Network traffic cleaning method and device, server and medium

By real-time monitoring and analyzing network traffic behavior characteristics, identifying abnormal traffic patterns and applying corresponding processing strategies, the problem that traditional traffic cleaning technology cannot be accurately cleaned is solved, and more efficient and safer traffic management is achieved.

CN120074942AActive Publication Date: 2025-05-30北京联广通网络科技有限公司
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510303265.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-05-30
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

Traditional traffic cleaning technology cannot accurately clean traffic for specific IP addresses or resources, resulting in some unnecessary traffic cleaning or failure to clear all abnormal traffic, reducing the efficiency of network resources and increasing the cost of procurement and export traffic.

Method used

By monitoring network traffic in real time, analyzing traffic behavior characteristics to identify abnormal traffic patterns, and cleaning according to preset abnormal traffic processing strategies. Policies include blocking all requests for the exception source IP address, filtering only access requests from the exception source IP address to a specific resource, or filtering exception protocol packets.

Benefits of technology

It improves the accuracy and efficiency of traffic cleaning, reduces the exit traffic, improves the stability and security of network services, and reduces procurement costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074942A_ABST
    Figure CN120074942A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network traffic cleaning method and device, a server and a medium, and the method comprises the steps: monitoring network traffic in real time, and analyzing traffic behavior characteristics to recognize an abnormal traffic mode; an abnormal source IP address corresponding to the abnormal traffic mode is determined, abnormal traffic cleaning is carried out according to a preset abnormal traffic processing strategy, and the preset abnormal traffic processing strategy comprises the steps that when the first abnormal traffic mode is detected, all requests of the abnormal source IP address are shielded; when a second abnormal flow mode is detected, only filtering an access request of an abnormal source IP address to a specific resource, and retaining access requests of other resources except the specific resource; and when a third abnormal traffic mode is detected, filtering the abnormal protocol data packet. By adopting the technical scheme, the accuracy and efficiency of flow cleaning are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of data communication technologies, and more particularly, to a network traffic cleaning method, apparatus, server, and medium. Background Art

[0002] As a network security protection service, traffic cleaning is mainly used to resist Distributed Denial of Service (DDoS) attacks.

[0003] Traditional traffic cleaning systems can identify and block abnormal traffic by monitoring and analyzing network traffic, distinguish normal traffic from attack traffic, and thus protect network services from attacks.

[0004] However, traditional traffic cleaning technologies mainly rely on filtering traffic size or source IP address (Internet Protocol Address). For example, when the traffic of a certain IP address exceeds a preset threshold, it is directly blocked, or data access from blacklisted IP addresses is prohibited. The above "one-size-fits-all" traffic cleaning method usually cannot perform accurate traffic cleaning operations for specific IP addresses or resources. Such a processing method may lead to partial unnecessary traffic cleaning or failure to clear all abnormal traffic, thereby reducing the utilization efficiency of network resources and possibly increasing the cost of purchasing export traffic. Summary of the Invention

[0005] Embodiments of the present invention provide a network traffic cleaning method, apparatus, server, and medium to improve the accuracy and efficiency of traffic cleaning, thereby reducing export traffic, increasing the proportion of the internal network, and reducing procurement costs.

[0006] In a first aspect, an embodiment of the present invention provides a network traffic cleaning method, which includes:

[0007] Real-time monitor network traffic and analyze traffic behavior characteristics to identify abnormal traffic patterns. The traffic behavior characteristics include: the request frequency of the source IP address, the access resource distribution, and the protocol type. The abnormal traffic patterns include any one of a first abnormal traffic pattern, a second abnormal traffic pattern, and a third abnormal traffic pattern. The first abnormal traffic pattern is that the request frequency of the source IP address reaches a first preset frequency threshold within a set time period. The second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches a second preset frequency threshold. The specific resource is: the access frequency of a specific port, a specific Uniform Resource Locator (URL) path, or a specific Application Programming Interface (API). The third abnormal traffic pattern is an abnormal protocol type.

[0008] Determine the abnormal source IP address corresponding to the abnormal traffic pattern, and perform abnormal traffic cleaning according to the preset abnormal traffic handling strategy, where the preset abnormal traffic handling strategy includes:

[0009] When detecting the first abnormal traffic pattern, block all requests from the abnormal source IP address;

[0010] When detecting the second abnormal traffic pattern, only filter the access requests of the abnormal source IP address to specific resources, and retain the access requests to other resources except specific resources;

[0011] When detecting the third abnormal traffic pattern, filter the abnormal protocol data packets.

[0012] Optionally, the method provided by the embodiment of the present invention further includes:

[0013] After performing abnormal traffic cleaning, redirect the cleaned normal traffic to a standby server or a cloud infrastructure platform, and perform real-time monitoring on the normal traffic.

[0014] Optionally, analyzing the traffic behavior characteristics to identify abnormal traffic patterns includes:

[0015] Analyze the traffic behavior characteristics based on the abnormal traffic cleaning model to identify abnormal traffic patterns;

[0016] Correspondingly, determining the abnormal source IP address corresponding to the abnormal traffic pattern and performing abnormal traffic cleaning according to the preset abnormal traffic handling strategy includes:

[0017] Based on the abnormal traffic cleaning model, in the case of identifying an abnormal traffic pattern, determine the abnormal traffic handling strategy corresponding to the abnormal traffic pattern, where the abnormal traffic cleaning model establishes an association relationship between the traffic behavior characteristics and the abnormal traffic handling strategy;

[0018] Perform abnormal traffic cleaning according to the preset abnormal traffic handling strategy.

[0019] Optionally, the abnormal traffic cleaning model is trained in the following manner:

[0020] Obtain network traffic, and obtain new attack samples from an open threat intelligence platform, and obtain the abnormal traffic handling strategy corresponding to the new attack samples, where the network traffic includes normal traffic and attack traffic;

[0021] Label the network traffic, and use the labeled network traffic and the new attack samples as sample data;

[0022] Input the sample data into the abnormal traffic cleaning model for training. When the value of the loss function of the abnormal traffic cleaning model reaches convergence, it is considered that the training of the abnormal traffic cleaning model is completed. The trained abnormal traffic cleaning model can establish the correlation between traffic behavior characteristics and abnormal traffic handling strategies. The loss function is as follows:

[0023] y = y 1 + y 2 + λ 3 y 3 + y 4 ,

[0024] where y 1 = λ 1 y 11 + λ 2 y 12 ,

[0025]

[0026] where y 1 represents the abnormal detection loss sub-function, y 11 represents the categorical cross-entropy loss, y 12 represents the auto-encoder reconstruction loss, y i ∈ {0, 1} represents the true label of the i-th sample. When i = 1, it represents abnormal traffic; when i = 0, it represents normal traffic; represents the predicted probability of the model for the i-th sample, λ 1 represents the hyperparameter used to control the importance of the classification task, represents the feature vector obtained after the i-th sample passes through the multi-modal feature fusion module. Encoder() represents the encoder part of the auto-encoder, which is used to compress the fusion feature into a low-dimensional latent representation; Decoder() represents the decoder part of the auto-encoder, which is used to reconstruct the original fusion feature from the latent representation, ‖·‖ 2 represents the Euclidean distance (L2 norm), λ 2 represents the hyperparameter used to control the importance of the reconstruction task, π θ (a t |s t ) represents the probability of the current policy network with parameter θ selecting action a t under state s t ; represents the probability of the old policy network with parameter θ old selecting action a t under state s t ; A t = Q(s t , a t ) - V(s t) represents the advantage function, Q(s t ,a t ) represents the state-action value function, V(s t ) represents the state value function; ε represents the truncation threshold; the clip function represents restricting the policy update ratio within the interval [1 - ε, 1 + ε]; E t represents the expectation over time t, and N represents the total number of samples; represents the spatial feature vector of the i-th sample, represents the temporal feature vector of the i-th sample, the sim function represents the cosine similarity; τ represents the temperature coefficient, K represents the number of negative samples, θ i represents the i-th parameter of the current model, θ old,i represents the i-th parameter of the historical model, F i represents the parameter θ i of the diagonal element of the Fisher information matrix; λ ewc represents the regularization strength coefficient.

[0027] Optionally, the method provided by the embodiments of the present invention further includes:

[0028] determining the business peak period of the current network according to the historical traffic data of the current network;

[0029] when reaching the business peak period, increasing the first preset frequency threshold and the second preset frequency threshold.

[0030] In a second aspect, the embodiments of the present invention further provide a network traffic cleaning device, and the device includes:

[0031] A traffic behavior feature analysis module, configured to monitor network traffic in real time and analyze traffic behavior features to identify abnormal traffic patterns, where the traffic behavior features include: the request frequency of the source IP address, the access resource distribution, and the protocol type, and the abnormal traffic patterns include any one of a first abnormal traffic pattern, a second abnormal traffic pattern, and a third abnormal traffic pattern, where the first abnormal traffic pattern is that the request frequency of the source IP address reaches the first preset frequency threshold within a set time period, the second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches the second preset frequency threshold, and the specific resource is: the access frequency of a specific port, a specific Uniform Resource Locator (URL) path, or a specific Application Programming Interface (API); the third abnormal traffic pattern is an abnormal protocol type;

[0032] An abnormal traffic cleaning module, configured to determine the abnormal source IP address corresponding to the abnormal traffic pattern and perform abnormal traffic cleaning according to a preset abnormal traffic processing policy, where the preset abnormal traffic processing policy includes:

[0033] When the first abnormal traffic pattern is detected, all requests from the abnormal source IP address are blocked;

[0034] When the second abnormal traffic pattern is detected, only the access requests from the abnormal source IP address to specific resources are filtered, and the access requests to other resources except the specific resources are retained;

[0035] When the third abnormal traffic pattern is detected, abnormal protocol data packets are filtered.

[0036] Optionally, the device provided by the embodiment of the present invention further includes:

[0037] A normal traffic redirection module, configured to redirect the cleaned normal traffic to a standby server or a cloud infrastructure platform after abnormal traffic cleaning, and perform real-time monitoring on the normal traffic.

[0038] Optionally, the traffic behavior feature analysis module is specifically configured to:

[0039] Analyze traffic behavior features based on an abnormal traffic cleaning model to identify abnormal traffic patterns;

[0040] Correspondingly, the abnormal traffic cleaning module is specifically configured to:

[0041] Based on the abnormal traffic cleaning model, when an abnormal traffic pattern is identified, determine an abnormal traffic processing strategy corresponding to the abnormal traffic pattern, wherein the abnormal traffic cleaning model establishes an association relationship between traffic behavior features and abnormal traffic processing strategies;

[0042] Perform abnormal traffic cleaning according to a preset abnormal traffic processing strategy.

[0043] Optionally, the abnormal traffic cleaning model is trained in the following manner:

[0044] Obtain network traffic, and obtain new attack samples from an open threat intelligence platform, and obtain abnormal traffic processing strategies corresponding to the new attack samples, wherein the network traffic includes normal traffic and attack traffic;

[0045] Label the network traffic, and use the labeled network traffic and the new attack samples as sample data;

[0046] Input the sample data into the abnormal traffic cleaning model for training. When the value of the loss function of the abnormal traffic cleaning model reaches convergence, it is considered that the training of the abnormal traffic cleaning model is completed. The trained abnormal traffic cleaning model can establish an association relationship between traffic behavior features and abnormal traffic processing strategies, wherein the loss function is:

[0047] y = y1 +y 2 +λ 3 y 3 +y 4 ,

[0048] Among them, y 1 =λ 1 y 11 +λ 2 y 12 ,

[0049]

[0050] Among them, y 1 represents the anomaly detection loss sub - function, y 11 represents the categorical cross - entropy loss, y 12 represents the auto - encoder reconstruction loss, y i ∈{0,1} represents the true label of the i - th sample. When i = 1, it represents abnormal traffic; when i = 0, it represents normal traffic; represents the predicted probability of the model for the i - th sample, λ 1 represents the hyper - parameter for controlling the importance of the classification task, represents the feature vector obtained after the i - th sample passes through the multi - modal feature fusion module. Encoder() represents the encoder part of the auto - encoder, which is used to compress the fused features into a low - dimensional latent representation; Decoder() represents the decoder part of the auto - encoder, which is used to reconstruct the original fused features from the latent representation, ‖·‖ 2 represents the Euclidean distance (L2 norm), λ 2 represents the hyper - parameter for controlling the importance of the reconstruction task, π θ (a t |s t ) represents the probability of the current policy network with parameter θ selecting action a t under state s t ; represents the probability of the old policy network with parameter θ old selecting action a t under state s t ; A t =Q(s t ,a t ) - V(s t ) represents the advantage function, Q(s t ,a t ) represents the state - action value function, V(s t ) represents the state value function; ε represents the truncation threshold; the clip function represents restricting the policy update ratio within the interval [1 - ε, 1+ε]; E tdenotes the expectation with respect to time t, and N denotes the total number of samples; denotes the spatial feature vector of the i-th sample, denotes the temporal feature vector of the i-th sample, the sim function denotes the cosine similarity; τ denotes the temperature coefficient, K denotes the number of negative samples, θ i denotes the i-th parameter of the current model, θ old,i denotes the i-th parameter of the historical model, F i denotes the parameter θ i the diagonal element of the Fisher information matrix of the parameter θ ewc denotes the regularization strength coefficient.

[0051] Optionally, the device provided by the embodiment of the present invention further includes:

[0052] A business peak period determination module, configured to determine the business peak period of the current network according to the historical traffic data of the current network;

[0053] A threshold dynamic adjustment module, configured to increase the first preset frequency threshold and the second preset frequency threshold when the business peak period is reached.

[0054] In a third aspect, an embodiment of the present invention further provides a server, including:

[0055] A memory storing executable program code;

[0056] A processor coupled to the memory;

[0057] The processor calls the executable program code stored in the memory and executes the network traffic cleaning method provided by any embodiment of the present invention.

[0058] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the network traffic cleaning method provided by any embodiment of the present invention.

[0059] The technical solution provided by the embodiment of the present invention sets corresponding traffic processing strategies for different abnormal traffic patterns. By analyzing the traffic behavior characteristics, in the case of identifying an abnormal traffic pattern, by adopting the abnormal traffic processing strategy corresponding to the abnormal traffic pattern, higher-precision abnormal traffic cleaning can be achieved, avoiding unnecessary traffic loss caused by the traditional traffic cleaning system directly blocking all requests of the source IP. The technology provided by the embodiment of the present invention can reduce the egress traffic and improve the stability and security of the network service.

[0060] The innovation points of the embodiment of the present invention include:

[0061] 1. When the access frequency of a specific resource by an IP address reaches the second preset frequency threshold, only the access requests of the abnormal source IP address to the specific resource are blocked, rather than blocking the access requests of the entire IP address, that is, the access requests to other resources outside the specific resource are retained. While cleaning abnormal traffic, unnecessary traffic cleaning is avoided, the loss of normal traffic is reduced, the accuracy and efficiency of traffic cleaning are improved, and thus the export traffic is reduced, the proportion of the internal network is increased, and the procurement cost is reduced. This is one of the innovative points of the embodiments of the present invention.

[0062] 2. By training an abnormal traffic cleaning model, the association relationship between traffic behavior characteristics and corresponding abnormal traffic processing strategies can be established, that is, an end-to-end method is provided to achieve the cleaning of abnormal traffic, effectively improving the detection, processing accuracy and efficiency of abnormal traffic. This is one of the innovative points of the embodiments of the present invention.

[0063] 3. The abnormal traffic cleaning model adopts a structure including a multi-modal feature extraction module, a multi-modal feature fusion module, an abnormal traffic monitoring module and a policy generation module. This structure can effectively improve the accuracy and cleaning efficiency of abnormal traffic cleaning by integrating spatio-temporal analysis, graph structure modeling and reinforcement learning. This is one of the innovative points of the embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0065] Figure 1 It is a flowchart of a network traffic cleaning method provided in Embodiment 1 of the present invention;

[0066] Figure 2a It is a flowchart of a network traffic cleaning method provided in Embodiment 2 of the present invention;

[0067] Figure 2b It is a schematic structural diagram of an abnormal traffic situation model provided in Embodiment 2 of the present invention;

[0068] Figure 3 It is a block diagram of the structure of a network traffic cleaning device provided in Embodiment 3 of the present invention;

[0069] Figure 4 It is a schematic structural diagram of a server provided in Embodiment 4 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0070] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0071] It should be noted that the terms "including" and "having" in the embodiments of the present invention and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0072] The embodiments of the present invention disclose a network traffic cleaning method, device, server, and medium. The following will be described in detail separately.

[0073] Embodiment 1

[0074] Figure 1 FIG. is a flowchart of a network traffic cleaning method provided in Embodiment 1 of the present invention. This method can be applied to an application scenario for resisting DDoS attacks. The method provided in this embodiment can be executed by a network traffic cleaning device, and this device can be implemented in a software and / or hardware manner. As Figure 1 shown, the method provided in this embodiment specifically includes:

[0075] S110. Monitor network traffic in real time and analyze traffic behavior characteristics to identify abnormal traffic patterns.

[0076] Among them, network traffic refers to data packets or data streams transmitted through the network, and specifically may include: request and response data generated by users accessing the server (such as web page access, file download, etc.); communication data between servers (such as data synchronization, API calls, etc.); potential abnormal or malicious data (such as DDoS attack traffic, high-frequency invalid requests, etc.). Network traffic usually exists in the form of data packets and contains information such as source IP address, destination IP address, port number, protocol type, and data volume size.

[0077] For real-time monitoring of network traffic, specific monitoring methods can be implemented in software and / or hardware. For example, network monitoring tools can be used to capture and analyze data packets. Among them, network monitoring tools can be Wireshark (a network protocol analyzer commonly used to capture and analyze network data packets), tcpdump (a network data collection and analysis tool), etc. Alternatively, when monitoring network traffic, a network splitter (Test Access Point or Terminal Access Point, TAP) can be directly connected to the physical link to mirror network traffic to the monitoring device. Or, port mirroring (Switched Port Analyzer, SPAN) can be used to copy the traffic of a specified port to the monitoring port through switch configuration. This embodiment does not specifically limit the method for monitoring network traffic.

[0078] Furthermore, for the network traffic captured in real time, preprocessing can be performed on the network traffic. For example, duplicate, invalid, or noisy data (such as broadcast packets) can be removed, or the data format can be standardized (such as unifying the timestamp format and IP address encoding).

[0079] In this embodiment, for the preprocessed network traffic, by analyzing the traffic behavior characteristics, abnormal traffic patterns are identified. Among them, the traffic behavior characteristics include: the request frequency of the source IP address, the access resource distribution, and the protocol type. The abnormal traffic patterns include any one or more of the first abnormal traffic pattern, the second abnormal traffic pattern, and the third abnormal traffic pattern. Among them, the first abnormal traffic pattern is that the request frequency of the source IP (Internet Protocol) address reaches the first preset frequency threshold within a set time period. The second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches the second preset frequency threshold, where the specific resource is: a specific port, a URL (Uniform Resource Locator) path, or the access frequency of a specific API (Application Programming Interface). The third abnormal traffic pattern is an abnormal protocol type.

[0080] S120. Determine the abnormal source IP address corresponding to the abnormal traffic pattern and perform abnormal traffic cleaning according to the preset abnormal traffic processing strategy.

[0081] Among them, the preset abnormal traffic processing strategy includes:

[0082] (1) When the first abnormal traffic pattern is detected, block all requests from the abnormal source IP address.

[0083] For example, the traffic cleaning system of the present invention is deployed in the global data center of an e-commerce platform. Since the platform has a large amount of user and transaction data, it is vulnerable to DDoS attacks. By adopting the traffic cleaning method provided in this embodiment, the platform can monitor the access traffic of each user IP in real time. Once it detects that the access volume of a specific IP address is abnormal, for example, a certain IP initiates 10,000 requests within 1 second, far exceeding normal user behavior, the system will quickly screen and block all request traffic of this IP address, and at the same time re-inject the normal user request traffic into the intranet, avoiding waste of system resources caused by attack traffic. By this method, it is possible to successfully reduce the occupancy of the external traffic on its egress bandwidth and reduce the procurement cost of the external traffic bandwidth.

[0084] (2) When detecting the second abnormal traffic pattern, only block the access requests of the abnormal source IP address to specific resources, and retain the access requests to other resources outside the specific resources.

[0085] In the related art, when detecting the second abnormal traffic pattern, a "one-size-fits-all" traffic cleaning method is adopted, that is, all access requests corresponding to the abnormal IP address are blocked. In this embodiment, the function of setting the abnormal traffic processing policy corresponding to the second abnormal traffic model is: when the access frequency of the IP address to the specific resource reaches the second preset frequency threshold, only the access requests of the abnormal source IP address to the specific resource are blocked, rather than blocking all access requests of the entire IP address, that is, retaining the access requests to other resources outside the specific resource. While cleaning the abnormal traffic, it avoids unnecessary traffic cleaning, reduces the loss of normal traffic, improves the accuracy and efficiency of traffic cleaning, and thus reduces the egress traffic, increases the intranet ratio, and reduces the procurement cost.

[0086] For example, when a certain ISP (Internet Service Provider) implements large-scale DDoS defense, it uses the traffic cleaning and screening method of the present invention to conduct refined management of network traffic. By analyzing the traffic patterns of different IP addresses and accessed resources, it is found that the traffic of some IP sources is large and there are abnormal access behaviors. For example, high-frequency call requests are initiated for a certain API interface (such as 300 times per second). The system only filters the access requests of the abnormal source IP address to specific resources and retains the access requests to other resources outside the specific resources. While blocking the abnormal access requests to specific resources, it retains the normal access to other resources. Through intelligent scheduling, the traffic cleaning system can inject the remaining clean traffic into the operator's intranet, improving the utilization rate of the intranet and reducing the procurement cost of the egress traffic.

[0087] (3) When detecting the third abnormal traffic pattern, discard the abnormal protocol data packets.

[0088] Exemplarily, when a protocol type anomaly is detected, such as when a forged TCP (Transmission Control Protocol) / UDP (User Datagram Protocol, a protocol in the transport layer of the Open Systems Interconnection model) packet is detected, or when the data packet format is incorrect, the abnormal protocol data packet is filtered.

[0089] It should be noted that in this embodiment, the first preset frequency threshold corresponding to the first abnormal traffic pattern and the second preset frequency threshold corresponding to the second abnormal traffic pattern can be set according to the requirements of the actual application scenario. For example, for the first preset frequency threshold, the overall access traffic of each IP can be counted by analyzing the historical traffic data of the current network, so as to obtain the first preset frequency threshold. For the second preset frequency threshold, the access frequency of each IP to a specific port, a specific URL path, or the call frequency of an API interface can be counted by analyzing the historical traffic data of the current network, so as to obtain the second preset frequency threshold.

[0090] Furthermore, the first preset frequency threshold and the second preset frequency threshold can also be set in a dynamically adjustable manner. Specifically, according to the historical traffic data of the current network, the overall access traffic of each IP at different time periods and the access traffic of each IP to specific resources at different time periods can be determined, so as to dynamically adjust the first preset frequency threshold and the second preset frequency threshold according to the traffic conditions at different time periods. For example, the peak business period of the current network can be determined according to the historical traffic data of the current network (for example, the period from 1 hour before to 3 hours after an e-commerce promotion is the peak period, or the opening / closing period of a trading day in the financial field and the end-of-month settlement period are peak periods; the morning and evening commuting times of social media (such as 7-9 am and 6-8 pm) are peak periods); when the peak business period is reached, the first preset frequency threshold and the second preset frequency threshold are increased. By dynamically increasing the threshold, the system can focus on abnormal traffic exceeding the adjusted threshold, thereby reducing misjudgment of legitimate high traffic and maintaining business continuity and user satisfaction.

[0091] In this embodiment, corresponding traffic processing strategies are set for different abnormal traffic patterns. By analyzing the traffic behavior characteristics, in the case of identifying an abnormal traffic pattern, by adopting the abnormal traffic processing strategy corresponding to the abnormal traffic pattern, higher-precision abnormal traffic cleaning can be achieved, avoiding unnecessary traffic loss caused by the traditional traffic cleaning system directly blocking all requests from the source IP. The technology provided in this embodiment can reduce the egress traffic and improve the stability and security of network services.

[0092] Further, after cleaning the abnormal traffic, the cleaned normal traffic is redirected to a standby server or a cloud infrastructure platform, and the normal traffic is monitored in real time.

[0093] Exemplarily, the traffic characteristics (such as request type, user geographical location, server load) can be analyzed in real time based on a deep learning model, and the optimal standby node or cloud platform can be dynamically selected. This setting can adapt to network fluctuations and improve resource utilization.

[0094] Exemplarily, the distributed architecture of edge nodes can also be utilized to deploy a lightweight traffic scheduler, and in combination with a geographical location database (GeoIP), the cleaned traffic can be preferentially distributed to the edge computing nodes closest to the user (such as CDN edge servers, 5G MEC (Multi-access Edge Computing)) etc.). This setting can reduce latency and improve the user experience.

[0095] Embodiment 2

[0096] Figure 2a The flowchart of a network traffic cleaning method provided by Embodiment 2 of the present invention. Based on the above embodiment, the determination process of the abnormal traffic processing strategy is optimized. By training an abnormal traffic cleaning model, the corresponding abnormal traffic processing strategy can be determined according to the traffic behavior characteristics, that is, an end-to-end method is provided to realize the cleaning of abnormal traffic. As Figure 2a shown, the method provided by this embodiment includes:

[0097] S210. Monitor network traffic in real time.

[0098] S220. Based on the abnormal traffic cleaning model, analyze the traffic behavior characteristics, and when an abnormal traffic pattern is identified, determine the preset abnormal traffic processing strategy corresponding to the abnormal traffic pattern.

[0099] Among them, the abnormal traffic cleaning model is a deep learning model. Figure 2b The structural schematic diagram of an abnormal traffic situation model provided by Embodiment 2 of the present invention. As Figure 2b shown, the abnormal traffic cleaning model includes: a multimodal feature extraction module 1, a multimodal feature fusion module 2, an abnormal traffic monitoring module 3, and a policy generation module 4. The structures and functions of each module will be introduced in detail below.

[0100] The multimodal feature extraction module 1 is used to extract the preliminary features of the traffic packet data, and the preliminary features include 3D spatio-temporal features, temporal features, graph embedding features, and semantic features.

[0101] The multimodal feature fusion module 2 is used to integrate multimodal features to form a global context representation;

[0102] The abnormal traffic detection module 3 is used to judge whether the traffic is abnormal based on the fused features and identify the abnormal types (such as DDoS, port scanning);

[0103] The policy generation module 4 is used to output an abnormal traffic handling policy according to the abnormal type and the current network state (such as bandwidth utilization, server load).

[0104] Next, the structures and functions of each module will be introduced in detail.

[0105] (1) Multimodal feature extraction module

[0106] The multimodal feature extraction module specifically includes a parallel first convolutional layer, a long short-term memory network, a graph attention network (Graph Attention Networks, GAT), and an embedding layer. Among them:

[0107] The 3D convolutional layer is used to extract the 3D spatio-temporal features of the traffic packet data;

[0108] The long short-term memory network is used to extract the temporal features of the traffic packet data, such as capturing long-term traffic trends (such as periodic access) and short-term abnormal fluctuations (such as DDoS bursts);

[0109] The graph attention network is used to process the network topology information to generate the embedding representations of nodes (IPs) and links (traffic paths), that is, to obtain node embedding vectors and link risk scores.

[0110] The embedding layer encodes IPs and resources into vectors.

[0111] (2) Multimodal feature fusion module

[0112] The multimodal feature fusion module is used to receive the feature information of the four branches output by the multimodal feature extraction module and map the features of each modality to a unified dimension through a fully connected layer. Then, the multi-head attention mechanism (Multi-Head Attention) can be used to integrate the multimodal features to form a global context representation. That is, the output of the multimodal feature fusion module is a fused global feature vector, which contains traffic spatio-temporal patterns, network topology associations, and resource access semantics. In this embodiment, the advantage of using the multi-head attention mechanism is that it can automatically adjust the importance of each modality according to the context, suppress the interference of low-quality modality features, and significantly improve the model's ability to detect complex abnormal traffic.

[0113] Among them, the integration process of the multi-head attention mechanism for multi-modal features can be achieved through the following process: The multi-head attention mechanism involves multiple attention heads, and calculates the query, key, and value matrices of each head itself. Then, each head calculates the attention weights, multiplies them with the value matrix to obtain the output, and finally concatenates the outputs of all heads and passes them through a linear transformation to obtain the final result, which can be specifically represented by the following formula:

[0114] Set the number of attention heads H = 8, indicating that the input features are split into 8 independent attention heads for parallel calculation, and the dimension of each head is d k = d v = 8, the query (Query) and key (Key) dimensions of each attention head are d k , and the value (Value) dimension is d v , where both are 8 here.

[0115] The query matrix (Q h ), key matrix (K h ), and value matrix (V h ) of the h-th head are generated as follows:

[0116]

[0117] Among them, F′ represents the input feature matrix, represents the learnable parameter.

[0118] The attention weights of the h-th head are calculated as follows:

[0119]

[0120] Multi-head concatenation and linear transformation:

[0121] MultiHead(F′) = Concat(Attention 1 , ……, Attention H )W O ;

[0122] Among them, MultiHead(F′) represents the result of the linear transformation, and Concat() represents concatenating the outputs of 8 heads in the feature dimension to obtain the concatenated matrix; represents the output projection matrix, which is used to map the concatenated result back to the original input dimension D to ensure the consistency of the input and output dimensions.

[0123] (3) Abnormal traffic detection module

[0124] An abnormal traffic detection module, which is used to receive the global context features output by the multi-modal feature fusion module, compress normal traffic into a low-dimensional representation using an autoencoder, and the decoder reconstructs the input. The autoencoder performs error reconstruction. The larger the reconstruction error, the more likely the traffic is abnormal. Then, the abnormal type (such as DDoS, port scanning) is output through a fully connected layer.

[0125] (4) Policy generation module

[0126] The policy generation module adopts a policy network based on reinforcement learning (RL). According to the abnormal type and the current network state (such as bandwidth utilization, server load), it outputs cleaning policies (such as blocking all access requests of an IP, filtering access requests of an IP to specific resources, or filtering abnormal protocol data).

[0127] The training process of the above abnormal traffic cleaning model is implemented through the following steps A to D:

[0128] A. Obtain network traffic, and obtain new attack samples from an open threat intelligence platform, and obtain the abnormal traffic processing policies corresponding to the new attack samples.

[0129] Among them, network traffic includes normal traffic and attack traffic.

[0130] B. Label the network traffic, and use the labeled network traffic and new attack samples as sample data.

[0131] C. Input the sample data into the abnormal traffic cleaning model for training. When the value of the loss function of the abnormal traffic cleaning model reaches convergence, the training of the abnormal traffic cleaning model is completed.

[0132] The trained abnormal traffic cleaning model can establish an association relationship between traffic behavior characteristics and abnormal traffic processing policies. Among them, the loss function y is composed of an anomaly detection loss sub-function y 1 , a policy generation loss sub-function y 2 , a multi-modal consistency loss sub-function y 3 and a continuous learning regularization loss sub-function y 4 These four parts are composed, that is, y = y 1 + y 2 + λ 3 y 3 + y 4

[0133] Among them, the anomaly detection loss sub-function is used to minimize the anomaly classification error and the reconstruction error, and improve the detection accuracy. The anomaly detection loss sub-function y 1 is composed of a classification cross-entropy loss y 11and the auto - encoder reconstruction loss y 12 is composed, that is, y 1 = λ 1 y 11 + λ 2 y 12 , where,

[0134]

[0135] where, y i ∈ {0, 1} represents the true label of the i - th sample. When i = 1, it represents abnormal traffic, and when i = 0, it represents normal traffic; represents the predicted probability of the model for the i - th sample, which is the probability that the sample is judged as abnormal, and the value range is [0, 1]; λ 1 represents the hyper - parameter used to control the importance of the classification task.

[0136]

[0137] where, represents the feature vector obtained after the i - th sample passes through the multi - modal feature fusion module, which is the fused global context information; Encoder() represents the encoder part of the auto - encoder, used to compress the fused feature into a low - dimensional latent representation; Decoder() represents the decoder part of the auto - encoder, used to reconstruct the original fused feature from the latent representation; ||·|| 2 represents the Euclidean distance (L2 norm), used to measure the difference between the original feature and the reconstructed feature; λ 2 represents the hyper - parameter used to control the importance of the reconstruction task.

[0138] In this embodiment, the above - mentioned anomaly detection loss sub - function, by jointly optimizing the classification accuracy and the feature reconstruction ability, enables the model to not only distinguish abnormal traffic but also learn the latent distribution of normal traffic, enhancing the detection ability for unknown attacks.

[0139] In addition, for the policy generation loss sub - function y 2 , it can be specifically represented by the following formula:

[0140]

[0141] where, π θ (a t |s t ) represents the probability of the current policy network with parameter θ selecting action a t under state s t ; represents the old policy network with parameter θ old under state s tThe probability of the following selection action a t ; A t =Q(s t , a t ) - V(s t ) represents the advantage function, which is used to measure the long-term value improvement of selecting action a t under state s t relative to the average policy. Q(s t , a t ) represents the state-action value function, and V(s t ) represents the state value function; ε represents the truncation threshold, which is used to prevent the difference between the new and old policies from being too large and ensure the training stability; the clip function represents clamping the policy update ratio within the interval [1 - ε, 1 + ε]; E t represents the expectation for time step t.

[0142] In this embodiment, the above-mentioned policy generation loss sub-function makes the new policy π θ not deviate too far from the old policy by adjusting the amplitude of the current policy update, thereby ensuring the training stability.

[0143] In addition, for the multi-modal consistency loss sub-function, the specific formula is:

[0144]

[0145] where N represents the total number of samples; represents the spatial feature vector of the i-th sample, represents the temporal feature vector of the i-th sample; the sim function represents the cosine similarity; τ represents the temperature coefficient, which is usually a constant and is used to adjust the sharpness of the similarity distribution; K represents the number of negative samples.

[0146] In this embodiment, by setting the multi-modal consistency loss sub-function, it can be ensured that different modal features can maintain semantic alignment after fusion and improve feature complementarity.

[0147] In addition, for the continual learning regularization loss sub-function, the specific formula is:

[0148]

[0149] where θ i represents the i-th parameter of the current model, and θ old,i represents the i-th parameter of the historical model; F i represents the diagonal element of the Fisher Information Matrix (Fisher Information Matrix) of the parameter θ i , λewc Represents the regularization intensity coefficient, which is used to control the strictness of historical parameter constraints.

[0150] In this embodiment, by setting the continuous learning regularization loss sub-function, the model's past historical attack patterns can be prevented, and the dynamic update of the model is supported.

[0151] In this embodiment, by adopting the above-mentioned anomaly detection loss sub-function, policy generation loss sub-function, multi-modal consistency loss sub-function, and continuous learning regularization loss sub-function to form the damage function of the abnormal traffic cleaning model, the detection accuracy of the model can be effectively improved.

[0152] S230. Clean the abnormal traffic according to the preset abnormal traffic processing policy.

[0153] In this embodiment, by training the abnormal traffic cleaning model, the association relationship between the traffic behavior characteristics and the corresponding abnormal traffic processing policy can be established, that is, an end-to-end method is provided to realize the cleaning of abnormal traffic, effectively improving the detection, processing accuracy and efficiency of abnormal traffic.

[0154] Embodiment III

[0155] Figure 3 It is a structural block diagram of a network traffic cleaning device provided in Embodiment III of the present invention. As Figure 3 shown, the device includes: a traffic behavior feature analysis module 310 and an abnormal traffic cleaning module 320, where

[0156] The traffic behavior feature analysis module 310 is configured to monitor network traffic in real time and analyze the traffic behavior features to identify abnormal traffic patterns. Among them, the traffic behavior features include: the request frequency of the source IP address, the access resource distribution, and the protocol type. The abnormal traffic patterns include any one of the first abnormal traffic pattern, the second abnormal traffic pattern, and the third abnormal traffic pattern. Among them, the first abnormal traffic pattern is that the request frequency of the source IP address reaches the first preset frequency threshold within a set time period, and the second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches the second preset frequency threshold. The specific resource is: the access frequency of a specific port, a specific uniform resource locator URL path, or a specific application programming interface API; the third abnormal traffic pattern is an abnormal protocol type.

[0157] The abnormal traffic cleaning module 320 is configured to determine the abnormal source IP address corresponding to the abnormal traffic pattern and clean the abnormal traffic according to the preset abnormal traffic processing policy. Among them, the preset abnormal traffic processing policy includes:

[0158] When the first abnormal traffic pattern is detected, all requests of the abnormal source IP address are blocked;

[0159] When a second abnormal traffic pattern is detected, only the access requests of the abnormal source IP address to specific resources are filtered, and the access requests to other resources except the specific resources are retained;

[0160] When a third abnormal traffic pattern is detected, abnormal protocol data packets are filtered.

[0161] Optionally, the device provided by the embodiment of the present invention further includes:

[0162] A normal traffic redirection module, configured to redirect the cleaned normal traffic to a standby server or a cloud infrastructure platform after abnormal traffic cleaning, and perform real-time monitoring on the normal traffic.

[0163] Optionally, the traffic behavior feature analysis module is specifically configured to:

[0164] Analyze traffic behavior features based on an abnormal traffic cleaning model to identify abnormal traffic patterns;

[0165] Correspondingly, the abnormal traffic cleaning module is specifically configured to:

[0166] Based on the abnormal traffic cleaning model, in the case of identifying an abnormal traffic pattern, determine an abnormal traffic processing strategy corresponding to the abnormal traffic pattern, wherein the abnormal traffic cleaning model establishes an association relationship between traffic behavior features and abnormal traffic processing strategies;

[0167] Perform abnormal traffic cleaning according to a preset abnormal traffic processing strategy.

[0168] Optionally, the abnormal traffic cleaning model is trained in the following manner:

[0169] Obtain network traffic, and obtain new attack samples from an open threat intelligence platform, and obtain abnormal traffic processing strategies corresponding to the new attack samples, wherein the network traffic includes normal traffic and attack traffic;

[0170] Label the network traffic, and use the labeled network traffic and the new attack samples as sample data;

[0171] Input the sample data into the abnormal traffic cleaning model for training. When the value of the loss function of the abnormal traffic cleaning model reaches convergence, it is considered that the training of the abnormal traffic cleaning model is completed. The trained abnormal traffic cleaning model can establish an association relationship between traffic behavior features and abnormal traffic processing strategies, wherein the loss function is:

[0172] y = y 1 +y 2 +λ3 y 3 +y 4 ,

[0173] where y 1 =λ 1 y 11 +λ 2 y 12 ,

[0174]

[0175] where y 1 represents the anomaly detection loss sub-function, y 11 represents the classification cross-entropy loss, y 12 represents the autoencoder reconstruction loss, y i ∈{0,1} represents the true label of the i-th sample. When i = 1, it represents abnormal traffic; when i = 0, it represents normal traffic; represents the predicted probability of the model for the i-th sample, λ 1 represents the hyperparameter used to control the importance of the classification task, represents the feature vector obtained after the i-th sample passes through the multi-modal feature fusion module. Encoder() represents the encoder part of the autoencoder, which is used to compress the fusion feature into a low-dimensional latent representation; Decoder() represents the decoder part of the autoencoder, which is used to reconstruct the original fusion feature from the latent representation, ||·|| 2 represents the Euclidean distance (L2 norm), λ 2 represents the hyperparameter used to control the importance of the reconstruction task, π θ (a t |s t ) represents the probability that the current policy network with parameter θ selects action a t under state s t ; represents the probability that the old policy network with parameter θ old selects action a t under state s t ; A t =Q(s t ,a t )-V(s t ) represents the advantage function, Q(s t ,a t ) represents the state-action value function, V(s t ) represents the state value function; ε represents the truncation threshold; the clip function represents restricting the policy update ratio within the interval [1 - ε, 1 + ε]; E t represents the expectation over time t, and N represents the total number of samples; represents the spatial feature vector of the i-th sample, represents the temporal feature vector of the i-th sample, the sim function represents the cosine similarity; τ represents the temperature coefficient, K represents the number of negative samples, θ i represents the i-th parameter of the current model, θ old,i represents the i-th parameter of the historical model, F i represents the parameter θ i the diagonal element of the Fisher information matrix of the parameter θ; λ ewc represents the regularization intensity coefficient.

[0176] Optionally, the device provided by the embodiments of the present invention further includes:

[0177] A business peak period determination module, configured to determine the business peak period of the current network according to the historical traffic data of the current network;

[0178] A threshold dynamic adjustment module, configured to increase the first preset frequency threshold and the second preset frequency threshold when the business peak period is reached.

[0179] Embodiment 4

[0180] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of a server provided by Embodiment 4 of the present invention.

[0181] As Figure 4 shown, the server may include:

[0182] A memory 701 storing executable program code;

[0183] A processor 702 coupled to the memory 701;

[0184] Among them, the processor 702 calls the executable program code stored in the memory 701 to execute the network traffic cleaning method provided by any embodiment of the present invention.

[0185] The embodiments of the present invention disclose a computer-readable storage medium, which stores a computer program, wherein the computer program enables a computer to execute the network traffic cleaning method provided by any embodiment of the present invention.

[0186] In various embodiments of the present invention, it should be understood that the magnitudes of the serial numbers of the above processes do not necessarily mean the order of execution. The execution order of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0187] In the embodiments provided by the present invention, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A. B can also be determined according to A and / or other information.

[0188] In addition, in each embodiment of the present invention, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0189] When the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-accessible memory. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc., specifically, the processor in the computer device) to execute some or all of the steps of the above-mentioned methods in each embodiment of the present invention.

[0190] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable storage medium. The storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electrically-erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc memories, a magnetic disk memory, a tape memory, or any other computer-readable medium that can be used to carry or store data.

[0191] Those of ordinary skill in the art can understand that the accompanying drawings are only schematic diagrams of an embodiment, and the modules or processes in the accompanying drawings are not necessarily essential for implementing the present invention.

[0192] Those of ordinary skill in the art can understand that the modules in the device in the embodiment can be distributed in the device of the embodiment according to the description of the embodiment, or can be correspondingly changed and located in one or more devices different from this embodiment. The modules of the above embodiments can be combined into one module, or further split into multiple sub-modules.

[0193] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network traffic cleaning method, characterized in that: include: Monitor network traffic in real time and analyze traffic behavior characteristics to identify abnormal traffic patterns, wherein the traffic behavior characteristics include: request frequency of the source IP address, access resource distribution and protocol type, and the abnormal traffic pattern includes any one or more of a first abnormal traffic pattern, a second abnormal traffic pattern and a third abnormal traffic pattern, wherein the first abnormal traffic pattern is that the request frequency of the source IP address within a set time period reaches a first preset frequency threshold, and the second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches a second preset frequency threshold, and the specific resource is: a specific port, a specific uniform resource locator URL path, or a specific application programming interface API access frequency; the third abnormal traffic pattern is a protocol type abnormality; Determine the abnormal source IP address corresponding to the abnormal traffic pattern, and clean the abnormal traffic according to the preset abnormal traffic processing strategy, wherein the preset abnormal traffic processing strategy includes: When the first abnormal traffic pattern is detected, all requests from the abnormal source IP address are blocked; When the second abnormal traffic pattern is detected, only access requests from the abnormal source IP address to the specific resource are filtered, and access requests to other resources other than the specific resource are retained; When the third abnormal traffic pattern is detected, abnormal protocol data packets are filtered.

2. The method according to claim 1, characterized in that The method further comprises: After cleaning the abnormal traffic, the cleaned normal traffic is redirected to a backup server or cloud-based platform, and the normal traffic is monitored in real time.

3. The method according to claim 1, characterized in that The analysis of traffic behavior characteristics to identify abnormal traffic patterns includes: Based on the abnormal traffic cleaning model, the traffic behavior characteristics are analyzed to identify abnormal traffic patterns; Accordingly, the abnormal source IP address corresponding to the abnormal traffic pattern is determined, and abnormal traffic cleaning is performed according to a preset abnormal traffic processing strategy, including: Based on the abnormal traffic cleaning model, when an abnormal traffic pattern is identified, an abnormal traffic processing strategy corresponding to the abnormal traffic pattern is determined, wherein the abnormal traffic cleaning model establishes an association relationship between traffic behavior characteristics and abnormal traffic processing strategies; Abnormal traffic cleaning is performed according to the preset abnormal traffic processing strategy.

4. The method according to claim 3, characterized in that The abnormal traffic cleaning model is trained in the following way: Obtain network traffic, and obtain new attack samples from an open threat intelligence platform, and obtain abnormal traffic processing strategies corresponding to the new attack samples, wherein the network traffic includes normal traffic and attack traffic; Annotating the network traffic, and using the annotated network traffic and the new attack sample as sample data; The sample data is input into the abnormal traffic cleaning model for training. When the value of the loss function of the abnormal traffic cleaning model reaches convergence, the training of the abnormal traffic cleaning model is completed. The trained abnormal traffic cleaning model can establish an association relationship between traffic behavior characteristics and abnormal traffic processing strategies, wherein the loss function is: y=y1+y2+λ3y3+y4, Where y1 = λ1y 11 +λ2y 12 , Among them, y1 represents the anomaly detection loss sub-function, y 11 represents the classification cross entropy loss, y 12 represents the autoencoder reconstruction loss, y i ∈{0,1} represents the true label of the i-th sample. When i=1, it indicates abnormal traffic, and when i=0, it indicates normal traffic. represents the predicted probability of the model for the i-th sample, λ1 represents the hyperparameter used to control the importance of the classification task, It represents the feature vector obtained after the i-th sample passes through the multimodal feature fusion module. Encoder() represents the encoder part of the autoencoder, which is used to convert the fused features is compressed into a low-dimensional potential representation; Decoder() represents the decoder part of the autoencoder, which is used to reconstruct the original fused features from the potential representation, ||·||2 represents the Euclidean distance (L2 norm), λ2 represents the hyperparameter that controls the importance of the reconstruction task, and π θ (a t |s t ) indicates that the current policy network with parameter θ is in state s t Next select action a t probability; Denote the parameter as θ old The old policy network is in state s t Next select action a t The probability of t =Q(s t ,a t )-V(s t ) represents the advantage function, Q(s t ,a t ) represents the state-action value function, V(s t ) represents the state value function; ε represents the cutoff threshold; the clip function represents the strategy update ratio in the interval [1-ε,1+ε]; E t represents the expectation at time t, and N represents the total number of samples; represents the spatial feature vector of the i-th sample, represents the time feature vector of the i-th sample, the sim function represents the cosine similarity; τ represents the temperature coefficient, K represents the number of negative samples, and θ i represents the current i-th parameter of the model, θ old,i represents the i-th parameter of the historical model, F i Denotes the parameter θ i The diagonal elements of the Fisher information matrix; λ ewc represents the regularization strength coefficient.

5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: Determine the peak period of the current network traffic according to the historical traffic data of the current network; When the service peak period is reached, the first preset frequency threshold and the second preset frequency threshold are increased.

6. A network traffic cleaning device, characterized in that: include: The traffic behavior characteristic analysis module is configured to monitor network traffic in real time and analyze the traffic behavior characteristics to identify abnormal traffic patterns, wherein the traffic behavior characteristics include: request frequency of the source IP address, access resource distribution and protocol type, and the abnormal traffic pattern includes any one or more of a first abnormal traffic pattern, a second abnormal traffic pattern and a third abnormal traffic pattern, wherein the first abnormal traffic pattern is that the request frequency of the source IP address within a set time period reaches a first preset frequency threshold, and the second abnormal traffic pattern is that the access frequency of the source IP address to a specific resource reaches a second preset frequency threshold, and the specific resource is: a specific port, a specific uniform resource locator URL path, or a specific application programming interface API access frequency; the third abnormal traffic pattern is a protocol type abnormality; The abnormal traffic cleaning module is configured to determine the abnormal source IP address corresponding to the abnormal traffic pattern and clean the abnormal traffic according to the preset abnormal traffic processing strategy, wherein the preset abnormal traffic processing strategy includes: When the first abnormal traffic pattern is detected, all requests from the abnormal source IP address are blocked; When the second abnormal traffic pattern is detected, only access requests from the abnormal source IP address to the specific resource are filtered, and access requests to other resources other than the specific resource are retained; When the third abnormal traffic pattern is detected, abnormal protocol data packets are filtered.

7. The device according to claim 6, characterized in that The device also includes: The normal traffic redirection module is configured to redirect the cleaned normal traffic to a backup server or a cloud-based platform after cleaning the abnormal traffic, and to monitor the normal traffic in real time.

8. The device according to claim 6, characterized in that The device also includes: A service peak period determination module is configured to determine the service peak period of the current network according to historical traffic data of the current network; The threshold dynamic adjustment module is configured to increase the first preset frequency threshold and the second preset frequency threshold when the business peak period is reached.

9. A server, characterized in that: The server comprises: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the network traffic cleaning method as described in any one of claims 1-6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the network traffic cleaning method as described in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Method, system and equipment for cleaning traffic

    CN101299724A

  • Network abnormal access identification method and device, electronic equipment and storage medium

    CN117201362A

  • Method and device for preventing DDoS attack based on node cleaning

    CN117375942A

  • Abnormal network flow detection system and method based on multi-modal fusion features

    CN118353690A

  • Industrial control network intrusion detection method and system based on ensemble learning

    CN118890166A