Switch address allocation and dynamic management method and system
By scanning the switch physical port information and building a network topology relationship diagram, combining the distributed hash mapping mechanism to realize dynamic allocation of MAC addresses and adaptive aging time control, it solves the problem that traditional static configuration methods cannot respond to network changes in real time, and improves network stability and resource utilization efficiency.
Patent Information
- Application Number
- CN202510532775.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-06-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional static configuration methods cannot respond to network topology changes in real time, resulting in address conflicts, resource waste or service interruptions.
By scanning and collecting the physical port information of the switch, a network topology relationship diagram is built, and the address space is divided using a distributed hash mapping mechanism to realize dynamic allocation of MAC addresses and adaptive address aging time control.
It realizes the optimized allocation and life cycle management of switch addresses, improves network stability and reliability, and reduces the risk of resource consumption and service interruption.
Smart Images

Figure CN120223673A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of switches, and particularly to a method and system for switch address allocation and dynamic management. Background Art
[0002] In the current highly interconnected information network environment, as one of the core devices for data transmission, the performance and management efficiency of switches directly affect the stability and response speed of the entire network. With the continuous expansion of the network scale, the limitations of traditional static address allocation methods have gradually emerged, such as difficulty in adapting to dynamically changing network topologies and inability to efficiently handle large-scale MAC address tables. These problems have prompted researchers to seek more intelligent and flexible methods to optimize switch address allocation and management to meet the requirements of modern complex network environments.
[0003] Existing switch address management methods usually rely on manual intervention or pre-set rules for configuration updates, which not only increases the operation and maintenance costs but also proves ineffective in the face of frequent changes in network topologies. For example, in large enterprise networks or data centers, due to the addition, removal, or failure of devices, the network topology often changes, resulting in the need for frequent updates to the MAC address table. However, traditional static configuration methods cannot respond to these changes in real time, which may lead to address conflicts, resource waste, or service interruptions, affecting user experience and service quality.
[0004] To solve the above problems, researchers have been working on developing a method that can automatically adapt to network topology changes and achieve dynamic allocation and management of MAC addresses. This method aims to scan physical port information through automated means, construct a network topology relationship graph, and use a distributed hash mapping mechanism to reasonably divide the address space, thereby achieving optimized allocation of MAC addresses. In addition, an adaptive address aging time control mechanism is introduced, which can effectively improve the flexibility and accuracy of address lifecycle management, reduce unnecessary resource consumption, and enhance the overall performance and reliability of the network. Research in this direction is of great significance for improving the intelligent management level of modern network systems. Summary of the Invention
[0005] The main objective of the present invention is to provide a method and system for switch address allocation and dynamic management, which solves the technical problem that traditional static configuration methods cannot respond to these changes in real time, which may lead to address conflicts, resource waste, or service interruptions.
[0006] To achieve the above objective, the present invention provides a method for switch address allocation and dynamic management, including the following steps: Scan and collect the physical port information of the switch to obtain a set of port status feature vectors; Based on the port state feature vector set, the network topology structure of the switch is intelligently inferred to obtain a switch topology relationship diagram; The address space of the switch topology diagram is divided by a distributed hash mapping mechanism to obtain an address allocation weight matrix; Dynamically assigning the MAC address table in the switch based on the address assignment weight matrix to obtain an optimized address assignment table; The optimized address allocation table is managed for its life cycle through an adaptive address aging time control mechanism.
[0007] Furthermore, the scanning and collection of the physical port information of the switch to obtain a port state feature vector set includes: Using a multi-threshold bandwidth monitoring technology to collect port traffic data on multiple physical ports of the switch to obtain a port traffic timing matrix; Performing spectrum analysis on the physical port of the switch based on the port traffic timing matrix to obtain a port bandwidth usage characteristic spectrum; The port bandwidth is subjected to multi-dimensional feature extraction using a feature spectrum through a self-organizing port state mapping mechanism to obtain a port state feature vector set.
[0008] Furthermore, the intelligent inference of the network topology structure of the switch based on the port state feature vector set to obtain a switch topology relationship diagram includes: Performing multi-dimensional correlation analysis on the port state feature vector set to obtain a port connection relationship matrix, and performing high-order spectrum decomposition on the port connection relationship matrix to obtain a port topology feature spectrum; Based on the port topology feature spectrum, the physical ports of the switch are intelligently inferred to form hierarchical connections to obtain a port hierarchical connection graph, and the port hierarchical connection graph is pruned for redundant paths to obtain an optimized port connection topology graph; Performing node aggregation on the optimized port connection topology graph through a recursive boundary detection mechanism to obtain a switch node cluster, and performing link state analysis based on the switch node cluster to obtain an inter-switch link weight table; An optimal path calculation is performed on the inter-switch link weight table to obtain a switch backbone network topology, and edge node association mapping is performed on the switch backbone network topology to obtain a switch topology relationship diagram.
[0009] Furthermore, the address space of the switch topology diagram is divided by a distributed hash mapping mechanism to obtain an address allocation weight matrix, including: Perform multi-dimensional fractal analysis on the switch topology relationship diagram to obtain a fractal dimension matrix of the topology structure, and perform hierarchical aggregation processing on the fractal dimension matrix of the topology structure to obtain a topology hierarchical structure diagram; Divide the address space of the topology hierarchical structure diagram through a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, and perform load balancing adjustment based on the preliminary address allocation mapping table to obtain a load balancing address allocation table; Perform multi-path routing optimization processing on the load balancing address allocation table to obtain an optimized address allocation path matrix, and perform conflict detection and resolution based on the optimized address allocation path matrix to obtain an address allocation path matrix after conflict resolution; Perform weight allocation on the address allocation path matrix after conflict resolution through multi-dimensional address weight calculation to obtain an address allocation weight matrix.
[0010] Further, the step of dividing the address space of the topology hierarchical structure diagram through a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table includes: Perform pre-allocation of the address space of the topology hierarchical structure diagram through a distributed hash mapping mechanism to obtain a set of pre-allocated address spaces, and generate topology-aware hash keys based on the set of pre-allocated address spaces to obtain a set of topology-aware hash keys; Perform consistent hash mapping on the set of pre-allocated address spaces based on the set of topology-aware hash keys to obtain a consistent hash address mapping table, and perform virtual address space mapping on the consistent hash address mapping table to obtain a virtual address space mapping table; Perform port group division on the switch topology relationship diagram based on the virtual address space mapping table to obtain a set of port groups, and perform address block allocation on the set of port groups to obtain an address block allocation table; Perform cross-layer address merging on the address block allocation table to obtain a preliminary address allocation mapping table.
[0011] Further, the step of dynamically allocating the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table includes: Perform traffic classification on each MAC address in the MAC address table based on the address allocation weight matrix to obtain a MAC address traffic class matrix, and perform QoS policy mapping on the MAC address traffic class matrix to obtain a MAC address QoS policy matrix; Perform virtualization division on the port resources in the switch based on the MAC address QoS policy matrix to obtain a virtualized pool of port resources, and perform dynamic resource allocation on the virtualized pool of port resources to obtain a MAC address resource allocation table; Perform a security risk assessment on each MAC address in the MAC address table based on the MAC address resource allocation table to obtain a MAC address security risk level matrix, and perform security policy configuration on the MAC address security risk level matrix to obtain a MAC address security policy table; Perform access control list binding on the MAC address table in the switch based on the MAC address security policy table to obtain an ACL-bound MAC address table, and perform real-time security monitoring on the ACL-bound MAC address table to obtain security monitoring logs; Perform dynamic security policy adjustment on the ACL-bound MAC address table based on the security monitoring logs to obtain an optimized address allocation table.
[0012] Furthermore, the life cycle management of the optimized address allocation table through the adaptive address aging time control mechanism includes: Perform an interaction frequency analysis on the MAC address entries in the optimized address allocation table to obtain a MAC address interaction frequency matrix, and perform multi-dimensional time series decomposition based on the MAC address interaction frequency matrix to obtain an address usage pattern feature set; Through the adaptive address aging time control mechanism, calculate the dynamic aging time for each MAC address entry based on the address usage pattern feature set to obtain an initial aging time allocation table, and perform network load correlation analysis on the initial aging time allocation table to obtain a load-aware aging time adjustment matrix; Perform anomaly detection on the load-aware aging time adjustment matrix through the spatio-temporal correlation analysis mechanism to obtain an aging time anomaly mark set, and perform aging policy optimization processing based on the aging time anomaly mark set to obtain an optimized aging policy table; Perform hierarchical implementation and deployment on the optimized aging policy table to obtain a hierarchical aging policy implementation matrix, and perform periodic cleaning and update management on the optimized address allocation table based on the hierarchical aging policy implementation matrix.
[0013] The present invention also provides a switch address allocation and dynamic management system, including: An acquisition module for scanning and acquiring the physical port information of the switch to obtain a port status feature vector set; An inference module for intelligently inferring the network topology structure of the switch based on the port status feature vector set to obtain a switch topology relationship diagram; A partitioning module for partitioning the address space of the switch topology relationship diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix; An allocation module, configured to dynamically allocate the MAC address table in the switch based on the address allocation weight matrix, so as to obtain an optimized address allocation table; A management module, configured to perform life cycle management on the optimized address allocation table through an adaptive address aging time control mechanism.
[0014] The present invention also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps of the method described in any one of the above are implemented.
[0015] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in any one of the above are implemented.
[0016] A method for switch address allocation and dynamic management provided by the present invention includes the following steps: scanning and collecting physical port information of the switch to obtain a port status feature vector set; intelligently inferring the network topology structure of the switch based on the port status feature vector set to obtain a switch topology relationship diagram; partitioning the address space of the switch topology relationship diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix; dynamically allocating the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table; performing life cycle management on the optimized address allocation table through an adaptive address aging time control mechanism, solving the technical problem that the traditional static configuration method cannot respond to these changes in real time, which may lead to address conflicts, resource waste or service interruption, and realizing the management of the optimized address allocation table by using an adaptive address aging time control mechanism, and the aging time of the address can be flexibly adjusted according to the actual usage situation. This method not only helps to release unused address resources, but also effectively prevents service quality problems caused by address expiration, enhancing the stability and reliability of the entire network system. Description of the Drawings
[0017] Figure 1 It is a schematic diagram of the steps of the method for switch address allocation and dynamic management in an embodiment of the present invention; Figure 2 It is a structural block diagram of the system for switch address allocation and dynamic management in an embodiment of the present invention; Figure 3 It is a schematic structural block diagram of a computer device in an embodiment of the present invention.
[0018] The implementation, functional characteristics and advantages of the object of the present invention will be further described in conjunction with the embodiments and with reference to the drawings. Detailed Embodiments
[0019] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0020] As Figure 1 shown, Figure 1 is a schematic diagram of the steps of a method for switch address allocation and dynamic management in an embodiment of the present invention; An embodiment of the present invention provides a method for switch address allocation and dynamic management, including the following steps: Step S1, scan and collect the physical port information of the switch to obtain a port status feature vector set.
[0021] Specifically, the step of scanning and collecting the physical port information of the switch to obtain a port status feature vector set aims to collect detailed data on all physical ports of the switch to obtain its current working status and configuration, so as to provide necessary input for subsequent steps. In the specific implementation process, first, a system or tool needs to be established to automatically execute the scanning task. This system can identify and connect to each switch in the network and perform read operations on each physical port. In this way, various parameters can be collected, including but not limited to the speed of the port, duplex mode, connection status (such as whether it is connected, connection type), error statistics, etc. These parameters are combined to form a port status feature vector set, which is essentially a data structure containing a detailed description of each port. To understand this process more clearly, we can imagine an application scenario in an enterprise-level data center. In this scenario, network administrators hope to improve the efficiency and stability of the entire network by optimizing the network topology. To this end, they first need to understand the specific working status of all switches and their ports. With the above method, administrators can automatically initiate a scanning request for all switch ports in the data center through the network management system. For example, when detecting the switch port connected to a key server, the system will record information that the port is in gigabit full-duplex mode and has not had any packet loss in the past 24 hours. Such information is crucial for constructing the port status feature vector set because it not only reflects the basic configuration of the port but also reveals the health status and performance of the port.
[0022] Step S2, based on the port status feature vector set, perform intelligent inference on the network topology of the switch to obtain a switch topology relationship diagram.
[0023] Specifically, the process of intelligently inferring the network topology structure of the switch based on the port status feature vector set to obtain the switch topology relationship diagram aims to utilize detailed port status information to intelligently infer and construct the connection relationships between switches in the network. The system first scans and collects the physical ports of each switch to generate a port status feature vector set. These feature vectors contain various status information of the ports, such as bandwidth utilization rate, traffic fluctuation conditions, and connection stability. Next, the system will use the data in these feature vector sets and infer the actual connection relationships between switches through a series of complex algorithms and analysis techniques. In the specific implementation process, the system will perform multi-dimensional correlation analysis on the port status feature vector set to obtain a port connection relationship matrix. In this application scenario, assume that we have an enterprise data center with three switches A, B, and C, and each switch has multiple physical ports connected to different devices. The system will analyze the status feature vector sets of each port, identify which ports have strong correlations, and form a port connection relationship matrix. For example, the system may find that there is frequent data transmission between a certain port of switch A and a certain port of switch B, so the correlation between these two ports is relatively high. Next, the system will perform high-order spectral decomposition on this matrix, convert the complex connection relationships into frequency domain features that are easy to analyze, and obtain a port topology feature spectrum. These features not only reflect the direct connection conditions between ports but also reveal the overall topology structure in the network. Based on the port topology feature spectrum, the system can perform hierarchical connection intelligent inference on the physical ports of the switch to obtain a port hierarchical connection diagram. For example, in the above application scenario of the enterprise data center, the system may find that some ports are mainly responsible for communication between the core layers, while other ports are mainly used for communication between the aggregation layer or access layer. Through this intelligent inference, the system can generate a port hierarchical connection diagram to show the hierarchical relationships of each port in the network. To improve network efficiency, the system will perform redundant path pruning on the port hierarchical connection diagram, remove those unnecessary duplicate connections, and finally generate an optimized port connection topology diagram. For example, in the above application scenario of the enterprise data center, assume that there is a core layer switch A, which is connected to multiple aggregation layer switches B, C, and D, and each aggregation layer switch is respectively connected to several access layer switches. The system first scans and collects the physical ports of all switches to generate a port status feature vector set. Through multi-dimensional correlation analysis of these feature vector sets, the system obtains a port connection relationship matrix and further performs high-order spectral decomposition to obtain a port topology feature spectrum. Based on this, the system infers the hierarchical relationships of each port in the network and forms a port hierarchical connection diagram. After redundant path pruning, the system obtains an optimized port connection topology diagram.This diagram not only shows the connection relationships between switches but also provides detailed path information, enabling administrators to clearly understand the topology of the entire network, thereby formulating more scientific and reasonable resource allocation and optimization plans. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0024] Step S3, perform address space partitioning on the switch topology relationship diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix.
[0025] Specifically, the process of dividing the address space of the switch topology relationship diagram through the distributed hash mapping mechanism to obtain the address allocation weight matrix aims to utilize the technical characteristics of the distributed hash mapping to efficiently map the nodes and connection relationships in the switch topology relationship diagram into a logical address space and generate an address allocation weight matrix that reflects the importance and priority of network resources. Specifically, the system first identifies the positions and roles of each switch and its ports in the network based on the structural information in the switch topology relationship diagram. For example, in the application scenario of an enterprise data center, assume we have three switches A, B, and C, where switch A is a core layer device, switch B is an aggregation layer device, and switch C is an access layer device. The system will allocate them to different logical address ranges based on the hierarchical relationship and connection density of these switches through the distributed hash mapping mechanism. During the implementation process, the distributed hash mapping mechanism generates a unique hash key value by performing a hash calculation on the nodes in the switch topology relationship diagram, thereby mapping each switch and its ports to a global address space. To ensure the uniformity of address allocation and load balancing, the system performs consistent hashing on the generated hash key values to avoid large-scale data migration due to node addition or deletion. At the same time, the system further optimizes the division of the address space in combination with the actual traffic distribution and topological characteristics of the network, so that the core layer switch obtains a larger address range to support higher data throughput, while the access layer switch is allocated a smaller address range to save resources. For example, in the above-mentioned enterprise data center application scenario, the system may find that switch A undertakes a large number of cross-region traffic forwarding tasks, so it is allocated a larger address range; while switch C mainly serves terminal devices with lower traffic requirements, so it is allocated a smaller address range. On this basis, the system comprehensively considers the traffic weight, hierarchical priority, and actual load of each switch to generate an address allocation weight matrix. This matrix not only records the address allocation of each switch and its ports but also reflects their importance and resource allocation priority in the network, providing an important basis for subsequent dynamic MAC address allocation and lifecycle management. This automated and intelligent address space division method greatly improves the utilization rate of network resources, making network operation and maintenance more efficient and reliable.
[0026] Step S4: Dynamically allocate the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table.
[0027] Specifically, the process of dynamically allocating the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table aims to rationally allocate MAC address resources by using the previously calculated address allocation weight matrix, thereby improving the overall performance and efficiency of the network. Specifically, the system first determines the importance and priority of each switch node in the overall network according to the weight value of each switch node in the address allocation weight matrix. Then, based on these weight values, the system dynamically allocates MAC address table entries for each switch node. For nodes with higher weights, it means that they undertake more data transmission tasks in the network, so they will be allocated more MAC address table entries to ensure that they can handle larger traffic and more device connections; on the contrary, for nodes with lower weights, fewer MAC address table entries will be allocated. To better understand this process, we can consider an application scenario in an enterprise data center where the administrator hopes to improve network performance by optimizing MAC address allocation. For example, within this data center, the core layer switches usually have higher weight values because they need to handle cross-regional data transmission tasks, while the access layer switches mainly serve terminal devices and have relatively lower weight values. In this case, the system will allocate more MAC address table entries for the core layer switches according to the address allocation weight matrix. Suppose the core layer switch A is responsible for connecting multiple aggregation layer switches and needs to handle a large amount of cross-regional data flows, the system will allocate more MAC address table entries for it than other ordinary access layer switches to ensure that it can efficiently handle these complex communication requirements. At the same time, for the access layer switches B and C located at the edge and mainly serving a small number of terminal devices, the system will allocate fewer MAC address table entries because their data processing requirements are relatively small. In this way, the system can not only ensure that key nodes have sufficient resources to handle high-load tasks but also avoid resource waste, making the entire network more balanced and efficient. The finally formed optimized address allocation table can significantly improve the network response speed and stability, and at the same time provide a solid foundation for subsequent life cycle management and adaptive adjustment. This dynamic allocation mechanism is particularly suitable for complex and changeable enterprise-level network environments and helps to achieve more efficient network resource management.
[0028] Step S5, perform life cycle management on the optimized address allocation table through an adaptive address aging time control mechanism.
[0029] Specifically, the process of managing the life cycle of the optimized address allocation table through the adaptive address aging time control mechanism aims to ensure that the entries in the MAC address table can dynamically adjust their life cycles according to the actual network usage conditions, thereby improving resource utilization and network performance. First, the system sets an initial aging time for each MAC address table entry based on factors such as the current network load, traffic pattern, and device connection status. This aging time is not fixed but is dynamically adjusted according to the real-time monitored data. For example, for those frequently used ports or high-priority switch nodes, the system will extend the aging time of their MAC address entries to reduce unnecessary refresh operations and ensure more stable and reliable communication on these critical paths. On the contrary, for those ports with lower usage frequency or that have been inactive for a long time, the system will shorten their aging time to release the resources that are no longer needed in a timely manner. In a specific application scenario, we can consider the network environment of an enterprise data center. Suppose the core layer switch A undertakes a large number of cross-regional data transmission tasks, and the ports it connects to are often in a high-load state. In this case, the system will recognize the high activity of these ports and correspondingly increase the aging time of their MAC address entries. For example, a certain server is connected to multiple aggregation layer switches through the core layer switch A, and the MAC address entry of this server will be given a longer aging time to ensure efficient and stable communication even when the network load fluctuates. At the same time, the access layer switch B serves some occasionally used terminal devices, such as projectors in the conference room. Since the usage frequency of these devices is low, the system will automatically shorten the aging time of their MAC address entries, so that when these devices are not used for a long time, the corresponding MAC addresses can be cleared from the address table faster, releasing valuable resources for other more active connections. In addition, the adaptive address aging time control mechanism can also make intelligent adjustments according to the overall health status of the network. For example, when detecting abnormal traffic or potential security threats in the network, the system can temporarily shorten the aging time of all MAC address entries to quickly clean up the possible invalid or malicious entries and enhance the security and stability of the network. In this way, the system can not only flexibly respond to various complex network environment changes, but also optimize resource utilization to the greatest extent while ensuring network performance, ensuring the efficient operation of the entire network system. This adaptive mechanism is especially suitable for large and complex networks, helping to achieve more intelligent and refined network management.
[0030] In a specific embodiment, scanning and collecting the physical port information of the switch to obtain a port status feature vector set includes: Collecting port traffic data of multiple physical ports of the switch by using multi-threshold bandwidth monitoring technology to obtain a port traffic time series matrix; Perform spectral analysis processing on the physical ports of the switch based on the port traffic time series matrix to obtain the port bandwidth usage characteristic spectrum; Perform multi-dimensional feature extraction on the port bandwidth usage characteristic spectrum through the self-organizing port state mapping mechanism to obtain the port state feature vector set.
[0031] Specifically, the process of scanning and collecting the physical port information of the switch to obtain the port status feature vector set includes multiple key steps: First, the multi-threshold bandwidth monitoring technology is used to collect port traffic data for multiple physical ports of the switch to obtain the port traffic time series matrix; then, based on the port traffic time series matrix, spectral analysis processing is performed on the physical ports of the switch to obtain the port bandwidth usage feature spectrum; finally, multi-dimensional feature extraction is performed on the port bandwidth usage feature spectrum through the self-organizing port status mapping mechanism to obtain the port status feature vector set. This complex process aims to comprehensively and accurately obtain the status information of the physical ports of the switch, providing a solid data foundation for subsequent network topology discovery and address allocation. In the specific implementation process, the first step is to use the multi-threshold bandwidth monitoring technology to collect port traffic data for multiple physical ports of the switch. The multi-threshold bandwidth monitoring technology here is an advanced traffic monitoring method that can set multiple monitoring thresholds according to different bandwidth usage situations, so as to more precisely capture the actual usage status of the ports. For example, in the application scenario of an enterprise data center, assume that we have three switches A, B, and C, and each switch has multiple physical ports connected to different devices. To accurately understand the traffic conditions of these ports, the system will set multiple bandwidth thresholds for each port, such as 10Mbps, 50Mbps, and 100Mbps. When the actual traffic of a port reaches or exceeds a certain threshold, the system will record the corresponding traffic data. In this way, by continuously collecting the traffic data of each port at different time periods, we can construct a port traffic time series matrix. This matrix not only contains the traffic values of each port at different times, but also reflects the trend of port traffic changing over time, which is crucial for subsequent analysis. Next, based on the port traffic time series matrix, spectral analysis processing is performed on the physical ports of the switch to obtain the port bandwidth usage feature spectrum. Spectral analysis is a technology that converts a time-domain signal into a frequency-domain signal, which can help us better understand the frequency components and their distribution in the signal. In this application scenario, by performing spectral analysis on the port traffic time series matrix, the distribution characteristics of port traffic at different frequencies can be revealed. For example, for a specific port of switch A, its traffic time series matrix shows the traffic fluctuations within a day. Through spectral analysis, we can identify that there are obvious high-frequency fluctuations in this port during certain specific time periods, which may mean that there is a large amount of bursty data transmission during this time. While in other time periods, it shows low-frequency fluctuations, indicating that the data transmission is relatively stable at this time. These spectral features together constitute the port bandwidth usage feature spectrum, which details the bandwidth usage patterns of each port at different frequencies and provides a rich information source for further feature extraction. Finally, multi-dimensional feature extraction is performed on the port bandwidth usage feature spectrum through the self-organizing port status mapping mechanism to obtain the port status feature vector set.The self-organizing port state mapping mechanism is an unsupervised learning method based on neural networks, which can automatically extract meaningful feature representations from complex datasets. In this process, the system first takes the port bandwidth usage feature spectrum as input and then processes it using the self-organizing mapping algorithm. Specifically, the self-organizing mapping algorithm creates a two-dimensional or three-dimensional grid structure in a high-dimensional space, and each grid node represents a prototype vector. By iteratively adjusting the positions of these prototype vectors, they can be made to match the feature distribution in the input data as closely as possible. During this process, similar features are mapped to adjacent grid nodes, thus forming a topological structure. Finally, the system generates a set of port state feature vectors based on this topological structure. Each vector contains various feature information about the corresponding port, such as bandwidth utilization rate, traffic fluctuation frequency, anomaly detection results, etc. These feature vectors can not only reflect the basic working state of the port but also reveal potential problems and optimization opportunities. For example, in the above application scenario of the enterprise data center, assume that we need to conduct a comprehensive state assessment of all ports of switch A. First, through multi-threshold bandwidth monitoring technology, we collect the traffic data of each port in the past 24 hours and construct a port traffic time series matrix. Then, we use spectral analysis to process these time series data and obtain a detailed port bandwidth usage feature spectrum. For example, we find that there are significant high-frequency fluctuations in port 1 between 9 am and 11 am, which may be due to a large number of employees accessing company internal resources after going to work; while port 2 maintains relatively stable low-frequency fluctuations throughout the day, indicating that it mainly undertakes background data transmission tasks. Finally, we apply the self-organizing port state mapping mechanism to process these feature spectra and generate a set of port state feature vectors. These feature vectors not only help us clearly understand the specific usage of each port but also provide important basis for subsequent network topology discovery and MAC address dynamic allocation. For example, based on the set of port state feature vectors, we can identify which ports carry critical business traffic and thus preferentially allocate more MAC address entries and longer aging times to ensure the stability and reliability of these important connections. In summary, through the comprehensive scanning and collection of switch physical port information, spectral analysis, and feature extraction, we can obtain a detailed set of port state feature vectors. These vectors not only cover the basic configuration information of the port but also deeply reveal its actual usage and potential problems, laying a solid foundation for subsequent network management and optimization. This method is particularly suitable for large and complex network environments and helps to implement more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network but also effectively improve the performance and stability of the entire network system.
[0032] In a specific embodiment, the intelligent inference of the network topology structure of the switch based on the port status feature vector set to obtain a switch topology relationship diagram includes: Perform multi-dimensional correlation analysis on the port status feature vector set to obtain a port connection relationship matrix, and perform high-order spectral decomposition on the port connection relationship matrix to obtain a port topology feature spectrum; Based on the port topology feature spectrum, perform hierarchical connection intelligent inference on the physical ports of the switch to obtain a port hierarchical connection diagram, and perform redundant path pruning on the port hierarchical connection diagram to obtain an optimized port connection topology diagram; Through a recursive boundary detection mechanism, perform node aggregation on the optimized port connection topology diagram to obtain a switch node cluster, and perform link state analysis based on the switch node cluster to obtain a link weight table between switches; Calculate the optimal path for the link weight table between switches to obtain a switch backbone network topology, and perform edge node association mapping on the switch backbone network topology to obtain a switch topology relationship diagram.
[0033] Specifically, the process of intelligently inferring the network topology structure of the switch based on the port status feature vector set to obtain the switch topology relationship diagram involves multiple complex steps and technical means. First, perform multi-dimensional correlation analysis on the port status feature vector set to obtain the port connection relationship matrix, and perform high-order spectral decomposition on the port connection relationship matrix to obtain the port topology feature spectrum; then, based on the port topology feature spectrum, perform hierarchical connection intelligent inference on the physical ports of the switch to obtain the port hierarchical connection diagram, and perform redundant path pruning on the port hierarchical connection diagram to obtain the optimized port connection topology diagram; next, perform node aggregation on the optimized port connection topology diagram through a recursive boundary detection mechanism to obtain the switch node cluster, and perform link state analysis based on the switch node cluster to obtain the inter-switch link weight table; finally, perform the optimal path calculation on the inter-switch link weight table to obtain the switch backbone network topology, and perform edge node association mapping on the switch backbone network topology to obtain the switch topology relationship diagram. This process aims to extract the hierarchical information of the network from the detailed port status feature vector set and generate a clear switch topology relationship diagram through a series of optimization and simplification steps. In the specific implementation process, the first step is to perform multi-dimensional correlation analysis on the port status feature vector set to obtain the port connection relationship matrix, and perform high-order spectral decomposition on the port connection relationship matrix to obtain the port topology feature spectrum. Multi-dimensional correlation analysis is a method for evaluating the strength of the relationship between different variables, which can reveal the potential connection patterns between ports. In this application scenario, assume that we have an enterprise data center with three switches A, B, and C, and each switch has multiple physical ports connected to different devices. The system will analyze the status feature vector set of each port, identify which ports have a strong correlation, and form the port connection relationship matrix. For example, the system may find that there is frequent data transmission between a certain port of switch A and a certain port of switch B, so the correlation between these two ports is relatively high. Next, the system will perform high-order spectral decomposition on this matrix, convert the complex connection relationship into frequency domain features that are easy to analyze, and obtain the port topology feature spectrum. These features not only reflect the direct connection between ports but also reveal the overall topology structure in the network. Subsequently, based on the port topology feature spectrum, perform hierarchical connection intelligent inference on the physical ports of the switch to obtain the port hierarchical connection diagram, and perform redundant path pruning on the port hierarchical connection diagram to obtain the optimized port connection topology diagram. Hierarchical connection intelligent inference is a method for inferring the hierarchical relationship of ports in the network based on their connection characteristics, which helps to construct a clearer topology structure. In this process, the system will use the information in the port topology feature spectrum, combined with the actual physical port connection situation, to infer the hierarchical relationship of each port in the network.For example, in the above application scenario of the enterprise data center, the system may find that some ports are mainly responsible for communication between the core layers, while others are mainly used for communication between the aggregation layer or the access layer. Through this intelligent inference, the system can generate a hierarchical connection diagram of ports, showing the hierarchical relationship of each port in the network. However, this diagram may contain some redundant paths, that is, unnecessary repeated connections. To improve network efficiency, the system will perform redundant path pruning on the hierarchical connection diagram of ports, removing those unnecessary or inefficient connections, and finally generating an optimized port connection topology diagram. Then, node aggregation is performed on the optimized port connection topology diagram through a recursive boundary detection mechanism to obtain a switch node cluster, and link state analysis is performed based on the switch node cluster to obtain a link weight table between switches. The recursive boundary detection mechanism is a method of identifying key nodes in the network and aggregating them, which helps to simplify the complex network structure. In this process, the system will utilize the information in the optimized port connection topology diagram, identify the key nodes (such as core layer switches) in the network through the recursive boundary detection mechanism, and aggregate these nodes together to form a switch node cluster. For example, in the above application scenario of the enterprise data center, the system may find that switch A and switch B are aggregated into a node cluster because they undertake a large number of cross-regional data transmission tasks. Next, the system will perform link state analysis on these switch node clusters, evaluate the link quality and load conditions between each switch, and form a link weight table between switches. This table records the link weights between each switch, reflecting the connection strength and importance between them. Finally, the optimal path calculation is performed on the link weight table between switches to obtain the switch backbone network topology, and edge node association mapping is performed on the switch backbone network topology to obtain the switch topology relationship diagram. The optimal path calculation is a method of finding the optimal communication path in the network, which can ensure the efficiency and reliability of data transmission. In this process, the system will utilize the information in the link weight table between switches, apply the shortest path algorithm or other optimization algorithms, calculate the optimal path between switches, and form the switch backbone network topology. For example, in the above application scenario of the enterprise data center, the system may find that there are multiple available paths from switch A to switch B, but some paths may have bottlenecks or high latency problems. Through the optimal path calculation, the system will select the optimal path and generate the switch backbone network topology. Next, the system will perform edge node association mapping on this topology, associate those unaggregated edge nodes (such as access layer switches) with their corresponding backbone nodes, and form a complete switch topology relationship diagram. This diagram not only shows the connection relationship between switches, but also provides detailed path information and weight allocation, laying a solid foundation for subsequent network management and optimization.For example, in the application scenario of the above enterprise data center, assume there is a core switch A, which is connected to multiple aggregation switches B, C, and D. Each aggregation switch is respectively connected to several access switches. The system first scans and collects the physical ports of all switches to generate a port status feature vector set. Through multi-dimensional correlation analysis of these feature vector sets, the system obtains a port connection relationship matrix, and further performs high-order spectral decomposition to obtain a port topology feature spectrum. Based on this, the system infers the hierarchical relationship of each port in the network to form a port hierarchical connection graph. After redundant path pruning, the system obtains an optimized port connection topology graph. Then, the system identifies key nodes in the network through a recursive boundary detection mechanism and aggregates these nodes into a switch node cluster. Based on these clusters, the system performs link state analysis to obtain a link weight table between switches. Finally, by calculating the optimal path for the link weight table, the system generates a switch backbone network topology and further associates the edge nodes with their corresponding backbone nodes to form a complete switch topology relationship graph. In summary, through a series of operations such as multi-dimensional correlation analysis, high-order spectral decomposition, hierarchical connection intelligent inference, redundant path pruning, recursive boundary detection mechanism, link state analysis, and optimal path calculation on the port status feature vector set, the network topology structure of the switch can be comprehensively and accurately inferred, and a clear switch topology relationship graph can be generated. This method is particularly suitable for large and complex network environments, helping to implement more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network, but also effectively improve the performance and stability of the entire network system. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0034] In a specific embodiment, the address space partitioning of the switch topology relationship graph through the distributed hash mapping mechanism to obtain an address allocation weight matrix includes: Perform multi-dimensional fractal analysis on the switch topology relationship graph to obtain a topological structure fractal dimension matrix, and perform hierarchical aggregation processing on the topological structure fractal dimension matrix to obtain a topological hierarchical structure graph; Perform address space partitioning on the topological hierarchical structure graph through the distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, and perform load balancing adjustment based on the preliminary address allocation mapping table to obtain a load balancing address allocation table; Perform multi-path routing optimization processing on the load balancing address allocation table to obtain an optimized address allocation path matrix, and perform conflict detection and resolution based on the optimized address allocation path matrix to obtain an address allocation path matrix after conflict resolution; Perform weight assignment on the address assignment path matrix after conflict resolution through multi-dimensional address weight calculation to obtain an address assignment weight matrix.
[0035] Specifically, the process of dividing the address space of the switch topology relationship diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix involves multiple complex steps and technical means. First, perform multi-dimensional fractal analysis on the switch topology relationship diagram to obtain a topological structure fractal dimension matrix, and perform hierarchical aggregation processing on the topological structure fractal dimension matrix to obtain a topological hierarchical structure diagram; then, divide the address space of the topological hierarchical structure diagram through a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, and perform load balancing adjustment based on the preliminary address allocation mapping table to obtain a load balancing address allocation table; next, perform multi-path routing optimization processing on the load balancing address allocation table to obtain an optimized address allocation path matrix, and perform conflict detection and resolution based on the optimized address allocation path matrix to obtain an address allocation path matrix after conflict resolution; finally, perform weight allocation on the address allocation path matrix after conflict resolution through multi-dimensional address weight calculation to obtain an address allocation weight matrix. This process aims to extract the hierarchical structure of the network from the detailed topology relationship diagram and generate a clear address allocation weight matrix through a series of optimization and simplification steps. In the specific implementation process, the first step is to perform multi-dimensional fractal analysis on the switch topology relationship diagram to obtain a topological structure fractal dimension matrix, and perform hierarchical aggregation processing on the topological structure fractal dimension matrix to obtain a topological hierarchical structure diagram. Multi-dimensional fractal analysis is a technology used to describe the characteristics of complex network structures, which can reveal the self-similarity and hierarchy in the network. In this application scenario, by applying multi-dimensional fractal analysis to the switch topology relationship diagram, we can identify the self-similar characteristics of each switch and its connections at different scales. For example, in an enterprise data center application scenario, assume we have three switches A, B, and C, and each switch has multiple physical ports connected to different devices. Through multi-dimensional fractal analysis, the system can calculate the fractal dimensions of each switch and its connections to form a topological structure fractal dimension matrix. These dimensions not only reflect the importance and complexity of each switch in the network but also provide a basis for subsequent hierarchical aggregation. Next, the system will perform hierarchical aggregation processing on this matrix, grouping switches with similar fractal dimensions into the same layer, thereby constructing a topological hierarchical structure diagram. This diagram not only shows the hierarchical relationship between switches but also reveals their relative importance in the network. Then, divide the address space of the topological hierarchical structure diagram through a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, and perform load balancing adjustment based on the preliminary address allocation mapping table to obtain a load balancing address allocation table. The distributed hash mapping mechanism is an efficient resource allocation method that can dynamically divide the address space according to the distribution of nodes. In this process, the system will allocate corresponding address intervals for each switch node according to the layer information in the topological hierarchical structure diagram.For example, in the application scenario of the above enterprise data center, since the core layer switch undertakes a large number of cross-region data transmission tasks, it usually requires a larger address range to handle more MAC address entries. The system will allocate a larger address range to the core layer switch and a smaller address range to the access layer switch. In this way, the system can generate a preliminary address allocation mapping table. However, the preliminary allocation may not be completely balanced, so the system also needs to perform load balancing adjustment. The goal of load balancing adjustment is to ensure that each node can handle as many tasks as possible within its capacity, avoiding overload or resource waste. For example, if the load of a certain switch node is too high, the system can relieve its burden by reallocating part of the address range, and finally generate a load-balanced address allocation table. Subsequently, perform multi-path routing optimization processing on the load-balanced address allocation table to obtain an optimized address allocation path matrix, and perform conflict detection and resolution based on the optimized address allocation path matrix to obtain an address allocation path matrix after conflict resolution. Multi-path routing optimization is an important technology to improve network reliability and efficiency. It can select the optimal path for data transmission among multiple available paths. In this process, the system will optimize the paths in the load-balanced address allocation table to reduce latency and improve bandwidth utilization. For example, in the application scenario of the above enterprise data center, the system may find that there are multiple available paths from switch A to switch B, but some paths may have bottlenecks or high latency problems. Through multi-path routing optimization, the system will select the optimal path and generate an optimized address allocation path matrix. However, there may be address conflict problems in the optimized path matrix, that is, two or more nodes are assigned to the same address range. To eliminate these conflicts, the system will perform conflict detection and resolution on the optimized path matrix. For example, if it is found that switch A and switch B are assigned to the same address range, the system will readjust their address allocations to ensure that each node has its own independent address range, thus generating an address allocation path matrix after conflict resolution. Finally, perform weight allocation on the address allocation path matrix after conflict resolution through multi-dimensional address weight calculation to obtain an address allocation weight matrix. Multi-dimensional address weight calculation is a method of determining address allocation weights by comprehensively considering various factors (such as traffic, priority, historical usage, etc.). In this process, the system will assign corresponding weight values to each node according to the information in the address allocation path matrix after conflict resolution and in combination with the actual network usage situation. For example, in the application scenario of the above enterprise data center, since the core layer switch bears a large amount of critical business traffic, it is usually given a higher weight value; while the access layer switch mainly serves terminal devices, and its weight value is relatively low.In this way, the system can generate an address allocation weight matrix, where the weight value of each node not only reflects its importance and priority in the network, but also provides an important basis for subsequent dynamic MAC address allocation. In short, through a series of operations such as multi-dimensional fractal analysis of the switch topology diagram, distributed hash mapping mechanism, load balancing adjustment, multi-path routing optimization, and conflict detection and resolution, the address space can be comprehensively and accurately divided and an address allocation weight matrix can be generated. This method is particularly suitable for large and complex network environments, helping to implement more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network, but also effectively improve the performance and stability of the entire network system. For example, in the application scenario of the above enterprise data center, through the generated address allocation weight matrix, administrators can clearly understand the address allocation situation between each switch and its ports, and then formulate a more scientific and reasonable resource allocation and optimization plan. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0036] In a specific embodiment, the address space of the topological hierarchical structure diagram is divided through a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, including: The address space of the topological hierarchical structure diagram is pre-divided through a distributed hash mapping mechanism to obtain a pre-allocated address space set, and based on the pre-allocated address space set, a topology-aware hash key is generated to obtain a topology-aware hash key set; Based on the topology-aware hash key set, a consistent hash mapping is performed on the pre-allocated address space set to obtain a consistent hash address mapping table, and a virtual address space mapping is performed on the consistent hash address mapping table to obtain a virtual address space mapping table; Based on the virtual address space mapping table, the switch topology diagram is divided into port groups to obtain a port group set, and address blocks are allocated to the port group set to obtain an address block allocation table; Cross-layer address merging is performed on the address block allocation table to obtain a preliminary address allocation mapping table.
[0037] Specifically, the process of dividing the address space of the topological hierarchical structure diagram through the distributed hash mapping mechanism to obtain the preliminary address allocation mapping table involves multiple complex steps and technical means. First, the address space of the topological hierarchical structure diagram is pre-divided through the distributed hash mapping mechanism to obtain a set of pre-allocated address spaces, and based on the set of pre-allocated address spaces, topological-aware hash key generation is performed to obtain a set of topological-aware hash keys; then, based on the set of topological-aware hash keys, consistent hash mapping is performed on the set of pre-allocated address spaces to obtain a consistent hash address mapping table, and virtual address space mapping is performed on the consistent hash address mapping table to obtain a virtual address space mapping table; next, based on the virtual address space mapping table, port group division is performed on the switch topology relationship diagram to obtain a set of port groups, and address block allocation is performed on the set of port groups to obtain an address block allocation table; finally, cross-layer address merging is performed on the address block allocation table to obtain the preliminary address allocation mapping table. This process aims to extract the hierarchical information of the network from the detailed topological hierarchical structure diagram and generate a clear preliminary address allocation mapping table through a series of optimization and simplification steps. In the specific implementation process, the first step is to pre-divide the address space of the topological hierarchical structure diagram through the distributed hash mapping mechanism to obtain a set of pre-allocated address spaces, and based on the set of pre-allocated address spaces, topological-aware hash key generation is performed to obtain a set of topological-aware hash keys. The distributed hash mapping mechanism is an efficient data distribution method that can dynamically divide the address space according to the distribution of nodes. In this application scenario, by applying the distributed hash mapping mechanism to the topological hierarchical structure diagram, the system can allocate corresponding address ranges to the switch nodes in each layer to form a set of pre-allocated address spaces. For example, in an enterprise data center application scenario, assume we have three switches A, B, and C, and each switch has multiple physical ports connected to different devices. The system will allocate a larger address range to the core layer switch and a smaller address range to the access layer switch according to the hierarchical relationship of these switches and their connections. Next, the system will generate a set of topological-aware hash keys based on these sets of pre-allocated address spaces. The goal of topological-aware hash key generation is to ensure that the hash key of each node not only reflects its position in the network but also takes into account its relationship with other nodes. For example, if a switch node undertakes a large amount of critical business traffic in the network, the system will assign it a higher priority when generating the hash key to ensure that its importance in the network is reflected. Subsequently, based on the set of topological-aware hash keys, consistent hash mapping is performed on the set of pre-allocated address spaces to obtain a consistent hash address mapping table, and virtual address space mapping is performed on the consistent hash address mapping table to obtain a virtual address space mapping table. Consistent hashing is an efficient distributed hashing technology that can minimize the impact of data migration when nodes are added or removed.In this process, the system performs a consistent hashing mapping on the pre-allocated address space set using the topology-aware hash key set to generate a consistent hashing address mapping table. For example, in the application scenario of the above enterprise data center, the system maps the consistent hashing keys generated by each switch node to ensure that each node can handle as many tasks as possible within its capabilities, avoiding overload or resource waste. Next, the system performs a virtual address space mapping on the consistent hashing address mapping table, converting the actual physical address into a virtual address to better manage and schedule resources. The goal of virtual address space mapping is to abstract a unified address space so that switch nodes at different levels can perform resource allocation and management within the same framework. For example, the system may allocate a virtual address range to each switch node, thus forming a virtual address space mapping table. Then, based on the virtual address space mapping table, port group partitioning is performed on the switch topology relationship graph to obtain a set of port groups, and address block allocation is performed on the set of port groups to obtain an address block allocation table. Port group partitioning is a method of classifying ports according to their functions and usage, which helps to manage and allocate resources more finely. In this process, the system will divide the ports of each switch into different port groups according to the information in the virtual address space mapping table and the actual connection situation in the switch topology relationship graph. For example, in the application scenario of the above enterprise data center, the system may find that some ports are mainly used for internal communication, while others are used for external data transmission. Through port group partitioning, the system can allocate different address blocks to these ports with different uses. For example, some ports of the core layer switch may be allocated larger address blocks to ensure that they can handle a large number of cross-region data transmission tasks; while the ports of the access layer switch may be allocated smaller address blocks because they mainly serve terminal devices. Finally, the system generates an address block allocation table, recording the address block allocation situation corresponding to each port group. Finally, cross-layer address merging is performed on the address block allocation table to obtain a preliminary address allocation mapping table. Cross-layer address merging is a method of integrating the address allocation results of different levels, which helps to eliminate redundancy and optimize the overall resource allocation. In this process, the system analyzes the information in the address block allocation table to identify which address blocks can be shared or merged between different levels. For example, in the application scenario of the above enterprise data center, the system may find that although some port groups are distributed at different levels, their actual usage situations are very similar, so they can share the same address block. Through cross-layer address merging, the system can further optimize the address allocation scheme, reduce resource waste, and improve the overall efficiency. The finally generated preliminary address allocation mapping table not only contains the specific address allocation situation of each switch node and its ports, but also provides detailed path and priority information, laying a solid foundation for subsequent MAC address dynamic allocation and lifecycle management.In summary, through a series of operations such as pre - partitioning the address space of the topology hierarchical structure diagram, generating topology - aware hash keys, performing consistent hashing mapping, virtual address space mapping, port - group partitioning, and cross - layer address merging, the address space can be comprehensively and accurately partitioned, and a preliminary address allocation mapping table can be generated. This method is particularly applicable to large and complex network environments, and helps to implement more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network, but also effectively improve the performance and stability of the entire network system. For example, in the above - mentioned application scenario of the enterprise data center, through the generated preliminary address allocation mapping table, administrators can clearly understand the address allocation situation between each switch and its ports, and then formulate a more scientific and reasonable resource allocation and optimization plan. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0038] In a specific embodiment, the dynamic allocation of the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table includes: Classifying the traffic of each MAC address in the MAC address table based on the address allocation weight matrix to obtain a MAC address traffic class matrix, and performing QoS policy mapping on the MAC address traffic class matrix to obtain a MAC address QoS policy matrix; Virtualizing and partitioning the port resources in the switch based on the MAC address QoS policy matrix to obtain a virtualized port resource pool, and performing dynamic resource allocation on the virtualized port resource pool to obtain a MAC address resource allocation table; Performing a security risk assessment on each MAC address in the MAC address table based on the MAC address resource allocation table to obtain a MAC address security risk level matrix, and performing security policy configuration on the MAC address security risk level matrix to obtain a MAC address security policy table; Binding an access control list to the MAC address table in the switch based on the MAC address security policy table to obtain an ACL - bound MAC address table, and performing real - time security monitoring on the ACL - bound MAC address table to obtain a security monitoring log; Performing dynamic security policy adjustment on the ACL - bound MAC address table based on the security monitoring log to obtain an optimized address allocation table.
[0039] Specifically, the process of dynamically allocating the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table involves multiple complex steps and technical means. First, each MAC address in the MAC address table is classified according to traffic based on the address allocation weight matrix to obtain a MAC address traffic class matrix, and a QoS policy mapping is performed on the MAC address traffic class matrix to obtain a MAC address QoS policy matrix; then, the port resources in the switch are virtualized and divided based on the MAC address QoS policy matrix to obtain a port resource virtualization pool, and dynamic resource allocation is performed on the port resource virtualization pool to obtain a MAC address resource allocation table; next, a security risk assessment is performed on each MAC address in the MAC address table based on the MAC address resource allocation table to obtain a MAC address security risk level matrix, and a security policy configuration is performed on the MAC address security risk level matrix to obtain a MAC address security policy table; subsequently, an access control list binding is performed on the MAC address table in the switch based on the MAC address security policy table to obtain an ACL-bound MAC address table, and real-time security monitoring is performed on the ACL-bound MAC address table to obtain a security monitoring log; finally, dynamic security policy adjustment is performed on the ACL-bound MAC address table based on the security monitoring log to obtain an optimized address allocation table. This process aims to extract hierarchical information of the network from the detailed address allocation weight matrix and generate a clear optimized address allocation table through a series of optimization and simplification steps. In the specific implementation process, the first step is to classify each MAC address in the MAC address table according to traffic based on the address allocation weight matrix to obtain a MAC address traffic class matrix, and a QoS policy mapping is performed on the MAC address traffic class matrix to obtain a MAC address QoS policy matrix. Traffic classification is a method of dividing data streams into different categories according to their characteristics, which helps to better manage and schedule network resources. In this application scenario, the system will divide the data streams of each MAC address into different categories according to the information in the address allocation weight matrix and the actual traffic situation in the MAC address table. For example, in the application scenario of an enterprise data center, assume that we have three switches A, B, and C, and each switch has multiple physical ports connected to different devices. The system will analyze the traffic characteristics of each MAC address, such as bandwidth utilization rate, latency sensitivity, etc., and divide these traffic into categories such as high priority, medium priority, and low priority to form a MAC address traffic class matrix. Next, the system will perform a QoS (Quality of Service) policy mapping on this matrix to allocate corresponding QoS policies to each traffic class to ensure that critical business traffic can obtain sufficient resource guarantee.For example, high-priority traffic may be assigned to paths with higher bandwidth and lower latency, while low-priority traffic may be assigned to other paths. Eventually, the system generates a MAC address QoS policy matrix that records the QoS policy corresponding to each MAC address. Subsequently, based on the MAC address QoS policy matrix, the port resources in the switch are virtualized and partitioned to obtain a virtualized port resource pool, and dynamic resource allocation is performed on the virtualized port resource pool to obtain a MAC address resource allocation table. Port resource virtualization is a method of abstracting physical port resources into virtual resources, which helps to manage and schedule resources more flexibly. In this process, the system divides the port resources into multiple virtual resource pools according to the information in the MAC address QoS policy matrix and in combination with the actual port resource situation of the switch. For example, in the application scenario of the above enterprise data center, the system may find that some ports are mainly used for internal communication, while others are used for external data transmission. Through port resource virtualization and partitioning, the system can allocate different virtual resource pools to these ports for different purposes. For example, some ports of the core layer switch may be assigned to a larger virtual resource pool to ensure that they can handle a large number of cross-region data transmission tasks; while the ports of the access layer switch may be assigned to a smaller virtual resource pool because they mainly serve terminal devices. Eventually, the system generates a MAC address resource allocation table that records the virtual resource allocation situation corresponding to each MAC address. Then, based on the MAC address resource allocation table, a security risk assessment is performed on each MAC address in the MAC address table to obtain a MAC address security risk level matrix, and security policy configuration is performed on the MAC address security risk level matrix to obtain a MAC address security policy table. Security risk assessment is a method of identifying potential threats and evaluating their impact levels, which helps to formulate effective security policies. In this process, the system performs a security risk assessment on each MAC address according to the information in the MAC address resource allocation table and in combination with the actual usage situation in the MAC address table. For example, in the application scenario of the above enterprise data center, the system may find that some MAC addresses frequently exhibit abnormal traffic or have potential security vulnerabilities, so more stringent security monitoring is required. Through security risk assessment, the system can divide the risk level of each MAC address into different levels such as high, medium, and low to form a MAC address security risk level matrix. Next, the system performs security policy configuration on this matrix and assigns corresponding security policies to MAC addresses of each risk level. For example, high-risk MAC addresses may be assigned to more stringent firewall rules and intrusion detection mechanisms, while low-risk MAC addresses may only require basic security protection measures. Eventually, the system generates a MAC address security policy table that records the security policy corresponding to each MAC address.Subsequently, based on the MAC address security policy table, access control list (ACL) binding is performed on the MAC address table in the switch to obtain an ACL-bound MAC address table, and real-time security monitoring is performed on the ACL-bound MAC address table to obtain security monitoring logs. ACL binding is a method of associating access control policies with MAC address table entries, which helps to achieve fine-grained access control. In this process, the system will bind the corresponding ACL rules to each entry in the MAC address table according to the information in the MAC address security policy table. For example, in the above application scenario of the enterprise data center, the system may find that certain MAC addresses require higher security protection, so more stringent ACL rules are bound to them. Through ACL binding, the system can ensure that each MAC address can only access the resources within its permission range, preventing unauthorized access behavior. Next, the system will perform real-time security monitoring on the ACL-bound MAC address table, recording all relevant security events and log information. For example, the system may monitor the traffic patterns, access requests, and their response situations of each MAC address, generating detailed security monitoring logs. Finally, based on the security monitoring logs, dynamic security policy adjustment is performed on the ACL-bound MAC address table to obtain an optimized address allocation table. Dynamic security policy adjustment is a method of continuously optimizing security policies according to real-time monitoring data, which helps to improve the overall security and flexibility of the network. In this process, the system will identify potential security threats and optimization opportunities according to the information in the security monitoring logs. For example, in the above application scenario of the enterprise data center, the system may find that although certain MAC addresses are currently in a low-risk state, their traffic patterns have changed significantly, which may pose potential security risks. Through dynamic security policy adjustment, the system can timely update the security policies of these MAC addresses to enhance their protection capabilities. For example, the system may reassign more stringent ACL rules to these MAC addresses or add additional security monitoring measures. Ultimately, the system will generate an optimized address allocation table, which not only contains the specific address allocation situation of each MAC address but also provides detailed path, priority, and security policy information, laying a solid foundation for subsequent network management and optimization. In summary, through a series of operations such as traffic classification, QoS policy mapping, port resource virtualization division, security risk assessment, ACL binding, and dynamic security policy adjustment on the address allocation weight matrix, dynamic allocation of the MAC address table can be comprehensively and precisely performed and an optimized address allocation table can be generated. This method is particularly suitable for large and complex network environments, helping to achieve more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network but also effectively improve the performance and security of the entire network system.For example, in the application scenario of the above enterprise data center, through the generated optimized address allocation table, the administrator can clearly understand the address allocation situation and security status between each switch and its ports, and then formulate a more scientific and reasonable resource allocation and optimization plan. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0040] In a specific embodiment, the life cycle management of the optimized address allocation table through the adaptive address aging time control mechanism includes: Analyze the interaction frequency of MAC address entries in the optimized address allocation table to obtain a MAC address interaction frequency matrix, and perform multi-dimensional time series decomposition based on the MAC address interaction frequency matrix to obtain an address usage pattern feature set; Through the adaptive address aging time control mechanism, calculate the dynamic aging time for each MAC address entry based on the address usage pattern feature set to obtain an initial aging time allocation table, and perform network load correlation analysis on the initial aging time allocation table to obtain a load-aware aging time adjustment matrix; Perform anomaly detection on the load-aware aging time adjustment matrix through the spatio-temporal correlation analysis mechanism to obtain an aging time anomaly mark set, and perform aging strategy optimization processing based on the aging time anomaly mark set to obtain an optimized aging strategy table; Perform hierarchical implementation and deployment on the optimized aging strategy table to obtain a hierarchical aging strategy implementation matrix, and perform periodic cleaning and update management on the MAC address table in the switch of the optimized address allocation table based on the hierarchical aging strategy implementation matrix.
[0041] Specifically, the process of lifecycle management of the optimized address allocation table through the adaptive address aging time control mechanism involves multiple complex steps and technical means. First, perform an interaction frequency analysis on the MAC address entries in the optimized address allocation table to obtain a MAC address interaction frequency matrix, and perform multi-dimensional time series decomposition based on the MAC address interaction frequency matrix to obtain an address usage pattern feature set; then, through the adaptive address aging time control mechanism, calculate the dynamic aging time for each MAC address entry based on the address usage pattern feature set to obtain an initial aging time allocation table, and perform a network load correlation analysis on the initial aging time allocation table to obtain a load-aware aging time adjustment matrix; next, perform anomaly detection on the load-aware aging time adjustment matrix through a spatio-temporal correlation analysis mechanism to obtain an aging time anomaly marker set, and perform aging policy optimization processing based on the aging time anomaly marker set to obtain an optimized aging policy table; finally, perform hierarchical implementation and deployment on the optimized aging policy table to obtain a hierarchical aging policy implementation matrix, and perform periodic cleaning and update management on the optimized address allocation table based on the hierarchical aging policy implementation matrix. This process aims to extract the usage patterns of MAC addresses from the detailed optimized address allocation table and generate clear aging policies through a series of optimization and simplification steps to ensure the efficient management and maintenance of the MAC address table. In the specific implementation process, the first step is to perform an interaction frequency analysis on the MAC address entries in the optimized address allocation table to obtain a MAC address interaction frequency matrix, and perform multi-dimensional time series decomposition based on the MAC address interaction frequency matrix to obtain an address usage pattern feature set. Interaction frequency analysis is a method of evaluating the activity level of MAC addresses based on their communication frequencies, which helps to identify which MAC addresses require longer aging times and which can be cleared more quickly. In this application scenario, assume that we have an enterprise data center with three switches A, B, and C, and each switch has multiple physical ports connected to different devices. The system will analyze the interaction frequency of each MAC address over a period of time, such as the number of communications per minute, hour, or day, to form a MAC address interaction frequency matrix. Next, the system will perform multi-dimensional time series decomposition on this matrix to separate the interaction frequency information at different time scales to reveal the usage patterns of MAC addresses. For example, some MAC addresses may communicate frequently during working hours and hardly have any activity during non-working hours; while other MAC addresses may remain active all day long. These usage patterns together constitute the address usage pattern feature set, providing a basis for subsequent aging time calculations.Subsequently, through the adaptive address aging time control mechanism, based on the address usage pattern feature set, dynamic aging time calculation is performed for each MAC address entry to obtain an initial aging time allocation table, and network load correlation analysis is carried out on the initial aging time allocation table to obtain a load-aware aging time adjustment matrix. Dynamic aging time calculation is a method that dynamically adjusts the aging time of a MAC address according to its actual usage situation, which can better adapt to network changes. In this process, the system will calculate a suitable initial aging time for each MAC address according to the information in the address usage pattern feature set and the specific usage situation of each MAC address. For example, in the application scenario of the above enterprise data center, the system may find that a certain MAC address is very active during working hours, so a longer aging time is allocated to it; while for those devices that are used occasionally, the system will allocate a shorter aging time. Next, the system will perform network load correlation analysis on the initial aging time allocation table, considering the overall load situation of the current network, and further adjust the aging time. For example, if the network load is high, the system may shorten the aging time of some low-priority MAC addresses to release more resources for critical business traffic. Finally, the system will generate a load-aware aging time adjustment matrix, recording the adjusted aging time corresponding to each MAC address. Then, anomaly detection is performed on the load-aware aging time adjustment matrix through the spatio-temporal correlation analysis mechanism to obtain an aging time anomaly marker set, and aging policy optimization processing is carried out based on the aging time anomaly marker set to obtain an optimized aging policy table. Spatio-temporal correlation analysis is a method for identifying abnormal behaviors, which can detect data points that do not conform to the expected pattern. In this process, the system will perform spatio-temporal correlation analysis on the data in the load-aware aging time adjustment matrix to identify which MAC address aging time settings may be abnormal. For example, in the application scenario of the above enterprise data center, the system may find that although some MAC addresses have hardly been active in the past few days, their aging times are set very long, which may be caused by historical configuration errors or other reasons. Through anomaly detection, the system can mark these abnormal aging time settings to form an aging time anomaly marker set. Next, the system will perform aging policy optimization processing based on these markers, adjusting these abnormal aging time settings to ensure that they conform to the current network usage situation. For example, for those MAC addresses that have not been active for a long time, the system may significantly shorten their aging times to prevent invalid entries from occupying too many resources. Finally, the system will generate an optimized aging policy table, recording the optimized aging time settings for each MAC address. Subsequently, hierarchical implementation and deployment are carried out on the optimized aging policy table to obtain a hierarchical aging policy implementation matrix, and periodic cleaning and update management are carried out on the optimized address allocation table based on the hierarchical aging policy implementation matrix.Hierarchical implementation and deployment is a method of gradually applying the aging strategy according to the network hierarchy, which helps to ensure the effectiveness and consistency of the strategy. In this process, the system will, based on the information in the optimized aging strategy table and combined with the actual hierarchy of the switch, deploy the aging strategy layer by layer to each level. For example, in the application scenario of the above enterprise data center, the system may first apply the aging strategy to the core layer switch to ensure the stability of critical business traffic; then sequentially apply the corresponding strategies to the aggregation layer and access layer switches. In this way, the system can generate a hierarchical aging strategy implementation matrix to record the strategy deployment situation corresponding to each level. Next, the system will perform periodic cleaning and update management on the optimized address allocation table based on this matrix. For example, the system will regularly check the entries in the MAC address table, automatically delete those entries that have exceeded the aging time and are no longer active according to the aging strategy, and update those entries that are still active. This can not only keep the MAC address table clean and efficient but also improve the stability and performance of the entire network system. For illustration, in the application scenario of the above enterprise data center, assume there is a core layer switch A, which is connected to multiple servers and aggregation layer switches B and C. The system will first analyze the interaction frequency of all MAC address entries on switch A to generate a MAC address interaction frequency matrix. Through multi-dimensional time series decomposition, the system finds that the MAC addresses of some servers communicate frequently during working hours and are almost inactive during non-working hours. Based on this, the system calculates a longer aging time for these MAC addresses and a shorter aging time for other inactive MAC addresses to form an initial aging time allocation table. Next, considering the current high network load, the system performs a network load correlation analysis on the initial aging time allocation table and further adjusts the aging time of some low-priority MAC addresses to obtain a load-aware aging time adjustment matrix. Through the spatio-temporal correlation analysis mechanism, the system discovers that there are abnormalities in the aging time settings of some MAC addresses. For example, the aging time of some long-unused MAC addresses is too long. The system performs optimization processing on its aging strategy to generate an optimized aging strategy table. Finally, the system deploys the optimized aging strategy layer by layer to switch A and its connected aggregation layer switches B and C to form a hierarchical aging strategy implementation matrix, and performs periodic cleaning and update management on the optimized address allocation table based on this matrix to ensure that the MAC address table always remains the latest and most effective state. For example, assume that the MAC address of a certain server has a large number of communication records every day in the past week. The system will assign a longer aging time (such as 24 hours) to ensure its connection status even during network fluctuations. While the MAC address of another printer that is only used occasionally will be assigned a shorter aging time (such as 1 hour) to reduce unnecessary resource occupancy.When the network load is high, the system will further adjust these aging times. For example, it will shorten the aging time of low-priority devices to 30 minutes to free up more resources for critical business traffic. Through spatio-temporal correlation analysis, the system finds that some MAC addresses have had little activity in the past few days, but their aging times are set very long. The system will adjust the aging times of these MAC addresses to 5 minutes and mark them as abnormal. After optimization, the system generates a new aging policy table and deploys these policies hierarchically to each switch level. Finally, the system regularly checks and cleans the entries in the MAC address table to ensure that only active MAC addresses are retained in the table, thereby improving the overall network performance and security. In summary, through a series of operations such as interaction frequency analysis, multi-dimensional time series decomposition, dynamic aging time calculation, network load correlation analysis, spatio-temporal correlation analysis, aging policy optimization, and hierarchical implementation and deployment of the MAC address entries in the optimized address allocation table, the aging time management of MAC addresses can be comprehensively and accurately carried out, and an optimized aging policy table can be generated. This method is particularly suitable for large and complex network environments and helps to implement more intelligent and refined network management strategies. In this way, administrators can not only timely discover and solve bottlenecks and faults in the network, but also effectively improve the performance and stability of the entire network system. This automated and intelligent network management method greatly improves work efficiency, reduces the need for manual intervention, and makes network operation and maintenance more efficient and reliable.
[0042] The above describes the switch address allocation and dynamic management method in the embodiments of the present invention. Next, the switch address allocation and dynamic management system in the embodiments of the present invention will be described. Please refer to Figure 2 , an embodiment of the switch address allocation and dynamic management system in the embodiments of the present invention includes: A collection module 21, configured to scan and collect physical port information of the switch to obtain a port status feature vector set; An inference module 22, configured to intelligently infer the network topology structure of the switch based on the port status feature vector set to obtain a switch topology relationship diagram; A partitioning module 23, configured to partition the address space of the switch topology relationship diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix; An allocation module 24, configured to dynamically allocate the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table; A management module 25, configured to perform life cycle management on the optimized address allocation table through an adaptive address aging time control mechanism.
[0043] In this embodiment, for the specific implementation of each unit in the above system embodiment, please refer to the above method embodiment, and details are not described herein again.
[0044] Referring to Figure 3 , an embodiment of the present invention further provides a computer device, and its internal structure may be as Figure 3 shown. The computer device includes a processor, a memory, a display screen, an input device, a network interface, and a database connected through a system bus. Among them, the processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store the corresponding data in this embodiment. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the above method is implemented.
[0045] Those skilled in the art can understand that Figure 3 the structure shown in
[0046] is only a block diagram of a part of the structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied.
[0047] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium provided by the present invention and used in the embodiments can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0048] It should be noted that in this document, the terms "include", "comprise", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, apparatus, article, or method including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, apparatus, article, or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article, or method including that element.
[0049] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied to other related technical fields, shall equally be included in the patent protection scope of the present invention.
Claims
1. A method for allocating and dynamically managing switch addresses, characterized in that: The following steps are involved: Scan and collect the physical port information of the switch to obtain a port state feature vector set; Based on the port state feature vector set, the network topology structure of the switch is intelligently inferred to obtain a switch topology relationship diagram; The address space of the switch topology diagram is divided by a distributed hash mapping mechanism to obtain an address allocation weight matrix; Dynamically assigning the MAC address table in the switch based on the address assignment weight matrix to obtain an optimized address assignment table; The optimized address allocation table is managed for its life cycle through an adaptive address aging time control mechanism.
2. The switch address allocation and dynamic management method according to claim 1, characterized in that: The scanning and collecting of the physical port information of the switch to obtain a port state feature vector set includes: Using a multi-threshold bandwidth monitoring technology to collect port traffic data on multiple physical ports of the switch to obtain a port traffic timing matrix; Performing spectrum analysis on the physical port of the switch based on the port traffic timing matrix to obtain a port bandwidth usage characteristic spectrum; The port bandwidth is subjected to multi-dimensional feature extraction using a feature spectrum through a self-organizing port state mapping mechanism to obtain a port state feature vector set.
3. The switch address allocation and dynamic management method according to claim 1, characterized in that: The intelligent inference of the network topology structure of the switch based on the port state feature vector set to obtain a switch topology relationship diagram includes: Performing multi-dimensional correlation analysis on the port state feature vector set to obtain a port connection relationship matrix, and performing high-order spectrum decomposition on the port connection relationship matrix to obtain a port topology feature spectrum; Based on the port topology feature spectrum, the physical ports of the switch are intelligently inferred to form hierarchical connections to obtain a port hierarchical connection graph, and the port hierarchical connection graph is pruned for redundant paths to obtain an optimized port connection topology graph; Performing node aggregation on the optimized port connection topology graph through a recursive boundary detection mechanism to obtain a switch node cluster, and performing link state analysis based on the switch node cluster to obtain an inter-switch link weight table; An optimal path calculation is performed on the inter-switch link weight table to obtain a switch backbone network topology, and edge node association mapping is performed on the switch backbone network topology to obtain a switch topology relationship diagram.
4. The switch address allocation and dynamic management method according to claim 1, characterized in that: The address space of the switch topology diagram is divided by a distributed hash mapping mechanism to obtain an address allocation weight matrix, including: Performing multi-dimensional fractal analysis on the switch topology relationship diagram to obtain a topology structure fractal dimension matrix, and performing hierarchical aggregation processing on the topology structure fractal dimension matrix to obtain a topology hierarchical structure diagram; The address space of the topological hierarchical structure diagram is divided by a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, and load balancing adjustment is performed based on the preliminary address allocation mapping table to obtain a load balancing address allocation table; Performing multipath routing optimization processing on the load balancing address allocation table to obtain an optimized address allocation path matrix, and performing conflict detection and resolution based on the optimized address allocation path matrix to obtain a conflict-resolved address allocation path matrix; The address allocation path matrix after the conflict is resolved is weighted by multi-dimensional address weight calculation to obtain an address allocation weight matrix.
5. The switch address allocation and dynamic management method according to claim 4, characterized in that: The address space of the topological hierarchical structure diagram is divided by a distributed hash mapping mechanism to obtain a preliminary address allocation mapping table, including: Pre-dividing the address space of the topological hierarchical structure diagram through a distributed hash mapping mechanism to obtain a pre-allocated address space set, and performing topology-aware hash key generation based on the pre-allocated address space set to obtain a topology-aware hash key set; Based on the topology-aware hash key set, the pre-allocated address space set is subjected to consistent hash mapping to obtain a consistent hash address mapping table, and the consistent hash address mapping table is subjected to virtual address space mapping to obtain a virtual address space mapping table; Dividing the switch topology relationship diagram into port groups based on the virtual address space mapping table to obtain a port group set, and allocating address blocks to the port group set to obtain an address block allocation table; The address block allocation table is subjected to cross-layer address merging to obtain a preliminary address allocation mapping table.
6. The switch address allocation and dynamic management method according to claim 1, characterized in that: The dynamically allocating the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table includes: Based on the address allocation weight matrix, traffic classification is performed on each MAC address in the MAC address table to obtain a MAC address traffic category matrix, and QoS policy mapping is performed on the MAC address traffic category matrix to obtain a MAC address QoS policy matrix; Virtualizing and dividing the port resources in the switch based on the MAC address QoS policy matrix to obtain a port resource virtualization pool, and dynamically allocating resources to the port resource virtualization pool to obtain a MAC address resource allocation table; Based on the MAC address resource allocation table, a security risk assessment is performed on each MAC address in the MAC address table to obtain a MAC address security risk level matrix, and a security policy is configured on the MAC address security risk level matrix to obtain a MAC address security policy table; Based on the MAC address security policy table, an access control list is bound to the MAC address table in the switch to obtain an ACL-bound MAC address table, and real-time security monitoring is performed on the ACL-bound MAC address table to obtain a security monitoring log; Dynamically adjust the security policy of the ACL-bound MAC address table based on the security monitoring log to obtain an optimized address allocation table.
7. The switch address allocation and dynamic management method according to claim 1, characterized in that: The performing lifecycle management on the optimized address allocation table by using an adaptive address aging time control mechanism includes: Performing interaction frequency analysis on the MAC address entries in the optimized address allocation table to obtain a MAC address interaction frequency matrix, and performing multi-dimensional time series decomposition based on the MAC address interaction frequency matrix to obtain an address usage pattern feature set; Through the adaptive address aging time control mechanism, dynamically calculate the aging time of each MAC address entry based on the address usage mode feature set to obtain an initial aging time allocation table, and perform network load correlation analysis on the initial aging time allocation table to obtain a load-aware aging time adjustment matrix; Anomaly detection is performed on the load-aware aging time adjustment matrix through a spatiotemporal correlation analysis mechanism to obtain an aging time anomaly mark set, and an aging strategy optimization process is performed based on the aging time anomaly mark set to obtain an optimized aging strategy table; The optimized aging strategy table is deployed in a hierarchical manner to obtain a hierarchical aging strategy implementation matrix, and the optimized address allocation table is periodically cleaned and updated based on the hierarchical aging strategy implementation matrix.
8. A switch address allocation and dynamic management system, characterized in that: include: A collection module, used to scan and collect the physical port information of the switch to obtain a port state feature vector set; An inference module, configured to perform intelligent inference of a network topology structure of the switch based on the port state feature vector set to obtain a switch topology relationship diagram; A partitioning module, used to partition the address space of the switch topology diagram through a distributed hash mapping mechanism to obtain an address allocation weight matrix; An allocation module, configured to dynamically allocate the MAC address table in the switch based on the address allocation weight matrix to obtain an optimized address allocation table; The management module is used to perform life cycle management on the optimized address allocation table through an adaptive address aging time control mechanism.
9. A computer device comprising a memory and a processor, wherein a computer program is stored in the memory, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.