An intelligent network fault early warning system based on a neural network prediction algorithm

Through the intelligent network failure warning system of neural network prediction algorithm, damaged and undamaged network paths are accurately screened out, solving the problem of inaccurate network abnormality monitoring and analysis in the existing technology, and improving early warning efficiency.

CN120090947BActive Publication Date: 2025-07-11BEIJING MILLENNIUM VISION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510536921.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-11
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

The monitoring and analysis of network abnormalities in the prior art lacks accuracy, resulting in frequent deviations in early warning judgments, and the inability to accurately distinguish damaged network paths, resulting in low early warning efficiency.

Method used

The intelligent network fault warning system based on neural network prediction algorithm is adopted to obtain network path information, traffic data and attack feature information through the information collection module. The abnormal path determination module determines the abnormal path based on the network traffic change rate. The early warning module includes explicit and implicit early warning units. The adjustment module adjusts the preset parameters based on the warning accuracy and abnormal path proportion, and accurately filters out damaged and undamaged network paths.

Benefits of technology

It improves the accuracy of monitoring and analysis of network abnormal conditions, reduces the deviation of early warning and judgment, and improves the efficiency of network fault warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090947B_ABST
    Figure CN120090947B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of network fault warning, and particularly to an intelligent network fault warning system based on a neural network prediction algorithm. The system includes an abnormal path determination module for determining an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs; a warning module, which includes a network traffic supply unit for supplying first network traffic to the abnormal path and for supplying second network traffic to the abnormal path that has not been explicitly warned, a explicit warning unit for determining whether to generate the explicit warning based on whether there is a network traffic interruption phenomenon or whether the network traffic abnormal distribution condition is satisfied in the abnormal path where the first network traffic is supplied, and a implicit warning unit for determining whether to generate an implicit warning based on whether there is a network traffic transmission fluctuation in the abnormal path where the second network traffic is supplied; the present invention improves the warning efficiency by improving the monitoring accuracy of network abnormal conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network fault warning, and in particular to an intelligent network fault warning system based on a neural network prediction algorithm. Background Art

[0002] With the rapid development of the Internet, the network has become an indispensable part of people's life and work. At the same time, the means and frequency of network attacks are also increasing continuously. When the network is attacked, various faults are likely to occur, such as network congestion, service interruption, data loss, etc. Most traditional network fault warning methods are rule-based, that is, some fixed rules and thresholds are set in advance. When the network traffic or other indicators exceed these rules and thresholds, a warning is issued. However, this method has obvious limitations. On the one hand, the formulation of rules requires manual intervention and it is difficult to adapt to the changing network environment and attack means. On the other hand, the rules are often static and cannot detect new types of attacks and abnormal situations in a timely manner.

[0003] For example, Chinese Patent Application Publication No.: CN107306200A discloses a network fault warning method and a gateway for network fault warning, which relates to the field of communication networks. The network fault warning method therein includes: the gateway of the internal network obtains the current usage conditions and current traffic data of the internal network for receiving and transmitting data; the gateway obtains the historical traffic data under the current usage conditions; the gateway determines whether the difference between the current traffic data and the historical traffic data under the current usage conditions conforms to a preset range. If not, a fault warning for the internal network is generated. This invention enables the gateway of the internal network to know the abnormal situation of the internal network usage according to the matching situation between the current traffic data and the historical traffic data under a certain usage condition, pre-warns potential network faults, is simple and easy to implement, and reduces the complexity of network fault diagnosis.

[0004] However, the prior art has problems such as the lack of accuracy in monitoring and analyzing network abnormal conditions, resulting in frequent deviations in warning judgments, being unable to accurately distinguish damaged network paths, and causing low warning efficiency. Summary of the Invention

[0005] Therefore, the present invention provides an intelligent network fault warning system based on a neural network prediction algorithm to overcome the problems in the prior art that the lack of accuracy in monitoring and analyzing network abnormal conditions leads to frequent deviations in warning judgments, being unable to accurately distinguish damaged network paths, and causing low warning efficiency.

[0006] To achieve the above object, the present invention provides an intelligent network fault warning system based on a neural network prediction algorithm, including:

[0007] An information collection module, which is used to collect network path information, network traffic data information, and attack feature information;

[0008] An abnormal path determination module, which is connected to the information collection module and is used to determine an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs;

[0009] A warning module, which is respectively connected to the information collection module and the abnormal path determination module, and includes:

[0010] A network traffic supply unit, which is used to supply the first network traffic to the abnormal path and supply the second network traffic to the abnormal path that has not been explicitly warned;

[0011] An explicit warning unit, which is connected to the network traffic supply unit and is used to determine whether to generate the explicit warning based on whether there is a network traffic interruption phenomenon in the abnormal path that supplies the first network traffic, or whether the network traffic abnormal distribution condition is satisfied;

[0012] A hidden warning unit, which is respectively connected to the network traffic supply unit and the explicit warning unit, and is used to determine whether to generate a hidden warning based on whether there is a network traffic transmission fluctuation in the abnormal path that supplies the second network traffic;

[0013] An adjustment module, which is respectively connected to the information collection module, the abnormal path determination module and the warning module, and is used to determine whether to adjust the preset network traffic change rate or whether to adjust the preset ratio range based on the warning accuracy rate within a preset period and the proportion of abnormal paths with network traffic transmission abnormal phenomena during the initial time period when the second network traffic is supplied.

[0014] Further, the abnormal path determination module is also used to determine an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs, where:

[0015] If the network traffic change rate of a network path during the time period when an attack occurs is greater than or equal to the preset network traffic change rate, determine that the network path is an abnormal path;

[0016] If the network traffic change rate of a network path during the time period when an attack occurs is less than the preset network traffic change rate, determine that the network path is a normal path.

[0017] Further, the first network traffic is determined by the average value of network traffic transmission during the normal working period of each abnormal path, and the second network traffic is determined by the network traffic change rate of each abnormal path during the time period when an attack occurs and the first network traffic.

[0018] Further, the explicit warning unit is also used to determine whether to generate an explicit warning based on whether there is a network traffic interruption phenomenon or whether the network traffic abnormal distribution condition is satisfied in the abnormal path supplying the first network traffic, where:

[0019] If there is a network traffic interruption phenomenon or the network traffic abnormal distribution condition is satisfied in the abnormal path supplying the first network traffic, it is determined to generate the explicit warning;

[0020] If there is no network traffic interruption phenomenon and the network traffic abnormal distribution condition is not satisfied in the abnormal path supplying the first network traffic, it is determined not to generate the explicit warning.

[0021] Further, the satisfaction of the network traffic abnormal distribution condition includes that the ratio between the sudden drop amount of the network traffic in the abnormal path and the sudden increase amount of the network traffic in at least three associated paths is not within the preset ratio range.

[0022] Further, the preset ratio range is determined according to the reference ratio and the tolerance boundary value.

[0023] Further, the implicit warning unit is also used to determine whether to generate an implicit warning based on whether there is network traffic transmission fluctuation in the abnormal path supplying the second network traffic, where:

[0024] If there is network traffic transmission fluctuation in the abnormal path supplying the second network traffic, it is determined to generate the implicit warning.

[0025] Further, the implicit warning unit is also used to determine whether there is network traffic transmission fluctuation in the abnormal path supplying the second network traffic based on the dispersion degree of the transmitted network traffic in the abnormal path supplying the second network traffic, where:

[0026] If the dispersion degree of the transmitted network traffic in the abnormal path supplying the second network traffic is greater than the preset dispersion degree, it is determined that there is network traffic transmission fluctuation in the abnormal path supplying the second network traffic.

[0027] Further, the adjustment module is also used to determine whether to adjust the preset network traffic change rate or whether to adjust the preset ratio range based on the warning accuracy rate within the preset period and the proportion of the abnormal paths with network traffic transmission abnormal phenomena in the initial period of supplying the second network traffic, where:

[0028] If the proportion of the abnormal paths with network traffic transmission abnormal phenomena in the initial period of supplying the second network traffic is greater than or equal to the preset proportion, it is determined to adjust the preset ratio range;

[0029] If the proportion of abnormal paths with abnormal network traffic transmission during the initial period of supplying the second network traffic is less than the preset proportion and the early warning accuracy rate within the preset period is less than the preset early warning accuracy rate, it is determined to adjust the preset network traffic change rate.

[0030] Furthermore, the adjustment amount of the preset network traffic change rate is negatively correlated with the early warning accuracy rate within the preset period.

[0031] Compared with the prior art, the beneficial effects of the present invention are as follows. The present invention determines abnormal paths by detecting the network traffic change rates of each network path during the time period when an attack occurs. When a network attack occurs, the network paths will be damaged. According to the technical means that the network traffic change rates of each network path during the time period when an attack occurs are greater than the preset network traffic change rate, the possibly damaged network paths can be screened out. By further judging the possibly damaged network paths, the actually damaged network paths and the undamaged network paths can be accurately screened out. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and further, the phenomenon of frequent deviation in early warning judgment is reduced to improve the efficiency of network fault early warning.

[0032] Furthermore, the present invention takes the average value of network traffic transmission during the normal working period of each abnormal path as the first network traffic to screen out the obviously damaged abnormal paths, and takes the sum of the product of the network traffic change rate during the time period when the abnormal path is attacked and the first network traffic and the first network traffic as the second network traffic to further screen out the implicitly damaged abnormal paths. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and further, the phenomenon of frequent deviation in early warning judgment is reduced to achieve the purpose of improving the early warning efficiency.

[0033] Furthermore, the present invention determines whether the explicit warning unit generates the explicit warning by taking the existence of network traffic interruption or meeting the abnormal network traffic distribution in the abnormal paths when supplying the first network traffic as a condition, and judges whether the sudden drop amount of the network traffic of the abnormal path and the sudden increase amounts of the network traffic of at least three associated paths are within the preset proportional range to determine whether the condition of abnormal network traffic distribution is met, and further determines whether the explicit warning unit generates the explicit warning. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and further, the phenomenon of frequent deviation in early warning judgment is reduced to achieve the purpose of improving the early warning efficiency.

[0034] Furthermore, the present invention determines whether to generate the implicit warning by checking whether there is network traffic transmission fluctuation in the abnormal path during the supply of the second network traffic. When under a cyber attack, the network path will be damaged to varying degrees. The network path with a large degree of damage can be directly judged by the explicit warning mechanism. However, the network path with a small degree of damage may not show abnormal transmission phenomena under the condition of transmitting the first network traffic. Therefore, the present invention determines whether to generate the implicit warning by checking whether there is network traffic transmission fluctuation in the abnormal path of the second network traffic, which can prevent the network path with a low degree of damage from being misjudged as a normal path. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in warning judgment is reduced, so as to achieve the purpose of improving the warning efficiency.

[0035] Furthermore, the present invention determines whether to adjust the preset network traffic change rate or the preset proportion range by the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial period of supplying the second network traffic according to the fluctuation amplitude of the warning within a preset period. When the fluctuation amplitude of the warning accuracy rate within a preset period is less than the preset fluctuation amplitude, the preset network change rate or the preset proportion range is adjusted. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in warning judgment is reduced, so as to achieve the purpose of improving the warning efficiency.

[0036] Furthermore, the present invention determines to adjust the preset proportion range according to the comparison result that the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial time period of the second network traffic is greater than or equal to the preset proportion. If the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial period of the second network traffic is greater than or equal to the preset proportion, it indicates that there are many abnormal paths with explicit characteristics in the implicit warning. At this time, the maximum value of the preset proportion range is adjusted with the first adjustment coefficient and the minimum value of the preset proportion range is adjusted with the second adjustment coefficient to expand the preset proportion range, thereby improving the warning efficiency. If the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial period of the second network traffic is less than the preset proportion and the warning accuracy rate within a preset period is less than the preset warning accuracy rate, it indicates that there are many normal paths in the abnormal paths. At this time, the preset network traffic change rate is adjusted with the second adjustment coefficient. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in warning judgment is reduced, so as to achieve the purpose of improving the warning efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] Figure 1 It is a schematic structural diagram of the network fault intelligent warning system based on the neural network prediction algorithm in the embodiment of the present invention;

[0038] Figure 2Schematic diagram of the warning module of the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention;

[0039] Figure 3 Flowchart of the operation of the abnormal path determination module in the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention;

[0040] Figure 4 Flowchart of the operation of the adjustment module in the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention. Detailed implementation manners

[0041] In order to make the objectives and advantages of the present invention clearer and more understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0042] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0043] In addition, it should be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two components. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0044] Please refer to Figures 1 - 4 as shown Figure 1 Schematic diagram of the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention; Figure 2 Schematic diagram of the warning module of the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention; Figure 3 Flowchart of the operation of the abnormal path determination module in the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention; Figure 4 Flowchart of the operation of the adjustment module in the network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention.

[0045] The network fault intelligent warning system based on the neural network prediction algorithm according to the embodiment of the present invention includes:

[0046] An information collection module, which is used to collect network path information, network traffic data information, and attack feature information;

[0047] An abnormal path determination module, which is connected to the information collection module and is used to determine an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs;

[0048] An early warning module, which is respectively connected to the information collection module and the abnormal path determination module, and includes:

[0049] A network traffic supply unit, which is used to supply the first network traffic to the abnormal path and supply the second network traffic to the abnormal path without explicit early warning;

[0050] An explicit early warning unit, which is connected to the network traffic supply unit and is used to determine whether to generate the explicit early warning based on whether there is a network traffic interruption phenomenon in the abnormal path where the first network traffic is supplied, or whether the network traffic abnormal distribution condition is met;

[0051] A hidden early warning unit, which is respectively connected to the network traffic supply unit and the explicit early warning unit, and is used to determine whether to generate a hidden early warning based on whether there is a network traffic transmission fluctuation in the abnormal path where the second network traffic is supplied;

[0052] An adjustment module, which is respectively connected to the information collection module, the abnormal path determination module and the early warning module, and is used to determine whether to adjust the preset network traffic change rate or whether to adjust the preset ratio range based on the early warning accuracy rate within a preset period and the proportion of abnormal paths with network traffic transmission anomalies during the initial period when the second network traffic is supplied.

[0053] In the embodiment of the present invention, the network path information includes but is not limited to "starting IP address, intermediate hop IP, target IP address", the network traffic data information includes but is not limited to "traffic value per second, daily traffic average value, traffic burst frequency", the attack feature information includes but is not limited to "attack occurrence time period, abnormal packet length, typical attack behavior pattern", the preset period is set between 10 minutes and 3 days, and the preferred value is 2 hours, because too short a period will increase the storage cost, and too long a period is likely to miss short-term abnormal fluctuations and attack behaviors; however, the above values are not limited to this, and those skilled in the art can also adjust the values according to actual needs.

[0054] Specifically, under the condition of determining an abnormal path, the abnormal path determination module determines the abnormal path according to the comparison result between the network traffic change rate of each network path during the time period when an attack occurs and the preset network traffic change rate;

[0055] If the network traffic change rate of the network path during the time period when the attack occurs is greater than or equal to the preset network traffic change rate, the abnormal path determination module determines that the network path is an abnormal path;

[0056] If the network traffic change rate of the network path during the time period when the attack occurs is less than the preset network traffic change rate, the abnormal path determination module determines that the network path is a normal path.

[0057] In the embodiment of the present invention, the preset network traffic change rate is four-fifths of the historical maximum value of the network traffic change rate during the normal transmission process of the network path. However, the above values are not limited to this, and those skilled in the art can also adjust the values according to actual needs.

[0058] The present invention determines the abnormal path by detecting the network traffic change rate of each network path during the time period when the attack occurs. When a network attack occurs, the network path will be damaged. According to the technical means that the network traffic change rate of each network path during the time period when the attack occurs is greater than the preset network traffic change rate, the network paths that may be damaged can be screened out, and the network paths that may be damaged are further judged to accurately screen out the actually damaged network paths and the undamaged network paths. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in early warning judgment is reduced, thereby improving the efficiency of network fault early warning.

[0059] In the embodiment of the present invention, the first network traffic is the average value of the network traffic transmission during the normal working period of each abnormal path. The second network traffic is determined according to the network traffic change rate during the time period when each abnormal path is attacked and the first network traffic. The second network traffic is the sum of the product of the network traffic change rate during the time period when the abnormal path is attacked and the first network traffic and the first network traffic. For example, the value of the first network traffic is 100 Mbps (megabits per second), and the value of the network traffic change rate is 20%. After calculation, the value of the second network traffic is 100 Mbps × 20% + 100 Mbps = 120 Mbps. That is, based on the value of the first network traffic and combined with the given network traffic change rate, the value of the second network traffic is obtained as 120 Mbps.

[0060] The present invention uses the average value of the network traffic transmission during the normal working period of each abnormal path as the first network traffic to screen out the obviously damaged abnormal paths, and uses the sum of the product of the network traffic change rate during the time period when the abnormal path is attacked and the first network traffic and the first network traffic as the second network traffic to further screen out the implicitly damaged abnormal paths. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in early warning judgment is reduced, so as to achieve the purpose of improving the early warning efficiency.

[0061] Specifically, under the condition of determining whether to generate an explicit warning, the explicit warning unit determines whether to generate an explicit warning based on whether there is a network traffic interruption phenomenon in the abnormal path supplying the first network traffic or whether the network traffic abnormal distribution condition is satisfied;

[0062] If there is a network traffic interruption phenomenon in the abnormal path supplying the first network traffic or the network traffic abnormal distribution condition is satisfied, the explicit warning unit determines to generate the explicit warning;

[0063] If there is no network traffic interruption phenomenon in the abnormal path supplying the first network traffic and the network traffic abnormal distribution condition is not satisfied, the explicit warning unit determines not to generate the explicit warning.

[0064] In the embodiment of the present invention, the satisfaction of the network traffic abnormal distribution condition includes that the ratio between the sudden drop amount of the network traffic in the abnormal path and the sudden increase amount of the network traffic in at least three associated paths is not within the preset ratio range; the preset ratio range is that if the sudden drop amount of the network traffic in the abnormal path is 1 unit, the sudden increase amount of the network traffic in the associated path is between 3 and 5 units, but the above values are not limited to this, and those skilled in the art can also adjust the values according to actual needs.

[0065] In the embodiment of the present invention, the preset ratio range is determined according to the reference ratio and the tolerance boundary value. The reference ratio and the tolerance boundary value can be determined by the following method. During the network operation, continuously collect a large amount of network traffic data when the network is in a normal operation state and when a network attack occurs. These data cover the traffic size of each path (such as the number of bytes or packets passing through per second) and the change of traffic over time (such as the rising and falling trends of traffic, etc.). The collected data can be stored in a database. Conduct in-depth analysis on the traffic data in different scenarios collected. When the network is abnormal, observe the sudden drop of the traffic in the abnormal path and the sudden increase of the traffic in at least three associated paths related to it. Through statistical analysis, find out the ratio relationship with a higher occurrence frequency between the sudden drop of the traffic in the abnormal path and the sudden increase of the traffic in the associated path among numerous abnormal events. This ratio relationship can be used as the reference ratio. For example, if in multiple abnormal events, it is found that the ratio between the sudden drop amount of the traffic in the abnormal path and the sudden increase amount of the traffic in the associated path is often close to 1:4, then 1:4 can be used as a reference ratio; determine the tolerance boundary value by statistically analyzing the dispersion degree of the ratio in historical data. Calculate the standard deviation of the ratio in historical data. The standard deviation reflects the dispersion degree of the data. Then, several times (such as 1 time, 2 times, or 3 times, etc.) of the standard deviation can be selected as the tolerance boundary value. For example, if the calculated standard deviation of the ratio is 0.5 and 2 times the standard deviation is selected as the tolerance boundary value, then the tolerance boundary value is 1, that is, the actual ratio fluctuating within the range of 1 above and below the reference ratio is considered reasonable.

[0066] The present invention determines whether the explicit warning unit generates the explicit warning by taking the presence of network traffic interruption or meeting the abnormal distribution of network traffic in the abnormal path supplying the first network traffic as a condition, and determines whether the condition of abnormal network traffic distribution is met by judging whether the sudden drop amount of network traffic in the abnormal path is within a preset ratio range compared with the sudden increase amounts of network traffic in at least three associated paths, and further determines whether the explicit warning unit generates the explicit warning. By the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and thus the phenomenon of frequent deviation in warning judgment is reduced to achieve the purpose of improving the warning efficiency.

[0067] Specifically, under the condition of determining whether to generate a hidden warning, the hidden warning unit determines whether to generate a hidden warning according to the presence of network traffic transmission fluctuations in the abnormal path supplying the second network traffic;

[0068] If there are network traffic transmission fluctuations in the abnormal path supplying the second network traffic, the hidden warning unit determines to generate a hidden warning;

[0069] If there are no network traffic transmission fluctuations in the abnormal path supplying the second network traffic, the hidden warning unit determines not to generate a hidden warning.

[0070] In the embodiment of the present invention, the hidden warning unit determines that there are network traffic transmission fluctuations in the abnormal path supplying the second network traffic, including that the dispersion degree of transmitting network traffic in the abnormal path supplying the second network traffic is greater than a preset dispersion degree. The dispersion degree is determined by dividing the traffic standard deviation during the attack occurrence time period by the traffic mean value during the attack occurrence time period. For example, the preset dispersion degree range value is set between 0.1 and 0.5, and the preferred value is 0.3. In the normal network traffic state, through multiple data statistics and analyses, it is found that the dispersion degree mostly fluctuates around 0.3. When the dispersion degree exceeds this value, the probability of abnormal transmission fluctuations of network traffic increases significantly. Therefore, 0.3 is determined as the preferred value of the preset dispersion degree to more accurately identify network traffic transmission fluctuations and trigger the hidden warning. However, the above values are not limited to this, and those skilled in the art can also adjust the values according to actual needs.

[0071] The present invention determines whether to generate the implicit warning by checking if there is network traffic transmission fluctuation in the abnormal path when supplying the second network traffic. When under a cyber attack, different degrees of damage will be caused to the network path. The network path with a large degree of damage can be directly judged by the explicit warning mechanism. However, for the network path with a small degree of damage, no abnormal transmission phenomenon may be shown under the condition of transmitting the first network traffic. Therefore, the present invention determines whether to generate the implicit warning by checking if there is network traffic transmission fluctuation in the abnormal path of the second network traffic, which can prevent the network path with a low degree of damage from being misjudged as a normal path. By the above method, the accuracy of monitoring and analyzing network anomalies is improved, and thus the phenomenon of frequent deviation in warning judgment is reduced to achieve the purpose of improving the warning efficiency.

[0072] Specifically, under the condition of determining whether to adjust the preset network traffic change rate or whether to adjust the preset ratio range, the adjustment module determines whether to adjust the preset network traffic change rate or whether to adjust the preset ratio range according to the warning accuracy rate within the preset period and the proportion of abnormal paths with network traffic transmission anomalies during the initial period of supplying the second network traffic.

[0073] If the proportion of abnormal paths with network traffic transmission anomalies during the initial period of supplying the second network traffic is greater than or equal to the preset proportion, the adjustment module determines to adjust the maximum value of the preset ratio range with the first adjustment coefficient and adjust the minimum value of the preset ratio range with the second adjustment coefficient.

[0074] If the proportion of abnormal paths with network traffic transmission anomalies during the initial period of supplying the second network traffic is less than the preset proportion and the warning accuracy rate within the preset period is less than the preset warning accuracy rate, the adjustment module determines to adjust the preset network traffic change rate with the first adjustment coefficient.

[0075] If the proportion of abnormal paths with network traffic transmission anomalies during the initial period of supplying the second network traffic is less than the preset proportion and the warning accuracy rate within the preset period is greater than or equal to the preset warning accuracy rate, the adjustment module determines not to adjust the preset network traffic change rate and not to adjust the preset ratio range.

[0076] In the embodiment of the present invention, the warning accuracy rate is the ratio of the number of network paths for which warnings are issued within a preset period to the number of network paths whose network traffic change rate is greater than a preset network traffic change rate during the time period when an attack occurs within the preset period. The preset warning accuracy rate is the average value of the warning accuracy rates within a number of preset periods. The initial time period for supplying the second network traffic is from the time when the second network traffic starts to be supplied to 1.1 times the time of the first network traffic. However, the above values are not limited to this, and those skilled in the art can also adjust these values according to actual needs.

[0077] In the embodiment of the present invention, the preset proportion range is set to 0.2 - 0.4. The value of the preset proportion is preferably 0.3. In a large number of past network traffic monitoring, when the proportion of abnormal paths with abnormal network traffic transmission phenomena reaches 0.3, the network performance begins to show significant fluctuations and the network fault incidence rate climbs sharply. However, the above values are not limited to this, and those skilled in the art can also adjust these values according to actual needs.

[0078] In the embodiment of the present invention, the value range of the first adjustment coefficient is set to 1.04 - 1.21, the value of the first adjustment coefficient is preferably 1.11, the value range of the second adjustment coefficient is set to 0.83 - 0.96, the value of the second adjustment coefficient is preferably 0.89. The adjustment amount of the preset network traffic change rate is negatively correlated with the warning accuracy rate within the preset period. However, the above values are not limited to this, and those skilled in the art can also adjust these values according to actual needs.

[0079] The present invention determines the adjustment of the preset proportion range according to the comparison result that the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial time period of the second network traffic is greater than or equal to the preset proportion. If the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial time period of the second network traffic is greater than or equal to the preset proportion, it indicates that there are many abnormal paths with obvious characteristics in the implicit warning. At this time, the maximum value of the preset proportion range is adjusted with the first adjustment coefficient and the minimum value of the preset proportion range is adjusted with the second adjustment coefficient to expand the preset proportion range and thus improve the warning efficiency. If the proportion of abnormal paths with abnormal network traffic transmission phenomena in the initial time period of the second network traffic is less than the preset proportion and the warning accuracy rate within the preset period is less than the preset warning accuracy rate, it indicates that there are many normal paths among the abnormal paths. At this time, the preset network traffic change rate is adjusted with the second adjustment coefficient. Through the above method, the accuracy of monitoring and analyzing network abnormal conditions is improved, and the phenomenon of frequent deviation in warning judgment is reduced, so as to achieve the purpose of improving the warning efficiency.

[0080] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. An intelligent network fault early warning system based on a neural network prediction algorithm, characterized in that Including: An information collection module for collecting network path information, network traffic data information, and attack feature information; An abnormal path determination module connected to the information collection module for determining an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs; An early warning module connected to the information collection module and the abnormal path determination module respectively, including: A network traffic supply unit for supplying first network traffic to the abnormal path and second network traffic to the abnormal path without explicit early warning; An explicit early warning unit connected to the network traffic supply unit for determining whether to generate the explicit early warning based on whether there is a network traffic interruption phenomenon in the abnormal path where the first network traffic is supplied, or whether the network traffic abnormal distribution condition is satisfied; A implicit early warning unit connected to the network traffic supply unit and the explicit early warning unit respectively for determining whether to generate an implicit early warning based on whether there is a network traffic transmission fluctuation in the abnormal path where the second network traffic is supplied; An adjustment module connected to the information collection module, the abnormal path determination module, and the early warning module respectively for determining whether to adjust the preset network traffic change rate or whether to adjust the preset proportion range based on the early warning accuracy rate within a preset period and the proportion of abnormal paths with network traffic transmission abnormal phenomena during the initial period when the second network traffic is supplied; The first network traffic is determined by the average value of network traffic transmission during the normal working period of each abnormal path, and the second network traffic is determined by the network traffic change rate and the first network traffic during the time period when each abnormal path is attacked.

2. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 1, wherein The abnormal path determination module is also used to determine an abnormal path based on the network traffic change rate of each network path during the time period when an attack occurs, where: If the network traffic change rate of a network path during the time period when an attack occurs is greater than or equal to the preset network traffic change rate, determine that the network path is an abnormal path; If the network traffic change rate of a network path during the time period when an attack occurs is less than the preset network traffic change rate, determine that the network path is a normal path.

3. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 2, characterized in that The explicit early warning unit is also used to determine whether to generate an explicit early warning based on whether there is a network traffic interruption phenomenon or whether the network traffic abnormal distribution condition is satisfied in the abnormal path where the first network traffic is supplied, where: If there is a network traffic interruption phenomenon or the network traffic abnormal distribution condition is satisfied in the abnormal path where the first network traffic is supplied, determine to generate the explicit early warning; If there is no network traffic interruption phenomenon and the network traffic abnormal distribution condition is not satisfied in the abnormal path where the first network traffic is supplied, determine not to generate the explicit early warning.

4. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 3, characterized in that, The satisfaction of the network traffic abnormal distribution condition includes that the ratio between the sudden drop amount of network traffic in the abnormal path and the sudden increase amount of network traffic in at least three associated paths is not within the preset proportion range.

5. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 4, wherein The preset proportion range is determined according to the reference proportion and the tolerance boundary value.

6. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 5, characterized in that The implicit warning unit is further configured to determine whether to generate an implicit warning based on whether there is network traffic transmission fluctuation in the abnormal path for supplying the second network traffic, where: If there is network traffic transmission fluctuation in the abnormal path for supplying the second network traffic, it is determined to generate an implicit warning.

7. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 6, characterized in that, The implicit warning unit is further configured to determine whether there is network traffic transmission fluctuation in the abnormal path for supplying the second network traffic based on the dispersion of the network traffic transmitted in the abnormal path for supplying the second network traffic, where: If the dispersion of the network traffic transmitted in the abnormal path for supplying the second network traffic is greater than a preset dispersion, it is determined that there is network traffic transmission fluctuation in the abnormal path for supplying the second network traffic.

8. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 7, characterized in that, The adjustment module is further configured to determine whether to adjust the preset network traffic change rate or whether to adjust the preset proportion range based on the warning accuracy rate within a preset period and the proportion of abnormal paths with network traffic transmission anomalies in the initial period for supplying the second network traffic, where: If the proportion of abnormal paths with network traffic transmission anomalies in the initial period for supplying the second network traffic is greater than or equal to a preset proportion, it is determined to adjust the preset proportion range; If the proportion of abnormal paths with network traffic transmission anomalies in the initial period for supplying the second network traffic is less than the preset proportion and the warning accuracy rate within the preset period is less than the preset warning accuracy rate, it is determined to adjust the preset network traffic change rate.

9. The intelligent network fault early warning system based on the neural network prediction algorithm according to claim 8, wherein, The adjustment amount of the preset network traffic change rate is negatively correlated with the warning accuracy rate within the preset period.

Citation Information

Patent Citations

  • Method for early warning of network fault and gateway for early warning of network fault

    CN107306200A

  • Network security protection method and network security protection system

    CN109889476A

  • Abnormal traffic management and control method and device, electronic equipment and storage medium

    CN119854165A