Computer intelligent service management system and method based on network big data

By introducing an intelligent service management system based on network big data in the enterprise computer management system, dynamically generate bandwidth thresholds and real-time monitoring, the problem of existing systems being difficult to identify and manage bandwidth abnormalities in DDoS attacks is solved, and the accuracy of security judgments and system functionality are improved.

CN120151052AActive Publication Date: 2025-06-13LUSHAN COLLEGE OF GUANGXI UNIV OF SCI & TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510354402.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-06-13
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

It is difficult for existing enterprise computer management systems to effectively identify and manage bandwidth abnormalities caused by DDoS attacks, and it is difficult to take into account the computer usage patterns of different working hours, making misjudgment and misjudgment.

Method used

The computer intelligent service management system based on network big data is adopted, and the computer runs the data acquisition module, the device grouping module, the bandwidth threshold generation module, the potential exception identification module and the exception reporting and management module to realize the generation and real-time monitoring of dynamic bandwidth thresholds to identify potential network security abnormalities.

Benefits of technology

It improves the accuracy of computer security judgment, enhances the functionality and practicality of the system, can adapt to computer security management during different working hours, and promptly identify and deal with low-intensity DDoS network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151052A_ABST
    Figure CN120151052A_ABST
Patent Text Reader

Abstract

The invention discloses a computer intelligent service management system and method based on network big data, and belongs to the technical field of computer network security, and the system comprises a computer operation data collection module, a computer equipment grouping module, a bandwidth threshold generation module, a potential anomaly recognition module, and an anomaly reporting and computer management module. And the computer operation data acquisition module is used for acquiring real-time bandwidth data in the use process of computer equipment under the administration of an enterprise on the basis of an SNMP (Simple Network Management Protocol). According to the computer intelligent service management system and method based on the network big data, specific grouping, real-time dynamic bandwidth threshold establishment and dynamic bandwidth curve comparison can be carried out on enterprise computer equipment based on different enterprise architectures, so that the real-time dynamic bandwidth threshold establishment and dynamic bandwidth curve comparison can be monitored under workdays, holidays and overtime working conditions; the computer equipment in different second-level groups is safe, and potential computer safety abnormity is identified, so that the practicability and functionality of the system are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer network security, and specifically relates to a computer intelligent service management system and method based on network big data. Background Art

[0002] With the rapid development of information technology, computers have become an indispensable infrastructure for modern corporate offices. The network security issues of corporate computer equipment have become increasingly complex and severe. DDoS attacks on key corporate computers occur from time to time. During DDoS network attacks, a large amount of device bandwidth will be occupied, resulting in bandwidth anomalies.

[0003] In the existing enterprise computer management process, computer security monitoring and management is usually based on a fixed judgment threshold to judge the security of computer equipment. However, different enterprise departments have different work tasks. The usage patterns and bandwidth characteristics of enterprise computers vary greatly during different time periods such as weekdays, weekends, and overtime. Fixed thresholds are difficult to take into account various situations, and are prone to misjudgment and missed judgment, resulting in management confusion and low practicality. At the same time, in the face of increasingly complex security attack methods, especially low-intensity DDoS network attacks, traditional computer management systems are difficult to effectively identify and have low functionality.

[0004] In response to the above, this case proposes a computer intelligent service management system and method based on network big data to solve the above technical problems. Summary of the invention

[0005] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention proposes a computer intelligent service management system and method based on network big data, which solves the above technical problems by improving the detection method and processing method.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] A computer intelligent service management system and method based on network big data, including a computer operation data acquisition module, a computer equipment grouping module, a bandwidth threshold generation module, a potential anomaly identification module, an anomaly reporting and computer management module;

[0008] The computer operation data collection module collects real-time bandwidth data of the computer equipment under the jurisdiction of the enterprise during use based on the SNMP protocol, collects historical bandwidth big data of the computer equipment under the jurisdiction of the enterprise and the affiliated departments of the computer equipment under the jurisdiction, and transmits the data to the subsequent modules;

[0009] The computer device grouping module creates files and groups computer devices under the organizational structure based on the enterprise architecture using InfluxDB. It creates computer device files in each group, where the files include computer device numbers, affiliated departments, historical bandwidth big data of the current computer device, bandwidth data collected in real time by the current computer device, and collection times. It performs secondary grouping based on the historical bandwidth big data of subordinate computer devices;

[0010] The bandwidth threshold generation module generates dynamic bandwidth thresholds based on the real-time bandwidth data of computer devices within the same secondary group. It monitors the bandwidth of computer devices within the same secondary group in real time and determines network security based on the dynamic bandwidth thresholds, identifying computer devices with network security anomalies and generating anomaly signals;

[0011] The potential anomaly identification module analyzes the network bandwidth change data of computer devices within the same secondary group to obtain a reference bandwidth change curve. It identifies potential network security anomalies for computer devices within the same secondary group based on the reference bandwidth change curve and generates anomaly signals;

[0012] The anomaly reporting and computer management module includes an audible and visual alarm. Based on the received anomaly signals, it emits alarm signals in the form of sound, light, and vibration to remind the duty personnel to comprehensively manage the abnormal computers.

[0013] Furthermore, the computer device grouping module creates files and groups computer devices under the organizational structure based on the enterprise architecture using InfluxDB. It creates computer device files in each group, where the files include computer device numbers, affiliated departments, historical bandwidth big data of the current computer device, bandwidth data collected in real time by the current computer device, and collection times. It performs secondary grouping based on the historical bandwidth big data of subordinate computer devices, including the following steps:

[0014] Create files for subordinate computer devices respectively, perform primary grouping on the computer device files based on the affiliated departments of the computer devices, and classify computer devices in the same department into the same department group. The computer device files in each group contain the device numbers and affiliated departments;

[0015] Collect the historical bandwidth big data of computer devices in each department group, perform secondary grouping on the computer devices in the primary group using K-means clustering based on the historical bandwidth big data, and record the real-time bandwidth data into the computer device files at the same time.

[0016] Furthermore, the step of collecting the historical bandwidth big data of computer devices in each department group and performing secondary grouping on the computer devices in the primary group using K-means clustering based on the historical bandwidth big data is specifically as follows:

[0017] Collect the historical bandwidth big data of each computer device within the first-level grouping as feature vectors, including the average bandwidth of the computer device, the peak bandwidth of the computer device, and the bandwidth standard deviation, and establish a multi-dimensional vector x i ={x i1 , x i2 , x i3}, where x i1 , x i2 , x i3 represent the average bandwidth, the peak bandwidth of the computer device, and the bandwidth standard deviation of the i-th computer device respectively;

[0018] Divide the computer devices within the first-level grouping into low, medium, and high bandwidth usage intensities, and set the number of clusters υ = 3;

[0019] Randomly select the feature vectors of F computer devices from the dataset as the initial centroids μ 1 , μ 2 ,..., μ F . For the feature vector x i of each computer device, calculate its distance from each centroid μ F based on the Euclidean distance algorithm, and assign the computer device x i to the cluster C F corresponding to the nearest centroid. At the same time, for each cluster C F , recalculate its centroid μ F , and its algorithm formula is:

[0020]

[0021] where μ Fj is the value of the centroid of the F-th cluster in the j-th dimension, |C F | represents the number of samples C F in the F-th cluster, and x ij represents the value of the i-th computer device in the j-th dimension;

[0022] Calculate the sum D of the Euclidean distances between the old and new centroids, and compare it with the convergence threshold η:

[0023] When D < η, it means that the current algorithm converges, the clustering process ends, and all computer devices in each first-level grouping are divided into different clusters, completing the second-level grouping. The names of each grouping are the low-bandwidth group, the medium-bandwidth group, and the high-bandwidth group respectively;

[0024] When D ≥ η, it means that the current algorithm does not converge. Recalculate the distance from each centroid μ F based on the Euclidean distance algorithm, and assign the computer device x iAllocate to the cluster C corresponding to the centroid with the closest distance F and continue with centroid recalculation and convergence threshold comparison and determination until the algorithm converges or reaches the maximum number of iterations N.

[0025] Furthermore, the bandwidth threshold generation module generates a dynamic bandwidth threshold based on the real-time bandwidth data of computer devices within the same secondary grouping, monitors the bandwidth of computer devices within the same secondary grouping in real time and determines network security based on the dynamic bandwidth threshold, identifies computer devices with network security anomalies and generates anomaly signals. The specific steps are as follows:

[0026] For the same secondary grouping, including the low-bandwidth group, medium-bandwidth group, and high-bandwidth group, extract real-time data from the computer device profiles in each secondary grouping to obtain the real-time bandwidth data of different computer devices under the current grouping and generate a real-time dynamic bandwidth threshold;

[0027] Based on the real-time dynamic bandwidth threshold, monitor the bandwidth of computer devices within the same secondary grouping in real time and determine network security, identify computer devices with network security anomalies and generate anomaly signals, and send the anomaly signals to the anomaly reporting and computer management module.

[0028] Furthermore, for the same secondary grouping, including the low-bandwidth group, medium-bandwidth group, and high-bandwidth group, extract real-time data from the computer device profiles in each secondary grouping to obtain the real-time bandwidth data of different computer devices under the current grouping and generate a real-time dynamic bandwidth threshold. The specific steps are as follows:

[0029] At each time t, collect the real-time bandwidth data of each computer device in the secondary grouping where i represents the computer device number within grouping K, e represents the data collection moment within time period t, and calculate the mean ε of the bandwidth data of grouping K within time period t K , and its algorithm formula is:

[0030]

[0031] where N is the number of computer devices within grouping K, M is the number of data collection points within time period t, and based on the mean ε K calculate the standard deviation σ K , obtain the real-time dynamic bandwidth threshold θ K = ε K + kσ K .

[0032] Further, based on the real-time dynamic bandwidth threshold, the bandwidth of computer devices within the same secondary group is monitored in real time and network security is determined. Computer devices with network security anomalies are identified and anomaly signals are generated, and the anomaly signals are sent to the anomaly reporting and computer management module. The specific steps are as follows:

[0033] In the next time period t, continue to collect the real-time bandwidth data of computer devices in group K represents the real-time bandwidth of computer device i at the new moment l. Combining the real-time dynamic bandwidth threshold, network security anomalies of computer devices within the current group are determined. The steps are as follows:

[0034] When , it means that computer device i has a network security anomaly. Extract the device number from the computer device file and transmit the anomaly signal to the anomaly reporting and computer management module;

[0035] When , continue to collect the real-time bandwidth data of each computer device in the secondary group Based on Calculate the real-time dynamic bandwidth threshold in the next next time period t. Based on the real-time dynamic bandwidth threshold in the next next time period t, network security anomalies of the real-time bandwidth data in the next next time period t are determined.

[0036] Further, the potential anomaly identification module analyzes the network bandwidth change data of computer devices within the same secondary group to obtain a reference bandwidth change curve. Based on the reference bandwidth change curve, potential network security anomalies of computer devices within the same secondary group are identified and anomaly signals are generated. The specific steps are as follows:

[0037] In each time interval [t 0 , t 1 , based on the computer device files within the same secondary group, extract the real-time bandwidth data during device operation, and calculate the bandwidth change curves of different computer devices within the group respectively. The specific steps are as follows:

[0038] For the same secondary group G, the computer devices within the group are H p , p = 1, 2, 3,..., n, where n is the number of computer devices in the current group. In the time interval [t 0 , t 1 , the real-time bandwidth data of computer device H p at the moment t ε is B p (t ε ). With the moment t ε as the horizontal axis and the real-time bandwidth data B p (tε ) is the vertical axis, and the bandwidth change curve y = B of each device is plotted p (t ε );

[0039] Based on the bandwidth change curves of different computer devices within the group, at the end of each time interval [t 0 , t 1 , the similarity of the bandwidth change curves in the current time interval [t 0 , t 1 is compared to identify potential abnormal computer devices and determine network security anomalies.

[0040] Further, based on the bandwidth change curves of different computer devices within the group, at the end of each time interval [t 0 , t 1 , the similarity of the bandwidth change curves in the current time interval [t 0 , t 1 is compared to identify potential abnormal computer devices and determine network security anomalies. The specific steps are as follows:

[0041] By the Euclidean distance method, calculate the Euclidean distance d p between device H q and H 0 within the time interval [t 1 , t pq of the bandwidth change curves. The algorithm formula is:

[0042]

[0043] For each device H p within the group, calculate its Euclidean distance from other computer devices respectively. Based on the similarity distance threshold θ, determine the Euclidean distance. When the Euclidean distance is greater than θ, it means that the bandwidth change curves of the two computer devices are not similar;

[0044] When the results of the Euclidean distance determination between device H p and the computer devices within the current group are all greater than θ, then mark device H p as a potential abnormal computer device, indicating that there is a network security anomaly. Extract the device number from the computer device file and transmit an abnormal signal to the abnormal reporting and computer management module.

[0045] A computer intelligent service management method based on network big data includes the following steps:

[0046] S1. Collect the real-time bandwidth data during the use of computer devices under the enterprise based on the SNMP protocol, collect the historical bandwidth big data of computer devices under the enterprise and the affiliated departments of computer devices under the enterprise, and establish files and groups for computer devices under the current enterprise organizational structure based on InfluxDB according to the enterprise architecture;

[0047] S2. Establish computer device files in each group. The files include computer device numbers, affiliated departments, the historical bandwidth big data of the current computer device, the bandwidth data collected in real time by the current computer device, and the collection time, and perform secondary grouping through the historical bandwidth big data of computer devices under the enterprise;

[0048] S3. Generate dynamic bandwidth thresholds based on the real-time bandwidth data of computer devices within the same secondary group, and perform real-time monitoring and network security determination on the bandwidth of computer devices within the same secondary group based on the dynamic bandwidth thresholds, identify computer devices with network security anomalies and generate anomaly signals;

[0049] S4. Analyze the obtained reference bandwidth change curve for the network bandwidth change data of computer devices within the same secondary group, identify potential network security anomalies for computer devices within the same secondary group based on the reference bandwidth change curve, and generate anomaly signals;

[0050] S5. Based on the received anomaly signals of computer devices under the enterprise, send out alarm signals and display the abnormal computer devices under the enterprise to remind the duty personnel to conduct comprehensive management of the abnormal computers.

[0051] Compared with the prior art, the beneficial effects of the present invention are:

[0052] 1. In the present invention, by setting a bandwidth threshold generation module, the real-time bandwidth data within the same group in the first time period is obtained and the real-time dynamic bandwidth threshold is calculated to perform computer network security determination on different devices within the same group in the second time period, and the real-time dynamic bandwidth threshold is continuously updated based on the real-time bandwidth data obtained in the second time period to perform network security determination on different computer devices within the same group in the third time period, and so on to achieve continuous real-time monitoring and management of the bandwidth of computer devices within the same group, so as to improve the accuracy of computer security determination;

[0053] 2. In the present invention, by continuously updating the real-time dynamic bandwidth threshold through a rolling time window, it can timely adapt to the changes in different computer network environments, avoid the limitations of a fixed threshold, and at the same time determine the value of the real-time dynamic threshold based on the real-time operating conditions of computer devices within the same secondary group, which can meet the computer security determination and management in different situations such as weekdays, weekends, and overtime. When the network environment changes, it can quickly adjust through the update of the real-time dynamic threshold to cope with the new usage pattern, enhancing the functionality of the system;

[0054] 3. In the present invention, by setting up a potential anomaly recognition module in cooperation with a bandwidth threshold generation module, within the same time interval, bandwidth change curves are respectively established for computer devices within the same secondary group and pairwise compared to identify and determine a DDoS network attack with low intensity to identify potential computer security anomalies, enhancing the practicality of the system;

[0055] 4. In the present invention, based on the enterprise architecture and combined with historical bandwidth big data, computer devices under the same architecture are grouped into secondary groups, which facilitates the calculation of real-time dynamic bandwidth thresholds within the secondary groups in different situations, thereby realizing the grouped monitoring and analysis of computer security under the enterprise architecture, enhancing the accuracy of computer security anomaly recognition;

[0056] The entire computer intelligent service management system and method based on network big data can, based on the architectures of different enterprises, perform specific grouping of enterprise computer devices, establish real-time dynamic bandwidth thresholds, and compare dynamic bandwidth curves to monitor the security of computer devices within different secondary groups on weekdays, holidays, and during overtime, and identify potential computer security anomalies, enhancing the practicality and functionality of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] Figure 1 It is a block diagram of a computer intelligent service management system based on network big data according to the present invention;

[0058] Figure 2 It is a flowchart of a computer intelligent service management method based on network big data according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0059] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0060] Embodiment 1:

[0061] As Figure 1 shown, a computer intelligent service management system based on network big data includes a computer operation data acquisition module, a computer device grouping module, a bandwidth threshold generation module, a potential anomaly identification module, and an anomaly reporting and computer management module;

[0062] The computer operation data acquisition module collects real-time bandwidth data during the use of computer devices under the enterprise based on the SNMP protocol, collects historical bandwidth big data of computer devices under the enterprise and the affiliated departments of the computer devices under the enterprise, and transmits the data into the subsequent modules;

[0063] The computer device grouping module establishes files and groups for computer devices under the organizational structure based on the enterprise architecture using InfluxDB, creates computer device files in each group, and the files include computer device numbers, affiliated departments, current historical bandwidth big data of computer devices, current bandwidth data collected in real time by computer devices, and collection time. Secondary grouping is performed based on the historical bandwidth big data of computer devices under the enterprise, including the following steps:

[0064] Establish computer device files under the enterprise respectively, perform primary grouping on the computer device files based on the affiliated departments of the computer devices, and classify computer devices in the same department into the same department group. The computer device files in each group contain the device numbers and affiliated departments;

[0065] Collect the historical bandwidth big data of computer devices in each department group, perform secondary grouping on the computer devices in the primary group using K-means clustering based on the historical bandwidth big data, and record the real-time bandwidth data into the computer device files at the same time;

[0066] Collect the historical bandwidth big data of devices in each department group, perform secondary grouping on the devices in the primary group using K-means clustering based on the historical bandwidth big data, and its specific steps are as follows:

[0067] Collect the historical bandwidth big data of each computer device in the primary group as feature vectors, including the average bandwidth of the computer device, the peak bandwidth of the computer device, and the bandwidth standard deviation, and establish a multi-dimensional vector x i ={x i1 ,x i2 ,x i3}, where x i1 ,x i2 ,x i3 represent the average bandwidth, peak bandwidth, and bandwidth standard deviation of the i-th computer device respectively;

[0068] Classify the computer devices in the primary group into low, medium, and high bandwidth usage intensities, and set the number of clusters υ = 3;

[0069] Randomly select the feature vectors of F computer devices from the dataset as the initial centroids μ 1 , μ 2 ,..., μ F . For the feature vector x of each computer device i , calculate its distance from each centroid μ F based on the Euclidean distance algorithm, and assign the computer device x i to the cluster C F corresponding to the centroid with the closest distance. At the same time, for each cluster C F , recalculate its centroid μ F . The algorithm formula is as follows:

[0070]

[0071] where μ Fj is the value of the centroid of the F-th cluster in the j-th dimension, |C F | represents the number of samples in the F-th cluster C F , and x ij represents the value of the i-th computer device in the j-th dimension;

[0072] It should be noted that the distance from each centroid μ F is calculated through the Euclidean distance. The algorithm formula is as follows:

[0073]

[0074] Assign the device x i to the cluster C F corresponding to the centroid with the closest distance, that is, when , then x i ∈C u .

[0075] Calculate the sum D of the Euclidean distances between the old and new centroids, and compare it with the convergence threshold η:

[0076] When D < η, it means that the current algorithm converges, the clustering process ends, and all computer devices in each first-level grouping are divided into different clusters, completing the second-level grouping. The names of each grouping are the low-bandwidth group, the medium-bandwidth group, and the high-bandwidth group respectively;

[0077] When D ≥ η, it means that the current algorithm does not converge. Recalculate the distance from each centroid μ F based on the Euclidean distance algorithm, and assign the computer device x i to the cluster C F corresponding to the centroid with the closest distance, and continue to recalculate the centroid and compare and determine the convergence threshold until the algorithm converges or reaches the maximum number of iterations N.

[0078] It should be noted that in the K-means clustering algorithm, the centroid is the center of each cluster and is used to represent the position of the cluster, |C F | is an integer used to calculate the average value. The convergence threshold η is generally set to 0.01, and can also be set by the empirical method according to actual usage needs. The maximum number of iterations N is set to 15, and can also be increased or decreased according to actual usage conditions.

[0079] Embodiment 2:

[0080] The bandwidth threshold generation module generates a dynamic bandwidth threshold based on the real-time bandwidth data of computer devices within the same secondary grouping, monitors the bandwidth of computer devices within the same secondary grouping in real time and determines network security based on the dynamic bandwidth threshold, identifies computer devices with network security anomalies and generates anomaly signals. The specific steps are as follows:

[0081] For the same secondary grouping, including the low-bandwidth group, medium-bandwidth group, and high-bandwidth group, real-time data extraction is performed on the computer device files in each secondary grouping to obtain the real-time bandwidth data of different computer devices under the current grouping, and a real-time dynamic bandwidth threshold is generated. The specific steps are as follows:

[0082] At each time t, collect the real-time bandwidth data of each computer device in the secondary grouping where i represents the computer device number within grouping K, e represents the data collection time within time period t, and calculate the average value ε of the bandwidth data of grouping K within time period t K , and its algorithm formula is:

[0083]

[0084] where N is the number of computer devices within grouping K, M is the number of data collection points within time period t, and based on the average value ε K calculate the standard deviation σ K , and obtain the real-time dynamic bandwidth threshold θ K = ε K + kσ K .

[0085] It should be noted that in the dynamic bandwidth threshold θ K = ε K + kσ K the value of k is set to 1.5. By adjusting the size of k, the looseness of the dynamic bandwidth threshold can be controlled. The time period t needs to be set according to the working time cycle of each department of the relevant enterprise, and is usually set to 5 minutes, and can also be adjusted according to actual conditions;

[0086] Based on the real-time dynamic bandwidth threshold, monitor the bandwidth of computer devices within the same secondary group in real time and conduct network security determination, identify computer devices with network security anomalies and generate anomaly signals, and send the anomaly signals to the anomaly reporting and computer management module. The specific steps are as follows:

[0087] In the next time period t, continue to collect the real-time bandwidth data of computer devices in group K Represents the real-time bandwidth of computer device i at the new moment l. Combine the real-time dynamic bandwidth threshold to conduct network security anomaly determination on the computer devices within the current group. The steps are as follows:

[0088] When then it means that computer device i has a network security anomaly. Extract the device number from the computer device file and transmit the anomaly signal to the anomaly reporting and computer management module;

[0089] When then continue to collect the real-time bandwidth data of each computer device in the secondary group Based on Calculate the real-time dynamic bandwidth threshold in the next next time period t. Based on the real-time dynamic bandwidth threshold in the next next time period t, conduct network security anomaly determination on the real-time bandwidth data in the next next time period t.

[0090] It should be noted that by obtaining and calculating the real-time dynamic bandwidth threshold for the real-time bandwidth data within the same group in the first time period t, conduct network security determination on different devices within the same group in the second time period t, and continue to update the real-time dynamic bandwidth threshold based on the real-time bandwidth data obtained in the second time period t to conduct network security determination on different devices within the same group in the third time period t, and so on in a cycle to achieve continuous real-time monitoring of the bandwidth of devices within the same group, so as to improve the accuracy of network security determination. And for the enterprise work conditions in different situations, use the operating devices under the same secondary group on weekdays, weekends, and when the department is working overtime as the benchmark conditions for generating the real-time dynamic threshold, so as to adapt to different actual usage situations;

[0091] Embodiment 3:

[0092] The potential anomaly identification module analyzes the network bandwidth change data of computer devices within the same secondary group to obtain the reference bandwidth change curve, and based on the reference bandwidth change curve, conducts potential network security anomaly identification on the computer devices within the same secondary group. The specific steps are as follows:

[0093] At each time interval [t 0 , t 1Among them, based on the computer device files within the same secondary grouping, real-time bandwidth data during device operation is extracted, and the bandwidth change curves of different computer devices within the group are calculated respectively. The specific steps are as follows:

[0094] For the same secondary grouping G, the computer devices within the group are H p , p = 1, 2, 3,..., n, where n is the number of computer devices within the current group. During the time interval [t 0 , t 1 , the real-time bandwidth data of computer device H p at time t ε is B p (t ε ). Taking time t ε as the horizontal axis and the real-time bandwidth data B p (t ε ) as the vertical axis, draw the bandwidth change curve of each device y = B p (t ε );

[0095] Based on the bandwidth change curves of different computer devices within the group, at the end of each time interval [t 0 , t 1 , compare the similarity of the bandwidth change curves in the current time interval [t 0 , t 1 , identify potential abnormal computer devices, and determine network security anomalies. The specific steps are as follows:

[0096] Using the Euclidean distance method, calculate the Euclidean distance d p between device H q and H 0 within the time interval [t 1 . Its algorithm formula is: pq

[0097]

[0098] For each device H p within the group, calculate its Euclidean distance from other computer devices respectively. Based on the similarity distance threshold θ, determine the Euclidean distance. When the Euclidean distance is greater than θ, it means that the bandwidth change curves of the two computer devices are not similar;

[0099] When the results of the Euclidean distance determination between device H p and the computer devices within the current grouping are all greater than θ, then device H pMark the computer device as a potential anomaly, representing a network security anomaly. Extract the device number from the computer device file and transmit the anomaly signal to the anomaly reporting and computer management module.

[0100] It should be noted that when there are significant differences in the bandwidth change curves of one or some devices within the same time interval compared to most devices within the current time interval, it indicates that the current device may be under a relatively low-intensity DDOS network attack. Mark this device as an abnormal device to identify potential network security anomalies. The similarity distance threshold θ needs to be set based on the empirical method by consulting experts in the relevant field and considering the software usage of the department's devices.

[0101] The anomaly reporting and computer management module includes an audible and visual alarm. Based on the received anomaly signal, it emits alarm signals in the forms of sound, light, and vibration to remind the duty personnel to comprehensively manage the abnormal computers.

[0102] Example 4:

[0103] As Figure 2 shown, a computer intelligent service management method based on network big data includes the following steps:

[0104] S1. Collect real-time bandwidth data during the use of computer devices under the enterprise based on the SNMP protocol, collect historical bandwidth big data of computer devices under the enterprise and the affiliated departments of the computer devices. According to the enterprise architecture, establish files and groups for computer devices under the current enterprise organizational structure based on InfluxDB.

[0105] S2. Establish computer device files in each group. The files include computer device numbers, affiliated departments, historical bandwidth big data of the current computer device, real-time bandwidth data collected by the current computer device, and collection time. Perform secondary grouping through the historical bandwidth big data of computer devices under the jurisdiction.

[0106] S3. Generate dynamic bandwidth thresholds based on the real-time bandwidth data of computer devices within the same secondary group. Based on the dynamic bandwidth thresholds, monitor the bandwidth of computer devices within the same secondary group in real time and conduct network security judgment, identify network security abnormal computer devices and generate anomaly signals.

[0107] S4. Analyze the network bandwidth change data of computer devices within the same secondary group to obtain a reference bandwidth change curve. Based on the reference bandwidth change curve, identify potential network security anomalies for computer devices within the same secondary group and generate anomaly signals.

[0108] S5. Based on the abnormal signals received from the computer devices under the enterprise, an alarm signal is issued to display the abnormal computer devices under the enterprise, so as to remind the duty personnel to comprehensively manage the abnormal computers.

[0109] In the embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation; the modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the method of this embodiment.

[0110] The above embodiments are only used to illustrate the technical methods of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical methods of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical methods of the present invention.

Claims

1. A computer intelligent service management system based on network big data, characterized by: It includes a computer operation data acquisition module, a computer equipment grouping module, a bandwidth threshold generation module, a potential anomaly identification module, an anomaly reporting and computer management module; The computer operation data collection module collects real-time bandwidth data of the computer equipment under the jurisdiction of the enterprise during use based on the SNMP protocol, collects historical bandwidth big data of the computer equipment under the jurisdiction of the enterprise and the affiliated departments of the computer equipment under the jurisdiction, and transmits the data to the subsequent modules; The computer equipment grouping module creates archives and groups computer equipment under the organizational structure based on InfluxDB based on the enterprise architecture, and creates computer equipment archives in each group. The archives include computer equipment number, affiliated department, current computer equipment historical bandwidth big data, current computer equipment real-time collected bandwidth data, collection time, and secondary grouping through the subordinate computer equipment historical bandwidth big data; The bandwidth threshold generation module generates a dynamic bandwidth threshold based on the real-time bandwidth data of computer devices in the same secondary group, performs real-time monitoring and network security determination on the bandwidth of computer devices in the same secondary group based on the dynamic bandwidth threshold, identifies abnormal computer devices in network security and generates abnormal signals; The potential anomaly identification module analyzes the network bandwidth change data of computer devices in the same secondary group to obtain a reference bandwidth change curve, identifies potential network security anomalies of computer devices in the same secondary group based on the reference bandwidth change curve, and generates an anomaly signal; The abnormality reporting and computer management module includes an audible and visual alarm, which sends out an alarm signal in the form of sound, light, and vibration based on the received abnormal signal to remind the on-duty personnel to carry out comprehensive management of the abnormal computer.

2. According to claim 1, a computer intelligent service management system based on network big data is characterized in that: The computer equipment grouping module creates archives and groups computer equipment under the organizational structure based on InfluxDB based on the enterprise architecture, and creates computer equipment archives in each group. The archives include computer equipment number, affiliated department, current computer equipment historical bandwidth big data, current computer equipment real-time collected bandwidth data, and collection time. Secondary grouping is performed through the historical bandwidth big data of subordinate computer equipment, including the following steps: Establish computer equipment files under the jurisdiction respectively, group the computer equipment files into the first level based on the departments to which the computer equipment belongs, and classify the computer equipment of the same department into the same department group. The computer equipment file in each group contains the equipment number and department to which it belongs. Collect the historical bandwidth big data of computer equipment in each department group, use K-means clustering to perform secondary grouping on the computer equipment in the primary group based on the historical bandwidth big data, and record the real-time bandwidth data into the computer equipment archive.

3. According to claim 2, a computer intelligent service management system based on network big data is characterized in that: The historical bandwidth big data of computer devices in each department group is collected, and K-means clustering is used to perform secondary grouping of computer devices in the primary group based on the historical bandwidth big data. The specific steps are as follows: Collect the historical bandwidth big data of each computer device in the first-level group as the feature vector, including the average bandwidth of the computer device, the peak bandwidth of the computer device, and the bandwidth standard deviation, and establish a multidimensional vector x i ={x i1 ,x i2 ,x i3 }, where x i1 、x i2 、x i3 They represent the average bandwidth, peak bandwidth, and standard deviation of bandwidth of the ith computer device, respectively; The computer devices in the first-level group are divided into low, medium and high bandwidth usage intensity, and the cluster number υ is set to 3; Randomly select the feature vectors of F computer devices from the data set as the initial centroids μ1, μ2, ..., μ F , for each computer device’s feature vector x i , based on the Euclidean distance algorithm, it is calculated with each centroid μ F distance, place the computer device x i Assign to the cluster C corresponding to the nearest centroid F In the example, for each cluster C F , recalculate its center of mass μ F , and its algorithm formula is: Among them, μ Fj The value of the centroid of the Fth cluster in the jth dimension, |C F | represents sample C in the Fth cluster F Quantity, x ij Represents the value of the i-th computer device in the j-th dimension; Calculate the sum of the Euclidean distances D between the new and old centroids and compare them with the convergence threshold η: When D < η, it means that the current algorithm converges and the clustering process ends. All computer devices in each first-level group are divided into different clusters to complete the second-level grouping. The names of each group are low-bandwidth group, medium-bandwidth group, and high-bandwidth group. When D ≥ η, it means that the current algorithm has not converged, and the Euclidean distance algorithm is used to calculate the distance between each centroid μ F distance, place the computer device x i Assign to the cluster C corresponding to the nearest centroid F The algorithm continues to recalculate the centroid and compare the convergence threshold until the algorithm converges or reaches the maximum number of iterations N.

4. According to claim 2, a computer intelligent service management system based on network big data is characterized in that: The bandwidth threshold generation module generates a dynamic bandwidth threshold based on the real-time bandwidth data of computer devices in the same secondary group, performs real-time monitoring and network security determination on the bandwidth of computer devices in the same secondary group based on the dynamic bandwidth threshold, identifies abnormal computer devices in network security and generates abnormal signals, and the specific steps are as follows: For the same secondary group, including low bandwidth group, medium bandwidth group and high bandwidth group, real-time data extraction is performed on the computer equipment files in each secondary group, the real-time bandwidth data of different computer equipment under the current group is obtained, and a real-time dynamic bandwidth threshold is generated; Based on the real-time dynamic bandwidth threshold, the bandwidth of computer devices in the same secondary group is monitored in real time and network security is determined. Abnormal computer devices with network security errors are identified and abnormal signals are generated, which are then sent to the abnormal reporting and computer management module.

5. According to claim 4, a computer intelligent service management system based on network big data is characterized in that: For the same secondary group, including the low bandwidth group, the medium bandwidth group, and the high bandwidth group, real-time data extraction is performed on the computer device files in each secondary group, the real-time bandwidth data of different computer devices in the current group is obtained, and a real-time dynamic bandwidth threshold is generated. The specific steps are: At each time t, collect the real-time bandwidth data of each computer device in the secondary group Where i represents the computer device number in group K, e represents the data collection time in time period t, and the mean value ε of the bandwidth data of group K in time period t is calculated. K , and its algorithm formula is: Where N is the number of computer devices in group K, M is the number of data collection points in time period t, based on the mean ε K Calculate the standard deviation σ K , obtain the real-time dynamic bandwidth threshold θ K =ε K +kσ K .

6. According to claim 5, a computer intelligent service management system based on network big data is characterized in that: Based on the real-time dynamic bandwidth threshold, the bandwidth of computer devices in the same secondary group is monitored in real time and network security is determined, computer devices with abnormal network security are identified and abnormal signals are generated, and the abnormal signals are sent to the abnormal reporting and computer management module. The specific steps are as follows: In the next time period t, continue to collect real-time bandwidth data of computer devices in group K Represents the real-time bandwidth of computer device i at the new time l, and combines the real-time dynamic bandwidth threshold to determine the network security anomaly of computer devices in the current group. The steps are: when When , it means that there is a network security anomaly in computer device i, the device number is extracted from the computer device file, and the anomaly signal is transmitted to the anomaly reporting and computer management module; when When the real-time bandwidth data of each computer device in the secondary group is collected, based on The real-time dynamic bandwidth threshold in the next time period t is calculated, and based on the real-time dynamic bandwidth threshold in the next time period t, network security anomaly determination is performed on the real-time bandwidth data in the next time period t.

7. According to claim 1, a computer intelligent service management system based on network big data is characterized in that: The potential anomaly identification module analyzes the network bandwidth change data of computer devices in the same secondary group to obtain a reference bandwidth change curve, identifies potential network security anomalies of computer devices in the same secondary group based on the reference bandwidth change curve, and generates an abnormal signal, and the specific steps are as follows: In each time interval [t0, t1], based on the computer equipment files in the same secondary group, the real-time bandwidth data during the equipment operation is extracted, and the bandwidth change curves of different computer equipment in the group are calculated respectively. The specific steps are as follows: For the same secondary group G, the computer equipment in the group is H p , p = 1, 2, 3, ..., n, where n is the number of computer devices in the current group. In the time interval [t0, t1], the number of computer devices H p At time t ε The real-time bandwidth data under B p (t ε ), at time t ε The horizontal axis is the real-time bandwidth data B p (t ε ) is the vertical axis, and the bandwidth change curve of each device is drawn y=B p (t ε ); Based on the bandwidth change curves of different computer devices in the group, at the end of each time interval [t0, t1], the bandwidth change curves under the current time interval [t0, t1] are compared for similarity to identify potential abnormal computer devices and determine network security anomalies.

8. A computer intelligent service management system based on network big data according to claim 7, characterized in that: Based on the bandwidth change curves of different computer devices in the group, at the end of each time interval [t0, t1], the bandwidth change curves under the current time interval [t0, t1] are compared for similarity, potential abnormal computer devices are identified, and network security abnormalities are determined. The specific steps are: By using the Euclidean distance method, calculate the device H p With H q The Euclidean distance d of the bandwidth variation curve in the time interval [t0, t1] pq , and its algorithm formula is: For each device H in the group p , calculate the Euclidean distance between it and other computer devices respectively, and judge the Euclidean distance based on the similarity distance threshold θ. When the Euclidean distance is greater than θ, it means that the bandwidth change curves of the two computer devices are not similar; When the device H p With the current group When the results of the Euclidean distance judgment of the computer devices are all greater than θ, the device H p A computer device marked as potentially abnormal indicates the existence of a network security anomaly. The device number is extracted from the computer device file and the abnormal signal is transmitted to the abnormal reporting and computer management module.

9. A computer intelligent service management method based on network big data, characterized in that: The method adopts the computer intelligent service management system based on network big data as described in any one of claims 1 to 8, comprising the following steps: S1. Collect the real-time bandwidth data of the computer equipment under the jurisdiction of the enterprise during use based on the SNMP protocol, collect the historical bandwidth big data of the computer equipment under the jurisdiction of the enterprise and the affiliated departments of the computer equipment under the jurisdiction, and establish archives and groups for the computer equipment under the current enterprise organizational structure based on InfluxDB according to the enterprise architecture; S2. Establish a computer equipment file in each group. The file includes the computer equipment number, affiliated department, current computer equipment historical bandwidth big data, current computer equipment real-time collected bandwidth data, and collection time. Secondary grouping is performed based on the historical bandwidth big data of the computer equipment under jurisdiction; S3. Generate a dynamic bandwidth threshold based on the real-time bandwidth data of computer devices in the same secondary group, perform real-time monitoring and network security determination on the bandwidth of computer devices in the same secondary group based on the dynamic bandwidth threshold, identify abnormal computer devices in network security and generate abnormal signals; S4. Analyze and obtain a reference bandwidth change curve for the network bandwidth change data of computer devices in the same secondary group, identify potential network security anomalies of computer devices in the same secondary group based on the reference bandwidth change curve, and generate an abnormal signal; S5. Based on the abnormal signals received from the computer equipment under the jurisdiction of the enterprise, an alarm signal is issued to display the abnormal computer equipment under the jurisdiction of the enterprise to remind the on-duty personnel to conduct comprehensive management of the abnormal computers.

Citation Information

Patent Citations

  • Intelligent network security system and method based on big data analysis

    CN117254973A

  • Network fault analysis method and system

    CN118282870A

  • Network security situation real-time sensing and co-processing method

    CN119652684A

  • Clustering and Outlier Detection in Anomaly and Causation Detection for Computing Environments

    US20180316707A1