling back to the initial parameter settings to maintain normal operation of the network.
[0064] The step S1043 may further include step S10431: when the monitored data related to the broadcast traffic is continuously higher than the dynamic threshold, gradually reducing the maximum forwarding times and / or the broadcast traffic rate.
[0065] For example, steps S1041 to S1044 further include the following steps:
[0066] A dynamic parameter adjustment module can be deployed, and the maximum forwarding times (i.e., the maximum number of times each broadcast data packet is allowed to be forwarded in the network. Broadcast data packets exceeding this number will be discarded) and the broadcast traffic rate (i.e., the number of broadcast data packets allowed to be sent per unit time, usually expressed in packets per second (pps)) can be set as key parameters for broadcast suppression. For example, the initial maximum forwarding times can be set to 5 times and the traffic rate to 100 pps. The broadcast traffic in the network can be continuously monitored, and data such as the current number of broadcast data packets, forwarding times, and traffic rate can be collected. A preset threshold (e.g., 80 pps) can be set. Based on historical data and prediction results, the parameter adjustment mechanism can be triggered by determining whether the current broadcast traffic exceeds the preset dynamic threshold (e.g., when the current broadcast traffic reaches 90 pps).
[0067] Based on real-time monitoring and pre-set thresholds, dynamic adjustment strategies are implemented. For example, if broadcast traffic is detected to be persistently above the dynamic threshold, the maximum number of forwarding attempts and the broadcast traffic rate can be gradually reduced. For example, the maximum number of forwarding attempts can be reduced from 5 to 3, and the traffic rate can be reduced from 100 pps to 80 pps. When broadcast traffic falls back within the dynamic threshold, the previous parameter settings are gradually restored to maintain normal network operation.
[0068] Implement a feedback control mechanism to ensure that the adjusted parameters effectively control broadcast traffic. Specifically, after adjusting the parameters, monitor changes in broadcast traffic in real time, record the number of broadcast packets and traffic rate before and after the adjustment, and evaluate the effectiveness of the adjustment based on the monitoring results. If the adjusted parameters still fail to effectively suppress broadcast traffic, further optimize the adjustment strategy. For example, if the traffic volume remains above the dynamic threshold after adjustment, further reduce the maximum forwarding times to 2 and the traffic rate to 60 pps, and monitor the results again.
[0069] Through the above steps, the dynamic parameter adjustment module can flexibly adjust the broadcast suppression parameters according to the traffic analysis and prediction results, effectively control the broadcast traffic, prevent the occurrence of broadcast storms, and ensure the stability and performance of the network.
[0070] In another embodiment of the present invention, after step S104, the method may further include step S105: monitoring data related to broadcast traffic in the target network based on a feedback mechanism, and optimizing the preset adjustment strategy according to the monitoring results.
[0071] In step S105, it can also include S1051: performing data analysis on the stored data related to the broadcast traffic; S1052: performing feedback adjustment based on the analysis results; S1053: updating the preset traffic feature recognition model within a preset period based on the data analysis results and feedback adjustment results.
[0072] For example, step S105 further includes the following steps:
[0073] Deploy a real-time monitoring and feedback module to continuously track broadcast traffic in the network. The real-time monitoring and feedback module should have data collection and data storage functions.
[0074] Based on real-time monitoring, establish an effectiveness evaluation mechanism to determine the effectiveness of adjusted parameters. Specifically, define evaluation metrics: key performance indicators, such as the rate of change in the number of broadcast packets and the stability of the traffic rate. Set a target range, such as maintaining the number of broadcast packets below 80 per second. Regularly analyze stored data and calculate the mean and standard deviation of the number of broadcast packets and traffic rate to assess whether the current broadcast traffic is within a reasonable range.
[0075] Based on the results of the effectiveness evaluation, a feedback adjustment strategy is implemented. Specifically, if monitoring data indicates that broadcast traffic remains above the set dynamic threshold, further adjustments to broadcast suppression parameters are necessary. For example, if the number of broadcast packets persists above 90, consider reducing the maximum number of forwarding attempts from 3 to 2, and the traffic rate from 80 pps to 60 pps. Furthermore, an automatic response mechanism is implemented within the monitoring system. When broadcast traffic exceeds the preset threshold, the system automatically triggers parameter adjustments without requiring manual intervention.
[0076] Regularly review (for example, weekly) and analyze feedback data to evaluate the long-term effectiveness of adjustment strategies to ensure continued stability of network performance. Based on historical data and new traffic patterns, regularly update traffic analysis and prediction models to improve their accuracy and adaptability.
[0077] Through the above steps, the real-time monitoring feedback module can effectively monitor and evaluate the adjustment effect of broadcast traffic, ensuring that the broadcast traffic remains within a reasonable range, thereby preventing the occurrence of broadcast storms and maintaining network stability and performance.
[0078] Based on the same general inventive concept, the present invention also protects a control device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-mentioned broadcast suppression method.
[0079] Based on the same general inventive concept, the present invention also protects a machine-readable storage medium, on which instructions are stored, and the instructions enable a machine to execute the above-mentioned broadcast suppression method.
[0080] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0081] Additionally, the terms "system" and "network" are often used interchangeably. The term "and / or" is simply used to describe a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " generally indicates an "or" relationship between the related objects.
[0082] It should be understood that in the embodiments of the present invention, "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B based solely on A; B can also be determined based on A and / or other information.
[0083] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0084] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0085] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be electrical, mechanical or other forms of connection.
[0086] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the objectives of the embodiments of the present invention.
[0087] In addition, the functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0088] From the above description of the embodiments, it will be apparent to those skilled in the art that the present invention can be implemented using hardware, firmware, or a combination thereof. When implemented using software, the aforementioned functionality may be stored in a computer-readable medium or transmitted as one or more instructions or codes on the computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media includes any medium that facilitates the transfer of computer programs from one location to another. Storage media can be any available medium that can be accessed by a computer. By way of example and not limitation, computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer. Furthermore, any suitable connection may constitute a computer-readable medium. For example, if the software is transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. As used herein, the terms "disk" and "disc" include compact discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs. Disks typically reproduce data magnetically, while discs use lasers to reproduce data optically. Combinations of the above should also be included within the scope of protection for computer-readable media.
[0089] In short, the above description is only a preferred embodiment of the technical solution of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included in the scope of protection of the present invention.
Claims
1. A broadcast suppression method for flat networking, characterized in that: The broadcast suppression method comprises: Monitor data related to broadcast traffic in the target network; Use the preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm characteristics; Using time series analysis techniques to predict traffic trends on the target network and identify potential broadcast storms in the monitored data; and Based on the identified monitored data for potential broadcast storm characteristics, the predicted traffic trends, and the identified potential broadcast storms, the parameters used to suppress broadcast storms in the target network are adjusted using a preset adjustment strategy, including: Set dynamic thresholds based on whether the monitored data has potential broadcast storm characteristics, predicted traffic trends, and identified potential broadcast storms; Identify key parameters related to broadcast suppression; When the monitored data related to the broadcast traffic is not within the dynamic threshold, adjusting the key parameters related to broadcast suppression; When the monitored data related to broadcast traffic is within the dynamic threshold range, the parameters are gradually called back to the initial settings to maintain normal network operation.
2. The broadcast suppression method according to claim 1, characterized in that: The step of monitoring data related to broadcast traffic in the target network includes: Deploy a traffic monitoring system to capture data related to broadcast traffic; Creating a database to store captured data related to broadcast traffic; Collect statistics related to broadcast traffic and store the results in the database.
3. The method according to claim 1, characterized in that The data related to broadcast traffic includes at least: broadcast traffic quantity, forwarding times, broadcast traffic frequency, and source IP address.
4. The broadcast suppression method according to claim 1, wherein: Before using the preset traffic feature recognition model to identify whether the monitored data has potential broadcast storm features, the broadcast suppression method further includes: Obtaining historical data related to broadcast traffic in the target network to construct a training set and a validation set; Build a long short-term memory network for identifying traffic characteristics and set the activation function and loss function; The long short-term memory network for identifying traffic characteristics is trained using the training set, and the long short-term memory network for identifying traffic characteristics is trained and verified using the validation set; The trained model is used as the preset traffic feature recognition model.
5. The broadcast suppression method according to claim 1, characterized in that: The method of using time series analysis technology to predict traffic trends of the target network and identify broadcast storms in the monitored data includes: Acquire historical data and real-time data related to broadcast traffic of the target network in chronological order to obtain time series data; Extracting features from the time series data that are helpful for prediction and constructing a training set and a validation set, wherein the features include at least moving average, seasonal decomposition, and autocorrelation; Use long short-term memory networks to build time series prediction models; The time series prediction model is trained using the training set, and the time series prediction model is trained and verified using the validation set; and The trained time series prediction model is used to predict traffic trends on the target network and identify broadcast storms in the monitored data.
6. The broadcast suppression method according to claim 5, characterized in that: The method of using the trained time series prediction model to predict the traffic trend of the target network and identify broadcast storms in the monitored data includes: Setting a preset threshold for broadcast traffic based on historical data related to broadcast traffic in the monitored target network; When the monitored data related to broadcast traffic exceeds a preset threshold, it is marked as a potential broadcast storm.
7. The broadcast suppression method according to claim 1, characterized in that: The key parameters related to broadcast suppression include at least: the maximum number of forwarding times allowed for each broadcast data packet in the network and the broadcast traffic rate.
8. The broadcast suppression method according to claim 1, wherein: When the monitored data related to the broadcast traffic is not within the dynamic threshold range, adjusting the key parameters related to broadcast suppression includes: When the monitored data related to the broadcast traffic is continuously higher than the dynamic threshold, the maximum forwarding times and / or the broadcast traffic rate are gradually reduced.
9. The broadcast suppression method according to claim 1, characterized in that: After adjusting the parameters for suppressing broadcast storms in the target network, the broadcast suppression method further includes: Based on the feedback mechanism, data related to broadcast traffic in the target network is monitored, and the preset adjustment strategy is optimized according to the monitoring results.
10. The broadcast suppression method according to claim 9, characterized in that: The optimization of the preset adjustment strategy includes: Performing data analysis on stored data related to broadcast traffic; Make feedback adjustments based on the analysis results; Within a preset period, the preset traffic feature recognition model is updated based on the data analysis results and feedback adjustment results.
11. A control device, characterized in that: The control device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to implement the broadcast suppression method according to any one of claims 1 to 10.
12. A machine-readable storage medium, characterized in that The machine-readable storage medium stores instructions, which enable the machine to execute the broadcast suppression method according to any one of claims 1-10.
Citation Information
Patent Citations
Broadcast storm detection and processing method based on situation awareness
CN111988184A
Storm control method based on application program identification
CN119094463A