Method and system for auditing abnormal traffic port based on data center
By implementing an abnormal traffic port audit method and system based on data center in the data center, the problem of private use of ports and traffic bandwidth cannot be activated normally is solved, real-time monitoring and analysis of port traffic is realized, ensuring the normal operation of services and the security of property.
Patent Information
- Application Number
- CN202510253027.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-10
AI Technical Summary
Telecom operators have problems in the data center where private port use and traffic bandwidth cannot be activated normally, resulting in property losses and business abnormalities.
A data center-based abnormal traffic port audit method and system is adopted to obtain port data, traffic data and service ordering data, perform logical port cleaning, traffic auditing and rectification, identify and process abnormal ports, and ensure the consistency of port usage and the rationality of traffic bandwidth.
It effectively prevents the illegal activation of private ports and traffic bandwidth, ensures the normal activation of traffic bandwidth services, reduces property losses, and realizes real-time monitoring and analysis of port traffic.
Smart Images

Figure CN120128368A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data center management, and specifically provides an auditing method and system for abnormal traffic ports based on a data center. Background Art
[0002] With the rapid development of the mobile Internet, the business volume carried by data centers has been increasing continuously, and enterprises have higher and higher requirements for traffic and bandwidth. Grassroots personnel of telecom operators have too much discretionary power. For the sake of immediate benefits, they privately open ports to provide traffic bandwidth for users or enterprises, resulting in problems such as property losses and abnormal business opening. In order to prevent the private use of ports and ensure the normal opening of services, telecom operators urgently need to establish an effective auditing method for abnormal traffic ports. Summary of the Invention
[0003] The purpose of the present invention is to provide an auditing method and system for abnormal traffic ports based on a data center to solve the problems raised in the above background art.
[0004] To achieve the above purpose, the present invention provides the following technical solution: An auditing method for abnormal traffic ports based on a data center, the method comprising the following steps:
[0005] Obtain port data from a resource system and obtain port traffic data from an IP workbench;
[0006] Perform logical port cleaning on the port traffic data of the IP workbench, retain the physical port traffic data, and audit the cleaned physical port data with the physical port data of the resource system. Using the device + port as the auditing condition, distinguish the consistent and inconsistent port data;
[0007] Perform traffic auditing on the port traffic data with consistent device + port. According to the traffic auditing rules, identify the traffic data with a flow rate greater than a preset threshold, obtain service subscription data from the BOSS system, audit the service subscription data and the traffic data greater than the preset threshold, and determine whether there is a service subscription for the port and whether the upstream and downstream flow rates exceed the subscribed bandwidth, and generate a list of abnormal ports accordingly;
[0008] Rectify the audited inconsistent port data and abnormal traffic port data, including port consistency rectification and port traffic rectification, and use the rectification results as the input for the next audit.
[0009] Preferably, the logical port cleaning step includes: filtering out logical ports from the port traffic data obtained from the IP workbench and only retaining the physical port traffic data for subsequent auditing.
[0010] Preferably, the port traffic auditing step further includes:
[0011] For traffic data with a flow rate greater than a preset threshold, check whether there is a corresponding service subscription record;
[0012] For ports with service subscription records, further audit whether their upstream and downstream flow rates exceed the subscribed bandwidth;
[0013] According to the audit results, mark ports without service subscription records or with upstream and downstream flow rates exceeding the subscribed bandwidth as abnormal ports, and generate a list of abnormal ports.
[0014] Preferably, the port rectification steps include:
[0015] Port consistency rectification: For data with inconsistent physical port audits, generate a list of unentered ports and a list of unmanaged ports respectively, and send them to the IP workbench and the asset management system for rectification respectively;
[0016] Port traffic rectification: For the ports in the abnormal traffic port list, send them to the relevant persons in charge of each province according to the province where they are located for port verification, and mark the verification results. The marked results are used as the input conditions for subsequent audits.
[0017] Preferably, the method can timely detect and handle abnormal traffic ports by real-time monitoring and analyzing the port traffic, port resource status, and port service subscription status in the data center, prevent unauthorized port opening and excessive traffic bandwidth opening, ensure the normal opening of the traffic bandwidth service, and reduce property losses.
[0018] An audit system for abnormal traffic ports based on a data center, which is applied to an audit method for abnormal traffic ports based on a data center. The system includes:
[0019] A data acquisition module, which acquires port data from the resource system and port traffic data from the IP workbench;
[0020] A logical port cleaning module, which performs logical port cleaning on the port traffic data of the IP workbench, retains the physical port traffic data, and audits the cleaned physical port data with the physical port data of the resource system. Using the device + port as the audit condition, distinguish the consistent and inconsistent port data;
[0021] A port traffic audit module, which audits the port traffic data with consistent device + port. According to the traffic audit rules, identify the traffic data with a flow rate greater than the preset threshold, obtain the service subscription data from the BOSS system, audit the service subscription data and the traffic data greater than the preset threshold, judge whether the port has a service subscription and whether the upstream and downstream flow rates exceed the subscribed bandwidth, and generate a list of abnormal ports accordingly;
[0022] The data rectification module rectifies the inconsistent port data and abnormal traffic port data identified by auditing, including port consistency rectification and port traffic rectification, and the rectification results are used as the input for the next audit.
[0023] Preferably, the logical port cleaning module filters out logical ports from the port traffic data obtained from the IP workbench and only retains the physical port traffic data for subsequent auditing.
[0024] Preferably, the port traffic auditing module further includes:
[0025] For traffic data with a flow rate greater than the preset threshold, check whether there is a corresponding service subscription record;
[0026] For ports with service subscription records, further audit whether their upstream and downstream flow rates exceed the subscribed bandwidth;
[0027] According to the audit results, mark the ports without service subscription records or with upstream and downstream flow rates exceeding the subscribed bandwidth as abnormal ports and generate a list of abnormal ports.
[0028] Preferably, the port rectification module includes:
[0029] Port consistency rectification: For the physically audited inconsistent data, respectively generate a list of unentered ports and a list of unmanaged ports, and send them to the IP workbench and the asset management system for rectification respectively;
[0030] Port traffic rectification: For the ports in the abnormal traffic port list, send them to the relevant persons in charge of each province according to the province where they are located for port verification, and mark the verification results. The marked results are used as the input conditions for subsequent auditing.
[0031] Preferably, the system monitors and analyzes the port traffic, port resource status, and port service subscription status of the data center in real time, discovers and processes abnormal traffic ports in a timely manner, prevents the unauthorized opening of ports and the over-opening of traffic bandwidth, ensures the normal opening of traffic bandwidth services, and reduces property losses.
[0032] Compared with the prior art, the beneficial effects of the present invention are:
[0033] The auditing method and system for abnormal traffic ports based on a data center proposed by the present invention monitor and analyze the traffic of data center ports, the status of port resources, and port service subscriptions, promptly detect abnormal traffic ports, and take corresponding measures for processing to prevent unauthorized use of ports and ensure the normal activation of services. It effectively solves the problems of unauthorized port opening and excessive traffic bandwidth opening, which lead to the inability to normally activate traffic bandwidth services and property losses. Through this solution, the auditing situations of inconsistent ports and abnormal traffic ports in each province, as well as the port bandwidth and actual port flow velocity of each port, can be displayed, enabling the monitoring and analysis of ports and promptly taking corresponding measures for processing. Through this solution, abnormal traffic ports can be quickly located, and the abnormal traffic ports can be blocked in a timely manner to support the normal activation of traffic bandwidth services. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] In order to clearly and completely describe the objectives, technical solutions, and advantages of the present invention, the following further elaborates on the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are some, but not all, embodiments of the present invention, and are only used to explain the embodiments of the present invention, not to limit the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0036] Embodiment 1, please refer to Figure 1 , the present invention provides a technical solution: an auditing method for abnormal traffic ports based on a data center, the method comprising the following steps:
[0037] Obtain port data from the resource system, obtain port traffic data from the IP workbench, obtain service subscription data from the BOSS, and comprehensively analyze and audit the above data. The auditing method (see appendix Figure 1 ):
[0038] 1. Physical port auditing: Perform logical port cleaning on the port traffic data of the IP workbench, filter out the logical ports and retain the physical port traffic data; then audit the physical port data after cleaning by the IP workbench with the physical port data of the resource system. Using the device + port as the auditing condition, audit the data where the device + port is consistent and the inconsistent data. The data where the device + port is inconsistent is automatically generated into a list and sent to the resource system and the IP workbench for rectification. The port traffic data where the device + port is consistent is used as the input condition for the next stage of auditing.
[0039] 2. Port traffic auditing: Conduct traffic auditing on the IP workbench traffic data that is consistent with the physical port auditing.
[0040] (1) According to the traffic auditing rules, audit the traffic data with a flow rate greater than 0.1 Mbps.
[0041] (2) Obtain service subscription data from the BOSS system.
[0042] (3) Audit the service subscription data and the traffic data greater than 0.1 Mbps.
[0043] ① Audit whether there is a service subscription for the port with traffic. If there is a service subscription, the port is normal; if there is no service subscription, the port is abnormal, and an abnormal port list is generated for rectification.
[0044] ② For the port with a service subscription, further audit whether the upstream and downstream flow rates are greater than the subscribed bandwidth. If the upstream and downstream flow rates are less than or equal to the subscribed bandwidth, the port is normal; if the upstream and downstream flow rates are greater than the subscribed bandwidth, the port is abnormal, and an abnormal port list is generated for rectification.
[0045] 3. Port rectification: Port rectification is divided into port consistency rectification and port traffic rectification.
[0046] (1) Port consistency rectification: Rectify the ports with inconsistent physical port auditing, and generate a port not entered list and a port not managed list respectively. The port not entered list is sent to the IP workbench for rectification by the IP workbench; the port not managed list is sent to the asset management system for rectification by the asset management system.
[0047] (2) Port traffic rectification: Rectify the abnormal port list generated by port traffic auditing, send it to the relevant persons in charge of each province according to the province for port verification, and mark the port verification results. The marked port results are used as the input for the next auditing.
[0048] Embodiment 2, based on Embodiment 1, proposes an auditing system for abnormal traffic ports based on a data center, which is applied to an auditing method for abnormal traffic ports based on a data center. The system includes:
[0049] A data acquisition module, which acquires port data from the resource system and port traffic data from the IP workbench.
[0050] The logical port cleaning module performs logical port cleaning on the port traffic data of the IP workbench, retains the physical port traffic data, and audits the cleaned physical port data against the physical port data of the resource system. Using the device + port as the audit condition, it differentiates the consistent and inconsistent port data; filters out the logical ports from the port traffic data obtained from the IP workbench and only retains the physical port traffic data for subsequent auditing.
[0051] The port traffic auditing module audits the port traffic data with consistent device + port. According to the traffic auditing rules, it identifies the traffic data with a flow rate greater than the preset threshold, obtains the service subscription data from the BOSS system, audits the service subscription data and the traffic data greater than the preset threshold, determines whether there is a service subscription for the port and whether the upstream and downstream flow rates exceed the subscribed bandwidth, and generates a list of abnormal ports accordingly;
[0052] Further includes:
[0053] For the traffic data with a flow rate greater than the preset threshold, check whether there is a corresponding service subscription record;
[0054] For the ports with service subscription records, further audit whether their upstream and downstream flow rates exceed the subscribed bandwidth;
[0055] According to the audit results, mark the ports without service subscription records or with upstream and downstream flow rates exceeding the subscribed bandwidth as abnormal ports and generate a list of abnormal ports.
[0056] The data rectification module rectifies the inconsistent port data and abnormal traffic port data identified through auditing, including port consistency rectification and port traffic rectification. The rectification results are used as the input for the next audit;
[0057] Port consistency rectification: For the data with inconsistent physical port audits, generate a list of unentered ports and a list of unmanaged ports respectively, and send them to the IP workbench and the asset management system for rectification;
[0058] Port traffic rectification: For the ports in the abnormal traffic port list, send them to the relevant persons in charge of each province according to the province where they are located for port verification, and mark the verification results. The marked results are used as the input conditions for subsequent audits.
[0059] The system monitors and analyzes the port traffic, port resource status, and port service subscription status in the data center in real time, discovers and processes abnormal traffic ports in a timely manner, prevents unauthorized port opening and excessive traffic bandwidth opening, ensures the normal opening of traffic bandwidth services, and reduces property losses.
[0060] Although embodiments of the present invention have been shown and described, those of ordinary skill in the art will appreciate that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for auditing abnormal traffic ports based on a data center, characterized by: The method comprises the following steps: Get port data from the resource system and port traffic data from the IP workbench; Perform logical port cleaning on the port traffic data of the IP workstation, retain the physical port traffic data, and audit the cleaned physical port data with the physical port data of the resource system, using device + port as the audit condition to distinguish consistent and inconsistent port data; Perform traffic audit on the port traffic data that is consistent with the device + port. According to the traffic audit rules, identify the traffic data with a flow rate greater than the preset threshold, obtain the service subscription data from the BOSS system, audit the service subscription data and the traffic data greater than the preset threshold, determine whether the port has a service subscription and whether the upstream and downstream flow rates exceed the subscription bandwidth, and generate a list of abnormal ports accordingly; Rectify the inconsistent port data and abnormal traffic port data found in the audit, including port consistency rectification and port traffic rectification. The rectification results will serve as input for the next audit.
2. According to claim 1, a method for auditing abnormal traffic ports based on a data center is characterized in that: The logical port cleaning step includes: filtering out the logical ports from the port traffic data obtained from the IP workbench, and retaining only the physical port traffic data for subsequent auditing.
3. The method for auditing abnormal traffic ports based on a data center according to claim 1, characterized in that: The port traffic auditing steps further include: For traffic data with a flow rate greater than a preset threshold, check whether there is a corresponding service subscription record; For ports with service subscription records, further check whether their upstream and downstream traffic rates exceed the subscription bandwidth; Based on the audit results, ports with no business subscription records or whose upstream and downstream traffic rates exceed the subscribed bandwidth are marked as abnormal ports, and a list of abnormal ports is generated.
4. The method for auditing abnormal traffic ports based on a data center according to claim 1, characterized in that: The port rectification steps include: Port consistency rectification: For inconsistent data in the physical port audit, a list of ports not entered and a list of ports not managed are generated, and sent to the IP workbench and the asset management system for rectification; Port traffic rectification: For the ports in the abnormal traffic port list, they will be sent to the relevant persons in charge of each province for port verification according to the province where they are located, and the verification results will be marked. The marked results will serve as input conditions for subsequent audits.
5. The method for auditing abnormal traffic ports based on a data center according to claim 1, characterized in that: The method timely discovers and handles abnormal traffic ports by real-time monitoring and analyzing the port traffic, port resource status and port service subscription status of the data center, prevents the behavior of privately opening ports and opening more traffic bandwidth, ensures the normal opening of traffic bandwidth services, and reduces property losses.
6. An audit system for abnormal traffic ports based on a data center, applied to an audit method for abnormal traffic ports based on a data center as described in any one of claims 1 to 5, characterized in that: The system comprises: Data acquisition module, which obtains port data from the resource system and port flow data from the IP workbench; The logical port cleaning module performs logical port cleaning on the port traffic data of the IP workstation, retains the physical port traffic data, and audits the cleaned physical port data with the physical port data of the resource system, using the device + port as the audit condition to distinguish consistent and inconsistent port data; The port traffic audit module performs traffic audit on the port traffic data that is consistent with the device + port. According to the traffic audit rules, it identifies the traffic data with a flow rate greater than the preset threshold, obtains the service subscription data from the BOSS system, audits the service subscription data and the traffic data greater than the preset threshold, determines whether the port has a service subscription and whether the upstream and downstream flow rates exceed the subscription bandwidth, and generates a list of abnormal ports accordingly; The data rectification module rectify the inconsistent port data and abnormal traffic port data found in the audit, including port consistency rectification and port traffic rectification. The rectification results serve as the input for the next audit.
7. The audit system for abnormal traffic ports based on a data center according to claim 6 is characterized in that: The logical port cleaning module filters out the logical ports from the port traffic data obtained from the IP workbench and only retains the physical port traffic data for subsequent auditing.
8. The audit system for abnormal traffic ports based on a data center according to claim 6 is characterized in that: The port traffic audit module further includes: For traffic data with a flow rate greater than a preset threshold, check whether there is a corresponding service subscription record; For ports with service subscription records, further check whether their upstream and downstream traffic rates exceed the subscription bandwidth; Based on the audit results, ports with no business subscription records or whose upstream and downstream traffic rates exceed the subscribed bandwidth are marked as abnormal ports, and a list of abnormal ports is generated.
9. The audit system for abnormal traffic ports based on a data center according to claim 6, characterized in that: The port rectification module includes: Port consistency rectification: For inconsistent data in the physical port audit, a list of ports not entered and a list of ports not managed are generated, and sent to the IP workbench and the asset management system for rectification; Port traffic rectification: For the ports in the abnormal traffic port list, they will be sent to the relevant persons in charge of each province for port verification according to the province where they are located, and the verification results will be marked. The marked results will serve as input conditions for subsequent audits.
10. The audit system for abnormal traffic ports based on a data center according to claim 6, characterized in that: The system monitors and analyzes the port traffic, port resource status and port service subscription status of the data center in real time, promptly discovers and handles abnormal traffic ports, prevents the unauthorized opening of ports and excessive opening of traffic bandwidth, ensures the normal opening of traffic bandwidth services, and reduces property losses.
Citation Information
Cited By
Service flow auditing method, system and device and storage medium
CN121561691A