Service network flow analysis system and method
By designing a business network traffic analysis system, real-time collection, processing and analysis of traffic data, dynamically generate traffic thresholds and triggering alarms, the problem of low troubleshooting efficiency in the existing technology is solved, and the second-level alarm and rapid fault location are achieved, reducing the risk of network attacks.
Patent Information
- Application Number
- CN202510651864.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-06-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing technology is difficult to monitor and alert service network traffic failures in real time, resulting in low troubleshooting efficiency and difficulty in responding to network failures in a timely manner. Especially when there are abnormalities in key links, it affects the normal use and security of the TV network system.
A business network traffic analysis system is designed, including traffic acquisition module, data processing module, data storage module, baseline warning module, alarm module and report query module. The SNMP protocol collects traffic data, cleans, aggregates and analyzes data, generates traffic indicators, and dynamically generates traffic thresholds based on historical data, compares the current traffic in real time, triggers alarms and performs fault locations.
It realizes second-level alarms for failures, improves the response speed of critical link abnormalities, reduces the risk of network attacks and network security threats, and promotes the transformation of operation and maintenance mode to active and refined.
Smart Images

Figure CN120166027A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic analysis, and particularly to a service network traffic analysis system and method. Background Art
[0002] The monitoring of service network traffic is a key task of the television network department. It can identify system failures by monitoring traffic in real time and dynamically allocate bandwidth resources according to traffic. In particular, when the television network system is under network attacks, link switches, or abnormal traffic, it will lead to a sudden increase in traffic; when there are routing losses, link failures, or equipment failures, it will lead to a sudden drop in traffic. Therefore, monitoring the sudden increase or decrease in service network traffic is of great significance for the normal operation of the television network system.
[0003] Currently, the industry can only monitor service network traffic and lacks alarms for faulty networks. The system can only identify sudden increases or decreases in traffic and cannot locate faults. It is necessary to use manual inspections to troubleshoot faults, and the troubleshooting efficiency is low, making it difficult to respond to network faults in a timely manner. In particular, when key links are abnormal, it will affect the normal use and experience of the entire television network system. In addition, in the event of network security threats, operation and maintenance personnel often notice and repair problems only after a long time of the occurrence of faults. The system is at high risk of being attacked by the network, and the response to network security threats lags. Summary of the Invention
[0004] Based on this, it is necessary to provide a service network traffic analysis system and method that can perform real-time fault alarms, improve the response speed to key link abnormalities, and reduce the risk of network attacks in view of the above deficiencies.
[0005] A service network traffic analysis system includes: A traffic collection module, configured to collect traffic data from the router / switch ports of key links through the SNMP protocol; A data processing module, configured to clean, aggregate, and analyze the collected traffic data to generate traffic metrics; A data storage module, configured to store historical data, baseline data, user information, and alarm records; A baseline warning module, configured to dynamically generate traffic thresholds for working days / holidays according to historical data, compare the current traffic with the traffic thresholds in real time, and trigger an alarm when the current traffic reaches a preset value; An alarm module, configured to issue an alarm and locate a fault when detecting traffic abnormalities or port status abnormalities; A report query module, configured to provide a multi-dimensional report query interface and analyze historical data.
[0006] In one embodiment, the business network traffic analysis system further includes a monitoring point construction module, and the monitoring point construction module includes: A topology discovery module, configured to discover devices and their connection relationships in the network through the network topology structure; A key link identification module, configured to determine a number of key links according to preset conditions to form a plurality of monitoring points; A monitoring point deployment module, configured to configure SNMP sending on routers / switches of key links; An optimization and adjustment module, configured to adjust monitoring points according to network topology changes.
[0007] In one embodiment, the preset conditions include service importance and traffic load; the key link identification module determines at least 800 key links according to the preset conditions.
[0008] In one embodiment, the baseline warning module generates upper and lower percentage baselines of the traffic threshold for the current time period according to historical data, and compares the current traffic. When the current traffic exceeds the upper and lower percentage of the threshold by n%, the warning module issues a warning; n is a number between 10 and 30; the warning module issues a warning when the current traffic reaches a preset value continuously for multiple times.
[0009] In one embodiment, the baseline warning module analyzes historical traffic data at 0:00 every day, identifies and calculates traffic models for working days and holidays according to the date, and saves the working day calculation model and the holiday calculation model as baselines respectively.
[0010] In one embodiment, the traffic metrics include traffic utilization rate and abnormal fluctuations; the warning module issues a warning in at least one of the ways of sound, light, email, or text message.
[0011] In one embodiment, the business network traffic analysis system further includes a data analysis module respectively connected to the data storage module and the report query module, and the data analysis module is configured to analyze the stored data and generate reports.
[0012] The present invention also discloses a business network traffic analysis method, which is implemented by using the above-mentioned business network traffic analysis system, and includes the following steps: S1. Collect traffic data from router / switch ports of key links through the SNMP protocol; S2. Clean, aggregate, and analyze the collected traffic data to generate traffic metrics; S3. Store historical data, baseline data, user information, and warning records; S4. Dynamically generate traffic thresholds for working days / holidays based on historical data, compare the current traffic with the traffic threshold in real time, and trigger an alarm when the current traffic reaches a preset value; S5. When traffic anomalies or port status anomalies are detected, issue an alarm and perform fault location; S6. Generate multi-dimensional reports and historical data analysis results.
[0013] In one embodiment, before step S1, it further includes: S01. Discover the devices in the network and their connection relationships through the network topology; S02. Determine several key links according to preset conditions to form multiple monitoring points; S03. Configure SNMP transmission on the routers / switches of the key links; S04. Dynamically adjust the monitoring points according to network topology changes.
[0014] In one embodiment, in step S5, the fault location includes: S51. When the traffic of a certain key link is abnormal, issue an alarm; S52. View the alarm details and confirm the difference between the actual value and the baseline value of the traffic data; S53. Analyze whether the associated key links trigger alarms, and combine whether the link group alarms trigger alarms to judge the reasons for traffic surges or drops; S54. The operation and maintenance personnel perform repairs according to the analysis results.
[0015] Implementing the business network traffic analysis system and method of the present invention, by collecting key link traffic data, and dynamically generating traffic thresholds for working days / holidays by the baseline warning module according to historical data, comparing the current traffic with the traffic threshold in real time, and triggering an alarm when the current traffic reaches a preset value, it can achieve second-level alarms for faults, promote the transformation of the operation and maintenance mode towards automation and refinement, improve the response speed of key link anomalies, and provide a data basis for early warning; by analyzing alarm records, faults can be located, so that operation and maintenance personnel can quickly respond to traffic anomalies and quickly troubleshoot faults in abnormal links, reducing the risks of network attacks and network security threats. Description of the Drawings
[0016] Figure 1 It is a schematic structural diagram of the business network traffic analysis system in an embodiment of the present invention. Detailed Embodiments
[0017] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings. Many specific details are set forth in the following description to facilitate a thorough understanding of the present invention. However, the present invention can be implemented in many other ways different from those described herein, and those skilled in the art can make similar improvements without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0018] Embodiment 1 Please refer to Figure 1 , the present invention discloses a business network traffic analysis system that can perform real-time fault warnings, improve the abnormal response speed of critical links, and reduce the risk of network attacks. The business network traffic analysis system includes a traffic collection module 100, a data processing module 200, a data storage module 300, a baseline warning module 400, an alarm module 500, and a report query module 600. Among them, the traffic collection module 100 is used to collect traffic data from the router / switch ports of critical links through the SNMP protocol. The SNMP protocol has good compatibility, can be applied to most network devices, has a small overhead, a light weight, is suitable for real-time monitoring, and can support multiple operations including GET, SET, and TRAP, facilitating data collection and device management. While the router / switch as a network device sends traffic data to the traffic collection module 100 through the SNMP protocol, it also synchronously sends device status information. The data processing module 200 is used to clean, aggregate, and analyze the collected traffic data to generate traffic metrics, so as to provide a basis for the baseline warning module 400 to compare and analyze the traffic metric data. In this embodiment, the traffic metrics include traffic utilization rate and abnormal fluctuations. The data storage module 300 is used to store historical data (historical traffic data), baseline data, user information, and alarm records. In this embodiment, the data storage module 300 can be a database. The baseline warning module 400 is used to dynamically generate traffic thresholds for weekdays / holidays based on historical data, compare the current traffic with the traffic thresholds in real time, and trigger an alarm when the current traffic reaches a preset value. The alarm module 500 is used to issue an alarm and perform fault location when traffic anomalies or port status anomalies are detected. The report query module 600 is used to provide a multi-dimensional report query interface and analyze historical data.
[0019] In this embodiment, the network device (router / switch) generates traffic statistical information based on the SNMP protocol, aggregates it, and sends it to the traffic collection module 100. The traffic collection module 100 can be a collector such as Cisco Stealthwatch or Elastic Flow, or other data collectors.
[0020] The data processing module 200 cleans the traffic data to ensure data quality. Specifically, the cleaning of traffic data includes removing duplicates by forming a unique identifier with the timestamp and device ID to eliminate duplicate data; when traffic data is missing, if the data missing rate is low (less than 3 consecutive missing data points), the missing values can be filled with the mean of the previous and next time points, and if the data missing rate is high (more than 3 consecutive missing data points), the missing data can be directly removed; detecting outliers through statistical methods such as Z-score (>3σ is abnormal) or IQR (exceeding 1.5 times the interquartile range), and filtering negative traffic and values exceeding the physical bandwidth limit (such as traffic on a 10G port > 10Gbps); finally, unifying the timestamp format (such as UTC time zone) and performing unit conversion (such as converting MB to GB) to obtain the cleaned traffic data in a standardized format.
[0021] The data processing module 200 converts fine-grained data into macro indicators readable by the business through the aggregation of traffic data. The aggregation of traffic data includes generating hourly / daily traffic sums, means, and peaks on demand, and calculating the moving average traffic over a past period; grouping and counting by device, region, and business type (such as the total incoming traffic of IDC computer room A), and performing multi-dimensional cross-analysis on traffic with time and region combinations; performing pre-calculation of key indicators. For example, calculating the traffic utilization rate through the formula: traffic utilization rate = (actual traffic / bandwidth limit) × 100%, and marking sudden increases and decreases according to the traffic month-on-month change exceeding ±30%.
[0022] The analysis of traffic data by the data processing module 200 includes utilization analysis and abnormal fluctuation detection. Specifically, taking the mean of the same time period in the past (such as 30 days) as the expected value, predicting future traffic through the Holt-Winters algorithm, and setting a confidence interval (such as 95%) to achieve baseline modeling. Through TopN analysis, finding ports or links with a utilization rate continuously exceeding 85%, and combining with business logs (such as a surge in video service traffic resulting in a high utilization rate) to achieve utilization analysis. Detecting abnormal fluctuations through the standard deviation method or the ratio of year-on-year / month-on-month, or through machine learning methods of supervised models or unsupervised models, or through DDoS attack characteristics (a large amount of SYN Flood traffic to the same target IP in a short time) or cycle disruption detection (the originally stable daily cycle traffic suddenly disappears) for pattern matching.
[0023] In one embodiment, the baseline warning module 400 generates the upper and lower percentage of the traffic threshold baseline for the current time period based on historical data, compares the current traffic, and when the current traffic exceeds the upper and lower percentage of the threshold by n%, the warning module 500 issues a warning; n is a number between 10 and 30. The upper and lower percentage of the traffic threshold baseline refers to in network security or performance monitoring, establishing a baseline value (Baseline) through statistical analysis of historical traffic data, and setting the range of allowable traffic fluctuations (such as ±10%, ±20%, etc.), and triggering a warning or action when exceeding this range. Among them, the baseline is the average traffic value or typical mode of the network in the normal business state (such as the average bandwidth per hour, the number of requests per second). In this embodiment, since the corresponding traffic thresholds are set separately according to weekdays / holidays, therefore, the baseline is actually a dynamic baseline that is dynamically adjusted based on the time period. In this embodiment, assuming the baseline is 100 Mbps, n is 20, and the upper and lower percentage is 20%, then the normal range of traffic is 80 Mbps to 120 Mbps, and when exceeding this range, a warning is triggered (such as a DDoS attack or a link failure occurs).
[0024] Further, in one embodiment, the baseline warning module 400 analyzes historical traffic data (such as historical traffic data within the past m days) at 00:00 every day, identifies and calculates the traffic models for weekdays and holidays according to the date, and saves the weekday calculation model and the holiday calculation model as baselines respectively. In this way, the dynamic generation of the traffic threshold (baseline + upper and lower percentage) can be realized, adapting to the traffic changes in different time periods, and realizing intelligent baseline warning; at the same time, the traffic data is transmitted through the SNMP protocol. The SNMP protocol can provide real-time and accurate traffic data, and the minimum dimension can collect traffic data once every 10 s, realizing high-precision and high-density collection of data, and improving the speed of responding to faults or network anomalies. Compare the current traffic value (actual traffic value) with the baseline threshold, and trigger an alarm exception when the current traffic value exceeds the baseline threshold to accurately identify scenarios such as abnormal traffic fluctuations and abnormal port states, facilitating the operation and maintenance personnel to handle them in a timely manner.
[0025] In addition, in this embodiment, through the baseline warning module 400 and SNMP protocol data collection, at the moment when the traffic is collected into the system, after comparing the actual value with the baseline threshold, if it exceeds the threshold, an alarm will be triggered immediately. The calculation time of the baseline warning module 400 can reach the second level. When the baseline threshold is triggered once, an alarm will be triggered at the second level, that is, the second-level alarm is realized. In other embodiments, the warning module 500 issues a warning when the current traffic reaches the preset value continuously for multiple times. For example, after the current traffic triggers the baseline threshold continuously 5 times through the calculation and processing of the baseline warning module 400, the warning module 500 issues a warning, reducing false alarms caused by occasional traffic surges and improving the reliability of the system warning.
[0026] The alarm module 500 is used to output alarm signals externally to prompt the operation and maintenance personnel. In this embodiment, the alarm module 500 issues alarms in at least one of the ways of sound, light, email, or text message. Additionally, in this embodiment, while outputting the alarm signal, the alarm module 500 also locates the fault or abnormal position and synchronously sends the location information externally along with the alarm information, so that the operation and maintenance personnel can promptly troubleshoot and maintain the fault point. In this embodiment, when the traffic of a certain critical link is abnormal, the alarm module 500 issues an alarm; the operation and maintenance personnel can view the alarm details through the system home page or alarm records to check the difference between the actual value and the baseline value of the traffic data; then, by analyzing whether the associated links trigger alarms and combining whether the link group alarms are triggered, a comparative analysis is performed on multiple monitoring points to determine the cause of the traffic sudden increase or decrease fault (for example, whether it is a positioning device fault or a partial port fault, etc.); finally, the operation and maintenance personnel repair according to the analysis results.
[0027] The report query module 600 can provide multiple query and analysis dimensions externally, so that the operation and maintenance personnel can obtain the corresponding traffic information according to their needs. Specifically, the multi-dimensional query includes queries in multiple aspects such as time dimension, device dimension, link dimension, link group dimension, and service dimension. Among them, the time dimension includes querying traffic data by time periods such as minutes, hours, days, and months; the device dimension includes querying traffic data by devices such as routers and switches; the link dimension includes querying traffic data by all critical links; the link group dimension includes dividing all critical links into multiple groups to query traffic data, such as Tencent CDN, Baiyunshan CDN, Alibaba CDN, etc.; the service dimension includes querying traffic data by services such as export, backbone network, 5G / fixed phone, government and enterprise, technology department, State Grid, Baolongshan, etc. Additionally, the report query module 600 can also support the backtracking of annual historical data and the comparison of cross-service traffic trends.
[0028] Furthermore, the business network traffic analysis system further includes a data analysis module 700 respectively connected to the data storage module 300 and the report query module 600. The data analysis module 700 is used to analyze the stored data and generate reports. After the data analysis module 700 analyzes the stored data and generates reports, it sends the reports to the report query module 600 so that the operation and maintenance personnel can query the relevant reports. Additionally, the business network traffic analysis system further includes a display device for displaying report queries and alarm information. The display device can be a PC, a mobile intelligent device, or other display devices, and users can query the relevant data through the Web interface of the PC or mobile intelligent device or through the API interface.
[0029] In a working process of a business network traffic analysis system, first, the traffic collection module 100 collects traffic data from a port (such as port 1) of a network device (such as router A) through the SNMP protocol; the data processing module 200 cleans and aggregates the collected data to calculate the traffic utilization rate of port 1; subsequently, the historical traffic and current traffic of port 1 are stored in the data storage module 300 (database); the baseline warning module 400 generates the upper and lower percentage of the traffic threshold baseline for the current time period based on the historical data and compares the current traffic; if the current traffic exceeds the upper and lower percentage n% (such as 20%) of the threshold, the alarm module 500 notifies the operation and maintenance personnel through audible and visual alarms, and the operation and maintenance personnel view the historical traffic data of port 1 through the report query module 600 to analyze the cause of the anomaly.
[0030] In addition, in an embodiment, the business network traffic analysis system further includes a monitoring point construction module 800. The monitoring point construction module 800 is used to construct a traffic monitoring system and build a system composed of multiple traffic monitoring points to comprehensively cover each key link, so as to provide a comprehensive and reliable traffic data source for network traffic analysis. The monitoring point construction module 800 includes a topology discovery module, a key link identification module, a monitoring point deployment module, and an optimization and adjustment module. The topology discovery module is used to discover the devices and their connection relationships in the network through the network topology structure; the key link identification module is used to determine several key links according to preset conditions to form multiple monitoring points. In this embodiment, the preset conditions include business importance and traffic load, that is, the key link identification module determines several key links (including exits, metropolitan area networks, and 5G / landline services, etc.) with higher business importance and larger traffic load according to business importance and traffic load. Further, the key link identification module determines at least 800 key links according to the preset conditions. Preferably, in this embodiment, the number of key links is 800, and the 800 key links are further divided into 120 link groups to quickly locate faults when a fault occurs. The monitoring point deployment module is used to configure SNMP transmission on the routers / switches (i.e., the monitored devices) of the key links to ensure that the traffic data on the key links can be collected. SNMP transmission refers to the standardized process of transmitting management information between network devices and management stations through the SNMP protocol. The optimization and adjustment module is used to adjust the monitoring points according to the change of the network topology so that the monitored traffic data is always the traffic data of the key links and ensure that the actual connection relationship between devices corresponds to the device connection relationship in the constructed traffic monitoring system. In this embodiment, the optimization and adjustment module is used to provide a medium or module for operators to manually adjust the monitoring points. In actual use, it can also optimize the algorithm and dynamically adjust the monitoring points according to the change of the network topology through an automatic adjustment method.
[0031] The above business network traffic analysis system collects traffic data of key links, and the baseline warning module 400 dynamically generates traffic thresholds for weekdays / holidays based on historical data, compares the current traffic with the traffic threshold in real time, triggers an alarm when the current traffic reaches the preset value, can achieve second-level alarm for faults, promotes the transformation of the operation and maintenance mode to automation and refinement, improves the response speed of key link anomalies, and provides a data basis for early warning; faults can be located by analyzing alarm records, so that operation and maintenance personnel can quickly respond and quickly troubleshoot abnormal links when traffic is abnormal, reducing the risk of network attacks and network security threats.
[0032] Embodiment 2 The present invention also discloses a business network traffic analysis method, which is implemented by using the above business network traffic analysis system. The business network traffic analysis method includes the following steps: S1. Collect traffic data from the router / switch ports of key links through the SNMP protocol. The router / switch generates traffic statistics based on the SNMP protocol, and at the same time sends traffic data and device status information. The collection of traffic data can be implemented by collectors such as Cisco Stealthwatch or Elastic Flow, or can be implemented by other data collectors.
[0033] Before step S1, it also includes constructing a traffic monitoring system, building a system composed of multiple traffic monitoring points to comprehensively cover each key link, so as to provide a comprehensive and reliable traffic data source for network traffic analysis. Specifically, it includes: S01. Discover the devices and their connection relationships in the network through the network topology structure.
[0034] S02. Determine several key links according to preset conditions to form multiple monitoring points. In this embodiment, the preset conditions include service importance and traffic load, that is, the key link identification module determines several key links with higher service importance and larger traffic load (including exits, metropolitan area networks, and 5G / fixed-line services, etc.) according to service importance and traffic load. Further, the key link identification module determines at least 800 key links according to the preset conditions. Preferably, in this embodiment, there are 800 key links, and the 800 key links are further divided into 120 link groups to quickly locate faults when a fault occurs.
[0035] S03. Configure SNMP sending on the routers / switches of key links to ensure that traffic data on key links can be collected. SNMP sending refers to the standardized process of transmitting management information between network devices and management stations through the SNMP protocol.
[0036] S04. Dynamically adjust the monitoring points according to the changes in the network topology, so that the monitored traffic data is always the traffic data of the critical link, and ensure that the actual connection relationship between devices corresponds to the device connection relationship in the constructed traffic monitoring system.
[0037] S2. Clean, aggregate, and analyze the collected traffic data to generate traffic metrics, including traffic utilization rate and abnormal fluctuations.
[0038] In this embodiment, the data quality is ensured by cleaning the traffic data. The cleaning of the traffic data includes removing duplicate data by using a unique identifier composed of a timestamp and a device ID; when traffic data is missing, if the data missing rate is low (less than 3 consecutive missing data points), the missing values can be filled by the mean of the previous and next time points, and if the data missing rate is high (more than 3 consecutive missing data points), the missing data can be directly removed; detecting outliers by statistical methods such as Z-score (>3σ is abnormal) or IQR (exceeding 1.5 times the interquartile range), and filtering negative traffic and values exceeding the physical bandwidth limit (such as traffic on a 10G port > 10Gbps); finally, unifying the timestamp format (such as UTC time zone) and performing unit conversion (such as converting MB to GB) to obtain the standardized and cleaned traffic data.
[0039] The aggregation of traffic data converts fine-grained data into macro metrics readable by the business. The aggregation of traffic data includes generating hourly / daily traffic sums, means, and peaks on demand, and statistically calculating the moving average traffic over a past period; grouping and counting by device, region, and business type (such as the total incoming traffic of IDC computer room A), and performing multi-dimensional cross-analysis on the traffic of the time and region combination; performing pre-calculation of key metrics. For example, calculate the traffic utilization rate through the formula: traffic utilization rate = (actual traffic / bandwidth limit) × 100%, and mark sudden increases and decreases according to the traffic month-on-month change exceeding ±30%.
[0040] The analysis of traffic data includes utilization analysis and abnormal fluctuation detection. Specifically, take the mean value of the same time period in the past period (such as 30 days) as the expected value, predict future traffic through the Holt-Winters algorithm, and set the confidence interval (such as 95%) to achieve baseline modeling. Through TopN analysis, find the ports or links with a continuous utilization rate exceeding 85%, and combine with business logs (such as a surge in video service traffic resulting in high utilization) to achieve the analysis of utilization. Detect abnormal fluctuations by means of the standard deviation method, the ratio of year-on-year / month-on-month, or by machine learning methods of supervised or unsupervised models, or by means of DDoS attack characteristics (a large amount of SYN Flood traffic to the same target IP in a short time) or cycle disruption detection (the originally stable daily cycle traffic suddenly disappears) for pattern matching.
[0041] S3. Store historical data, baseline data, user information, and alarm records. In this embodiment, the historical data, baseline data, user information, and alarm records are stored in a database. By storing data such as historical data, baseline data, user information, and alarm records, conditions are provided for the calculation and analysis of traffic values.
[0042] S4. Dynamically generate traffic thresholds for weekdays / holidays based on historical data, compare the current traffic with the traffic threshold in real time, and trigger an alarm when the current traffic reaches a preset value.
[0043] Specifically, step S4 includes: generating the upper and lower percentage of the traffic threshold baseline for the current time period based on historical data, comparing the current traffic, and when the current traffic exceeds the upper and lower percentage n% of the threshold, the alarm module 500 issues an alarm; n is a number between 10 and 30. The upper and lower percentage of the traffic threshold baseline refers to in network security or performance monitoring, establishing a baseline value (Baseline) through statistical analysis of historical traffic data, and setting the range of allowable traffic fluctuations (such as ±10%, ±20%, etc.). When the range is exceeded, an alarm or action is triggered. Among them, the baseline is the average traffic value or typical mode of the network under normal business conditions (such as the average bandwidth per hour, the number of requests per second). In this embodiment, since the traffic thresholds are set separately for weekdays / holidays, the baseline is actually a dynamic baseline that is dynamically adjusted based on the time period. In this embodiment, assuming the baseline is 100Mbps, n is 20, and the upper and lower percentage is 20%, then the normal range of traffic is 80Mbps to 120Mbps. When this range is exceeded, an alarm is triggered (such as a DDoS attack or a link failure occurs).
[0044] Furthermore, analyze the historical traffic data (such as the historical traffic data within the past m days) at 00:00 every day, identify and calculate the traffic models for weekdays and holidays based on the date, and save the weekday calculation model and the holiday calculation model as baselines respectively. In this way, the baseline is updated every 24h, and the update can be completed within 1min. In this way, the dynamic generation of traffic thresholds (baseline + upper and lower percentage) can be realized, adapting to traffic changes in different time periods, and realizing intelligent baseline warning. At the same time, transmit traffic data through the SNMP protocol. The SNMP protocol can provide real-time and accurate traffic data, and the minimum dimension can collect traffic data once every 10s, realizing high-precision and high-density collection of data, and improving the speed of responding to faults or network anomalies. Compare the current traffic value (actual traffic value) with the baseline threshold, and trigger an alarm anomaly when the current traffic value exceeds the baseline threshold to accurately identify scenarios such as abnormal traffic fluctuations and abnormal port states, facilitating timely handling by operation and maintenance personnel.
[0045] S5. When traffic anomalies or port status anomalies are detected, alarms are issued and fault location is performed.
[0046] Specifically, when the baseline threshold is triggered once, an alarm will be issued, which will be triggered at the second level, that is, second-level alarms are achieved. Further, when the current traffic reaches the preset value continuously for multiple times, an alarm is issued. For example, an alarm is only issued after the current traffic triggers the baseline threshold 5 times continuously, reducing false alarms caused by occasional sudden traffic increases and improving the reliability of alarms. In this embodiment, the alarm can be issued in at least one of the ways of sound, light, email, or text message to meet the working habits of different users.
[0047] In step S5, fault location includes: S51. When the traffic of a certain critical link is abnormal, an alarm is issued.
[0048] S52. View the alarm details and confirm the difference between the actual value and the baseline value of the traffic data.
[0049] S53. Analyze whether the associated critical links trigger alarms, and compare and analyze multiple monitoring points in combination with whether the link group alarms are triggered to determine the cause of traffic surges or drops (for example, whether it is a positioning device failure or a partial port failure, etc.).
[0050] S54. The operation and maintenance personnel perform repairs according to the analysis results.
[0051] S6. Generate multi-dimensional reports and historical data analysis results.
[0052] The multi-dimensional reports include generating corresponding reports in multiple aspects such as time dimension, device dimension, link dimension, link group dimension, and business dimension. Among them, the time dimension includes querying traffic data by time periods such as minutes, hours, days, and months; the device dimension includes querying traffic data by devices such as routers and switches; the link dimension includes querying traffic data by all critical links; the link group dimension includes dividing all critical links into multiple groups to query traffic data, such as Tencent CDN, Baiyunshan CDN, Alibaba CDN, etc.; the business dimension includes querying traffic data by services such as export, backbone network, 5G / fixed phone, government and enterprise, technology department, state grid, Baolongshan, etc. Historical data analysis includes annual historical data backtracking and cross-service traffic trend comparison, etc.
[0053] During a business network traffic analysis process, traffic data is first collected from a port (such as port 1) of a network device (such as router A) through the SNMP protocol; after cleaning and aggregating the collected data, the traffic utilization rate of port 1 is calculated; subsequently, the historical traffic and current traffic of port 1 are stored; the upper and lower percentage of the traffic threshold baseline for the current time period is generated based on the historical data, and the current traffic is compared; if the current traffic exceeds the upper and lower percentage of the threshold by n% (such as 20%), the operation and maintenance personnel are notified through audible and visual alarms. The operation and maintenance personnel view the historical traffic data of port 1 and analyze the cause of the anomaly.
[0054] For the above business network traffic analysis method, by collecting traffic data of key links and dynamically generating traffic thresholds for working days / holidays by the baseline warning module 400 according to historical data, comparing the current traffic with the traffic threshold in real time, and triggering an alarm when the current traffic reaches the preset value, it can achieve second-level alarms for faults, promote the transformation of the operation and maintenance mode towards automation and refinement, improve the response speed to key link anomalies, and provide a data basis for early warning; by analyzing the alarm records, the faults can be located so that the operation and maintenance personnel can quickly respond and quickly troubleshoot the abnormal links when the traffic is abnormal, reducing the risks of network attacks and network security threats.
[0055] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as these combinations of technical features do not conflict, they should be considered as the scope described in this specification.
[0056] The above embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the invention patent should be subject to the appended claims.
Claims
1. A business network traffic analysis system, characterized in that: include: Traffic collection module, used to collect traffic data from router / switch ports of key links through SNMP protocol; The data processing module is used to clean, aggregate, and analyze the collected traffic data to generate traffic indicators; Data storage module, used to store historical data, baseline data, user information and alarm records; Baseline warning module, which is used to dynamically generate traffic thresholds for weekdays / holidays based on historical data, compare the current traffic with the traffic threshold in real time, and trigger an alarm when the current traffic reaches the preset value; The alarm module is used to issue an alarm and locate the fault when abnormal traffic or abnormal port status is detected; The report query module is used to provide a multi-dimensional report query interface and analyze historical data.
2. The service network traffic analysis system according to claim 1, characterized in that: It also includes a monitoring point construction module, which includes: The topology discovery module is used to discover the devices and their connection relationships in the network through the network topology structure; A key link identification module, used to determine a number of key links according to preset conditions to form multiple monitoring points; Monitoring point deployment module, used to configure SNMP sending on routers / switches of key links; The optimization and adjustment module is used to adjust the monitoring points according to the changes in network topology.
3. The service network traffic analysis system according to claim 2, characterized in that: The preset conditions include business importance and traffic load; the key link identification module determines at least 800 key links according to the preset conditions.
4. The service network traffic analysis system according to claim 1, characterized in that: The baseline warning module generates the upper and lower percentages of the flow threshold baseline for the current time period based on historical data, and compares it with the current flow. When the current flow exceeds the upper and lower percentages of the threshold by n%, the alarm module issues an alarm; n is a number between 10-30; the alarm module issues an alarm when the current flow reaches the preset value for multiple consecutive times.
5. The service network traffic analysis system according to claim 1, characterized in that: The baseline warning module analyzes historical traffic data in the early morning of each day, identifies and calculates the traffic models of weekdays and holidays according to the dates, and saves the weekday calculation model and the holiday calculation model as baselines respectively.
6. The business network traffic analysis system according to claim 1, characterized in that: The flow indicators include flow utilization and abnormal fluctuations; the alarm module issues an alarm through at least one of sound, light, email or text message.
7. The service network traffic analysis system according to claim 1, characterized in that: It also includes a data analysis module connected to the data storage module and the report query module respectively, and the data analysis module is used to analyze the stored data and generate reports.
8. A method for analyzing business network traffic, implemented by the business network traffic analysis system according to any one of claims 1 to 7, characterized in that: The following steps are involved: S1. Collect traffic data from router / switch ports of key links through SNMP protocol; S2. Clean, aggregate, and analyze the collected traffic data to generate traffic indicators; S3, stores historical data, baseline data, user information and alarm records; S4. Dynamically generate traffic thresholds for weekdays / holidays based on historical data, compare current traffic with traffic thresholds in real time, and trigger an alarm when current traffic reaches a preset value; S5. When abnormal traffic or abnormal port status is detected, an alarm is issued and fault location is performed; S6. Generate multi-dimensional reports and historical data analysis results.
9. The service network traffic analysis method according to claim 8, characterized in that: Before step S1, the method further includes: S01. Discover the devices in the network and their connection relationships through the network topology structure; S02. Determine a number of key links according to preset conditions to form multiple monitoring points; S03. Configure SNMP sending on the routers / switches of key links; S04. Dynamically adjust monitoring points according to changes in network topology.
10. The service network traffic analysis method according to claim 8, characterized in that: In step S5, the fault location includes: S51. When the traffic on a key link is abnormal, an alarm is issued; S52, check the alarm details to confirm the difference between the actual flow data value and the baseline value; S53, analyzing whether the associated key links trigger alarms, and judging the cause of the sudden increase or decrease in traffic based on whether the link group alarm triggers an alarm; S54. The operation and maintenance personnel perform repairs based on the analysis results.
Citation Information
Patent Citations
Complex network traffic packet smart analysis system
CN108039957A
Alarm system and method based on flow data
CN116886517A
Flow monitoring system and method based on MPLS-VPN network
CN118890253A
Cited By
Intelligent operation and maintenance monitoring alarm method and system
CN120639591A
Intelligent operation and maintenance monitoring and alarming method and system
CN120639591B