Information exchange method and device for multiple Ethernet switches
Through network monitoring equipment recording and preprocessing switch data, combined with machine learning algorithms and adaptive loop prevention methods, the shortcomings of feature extraction and risk management in the prior art are solved, deep monitoring and dynamic risk management of the switch network are realized, and network security and stability are improved.
Patent Information
- Application Number
- CN202510073319.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-01-17
AI Technical Summary
The prior art relies on simple statistical features in feature extraction, lacks effective mining of deep-level features, and loop prevention and risk area identification rely on static rules, making it difficult to adapt to dynamically changing network environments.
The network monitoring device records the transmission traffic data of the switch ports, captures the connection relationship between switches in the network, and integrates the switch original data set. The data set is then preprocessed to extract the principal component features. A forwarding path prediction model is constructed based on machine learning algorithms, and a risk area is identified using adaptive loop prevention methods, and a port state adjustment strategy is formulated.
It realizes deep feature extraction and dynamic risk management of switch networks, improves the accuracy and adaptability of network monitoring, and ensures the security and stability of the network.
Smart Images

Figure CN119922115A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of switch information exchange, and in particular to an information exchange method and device for multiple Ethernet switches. Background Art
[0002] Switch information exchange technology refers to the technology that uses switch devices to achieve efficient and secure transmission of data frames in network communications.
[0003] In the field of switch information exchange technology, in the existing technology, network monitoring equipment only records transmission flow data and ignores the network topology status, which leads to the one-sidedness of the data and cannot fully reflect the real situation of the network. In addition, the existing methods often rely on simple statistical features in feature extraction and lack effective mining of deep-level features. At the same time, the existing technology for loop prevention and identification of risk areas often relies on static rules and is difficult to adapt to the dynamically changing network environment. Summary of the invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides an information exchange method for multiple Ethernet switches to solve the problem that the existing methods often rely on simple statistical features in feature extraction and lack effective mining of deep-level features.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides an information exchange method for multiple Ethernet switches, comprising: recording transmission flow data of switch ports through a network monitoring device, and capturing connection relationships between switches in a network, obtaining transmission flow data and network topology status, integrating the transmission flow data and network topology status, and forming a switch original data set;
[0008] Preprocessing the original switch data set to obtain a preprocessed feature vector set;
[0009] Building a forwarding path prediction model based on a machine learning algorithm, inputting a feature vector set into the forwarding path prediction model, outputting a forwarding path, and forwarding data frames based on the forwarding path;
[0010] Using an adaptive loop prevention method to identify risk areas in the data frame forwarding process and generate identification results;
[0011] Based on the identification result, a port state adjustment strategy is formulated to adjust the port state to obtain an updated port state;
[0012] Based on the updated port status, the switch device is configured using the API interface.
[0013] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: the transmission flow data of the switch port is recorded by the network monitoring device, and the connection relationship between the switches in the network is captured to obtain the transmission flow data and the network topology state, and the transmission flow data and the network topology state are integrated to form the switch original data set, and the specific steps are as follows:
[0014] Configure the network monitoring device Prometheus to record the transmission flow data of the switch port;
[0015] Use LLDP protocol to capture the connection relationship between switches in the network, parse the link and collect switch protocol data packets;
[0016] Query the switch protocol data packet through the SNMP v2c network management protocol to obtain the switch interface status, MAC address and ARP information in the switch protocol data packet, and obtain the network topology status;
[0017] The transmission flow data is aligned with the timestamp in the network topology status and stored in a centralized database to form the switch raw data set.
[0018] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: the original data set of the switch is preprocessed to obtain the preprocessed feature vector set, and the specific steps are:
[0019] A low-pass filter is used to remove noise from the transmission flow data and network topology status in the original data set of the switch to obtain a preliminary data set after noise removal;
[0020] The preliminary data set after noise removal is standardized to obtain a standardized data set S;
[0021] Based on the standardized data set S, the autoencoder and sparse PCA method are used to extract the principal component feature ω, which is expressed as:
[0022] ω=(SS θ )W k +α·AEder(S)+β·SPCA(S);
[0023] Among them, S θ is the mean vector of the standardized data set S, W k is the projection matrix composed of the eigenvectors corresponding to the first k largest eigenvalues, α and β are weight parameters, AEder(S) is the component feature extracted by the autoencoder, and SPCA(S) is the component feature extracted by sparse PCA;
[0024] The maximum variance directional feature in the principal component feature ω is set to The second largest variance directional feature is set as
[0025] Based on the maximum variance directional feature and the second largest variance direction feature Construct a feature vector set, the expression is:
[0026]
[0027] Among them, H is the feature vector set, and is the principal component feature extracted by sparse PCA, and α is the weight parameter.
[0028] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: the forwarding path prediction model is constructed based on the machine learning algorithm, the feature vector set is input into the forwarding path prediction model, the forwarding path is output, and the data frame is forwarded based on the forwarding path, the specific steps are:
[0029] Construct a forwarding path prediction model based on the feature vector set H and the support vector machine SVM algorithm;
[0030] The feature vector set H is divided into a training set and a validation set. The data of the i-th sample in the training set is set to H i , the category of the i-th sample in the training set is set to y i ;
[0031] The feature vector set H and the data H of the i-th sample in the training set i In the input forwarding path prediction model, the decision function is used to calculate the prediction result of the forwarding path, and the expression is:
[0032]
[0033]
[0034] Among them, Y is the predicted forwarding path, b represents the bias term in the decision function, and α i is the Lagrange multiplier of the i-th sample, K(H,H i ) is the kernel function, γ is the parameter of the kernel function, exp represents the exponential function, and n represents the number of training samples in the training set;
[0035] Based on the predicted forwarding path Y, the data frame is forwarded.
[0036] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: the use of the adaptive loop prevention method to identify the risk area in the data frame forwarding process and generate the identification result, the specific steps are:
[0037] All predicted forwarding paths are integrated to obtain the candidate path set P. Candidate Paths represents the candidate path from the previous starting point to the current starting point, An index variable representing a candidate path;
[0038] For Candidate Paths Collects traffic data on the links along its path Link volatility and the length of the link
[0039] Define the loop risk assessment index, the expression is:
[0040]
[0041] in, For the The risk scores of candidate paths, w1, w2, w3 are weight coefficients, Candidate path The length of the upper link, Candidate path Uplink transmission traffic data, Candidate path Uplink volatility;
[0042] Set the risk threshold M to filter all risk scores The candidate paths that are greater than the risk threshold M form a risk area, which is expressed as:
[0043]
[0044] Among them, Z is the risk area, For the The risk score of candidate paths, M is the risk threshold, Indicates candidate paths.
[0045] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: based on the identification result, a port state adjustment strategy is formulated to adjust the port state to obtain the adjusted port state, and the specific steps are:
[0046] Based on all risk scores For candidate paths with a risk threshold greater than M, find the port connected to the risk area Z;
[0047] Detecting a port status ∩, wherein the port status refers to open, closed, and blocked;
[0048] When the port status ∩ is open, it means that the port currently allows traffic data to pass through;
[0049] When the port status ∩ is closed, it means that the port has been disabled and no transmission traffic data is allowed to pass;
[0050] When the port status ∩ is blocked, it means that the port receives but does not send data packets;
[0051] Develop port status adjustment strategies based on risk areas and port status;
[0052] When the port is in the risk area and the port status is open, change the port status from open to closed;
[0053] When the port is in the risk area and the port status is closed, no adjustment is required;
[0054] When a port is in a risky area and is blocked, its priority is lowered and the spanning tree protocol (STP) is modified to make it a secondary choice when selecting a path on the network.
[0055] As a preferred solution of the information exchange method of the multi-Ethernet switch of the present invention, wherein: based on the adjusted port status, the iterative optimization method is used for updating, and based on the updated port status, the switch device is configured using the API interface, and the specific steps are:
[0056] Based on the adjusted port status, if the port is still in the risk area, the risk score of each path is recalculated using the loop risk assessment indicator expression and marked as a new risk area;
[0057] Enable access control list (ACL) to limit the type of traffic that passes through the port and block unnecessary communications. Enable port security to limit the maximum number of MAC addresses allowed on the port and prevent unauthorized device access.
[0058] When the port is not in the risk area, no update is required;
[0059] Based on the updated port status, select the interface protocol SNMP to perform network management configuration on the switch device;
[0060] Synchronize network management configuration to all connected switch devices and complete information exchange between all switch devices.
[0061] In a second aspect, the present invention provides an information exchange device for a multi-Ethernet switch, comprising: a data acquisition module, a data processing module, a path prediction module, a risk identification module, a port status module, and a configuration module;
[0062] The data processing module is used to record the transmission flow data of the switch port through the network monitoring device, and capture the connection relationship between the switches in the network, obtain the transmission flow data and the network topology status, and integrate the transmission flow data and the network topology status to form the switch original data set;
[0063] The data processing module is used to preprocess the original data set of the switch to obtain a preprocessed feature vector set;
[0064] The path prediction module is used to build a forwarding path prediction model based on a machine learning algorithm, input the feature vector set into the forwarding path prediction model, output the forwarding path, and forward the data frame based on the forwarding path;
[0065] The risk identification module is used to identify risk areas in the data frame forwarding process using an adaptive loop prevention method and generate an identification result;
[0066] The port status module is used to formulate a port status adjustment strategy to adjust the port status based on the identification result to obtain the adjusted port status;
[0067] The configuration module is used to update the port status based on the adjusted port status by adopting an iterative optimization method, and configure the switch device by using an API interface based on the updated port status.
[0068] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the information exchange method of a multi-Ethernet switch as described in the first aspect of the present invention is implemented.
[0069] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the information exchange method for multiple Ethernet switches as described in the first aspect of the present invention is implemented.
[0070] The beneficial effects of the present invention are as follows: by configuring the network monitoring device Prometheus, a comprehensive record of the switch port transmission flow data is achieved. At the same time, the LLDP protocol is used to capture the connection relationship between switches, and the SNMP v2c protocol is used to obtain detailed switch interface status, MAC address and ARP information, thereby ensuring the accuracy of the network topology status. By performing low-pass filter processing on the original switch data set, noise interference is removed, and a purer preliminary data set is obtained. After further standardization, the various features in the data set are comparable, which improves the reliability of subsequent analysis. A forwarding path prediction model is constructed by a support vector machine algorithm, and the feature vector set is divided into a training set and a validation set, thereby ensuring the generalization ability and stability of the forwarding path prediction model. The decision function is used to calculate the prediction result of the forwarding path, which not only considers the category label of the sample, but also introduces a kernel function to adapt to the nonlinear relationship, thereby improving the accuracy of the prediction. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0072] Figure 1 This is a flow chart of the information exchange method of multiple Ethernet switches in Example 1.
[0073] Figure 2 This is a diagram of an information exchange device of multiple Ethernet switches in Example 1. DETAILED DESCRIPTION
[0074] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0075] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0076] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0077] Example 1, reference Figure 1 and Figure 2 , which is the first embodiment of the present invention, provides an information exchange method for multiple Ethernet switches, comprising the following steps:
[0078] S1. Record the transmission flow data of the switch port through the network monitoring device, and capture the connection relationship between the switches in the network, obtain the transmission flow data and the network topology status, integrate the transmission flow data and the network topology status, and form the switch original data set;
[0079] Furthermore, the network monitoring device Prometheus is configured to record the transmission flow data of the switch port;
[0080] Use LLDP protocol to capture the connection relationship between switches in the network, parse the link and collect switch protocol data packets;
[0081] Query the switch protocol data packet through the SNMP v2c network management protocol to obtain the switch interface status, MAC address and ARP information in the switch protocol data packet, and obtain the network topology status;
[0082] Align the transmission flow data with the timestamp in the network topology status and store it in a centralized database to form the switch raw data set;
[0083] It should be noted that this step ensures the integrity and consistency of the data, so that subsequent analysis can be performed based on accurate time series. By using Prometheus, LLDP, and SNMP v2c protocols, not only comprehensive data collection is achieved, but also the diversity and reliability of data sources are guaranteed. The final raw data set of the switch provides a solid foundation for subsequent processing and analysis.
[0084] S2, preprocessing the original switch data set to obtain a preprocessed feature vector set;
[0085] Furthermore, a low-pass filter is used to remove noise from the transmission flow data and network topology status in the original data set of the switch to obtain a preliminary data set after noise removal;
[0086] The preliminary data set after noise removal is standardized to obtain a standardized data set S;
[0087] Based on the standardized data set S, the autoencoder and sparse PCA method are used to extract the principal component feature ω, which is expressed as:
[0088] ω=(SS θ )W k +α·AEder(S)+β·SPCA(S);
[0089] Among them, S θ is the mean vector of the standardized data set S, W k is the projection matrix composed of the eigenvectors corresponding to the first k largest eigenvalues, α and β are weight parameters, AEder(S) is the component feature extracted by the autoencoder, and SPCA(S) is the component feature extracted by sparse PCA;
[0090] The maximum variance directional feature in the principal component feature ω is set to The second largest variance directional feature is set as
[0091] Based on the maximum variance directional feature and the second largest variance directional feature Construct a feature vector set, the expression is:
[0092]
[0093] Among them, H is the feature vector set, and is the principal component feature extracted by sparse PCA, and α is the weight parameter;
[0094] It should be noted that the preprocessing step effectively reduced noise interference and improved the quality of the feature vector set, and the standardization process ensured the comparability of different features. The application of autoencoders and sparse PCA methods extracted key features from complex data, simplified the subsequent modeling process, and retained important information.
[0095] S3. Build a forwarding path prediction model based on a machine learning algorithm, input the feature vector set into the forwarding path prediction model, output the forwarding path, and forward the data frame based on the forwarding path;
[0096] Furthermore, a forwarding path prediction model is constructed based on the feature vector set H and the support vector machine SVM algorithm;
[0097] The feature vector set H is divided into a training set and a validation set. The data of the i-th sample in the training set is set to H i , the category of the i-th sample in the training set is set to y i ;
[0098] The feature vector set H and the data H of the i-th sample in the training set i In the input forwarding path prediction model, the decision function is used to calculate the prediction result of the forwarding path, and the expression is:
[0099]
[0100]
[0101] Among them, Y is the predicted forwarding path, b represents the bias term in the decision function, and α i is the Lagrange multiplier of the i-th sample, K(H,H i ) is the kernel function, γ is the parameter of the kernel function, exp represents the exponential function, and n represents the number of training samples in the training set;
[0102] Forwarding the data frame based on the predicted forwarding path Y;
[0103] It should be noted that the forwarding path prediction model constructed using the SVM algorithm can find the optimal hyperplane in high-dimensional space, thereby achieving accurate path prediction. By dividing the training set and the validation set, the generalization ability and stability of the forwarding path prediction model are ensured, the prediction accuracy is improved, and the forwarding efficiency of the data frame is optimized.
[0104] S4, using an adaptive loop prevention method to identify risk areas in the data frame forwarding process and generate an identification result;
[0105] Furthermore, all predicted forwarding paths are integrated to obtain the candidate path set P. Candidate Paths represents the candidate path from the previous starting point to the current starting point, An index variable representing a candidate path;
[0106] For Candidate Paths Collects traffic data on the links along its path Link volatility and the length of the link
[0107] Define the loop risk assessment index, the expression is:
[0108]
[0109] in, For the The risk scores of candidate paths, w1, w2, w3 are weight coefficients, Candidate path The length of the upper link, Candidate path Uplink transmission traffic data, Candidate path Uplink volatility;
[0110] Set the risk threshold M to filter all risk scores The candidate paths that are greater than the risk threshold M form a risk area, which is expressed as:
[0111]
[0112] Among them, Z is the risk area, For the The risk score of candidate paths, M is the risk threshold, Indicates candidate paths;
[0113] It should be noted that the loop risk assessment index comprehensively considers the link length, transmission traffic and volatility, ensuring the comprehensiveness and accuracy of the risk assessment. By setting the risk threshold, it can effectively identify high-risk paths, providing a scientific basis for subsequent risk management and port status adjustment.
[0114] S5. Based on the identification result, formulate a port state adjustment strategy to adjust the port state to obtain an updated port state;
[0115] Furthermore, based on all risk scores For candidate paths with a risk greater than the risk threshold M, find the port connected to the risk area Z;
[0116] Check the port status ∩, the port status refers to open, closed and blocked;
[0117] When the port status ∩ is open, it means that the port currently allows traffic data to pass through;
[0118] When the port status ∩ is closed, it means that the port has been disabled and no transmission traffic data is allowed to pass;
[0119] When the port status ∩ is blocked, it means that the port receives but does not send data packets;
[0120] Develop port status adjustment strategies based on risk areas and port status;
[0121] When the port is in the risk area and the port status is open, change the port status from open to closed;
[0122] When the port is in the risk area and the port status is closed, no adjustment is required;
[0123] When a port is in a risky area and is blocked, its priority is lowered and the spanning tree protocol (STP) is modified to make it the second choice when selecting a path on the network.
[0124] It should be noted that the port status adjustment strategy is designed to minimize the impact of risk areas and ensure network security and stable operation. By dynamically adjusting the port status, potential threats can be responded to in a timely manner to ensure network performance and data transmission security. Specific measures include closing high-risk ports, keeping closed ports unchanged, and adjusting the priority of blocked ports to prevent loops from forming.
[0125] S6. Based on the updated port status, configure the switch device using the API interface;
[0126] Furthermore, based on the adjusted port status, when the port is still in the risk area, the risk score of each path is recalculated using the loop risk assessment indicator expression and marked as a new risk area;
[0127] Enable access control list (ACL) to limit the type of traffic that passes through the port and block unnecessary communications. Enable port security to limit the maximum number of MAC addresses allowed on the port and prevent unauthorized device access.
[0128] When the port is not in the risk area, no update is required;
[0129] Based on the updated port status, select the interface protocol SNMP to perform network management configuration on the switch device;
[0130] Synchronize network management configuration to all connected switch devices and complete information exchange between all switch devices;
[0131] It should be noted that configuration through the API interface realizes automated and intelligent network management, ensures the consistency and real-time nature of the configuration, and enables ACL and Port Security to enhance the network's security protection capabilities, prevent unauthorized access and abnormal traffic. The continuous risk assessment and configuration update mechanism enables the system to flexibly respond to the ever-changing network environment, ensuring the efficient operation and security of the overall network.
[0132] This embodiment also provides an information exchange device for a multi-Ethernet switch, including: a data acquisition module, a data processing module, a path prediction module, a risk identification module, a port status module, and a configuration module;
[0133] The data processing module is used to record the transmission flow data of the switch port through the network monitoring device, and capture the connection relationship between the switches in the network, obtain the transmission flow data and the network topology status, and integrate the transmission flow data and the network topology status to form the switch original data set;
[0134] The data processing module is used to preprocess the original data set of the switch to obtain a preprocessed feature vector set;
[0135] A path prediction module is used to build a forwarding path prediction model based on a machine learning algorithm, input a feature vector set into the forwarding path prediction model, output a forwarding path, and forward data frames based on the forwarding path;
[0136] A risk identification module, used to identify risk areas in the data frame forwarding process using an adaptive loop prevention method and generate an identification result;
[0137] The port status module is used to formulate a port status adjustment strategy to adjust the port status based on the identification result to obtain the adjusted port status;
[0138] The configuration module is used to update the port status based on the adjusted port status by adopting an iterative optimization method, and configure the switch device by using an API interface based on the updated port status.
[0139] This embodiment also provides a computer device, which is applicable to the information exchange method of multiple Ethernet switches, including: a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to implement the information exchange method of multiple Ethernet switches proposed in the above embodiment.
[0140] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.
[0141] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the information exchange method for implementing a multi-Ethernet switch as proposed in the above embodiment is implemented; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, referred to as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, referred to as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, referred to as EPROM), programmable read-only memory (Programmable Red-Only Memory, referred to as PROM), read-only memory (Read-Only Memory, referred to as ROM), magnetic storage, flash memory, magnetic disk or optical disk.
[0142] In summary, the present invention realizes comprehensive recording of switch port transmission flow data by configuring the network monitoring device Prometheus. At the same time, the LLDP protocol is used to capture the connection relationship between switches, and the SNMP v2c protocol is used to obtain detailed switch interface status, MAC address and ARP information, thereby ensuring the accuracy of the network topology status. By performing low-pass filter processing on the original data set of the switch, noise interference is removed, and a purer preliminary data set is obtained. After further standardization, the various features in the data set are comparable, which improves the reliability of subsequent analysis. The forwarding path prediction model is constructed by the support vector machine algorithm, and the feature vector set is divided into a training set and a validation set, thereby ensuring the generalization ability and stability of the forwarding path prediction model. The decision function is used to calculate the prediction result of the forwarding path, which not only considers the category label of the sample, but also introduces the kernel function to adapt to the nonlinear relationship, thereby improving the accuracy of the prediction.
[0143] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A method for exchanging information of multiple Ethernet switches, characterized in that: include: The transmission flow data of the switch port is recorded through the network monitoring equipment, and the connection relationship between the switches in the network is captured to obtain the transmission flow data and the network topology status, and the transmission flow data and the network topology status are integrated to form the original data set of the switch; Preprocessing the original switch data set to obtain a preprocessed feature vector set; Building a forwarding path prediction model based on a machine learning algorithm, inputting a feature vector set into the forwarding path prediction model, outputting a forwarding path, and forwarding data frames based on the forwarding path; Using an adaptive loop prevention method to identify risk areas in the data frame forwarding process and generate identification results; Based on the identification result, a port state adjustment strategy is formulated to adjust the port state to obtain an updated port state; Based on the updated port status, the switch device is configured using the API interface.
2. The information exchange method of a multi-Ethernet switch according to claim 1, characterized in that: The transmission flow data of the switch port is recorded by the network monitoring device, and the connection relationship between the switches in the network is captured to obtain the transmission flow data and the network topology status, and the transmission flow data and the network topology status are integrated to form the switch original data set. The specific steps are as follows: Configure the network monitoring device Prometheus to record the transmission flow data of the switch port; Use LLDP protocol to capture the connection relationship between switches in the network, parse the link and collect switch protocol data packets; Query the switch protocol data packet through the SNMP v2c network management protocol to obtain the switch interface status, MAC address and ARP information in the switch protocol data packet, and obtain the network topology status; The transmission flow data is aligned with the timestamp in the network topology status and stored in a centralized database to form the switch raw data set.
3. The information exchange method of a multi-Ethernet switch according to claim 2, characterized in that: The switch original data set is preprocessed to obtain a preprocessed feature vector set, and the specific steps are as follows: A low-pass filter is used to remove noise from the transmission flow data and network topology status in the original data set of the switch to obtain a preliminary data set after noise removal; The preliminary data set after noise removal is standardized to obtain a standardized data set S; Based on the standardized data set S, the autoencoder and sparse PCA method are used to extract the principal component feature ω, which is expressed as: ω=(SS θ )W k +α·AEder(S)+β·SPCA(S); Among them, S θ is the mean vector of the standardized data set S, W k is the projection matrix composed of the eigenvectors corresponding to the first k largest eigenvalues, α and β are weight parameters, AEder(S) is the component feature extracted by the autoencoder, and SPCA(S) is the component feature extracted by sparse PCA; The maximum variance directional feature in the principal component feature ω is set to The second largest variance directional feature is set as Based on the maximum variance directional feature and the second largest variance direction feature Construct a feature vector set, the expression is: Among them, H is the feature vector set, and is the principal component feature extracted by sparse PCA, and α is the weight parameter.
4. The information exchange method of a multi-Ethernet switch according to claim 3, characterized in that: The forwarding path prediction model is constructed based on the machine learning algorithm, the feature vector set is input into the forwarding path prediction model, the forwarding path is output, and the data frame is forwarded based on the forwarding path. The specific steps are as follows: Construct a forwarding path prediction model based on the feature vector set H and the support vector machine SVM algorithm; The feature vector set H is divided into a training set and a validation set. The data of the i-th sample in the training set is set to H i , the category of the i-th sample in the training set is set to y i ; The feature vector set H and the data H of the i-th sample in the training set i In the input forwarding path prediction model, the decision function is used to calculate the prediction result of the forwarding path, and the expression is: Among them, Y is the predicted forwarding path, b represents the bias term in the decision function, and α i is the Lagrange multiplier of the i-th sample, K(H,H i ) is the kernel function, γ is the parameter of the kernel function, exp represents the exponential function, and n represents the number of training samples in the training set; Based on the predicted forwarding path Y, the data frame is forwarded.
5. The information exchange method of a multi-Ethernet switch according to claim 4, characterized in that: The method of using the adaptive loop prevention method to identify the risk area in the data frame forwarding process and generate the identification result comprises the following specific steps: All predicted forwarding paths are integrated to obtain the candidate path set P. Candidate Paths represents the candidate path from the previous starting point to the current starting point, An index variable representing a candidate path; For Candidate Paths Collects traffic data on the links along its path Link volatility and the length of the link Define the loop risk assessment index, the expression is: in, For the The risk scores of candidate paths, w1, w2, w3 are weight coefficients, Candidate path The length of the upper link, Candidate path Uplink transmission traffic data, Candidate path Uplink volatility; Set the risk threshold M to filter all risk scores The candidate paths that are greater than the risk threshold M form a risk area, which is expressed as: Among them, Z is the risk area, For the The risk score of candidate paths, M is the risk threshold, Indicates candidate paths.
6. The information exchange method of a multi-Ethernet switch according to claim 5, characterized in that: Based on the identification result, a port state adjustment strategy is formulated to adjust the port state to obtain the adjusted port state, and the specific steps are as follows: Based on all risk scores For candidate paths with a risk threshold greater than M, find the port connected to the risk area Z; Detecting a port status ∩, wherein the port status refers to open, closed, and blocked; When the port status ∩ is open, it means that the port currently allows traffic data to pass through; When the port status ∩ is closed, it means that the port has been disabled and no transmission traffic data is allowed to pass; When the port status ∩ is blocked, it means that the port receives but does not send data packets; Develop port status adjustment strategies based on risk areas and port status; When the port is in the risk area and the port status is open, change the port status from open to closed; When the port is in the risk area and the port status is closed, no adjustment is required; When a port is in a risky area and is blocked, its priority is lowered and the spanning tree protocol (STP) is modified to make it a secondary choice when selecting a path on the network.
7. The information exchange method of a multi-Ethernet switch according to claim 6, characterized in that: The method of updating the adjusted port status by adopting the iterative optimization method is used, and the switch device is configured by using the API interface based on the updated port status. The specific steps are as follows: Based on the adjusted port status, if the port is still in the risk area, the risk score of each path is recalculated using the loop risk assessment indicator expression and marked as a new risk area; Enable access control list (ACL) to limit the type of traffic that passes through the port and block unnecessary communications. Enable port security to limit the maximum number of MAC addresses allowed on the port and prevent unauthorized device access. When the port is not in the risk area, no update is required; Based on the updated port status, select the interface protocol SNMP to perform network management configuration on the switch device; Synchronize network management configuration to all connected switch devices and complete information exchange between all switch devices.
8. An information exchange device for a multi-Ethernet switch, based on the information exchange method for a multi-Ethernet switch according to any one of claims 1 to 7, characterized in that: include: Data collection module, data processing module, path prediction module, risk identification module, port status module and configuration module; The data processing module is used to record the transmission flow data of the switch port through the network monitoring device, and capture the connection relationship between the switches in the network, obtain the transmission flow data and the network topology status, and integrate the transmission flow data and the network topology status to form the switch original data set; The data processing module is used to preprocess the original data set of the switch to obtain a preprocessed feature vector set; The path prediction module is used to build a forwarding path prediction model based on a machine learning algorithm, input the feature vector set into the forwarding path prediction model, output the forwarding path, and forward the data frame based on the forwarding path; The risk identification module is used to identify risk areas in the data frame forwarding process using an adaptive loop prevention method and generate an identification result; The port status module is used to formulate a port status adjustment strategy to adjust the port status based on the identification result to obtain the adjusted port status; The configuration module is used to update the port status based on the adjusted port status by adopting an iterative optimization method, and configure the switch device by using an API interface based on the updated port status.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the information exchange method of the multi-Ethernet switch according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the information exchange method of a multi-Ethernet switch according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Network intrusion anomaly detection method
CN104869126A
Network attack traceability evidence obtaining method
CN115134250A
Method and system for evaluating integrated circuit
CN118690713A
Encrypted network traffic classification method based on integrated prototype network
CN118740414A
High-speed data transmission hub system and data transmission method
CN118869572A
Cited By
Adaptive loop detection method and system based on flow characteristics
CN120825432A