Metropolitan area network multi-network segment flow monitoring method and related device

By building a big data set of traffic and operating status of education network nodes and performing abnormal monitoring and analysis, the problem of difficulty in monitoring multi-network traffic in the existing technology is solved, and more accurate traffic monitoring and abnormal detection is achieved.

CN119966800AActive Publication Date: 2025-05-09深圳市宝安区教育事业发展中心

Patent Information

Application Number
CN202510017298.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-09
Estimated Expiration
2045-01-06

AI Technical Summary

Technical Problem

It is difficult for the existing technology to achieve unified and accurate monitoring of the traffic of multiple network segments in the educational metropolitan area network. The interfaces of commercial network management software and traffic monitoring software are limited, and it is impossible to effectively monitor the traffic of multiple network segments.

Method used

By obtaining the traffic data and operating status data of educational network nodes, a network traffic big data collection and operating status big data collection are constructed, and abnormal monitoring and analysis are carried out to achieve more accurate monitoring of multi-segment traffic in the metropolitan area network.

Benefits of technology

It realizes more accurate monitoring of multi-network traffic in the metropolitan area network, can promptly detect abnormal situations in the network, and improves the accuracy and effectiveness of the traffic monitoring process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966800A_ABST
    Figure CN119966800A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the field of data processing, and provides a metropolitan area network multi-network segment flow monitoring method and a related device, the method and the device are applied to a server in an education network system, the education network system comprises the server and k education network nodes, and the method comprises the following steps: obtaining flow data of the k education network nodes to obtain a network flow big data set, obtaining operation state data of k educational network nodes to obtain an operation state big data set; performing anomaly monitoring analysis on the k educational network nodes according to the network flow big data set and the operation state big data set to obtain an anomaly monitoring analysis result; and the abnormal monitoring analysis result is displayed, so that a more accurate abnormal monitoring analysis result can be obtained, and more accurate metropolitan area network multi-network segment flow monitoring can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a method and related device for monitoring multi-segment traffic in a metropolitan area network. Background Art

[0002] The education metropolitan area network can access a large number of primary and secondary schools and kindergartens, and can cover a large number of in-network terminals and various network devices and server devices in the metropolitan area network and data center. With the increasing number of network segment planning for various network devices and server devices, many network segments cannot communicate with each other due to the requirements of security management and need to be isolated by the Internet of Things. At present, it is difficult to implement unified traffic monitoring for multiple network segments of the education metropolitan area network and data center, and many commercial network management software or traffic monitoring software have very limited interfaces, and the number of network segments that can be monitored is very limited. Therefore, how to achieve more accurate multi-segment traffic monitoring of the metropolitan area network has become a problem that needs to be solved urgently. Summary of the invention

[0003] The embodiment of the present application provides a method and related devices for monitoring multi-segment traffic in a metropolitan area network, which can perform abnormal monitoring and analysis on each education network node based on a network traffic big data set and an operation status big data set to obtain more accurate abnormal monitoring and analysis results, which is conducive to achieving more accurate multi-segment traffic monitoring in a metropolitan area network.

[0004] A first aspect of an embodiment of the present application provides a method for monitoring multi-segment traffic in a metropolitan area network, which is applied to a server in an education network system, wherein the education network system includes a server and k education network nodes, and the method includes:

[0005] Obtaining the flow data of k education network nodes to obtain a network flow big data set, and obtaining the operation status data of k education network nodes to obtain an operation status big data set;

[0006] Perform abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set, and obtain the abnormal monitoring and analysis results;

[0007] Displays abnormal monitoring analysis results.

[0008] In this example, a network traffic big data set is obtained by acquiring the traffic data of k education network nodes, and an operation status big data set is obtained by acquiring the operation status big data set of k education network nodes. The k education network nodes can be further subjected to abnormal monitoring and analysis based on the network traffic big data set and the operation status big data set to obtain more accurate abnormal monitoring and analysis results, thereby displaying the abnormal monitoring and analysis results, which is conducive to achieving more accurate multi-segment traffic monitoring in the metropolitan area network.

[0009] A second aspect of an embodiment of the present application provides a multi-segment traffic monitoring device for a metropolitan area network, the device comprising:

[0010] An acquisition unit, used for acquiring the flow data of k education network nodes to obtain a network flow big data set, and acquiring the operation status data of k education network nodes to obtain an operation status big data set;

[0011] A processing unit, used for performing abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results;

[0012] A display unit is used to display the abnormal monitoring and analysis results.

[0013] A third aspect of an embodiment of the present application provides a terminal, comprising a processor, an input device, an output device and a memory, wherein the processor, input device, output device and memory are interconnected, wherein the memory is used to store a computer program, the computer program comprises program instructions, and the processor is configured to call the program instructions to execute the step instructions in the first aspect of the embodiment of the present application.

[0014] The fourth aspect of the embodiments of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program for electronic data exchange, wherein the computer program enables a computer to execute part or all of the steps described in the first aspect of the embodiments of the present application.

[0015] A fifth aspect of the embodiments of the present application provides a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute some or all of the steps described in the first aspect of the embodiments of the present application. The computer program product may be a software installation package. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0017] Figure 1 A schematic diagram of an application environment of a method for monitoring multi-segment traffic in a metropolitan area network is provided for an embodiment of the present application;

[0018] Figure 2A flow chart of a method for monitoring multi-segment traffic in a metropolitan area network is provided for an embodiment of the present application;

[0019] Figure 3 A schematic diagram of the structure of a terminal provided in an embodiment of the present application;

[0020] Figure 4 A structural schematic diagram of a multi-segment traffic monitoring device for a metropolitan area network is provided for an embodiment of the present application. DETAILED DESCRIPTION

[0021] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0022] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.

[0023] Reference to "embodiments" in this application means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments.

[0024] In order to better understand the method for monitoring multi-segment traffic in a metropolitan area network provided by the embodiment of the present application, the following first briefly introduces the scenario in which the method for monitoring multi-segment traffic in a metropolitan area network is applied. In today's digital age, the metropolitan area network carries a large number of network communication services in many organizations and regions, and it is very important to accurately monitor the traffic of its multiple segments. However, the existing metropolitan area network multi-segment traffic monitoring technology has many defects, which affects the accuracy of the monitoring results.

[0025] On the one hand, from a hardware perspective, some network devices used for traffic collection have limited accuracy. For example, some traditional network interface cards (NICs) may lose packets or misjudge packets when capturing and measuring data packets in a high-speed network environment, resulting in a deviation between the statistical traffic data and the actual traffic. Moreover, when the concurrent traffic volume of multiple network segments is extremely high, the processing power of the hardware equipment is insufficient and it is impossible to record all traffic information in real time and completely, which in turn affects the accuracy of subsequent traffic analysis.

[0026] On the other hand, software issues are equally prominent. Many commercial traffic monitoring software are often developed based on general models, which are difficult to adapt to the complex and diverse network topology structures in metropolitan area networks and the personalized needs of different network segments. When they identify and classify multi-segment traffic, they are prone to protocol parsing errors or misjudgment of traffic attribution, making traffic statistics inaccurate. At the same time, although some open source traffic monitoring tools are low-cost and highly customizable, they lack a complete verification mechanism. During long-term operation, traffic data may drift due to factors such as data accumulation and algorithm errors, and cannot accurately reflect the real-time traffic status of each network segment.

[0027] Furthermore, in the network configuration and management process, different access rules and firewall policies are set between network segments due to security policies, network isolation and other requirements, which makes the traffic monitoring system face many obstacles when obtaining accurate data across network segments. For example, in some situations where it is necessary to penetrate network segments for traffic collection, some traffic data will be lost or unable to be obtained due to permission restrictions or network blocking, which ultimately affects the comprehensive and accurate monitoring of the multi-segment traffic of the entire metropolitan area network.

[0028] Since the existing multi-segment traffic monitoring in metropolitan area networks has many defects in accuracy in hardware, software, and network configuration management, the present application provides a multi-segment traffic monitoring method for metropolitan area networks, which can achieve more accurate monitoring of metropolitan area networks and obtain more accurate abnormal monitoring and analysis results, which is conducive to improving the accuracy and effectiveness of the traffic monitoring process to meet the growing demand for accurate network traffic monitoring.

[0029] The multi-segment traffic monitoring method of metropolitan area network can be applied in the following situations: Figure 1In an application environment, the client communicates with the server through a network. Exemplarily, taking the scenario of monitoring multi-segment traffic in a metropolitan area network for an education network system as an example, the target user (manager or R&D personnel) can upload the traffic data of k education network nodes through the client to obtain a network traffic big data set, and the operating status data of k education network nodes to obtain an operating status big data set. Correspondingly, the server can obtain the traffic data of k education network nodes through the client to obtain a network traffic big data set, and obtain the operating status data of k education network nodes to obtain an operating status big data set, and can further perform abnormal monitoring and analysis on the k education network nodes based on the network traffic big data set and the operating status big data set to obtain more accurate abnormal monitoring and analysis results, and feed the abnormal monitoring and analysis results back to the client. Correspondingly, the client can receive the abnormal monitoring and analysis results from the server, and can display the abnormal monitoring and analysis results on the client for the target user to query or browse. By adopting the metropolitan area network multi-segment traffic monitoring method provided in this application, it is possible to perform abnormal monitoring and analysis on each education network node based on the network traffic big data set and the operation status big data set to obtain more accurate abnormal monitoring and analysis results, which is conducive to achieving more accurate metropolitan area network multi-segment traffic monitoring.

[0030] The client may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, and portable wearable devices. The server may be implemented by an independent server or a server cluster consisting of multiple servers. The present invention is described in detail below through specific embodiments.

[0031] See also Figure 2 , Figure 2 The present application provides a flow chart of a method for monitoring traffic in multiple network segments of a metropolitan area network. Figure 2 As shown, the method includes:

[0032] 201. Obtain the traffic data of k education network nodes to obtain a network traffic big data set, and obtain the operation status data of k education network nodes to obtain an operation status big data set.

[0033] The education network node can be understood as a key connection point in the education network system, which can be the source of generating and transmitting network traffic. The education network node can be a network server in the school, a network access device in each teaching building or office building, etc.

[0034] The traffic data of the education network node can be used to indicate various types of information related to data traffic generated by each network node in the education network system (such as the network nodes of the teaching building and the network nodes of the office building in the school) during the network communication process, such as the amount of data packets sent and received in different time periods, the use of network bandwidth by each application, etc. The operation status data can be other related data reflecting the operation status of the education network node in addition to the traffic information, such as the CPU usage, memory usage, device temperature, port connection status, etc. of the network device corresponding to the education network node.

[0035] By acquiring the traffic data of k education network nodes in the education network system, a network traffic big data set can be formed; by acquiring the operating status data of k education network nodes in the education network system, an operating status big data set can be formed; the network traffic big data set and the operating status big data set can be important basic data sources for subsequent abnormal monitoring and analysis, and can reflect the operating status of each education network node from the traffic level.

[0036] 202. Perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results.

[0037] Based on the acquired network traffic big data set and operation status big data set, and using preset algorithms, rules and analysis models, a comprehensive inspection and judgment of k education network nodes can be carried out to find out nodes that may have abnormalities, such as sudden abnormal increase in traffic, excessive equipment resource usage, frequent connection failures on ports, etc., and the judgment results, i.e., abnormal monitoring and analysis results, are obtained to help operation and maintenance personnel to promptly discover potential problems in the network.

[0038] It should be noted that the relevant steps of performing abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain the abnormal monitoring and analysis results can be found in the specific description in the embodiment shown below, and this application will not repeat them here.

[0039] 203. Display the abnormal monitoring and analysis results.

[0040] Furthermore, the results obtained through abnormal monitoring and analysis are presented in an intuitive and visual manner (for example, through charts, reports, alarm prompts, etc.), which can facilitate relevant management personnel, operation and maintenance personnel, etc. to quickly check and understand whether there are abnormalities in each education network node and the specific circumstances of the abnormalities, and then take corresponding measures in time to deal with the problems and ensure the normal and stable operation of the network.

[0041] In this example, a network traffic big data set is obtained by acquiring the traffic data of k education network nodes, and an operation status big data set is obtained by acquiring the operation status big data set of k education network nodes. The k education network nodes can be further subjected to abnormal monitoring and analysis based on the network traffic big data set and the operation status big data set to obtain more accurate abnormal monitoring and analysis results, thereby displaying the abnormal monitoring and analysis results, which is conducive to achieving more accurate multi-segment traffic monitoring in the metropolitan area network.

[0042] In a possible implementation, a method for performing abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results includes:

[0043] A1. Constructing a metropolitan area network node portrait according to the network traffic big data set and the operation status big data set to obtain a metropolitan area network node portrait;

[0044] A2. Perform abnormal monitoring and analysis on k education network nodes according to the metropolitan area network node portrait to obtain abnormal monitoring and analysis results.

[0045] The server can build a metropolitan area network node portrait by comprehensively utilizing the network traffic big data set and the operation status big data set. It should be noted that the network traffic big data set can cover detailed traffic-related information such as traffic size, traffic direction, and traffic peak time period of each education network node during network use; while the operation status big data set can include non-traffic data such as the resource usage of the node's corresponding network device itself and the device connection status.

[0046] The server can integrate these rich data through preset data analysis, integration and modeling methods to create a portrait for each education network node that fully reflects its characteristics and status in the metropolitan area network, that is, the above-mentioned metropolitan area network node portrait. The metropolitan area network node portrait can characterize the network behavior, operation health, etc. of the education network node from multiple dimensions, and this application does not limit this.

[0047] After constructing the metropolitan area network node portrait, it can be used as a basis for abnormal monitoring and analysis of k education network nodes. Since the metropolitan area network node portrait can present many characteristics and states of each node under normal conditions in detail, it is possible to check whether each node has abnormal traffic (such as sudden abnormal fluctuations in traffic, long-term exceeding of the normal bandwidth range, etc.), abnormal operation status (such as excessive consumption of equipment resources, unreasonable connection interruption on the port, etc.) and other situations by comparing the difference between the current state presented by the portrait and the past normal state, or referring to the established reasonable indicator range, network operation standards, etc.

[0048] After the above comprehensive and targeted analysis process, we can obtain the abnormal monitoring analysis results on whether there are abnormalities in the k education network nodes and the specific abnormal situations, which can further help the operation and maintenance personnel to accurately locate the nodes where problems may occur and take corresponding solutions in time.

[0049] In this example, by constructing a metropolitan area network node portrait based on the network traffic big data set and the operating status big data set to perform abnormal monitoring and analysis, it is possible to fully integrate various aspects of the education network node data, and to fully characterize each education network node from traffic characteristics to operating status, so that the portrait can more accurately reflect the actual situation of the node; the abnormal monitoring and analysis based on the metropolitan area network node portrait can more keenly and accurately detect whether there are abnormalities in the node, whether it is abnormal traffic fluctuations or poor operating status. Problems can be discovered in a timely manner, which helps operation and maintenance personnel to quickly locate and solve problems and ensure the stable and efficient operation of the education network system.

[0050] In a possible implementation, when performing abnormal monitoring and analysis on a metropolitan area network, such as an educational metropolitan area network, due to the particularity of the educational metropolitan area network, in many network segments, due to security management requirements, they need to be isolated from each other and cannot communicate with each other. Therefore, when performing abnormal monitoring and analysis on the educational metropolitan area network, usually only different network segments can be analyzed for abnormalities, and the analysis usually directly performs flow analysis and status analysis, etc., which cannot reflect the status of the entire network segment (when there are multiple nodes) as a whole, resulting in low accuracy when performing abnormal analysis. In order to solve the above problem, a method is provided for performing abnormal monitoring and analysis on k nodes of the educational network according to the network flow big data set and the operation status big data set to obtain abnormal monitoring and analysis results, so that the nodes can be reflected as a whole by constructing node portraits, as well as the flow correlation between nodes, etc., so as to perform subsequent abnormal monitoring and analysis, thereby improving the accuracy of abnormal monitoring and analysis, as follows:

[0051] B1. constructing a traffic image of k education network nodes according to the traffic big data set to obtain k first target traffic images;

[0052] B2. constructing a second target traffic profile of the education network system according to the k first target traffic profiles;

[0053] B3. Perform a preliminary abnormality analysis on the education network system according to the second target traffic profile to obtain a first preliminary abnormality analysis result;

[0054] B4. If the first preliminary abnormality analysis result indicates that an abnormality exists in the education network system, use k first target traffic portraits to perform abnormality analysis on the corresponding education network nodes to obtain k first reference abnormality analysis results;

[0055] B5. extracting n target abnormality analysis results from the k first reference abnormality analysis results, wherein the target abnormality analysis results indicate that the corresponding education network node is suspected to be abnormal;

[0056] B6. Performing status analysis on the k education network nodes according to the operation status big data set to obtain status analysis results of the k education network nodes;

[0057] B7, extracting m target state analysis results from the k education network node state analysis results, wherein the target state analysis results indicate that the corresponding education network node is suspected to be abnormal;

[0058] B8. Determine the final abnormality analysis result based on the n target abnormality analysis results and the m target status analysis results.

[0059] Among them, the traffic big data set can be a set of various traffic-related data generated by k education network nodes during network communication. The traffic big data set can contain rich information such as the amount of data packets sent and received at each node at different time nodes, the size of traffic generated by different applications, and the flow direction of traffic between various network segments, which can be the basic data source for the subsequent construction of traffic images.

[0060] Traffic image construction can be understood as the process of converting abstract data in a traffic big data set into intuitive images through preset data visualization methods. For example, the traffic size of education network nodes in different time periods can be displayed in the form of a line graph, and the proportion of traffic occupied by different applications can be reflected in a bar graph. Each education network node can construct an image that can intuitively reflect its traffic characteristics, that is, the first target traffic image; k education network nodes can correspond to k first target traffic images, and the k first target traffic images help to more clearly observe the changing trends, laws, and characteristics of each node's traffic.

[0061] Furthermore, based on the k first target traffic portraits, by integrating, summarizing, and analyzing the commonalities and correlations in the traffic portraits of each node, a portrait that can reflect the overall traffic situation of the entire education network system can be constructed, namely the second target traffic portrait. The second target traffic portrait can show the traffic distribution law of the entire education network system at the macro level, the relationship between the traffic of nodes in different regions, and the general trend of the overall traffic of the education network system over time, and can describe the traffic characteristics of the education network system from a holistic perspective.

[0062] Based on the normal characteristics and rules of the overall traffic of the education network system presented by the second target traffic portrait and the pre-set reasonable traffic range, indicators and other reference standards, the traffic situation of the current education network system is checked and compared to determine whether there is any situation that does not conform to the normal state, such as whether there is a sudden abnormal peak in the overall traffic, whether there is a traffic fluctuation that does not conform to the daily rules, etc., and the first preliminary abnormal analysis result can be obtained.

[0063] The first preliminary abnormality analysis result can be used to indicate the judgment result of whether there is any abnormality in the flow of the education network system as a whole after the preliminary abnormality analysis. If the first preliminary abnormality analysis result shows that there is an abnormality, it means that the flow of the education network system has deviated from the normal state, and further in-depth analysis of the situation of each node is required to determine the specific abnormal point; if the first preliminary abnormality analysis result shows that there is no abnormality, it means that the education network system is currently in a normal operating state from the perspective of overall flow.

[0064] For each education network node, we compare its normal traffic patterns, past traffic data, and reasonable traffic ranges to check whether there are any abnormal phenomena in the current traffic portrait, such as abnormally high or low traffic values, excessively frequent or drastic traffic fluctuations, etc., which do not conform to the normal state. In this way, we can determine whether there are any traffic anomalies at each node, and obtain k first reference anomaly analysis results.

[0065] It is understandable that the k first reference anomaly analysis results can be reference judgment results of whether there is traffic anomaly in each node after performing the above anomaly analysis on the k education network nodes one by one. The k first reference anomaly analysis results can help further screen out nodes that may have problems and prepare for more accurate anomaly positioning in the future.

[0066] Further, from the k first reference abnormal analysis results, the results indicating that the corresponding education network nodes are suspected to have abnormalities in terms of traffic can be screened out to obtain n target abnormal analysis results. Optionally, the screening can be performed by certain screening criteria or manual judgment, and this application does not limit this. It is understandable that finding the analysis results corresponding to the education network nodes that are more likely to have abnormal traffic can determine the objects that need to be focused on and further investigated for subsequent steps.

[0067] According to the data in the operation status big data set, referring to the corresponding equipment normal operation indicator range, network stability standards, etc., the operation status of each education network node is checked and evaluated one by one to see whether there are situations that do not meet the normal operation requirements, such as excessive consumption of equipment resources, frequent connection failures of ports, and excessive temperature. The status analysis results of k education network nodes can be obtained.

[0068] The k education network node status analysis results can be the judgment results of whether the operation status of each education network node is normal. Through the k education network node status analysis results, the specific situation of each education network node at the equipment operation level can be understood, which can provide an important basis for comprehensive judgment whether there is any abnormality in the education network node.

[0069] From the k education network node status analysis results, the results showing that the corresponding education network nodes are suspected to be abnormal in terms of operation status can be screened out to obtain m target status analysis results. Optionally, the analysis results corresponding to the nodes whose operation status may be abnormal can be found according to a certain screening logic or based on actual operation and maintenance experience, and the nodes pointed to by the m education network node status analysis results can be the objects that need to be subsequently investigated and processed.

[0070] It can be understood that the n target anomaly analysis results can be the analysis results corresponding to the education network nodes suspected of having abnormalities screened out from the traffic perspective, which can reflect the possibility of abnormalities in the education network nodes in terms of traffic; the m target status analysis results can be the analysis results corresponding to the education network nodes suspected of having abnormalities screened out from the operating status perspective, which can reflect the possibility of abnormalities in the education network nodes in terms of equipment operation and other aspects.

[0071] Taking into account the above-mentioned n target anomaly analysis results (abnormalities in terms of traffic) and m target state analysis results (abnormalities in terms of operating status), and through further comparison, analysis, and integration of this information, it is possible to finally determine the accurate judgment results of the existence of abnormalities and specific abnormal manifestations in the k education network nodes, that is, to obtain the final abnormal analysis results. The abnormal analysis results can provide a reliable basis for subsequent targeted solutions to repair network problems. Specifically, the target abnormal analysis result can indicate that the corresponding education network node is suspected to be abnormal, and the corresponding target state analysis result indicates that the education network node is suspected to be abnormal, then the education network node can be determined to be an abnormal node, otherwise, it can be determined to be a normal node. Thereby, the accuracy of determining the final abnormal analysis results can be further improved.

[0072] In this example, by constructing the traffic image of each education network node and the traffic portrait of the entire system, the abstract traffic data can be visualized, which is convenient for intuitive insight into the traffic characteristics and patterns of the system and each node, laying the foundation for subsequent analysis. The preliminary anomaly analysis based on the system traffic portrait can quickly screen the overall anomaly. When the system is abnormal, the node traffic portrait is used for in-depth analysis, and the final anomaly analysis result is determined by combining the suspected anomaly results extracted from the traffic and operating status. This realizes a multi-dimensional comprehensive judgment from the overall to the local, from the traffic to the operating status, making the anomaly judgment more accurate and comprehensive, which helps operation and maintenance personnel to quickly lock abnormal nodes and accurately solve problems, effectively ensuring the smooth and reliable operation of the education network system.

[0073] In a possible implementation, a possible method for constructing a traffic image of k education network nodes according to the traffic big data set to obtain k first target traffic images includes:

[0074] C1. Extracting a first flow data set and a second flow data set of a target education network node from the flow big data set, the flow data in the first flow data set is the flow data in the education network node, the second flow data set is the flow data associated with the first flow data in the education network node, and the target education network node is any one of the k education network nodes;

[0075] C2. constructing a traffic image according to the traffic data in the first traffic data set and the corresponding second traffic data to obtain a first target traffic image;

[0076] C3. Repeat the above steps of extracting the first traffic data set and the second traffic data set of the target education network node from the traffic big data set, constructing a traffic image according to the traffic data in the first traffic data set and the corresponding second traffic data, and obtaining a first target traffic image, until the first target traffic images corresponding to k education network nodes are obtained, and k first target traffic images are obtained.

[0077] For the target education network node, the traffic data extracted from the traffic big data set, i.e., the first traffic data set, can more directly reflect the traffic situation generated by the network activities of the education network node itself. For example, the amount of data sent out by the education network node itself and the amount of data received at different time periods in a day, or the traffic size occupied by a specific network service on the education network node. The first traffic data set focuses on the traffic status of the education network node itself and is one of the core data components for constructing the traffic image of the corresponding education network node.

[0078] The traffic data included in the second traffic data set is the traffic data associated with the first traffic data in the target education network node. The association can be reflected in many aspects, such as traffic data generated by other education network nodes that have data interaction with the education network node, external traffic data that flows to the network segment where the education network node is located and will have an impact on it, or related traffic data caused by a certain network behavior of the education network node (such as accessing specific resources). The second traffic data set can supplement the information related to the traffic of the target education network node from a broader perspective, and cooperate with the first traffic data set to more comprehensively characterize the traffic environment and association relationship of the target education network node.

[0079] The traffic data in the extracted first traffic data set and the data in the corresponding second traffic data set are converted into intuitive visualization images by using appropriate data visualization methods and tools (such as using chart drawing tools to draw traffic data in different time periods into line graphs to show traffic change trends, and using pie charts to show the proportion of traffic generated by each application, etc.), and the first target traffic image can be obtained. The first target traffic image can clearly present the traffic characteristics, traffic change rules, and correlation with surrounding traffic of the target education network node in the entire network environment, so as to more intuitively understand and analyze the traffic status of the education network node.

[0080] Optionally, importance-related calculations may be performed based on the traffic data in the first traffic data set and the corresponding second traffic data, such as calculations including but not limited to connection importance, shortest distance importance, comprehensive importance, etc., so as to further construct a traffic image based on the results of the importance-related calculations, thereby obtaining the above-mentioned first target traffic image. Among them, connection importance can reflect the importance of each traffic data as a connection point, such as the more connections a traffic data has with other traffic data, which often means that it is more critical in the logical interaction of the traffic data. The shortest distance importance can measure the shortest path length from each traffic data to all other traffic data, and can reflect the efficiency of each traffic data in transmitting information in the graph. The comprehensive importance can reflect the impact of the direct connection between a traffic data and other traffic data, as well as the impact of the indirect connection, that is, the impact of the comprehensive connection.

[0081] Specifically, taking the first flow data i in the first flow data set as an example, the number of connection edges between the first flow data i and the flow data in the second flow data can be obtained to determine the connection degree of the first flow data i, and the calculation result of the connection importance of the first flow data i is determined according to the connection degree. Optionally, the specific process can be referred to the following formula:

[0082]

[0083] Wherein, I1(i) is the calculation result of the connection importance; i is the index of the first flow data; D(i) is the connection degree of the first flow data i; n is the number of flow data. The number of connecting edges between the first flow data i and the flow data in the second flow data is obtained to determine the connection degree of the first flow data i. Specifically, the number of edges is determined as the connection degree, and of course, the number of edges can also be normalized and determined as the connection degree.

[0084] Further, taking the second flow data corresponding to the first flow data i as the second flow data j as an example, the calculation result of the shortest distance importance of the first flow data i can be calculated. The specific process can be referred to in the following formula:

[0085]

[0086] Where dis(i) is the average shortest distance from the first flow data i to all other nodes; i is the index of the first flow data; d ij is the average distance from the first flow data i to the second flow data j; j is the index of the second flow data; n is the number of nodes in the graph; I2(i) is the calculation result of the shortest distance importance of the first flow data i. Therefore, using the average distance can carry a whole feature and improve the subsequent accuracy.

[0087] It is understandable that if point v i To node v j There is no path between them, so define d ij is infinite, then C c (i) is 0.

[0088]

[0089] Among them, C k (i) is node v i The Katz centrality value of the graph; A is the adjacency matrix of the graph; A ij Represents node v i To node v j Is there an edge between them? β is a constant, usually 1; α is the attenuation factor, satisfying where λ max is the maximum eigenvalue of the adjacency matrix A. For the entire graph, the calculation process of its Katz centrality value can be obtained by following the formula:

[0090] C k =(I-αA) -1 β

[0091] Among them, C kis the Katz centrality value of the entire graph; I is the identity matrix; A is the adjacency matrix of the graph; α is the attenuation factor, satisfying where λ max is the largest eigenvalue of the adjacency matrix A; β is a constant, usually 1.

[0092] And the calculation result of Katz centrality, so as to convert the above calculation result into an image form in a preset manner (for example), so as to present the importance correlation information between each flow data in a visual first target flow image.

[0093] According to the above-mentioned complete process of extracting the first flow data set and the second flow data set of the target education network node from the flow big data set, and then constructing the flow image based on the extracted data to obtain the first target flow image, each education network node is operated in turn. In other words, the first education network node among the k education network nodes is processed first, and after completing its flow image construction, the second education network node among the k education network nodes is selected to repeat the same operation, and this cycle is repeated until the corresponding flow image construction work is completed for all k education network nodes, and finally k first target flow images can be obtained, thereby achieving the purpose of visualizing the flow conditions of each node in the entire education network system.

[0094] In this example, by extracting the first flow data set and the second flow data set of the target education network node from the traffic big data set, we can fully consider the node itself and the traffic data associated with it, and then construct the traffic image based on this, and finally obtain k first target traffic images. It can not only display the originally abstract and complex traffic data of each education network node in an intuitive and visual form, but also help to comprehensively and accurately present the traffic environment, traffic change patterns and mutual correlations of each node from multiple dimensions, laying a solid foundation for subsequent more in-depth and detailed abnormal monitoring and analysis of the education network system, timely discovery of potential problems, and ensuring stable and efficient operation of the entire network.

[0095] In a possible implementation, a possible method for monitoring traffic in multiple segments of a metropolitan area network may further include:

[0096] D1. If the abnormal monitoring analysis result indicates that there is an abnormal education network node, obtain a first target traffic profile of the abnormal education network node;

[0097] D2. Determine abnormal factors based on the first target traffic profile;

[0098] D3. Determine abnormal alarm information according to the abnormal factors;

[0099] D4. Display the abnormal alarm information.

[0100] When the abnormal monitoring analysis results indicate the existence of an abnormal education network node, the traffic data and related characteristics displayed therein can be deeply analyzed based on the first target traffic portrait of the abnormal education network node to find out the specific cause of the abnormality of the node, that is, to determine the abnormal factor.

[0101] For example, the first traffic profile shows that the amount of data sent by a certain education network node in a specific time period far exceeds the normal level. After further investigation, it may be found that a device in the education network node has been maliciously implanted with a virus, which continuously initiates abnormal network connections. In this case, the device being implanted with a virus can be an abnormal factor; or the first traffic profile shows that a certain education network node receives an abnormal increase in traffic from a specific network segment. After analysis, it is found that a large amount of data is mistakenly sent to this education network node due to a newly launched application configuration error in the network segment. In this case, the application configuration error can be the corresponding abnormal factor. Clarifying the abnormal factors can help accurately locate the source of the problem and provide direction for subsequent resolution of abnormal situations.

[0102] According to the abnormal factors that have been determined, prompt information can be generated according to preset rules and formats, that is, the abnormal alarm information mentioned above. The abnormal alarm information can promptly inform the relevant network management personnel, operation and maintenance personnel, etc. of the abnormal situation, so that they can quickly know the problems in the network and the approximate causes of the problems.

[0103] Optionally, the abnormal alarm information may include, but is not limited to, key content such as the node identification where the abnormality occurred, the time when the abnormality occurred, the approximate abnormal manifestation, and the preliminary judgment of the abnormal factors, so as to convey important information related to the abnormality in a concise and clear manner, and remind relevant personnel to take corresponding measures to deal with the abnormality as soon as possible, so as to ensure the normal operation of the network.

[0104] Furthermore, the generated abnormal alarm information can be presented in an appropriate manner. Optional, common display methods can be to pop up an alarm prompt box on the operation interface of the network management system, displaying the alarm content in eye-catching text; or to list various alarm information in a list form on a special monitoring alarm page, so that it is convenient to view the details; or to send the alarm information to relevant responsible personnel through emails, text messages, etc., to ensure that they can obtain abnormal notifications in time; so that personnel who need to pay attention to the network operation status can be aware of the abnormal situation at the first time, and then respond quickly.

[0105] In this example, when the abnormal monitoring analysis results indicate the existence of abnormal education network nodes, the abnormal factors are determined by obtaining the first target traffic portrait, which can accurately locate the root cause of the problem and let the operation and maintenance personnel clearly know the specific reason for the abnormality. Abnormal alarm information is generated and displayed based on the abnormal factors, which can promptly and intuitively convey the abnormal situation to relevant management personnel, so that they can respond quickly and take targeted measures to solve the problem in the shortest time, thereby effectively reducing the impact of the abnormality on the normal operation of the education network system and ensuring that the network stably and efficiently serves educational and teaching activities.

[0106] For the above embodiments, please refer to Figure 3 , Figure 3 A schematic diagram of the structure of a terminal provided in an embodiment of the present application, such as Figure 3 As shown, it includes a processor, an input device, an output device and a memory, which are connected to each other, wherein the memory is used to store a computer program, the computer program includes program instructions, the processor is configured to call the program instructions, and the program includes instructions for executing the following steps;

[0107] Acquire the flow data of k education network nodes to obtain a network flow big data set, and acquire the operation status data of k education network nodes to obtain an operation status big data set;

[0108] Performing abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results;

[0109] The abnormal monitoring and analysis results are displayed.

[0110] In this example, a network traffic big data set is obtained by acquiring the traffic data of k education network nodes, and an operation status big data set is obtained by acquiring the operation status big data set of k education network nodes. The k education network nodes can be further subjected to abnormal monitoring and analysis based on the network traffic big data set and the operation status big data set to obtain more accurate abnormal monitoring and analysis results, thereby displaying the abnormal monitoring and analysis results, which is beneficial to improving the effectiveness of the traffic monitoring process.

[0111] The above mainly introduces the scheme of the embodiment of the present application from the perspective of the execution process on the method side. It is understandable that in order to realize the above functions, the terminal includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments provided herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0112] The embodiment of the present application can divide the terminal into functional units according to the above method example. For example, each functional unit can be divided according to each function, or two or more functions can be integrated into one processing unit. The above integrated unit can be implemented in the form of hardware or in the form of software functional units. It should be noted that the division of units in the embodiment of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation.

[0113] In line with the above, see Figure 4 , Figure 4 The present application provides a schematic diagram of the structure of a multi-segment traffic monitoring device for a metropolitan area network. Figure 4 As shown, the device comprises:

[0114] An acquisition unit 101 is used to acquire the flow data of k education network nodes to obtain a network flow big data set, and to acquire the operation status data of k education network nodes to obtain an operation status big data set;

[0115] The processing unit 102 is used to perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results;

[0116] The display unit 103 is used to display the abnormal monitoring and analysis results.

[0117] In a possible implementation, the processing unit 102 is used to perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results, specifically for:

[0118] Constructing a metropolitan area network node portrait according to the network traffic big data set and the operation status big data set to obtain a metropolitan area network node portrait;

[0119] According to the metropolitan area network node portrait, abnormal monitoring and analysis are performed on the k education network nodes to obtain abnormal monitoring and analysis results.

[0120] In a possible implementation, the processing unit 102 is used to perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results, specifically for:

[0121] Constructing flow images of k education network nodes according to the flow big data set to obtain k first target flow images;

[0122] Constructing a second target traffic profile of the education network system according to the k first target traffic profiles;

[0123] Performing a preliminary anomaly analysis on the education network system according to the second target traffic profile to obtain a first preliminary anomaly analysis result;

[0124] If the first preliminary abnormality analysis result indicates that an abnormality exists in the education network system, k first target traffic profiles are used to perform abnormality analysis on the corresponding education network nodes to obtain k first reference abnormality analysis results;

[0125] Extracting n target abnormality analysis results from the k first reference abnormality analysis results, wherein the target abnormality analysis results indicate that the corresponding education network node is suspected to be abnormal;

[0126] Performing status analysis on the k education network nodes according to the operation status big data set to obtain status analysis results of the k education network nodes;

[0127] Extracting m target state analysis results from k education network node state analysis results, wherein the target state analysis results indicate that the corresponding education network node is suspected to be abnormal;

[0128] The final abnormality analysis result is determined based on the n target abnormality analysis results and the m target status analysis results.

[0129] In a possible implementation, the processing unit 102 is used to construct a traffic image of k education network nodes according to the traffic big data set to obtain k first target traffic images, specifically for:

[0130] Extracting a first flow data set and a second flow data set of a target education network node from the flow big data set, the flow data in the first flow data set is the flow data in the education network node, the second flow data set is the flow data associated with the first flow data in the education network node, and the target education network node is any one of the k education network nodes;

[0131] Constructing a traffic image based on the traffic data in the first traffic data set and the corresponding second traffic data to obtain a first target traffic image;

[0132] Repeat the above steps of extracting the first traffic data set and the second traffic data set of the target education network node from the traffic big data set, constructing a traffic image according to the traffic data in the first traffic data set and the corresponding second traffic data, and obtaining a first target traffic image, until the first target traffic images corresponding to k education network nodes are obtained, and k first target traffic images are obtained.

[0133] In a possible implementation, the processing unit 102 is further configured to:

[0134] If the abnormal monitoring analysis result indicates that there is an abnormal education network node, obtaining a first target traffic profile of the abnormal education network node;

[0135] Determining abnormal factors according to the first target traffic profile;

[0136] Determine abnormal alarm information according to the abnormal factors;

[0137] The abnormal warning information is displayed.

[0138] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute part or all of the steps of any metropolitan area network multi-segment traffic monitoring method recorded in the above method embodiments.

[0139] An embodiment of the present application also provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program enables a computer to execute part or all of the steps of any metropolitan area network multi-segment traffic monitoring method recorded in the above method embodiments.

[0140] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0141] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0142] In the several embodiments provided in the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only schematic, such as the division of the units, which is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the device or unit can be electrical or other forms.

[0143] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0144] In addition, the functional units in the various embodiments of the application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software program modules.

[0145] If the integrated unit is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a memory, including a number of instructions to enable a computer device (which can be a personal computer, server or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned memory includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, disk or optical disk and other media that can store program codes.

[0146] A person of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable memory, which can include: a flash drive, a read-only memory, a random access memory, a magnetic disk or an optical disk, etc.

[0147] The embodiments of the present application are introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of ​​the present application. At the same time, for general technical personnel in this field, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A method for monitoring multi-segment traffic in a metropolitan area network, characterized in that: The method is applied to a server in an education network system, wherein the education network system includes a server and k education network nodes. Acquire the flow data of k education network nodes to obtain a network flow big data set, and acquire the operation status data of k education network nodes to obtain an operation status big data set; Performing abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results; The abnormal monitoring and analysis results are displayed.

2. The method for monitoring multi-segment traffic in a metropolitan area network according to claim 1, characterized in that: The abnormal monitoring and analysis of the k education network nodes is performed according to the network traffic big data set and the operation status big data set to obtain the abnormal monitoring and analysis results, including: Constructing a metropolitan area network node portrait according to the network traffic big data set and the operation status big data set to obtain a metropolitan area network node portrait; According to the metropolitan area network node portrait, abnormal monitoring and analysis are performed on the k education network nodes to obtain abnormal monitoring and analysis results.

3. The method for monitoring multi-segment traffic in a metropolitan area network according to claim 1, characterized in that: The abnormal monitoring and analysis of the k education network nodes is performed according to the network traffic big data set and the operation status big data set to obtain the abnormal monitoring and analysis results, including: Constructing flow images of k education network nodes according to the flow big data set to obtain k first target flow images; Constructing a second target traffic profile of the education network system according to the k first target traffic profiles; Performing a preliminary anomaly analysis on the education network system according to the second target traffic profile to obtain a first preliminary anomaly analysis result; If the first preliminary abnormality analysis result indicates that an abnormality exists in the education network system, k first target traffic profiles are used to perform abnormality analysis on the corresponding education network nodes to obtain k first reference abnormality analysis results; Extracting n target abnormality analysis results from the k first reference abnormality analysis results, wherein the target abnormality analysis results indicate that the corresponding education network node is suspected to be abnormal; Performing status analysis on the k education network nodes according to the operation status big data set to obtain status analysis results of the k education network nodes; Extracting m target state analysis results from k education network node state analysis results, wherein the target state analysis results indicate that the corresponding education network node is suspected to be abnormal; The final abnormality analysis result is determined based on the n target abnormality analysis results and the m target status analysis results.

4. The method for monitoring multi-segment traffic in a metropolitan area network according to claim 3, characterized in that: The process of constructing the traffic images of k education network nodes according to the traffic big data set to obtain k first target traffic images includes: Extracting a first flow data set and a second flow data set of a target education network node from the flow big data set, the flow data in the first flow data set is the flow data in the education network node, the second flow data set is the flow data associated with the first flow data in the education network node, and the target education network node is any one of the k education network nodes; Constructing a traffic image based on the traffic data in the first traffic data set and the corresponding second traffic data to obtain a first target traffic image; Repeat the above steps of extracting the first traffic data set and the second traffic data set of the target education network node from the traffic big data set, constructing a traffic image according to the traffic data in the first traffic data set and the corresponding second traffic data, and obtaining a first target traffic image, until the first target traffic images corresponding to k education network nodes are obtained, and k first target traffic images are obtained.

5. The method for monitoring multi-segment traffic in a metropolitan area network according to claim 3 or 4, characterized in that: The method further comprises: If the abnormal monitoring and analysis result indicates that there is an abnormal education network node, obtaining a first target traffic profile of the abnormal education network node; Determining abnormal factors according to the first target traffic profile; Determine abnormal alarm information according to the abnormal factors; The abnormal warning information is displayed.

6. A multi-segment traffic monitoring device for a metropolitan area network, characterized in that: The device comprises: An acquisition unit, used for acquiring the flow data of k education network nodes to obtain a network flow big data set, and acquiring the operation status data of k education network nodes to obtain an operation status big data set; A processing unit, used for performing abnormal monitoring and analysis on k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results; A display unit is used to display the abnormal monitoring and analysis results.

7. The multi-segment traffic monitoring device for a metropolitan area network according to claim 6, characterized in that: The processing unit is used to perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results, specifically for: Constructing a metropolitan area network node portrait according to the network traffic big data set and the operation status big data set to obtain a metropolitan area network node portrait; According to the metropolitan area network node portrait, abnormal monitoring and analysis are performed on the k education network nodes to obtain abnormal monitoring and analysis results.

8. The multi-segment traffic monitoring device for a metropolitan area network according to claim 6, characterized in that: The processing unit is used to perform abnormal monitoring and analysis on the k education network nodes according to the network traffic big data set and the operation status big data set to obtain abnormal monitoring and analysis results, specifically for: Constructing flow images of k education network nodes according to the flow big data set to obtain k first target flow images; Constructing a second target traffic profile of the education network system according to the k first target traffic profiles; Performing a preliminary anomaly analysis on the education network system according to the second target traffic profile to obtain a first preliminary anomaly analysis result; If the first preliminary abnormality analysis result indicates that an abnormality exists in the education network system, k first target traffic profiles are used to perform abnormality analysis on the corresponding education network nodes to obtain k first reference abnormality analysis results; Extracting n target abnormality analysis results from the k first reference abnormality analysis results, wherein the target abnormality analysis results indicate that the corresponding education network node is suspected to be abnormal; Performing status analysis on the k education network nodes according to the operation status big data set to obtain status analysis results of the k education network nodes; Extracting m target state analysis results from k education network node state analysis results, wherein the target state analysis results indicate that the corresponding education network node is suspected to be abnormal; The final abnormality analysis result is determined based on the n target abnormality analysis results and the m target status analysis results.

9. A terminal, characterized in that: The method comprises a processor, an input device, an output device and a memory, wherein the processor, the input device, the output device and the memory are interconnected, wherein the memory is used to store a computer program, the computer program comprises program instructions, and the processor is configured to call the program instructions to execute the method according to any one of claims 1 to 5.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to perform the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Internet of Things terminal network portrait and abnormal network access behavior detection method

    CN109600363A

  • Abnormal behavior capturing method and system based on education cloud platform

    CN115545983A

  • Smart campus data security monitoring system and method

    CN118400275A

  • Network flow monitoring management system and method based on data analysis

    CN118400300A

  • Encrypted traffic anomaly detection method based on high-performance traffic collection

    CN119094215A

Cited By

  • Hybrid Katz centrality measurement system based on pre-filtering, electronic equipment and storage medium

    CN121418312A

  • A pre-filtered hybrid Katz centrality measurement system, electronic device, and storage medium

    CN121418312B