Data flow monitoring method and system based on Internet communication
Through the data traffic monitoring method based on Internet communication, a traffic mode library is built using three-dimensional features, combined with dynamic period detection and multi-scale fusion, real-time abnormal collaborative verification and dynamic parameter correction, solving the problem of high false alarm rate, inability to accurately identify abnormal traffic and insufficient dynamic adaptability in the existing technology, and achieving high-precision and high-adaptive abnormal detection.
Patent Information
- Application Number
- CN202510776507.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-11
AI Technical Summary
The existing data traffic monitoring technology has problems such as high false alarm rate, inability to accurately identify abnormal traffic, insufficient dynamic adaptability, and difficulty in fusion of long-term and short-term traffic modes.
Through the data traffic monitoring method based on Internet communication, a traffic mode library is built using three-dimensional features, combining dynamic period detection and multi-scale fusion, real-time abnormal collaborative verification, parallel operation of threshold detectors and prediction detectors, dynamic parameter correction, and optimize PID control parameters using false positive feedback and reinforcement learning to achieve the integration of threshold adaptive adjustment and long-term and short-term traffic modes.
It significantly improves the accuracy of abnormal detection and the robustness of the system, reduces false alarms and missed reports, can quickly respond to short-term traffic changes and retain long-term traffic rules, and improves the system's adaptability and decision-making efficiency in complex network environments.
Smart Images

Figure CN120301802A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data traffic monitoring, and specifically to a data traffic monitoring method and system based on Internet communication. Background Art
[0002] In the field of Internet communication, data traffic monitoring is a key technology to ensure the stable operation and security of the network. With the continuous expansion of the network scale and the increase in traffic complexity, traditional data traffic monitoring methods face many challenges. For example, traditional monitoring methods usually rely on simple threshold detection, which is difficult to adapt to the dynamic changes of traffic and is prone to a large number of false alarms or missed reports. In addition, when existing monitoring systems process large-scale data, they often lack an accurate model for the periodic behavior of traffic, resulting in the inability to effectively distinguish normal traffic fluctuations from abnormal traffic.
[0003] Existing data traffic monitoring technologies have obvious limitations when facing complex network environments. On the one hand, traditional monitoring methods cannot effectively integrate multi-dimensional features (such as time, space, and content features), resulting in inaccurate identification of abnormal traffic. On the other hand, existing systems have deficiencies in dynamic parameter adjustment and are difficult to perform adaptive optimization based on real-time network status and false alarm feedback. In addition, existing technologies lack an effective fusion mechanism when dealing with long-term and short-term traffic patterns, resulting in insufficient robustness of the system in the face of sudden traffic changes.
[0004] To solve the above defects, a technical solution is provided now. Summary of the Invention
[0005] The purpose of the present invention is to solve the problems of high false alarm rate, inability to accurately identify abnormal traffic, insufficient dynamic adaptability, and difficulty in fusing long-term and short-term traffic patterns existing in existing data traffic monitoring technologies, and to propose a data traffic monitoring method and system based on Internet communication.
[0006] The purpose of the present invention can be achieved through the following technical solutions:
[0007] A data traffic monitoring method based on Internet communication includes the following steps:
[0008] Q1. Historical feature spatio-temporal modeling: Construct a traffic pattern library through three-dimensional features, and combine dynamic period detection and multi-scale fusion to extract normal periodic behaviors and abnormal patterns, providing a benchmark model for subsequent detection;
[0009] Q2. Real-time anomaly collaborative verification: Run a threshold detector and a prediction detector in parallel, and adjust the multi-dimensional score through scene-aware dynamic weights to distinguish real anomalies from false alarms;
[0010] Q3. Dynamic parameter correction, based on false alarm feedback and reinforcement learning to optimize PID control parameters, combined with an exponentially decaying update mode library, to achieve the fusion of threshold adaptive adjustment and long-term and short-term traffic patterns, and improve the system robustness.
[0011] Further, the specific process of the above Q1 is as follows:
[0012] Establish a traffic feature tensor: Define a three-dimensional feature space , and comprehensively describe the time, space, and content characteristics of traffic through the three-dimensional feature space;
[0013] Among them: T is the time dimension, including the hourly trend and minute-level fluctuations;
[0014] S is the space dimension, based on the distribution entropy values of the source IP and destination IP;
[0015] C is the content dimension, the payload entropy , where represents entropy, represents the probability that the random variable x takes a specific value, x is a random variable, and log is the operation of taking the logarithm of the probability ;
[0016] Construct a typical mode library, periodic pattern extraction: , through the periodic stacking of historical data; among them is the periodic pattern function, Td is the traffic period, is the global historical period number, is the eigenvalue at time point t in the kth period;
[0017] The abnormal mode clustering uses an improved DBSCAN algorithm, and the density threshold is defined as: , is the neighborhood sample mean, is the standard deviation.
[0018] Further, a dynamic period detection algorithm and a multi-scale feature fusion mechanism are added to the periodic pattern extraction in the above Q1, and the process is as follows:
[0019] Perform a fast Fourier transform on the historical traffic data : , extract the frequencies of the significant peaks in the amplitude spectrum , and calculate the candidate period ; among them is the Fourier transform result of the historical traffic data ; j is the ordinal unit, w is the angular function, and t is the time;
[0020] Define the period stability index: , where M is the number of verification periods, and retain The period; where is the period stability index, m is the m-th verification period, is the correlation function, and Td is the traffic period;
[0021] If multiple valid periods are detected , reconstruct the period pattern: , where is the number of historical periods corresponding to each period, is the number of candidate periods;
[0022] Expand the time dimension T into a multi-scale structure: , and calculate the trend components at each scale respectively ;
[0023] Dynamically fuse multi-scale features through the attention mechanism: , , is the attention weight of each time scale, is the trainable weight parameter, Time scale type.
[0024] Furthermore, the specific operation steps of the Q2 are as follows:
[0025] Parallel computing by multiple detectors, threshold detector: , detect instantaneous anomalies based on the 3σ principle. If the current value exceeds three times the standard deviation of the historical mean, an alarm is triggered; where are the historical mean and historical standard deviation respectively, and x is the current traffic feature value;
[0026] The prediction detector uses an LSTM model, and the anomaly criterion is: , where are the actual observed value and the predicted value of the LSTM model respectively, is the error tolerance threshold; by comparing the relative error between the actual value and the predicted value, identify the traffic anomaly deviation caused by attacks or congestion;
[0027] Verify the decision function, and the comprehensive scoring formula is: ;
[0028] Among them: is the temporal similarity, measuring the temporal correlation between the current time point and historical anomaly events. In the formula is the time decay coefficient, is the timestamp of the historical anomaly event;
[0029] , measure the similarity between the current traffic and historical anomalies in spatial features through cosine similarity, is the traffic space feature vector; is the adjustable weight coefficient.
[0030] Furthermore, on the verification decision function in Q2, a scenario-aware dynamic weight adjustment algorithm is introduced. By analyzing traffic characteristics and network environment in real time, the weight coefficients in the time, space, and content dimensions are automatically optimized. The specific process is as follows:
[0031] Extract the following environmental indicators:
[0032] Traffic type;
[0033] Network load rate;
[0034] Known threat intelligence matching degree;
[0035] Map the environmental state to a feature vector: , where the traffic type uses one-hot encoding;
[0036] Construct a lightweight neural network model, with the input being the scenario feature vector , and the output being the weight coefficient: , where W and b are model parameters, trained with historical data, and the objective function is to minimize the verification error;
[0037] Recalculate the weights every 5 minutes. If the environmental state changes by more than the threshold, trigger the weight update immediately;
[0038] The constraint condition is: forcefully satisfy , and ensure the output is legal through the Lagrange multiplier method;
[0039] To avoid sudden weight changes, adopt smoothing processing: , where is the smoothing factor.
[0040] Furthermore, the specific operation steps of Q3 are as follows:
[0041] False alarm feature analysis, define the feature drift degree: , quantifying the degree to which the current feature deviates from the historical normal range, where is the current feature value, are the historical feature mean and standard deviation respectively;
[0042] When , trigger the parameter update;
[0043] Adaptive threshold adjustment, adopt proportional-integral control: , where are the proportional and integral coefficients;
[0044] The error term i.e., the target false alarm rate - the actual value;
[0045] Dynamically adjust the detection threshold through PID control, automatically reduce the sensitivity when the false alarm rate is too high, and increase it otherwise;
[0046] Incremental update of the pattern library, update strategy: , where is the attenuation factor, , hour time constant, is the current traffic pattern.
[0047] Furthermore, a parameter optimization module driven by reinforcement learning is introduced in Q3, and the proportional coefficient and integral coefficient are automatically optimized through real-time feedback. The specific operation steps are as follows:
[0048] Define the environmental state Senv to include: the current false alarm rate , network load rate L = current bandwidth usage / total bandwidth, and recent attack type distribution;
[0049] Define the action A as the adjustment of PID parameters: , , and limit the single adjustment amplitude;
[0050] Multi-objective reward function: , where is the weight coefficient; is the threshold adjustment amplitude;
[0051] Construct a deep Q network, with the input being the environmental state Senv and the output being the Q values of each action space A: , where Senv is the environmental state and A is the action space, are the network parameters;
[0052] Store historical state transition data , sample batch data every 10 minutes to update the network parameters, and preferentially replay high-reward experiences;
[0053] Forcefully constrain the PID parameter range: , , to prevent unreasonable values from being generated during the learning process; if the false alarm rate increases by more than 5% after 3 consecutive adjustments, automatically roll back to the previous stable parameter configuration.
[0054] An Internet communication-based data traffic monitoring system, including:
[0055] A multi-dimensional feature modeling module, used to construct a traffic feature tensor through a three-dimensional feature space, and generate a historical traffic pattern library by combining dynamic period detection and multi-scale fusion;
[0056] A real-time anomaly detection module, which is used to run a threshold detector and a prediction detector in parallel to capture traffic anomalies in real time;
[0057] A decision verification module, which is used to verify the authenticity of anomalies through a scenario-aware dynamic weight adjustment algorithm, combined with multi-dimensional similarity scores of time series, space, and content;
[0058] A parameter dynamic optimization module, which is used to online optimize the PID control parameters by using reinforcement learning, and automatically adjust the detection threshold and the pattern library update strategy in combination with false alarm feedback;
[0059] A knowledge base management module, which is used to store historical traffic patterns, anomaly feature vectors, and optimization parameters, and supports incremental updates and multi-version backtracking.
[0060] Compared with the prior art, the beneficial effects of the present invention are:
[0061] (1) In the present invention, through multi-dimensional feature modeling (time, space, and content dimensions) and a dynamic period detection mechanism, the traffic characteristics can be comprehensively and accurately described, and the normal periodic behavior and abnormal patterns can be effectively extracted. At the same time, combined with the improved DBSCAN algorithm and the multi-scale feature fusion mechanism, the recognition ability of low-density abnormal points is enhanced, the accuracy and effectiveness of anomaly detection are significantly improved, and the false alarm and missed alarm phenomena are reduced;
[0062] (2) In the present invention, a dynamic parameter correction mechanism based on false alarm feedback and reinforcement learning is introduced. The detection threshold is dynamically adjusted through proportional-integral control (PID), and the pattern library is updated in combination with the exponential decay strategy. This adaptive adjustment mechanism can automatically optimize the detection parameters according to the real-time network state and false alarm feedback, quickly respond to short-term traffic changes, and at the same time retain the long-term traffic rules, significantly improving the robustness and adaptability of the system in a complex network environment;
[0063] (3) In the present invention, a scenario-aware dynamic weight adjustment algorithm is adopted, which can analyze the traffic characteristics and network environment in real time, automatically optimize the multi-dimensional scoring weights, and accurately distinguish real anomalies from false alarms. In addition, the system stores historical traffic patterns, anomaly feature vectors, and optimization parameters through the knowledge base management module, and supports incremental updates and multi-version backtracking, which is convenient for management and optimization, and further improves the decision-making efficiency and management convenience of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings;
[0065] Figure 1 It is the system general block diagram of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0066] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0067] It should be understood that the terms "including" and "comprising" used in the specification and claims of this disclosure indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0068] It should also be understood that the terms used in this disclosure specification are only for the purpose of describing specific embodiments and are not intended to limit this disclosure. As used in this disclosure specification and claims, unless the context clearly indicates otherwise, the singular forms "a", "an", and "the" are intended to include the plural forms. It should also be further understood that the term "and / or" used in this disclosure specification and claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0069] As Figure 1 shown, a data traffic monitoring method based on Internet communication includes the following steps:
[0070] Step 1. Historical feature spatio-temporal modeling. Build a traffic pattern library through three-dimensional features (time, space, and content dimensions), combine dynamic period detection and multi-scale fusion, extract normal periodic behaviors and abnormal patterns, and provide a benchmark model for subsequent detection;
[0071] Establish a traffic feature tensor: Define a three-dimensional feature space , comprehensively describe the time, space, and content characteristics of traffic through the three-dimensional feature space, and provide a structured data basis for subsequent pattern analysis; where: T is the time dimension, including hourly trends and minute-level fluctuations; S is the space dimension, based on the distribution entropy values of the source IP and the destination IP (measuring the randomness of the IP address distribution); C is the content dimension (payload entropy , where represents entropy (information entropy), used to measure the amount of information in the data packet content, represents the probability that the random variable x takes a certain specific value, x is a random variable, and log is the operation of taking the logarithm of the probability ), used to measure the amount of information in the data packet content;
[0072] Build a typical pattern library, extract periodic patterns: , by superimposing the cycles of historical data, a stable traffic pattern is extracted to identify normal periodic behaviors (such as daily business peaks); among them is the periodic pattern function, Td is the traffic period, is the global historical cycle number, is the eigenvalue at time point t in the k-th cycle; a dynamic cycle detection algorithm and a multi-scale feature fusion mechanism are added to the periodic pattern extraction, and the process is as follows:
[0073] For historical traffic data Perform a fast Fourier transform (FFT): , extract the frequencies of the significant peaks in the amplitude spectrum , calculate the candidate period ; among them is the Fourier transform result of the historical traffic data ; j is the ordinal unit, w is the angular function, and t is the time;
[0074] Define the period stability index: , where M is the number of verification cycles, and retain the period of ; among them is the period stability index, m is the m-th verification cycle, is the correlation function, and Td is the traffic period;
[0075] If multiple valid cycles are detected , reconstruct the periodic pattern: , where is the historical cycle number corresponding to each cycle, is the number of candidate periods; expand the time dimension T into a multi-scale structure: , calculate the trend component at each scale ; dynamically fuse multi-scale features through an attention mechanism: , , where is the attention weight of each time scale, is the trainable weight parameter, time scale type (second level, hour level, week level).
[0076] The improved DBSCAN algorithm is used for abnormal pattern clustering, and the density threshold is defined as: , is the mean of the neighborhood samples, is the standard deviation; in the improved DBSCAN algorithm, by reducing the density threshold (mean minus twice the standard deviation), the ability to identify low-density abnormal points is enhanced.
[0077] Step 2: Real-time anomaly collaborative verification. Run the threshold detector (3σ principle) and the prediction detector (LSTM model) in parallel. Adjust the multi-dimensional scores (time series, space, content) dynamically through scenario awareness, and accurately distinguish real anomalies from false alarms;
[0078] Parallel computing of multiple detectors. Threshold detector: , detect instantaneous anomalies based on the 3σ principle. If the current value exceeds three times the standard deviation of the historical mean, an alarm is triggered; where are the historical mean and historical standard deviation respectively, and x is the current traffic feature value;
[0079] The prediction detector uses the LSTM model, and the anomaly criterion is: , where are the actual observed value and the predicted value of the LSTM model respectively, is the error tolerance threshold; by comparing the relative error between the actual value and the predicted value, identify the traffic anomaly deviation caused by attacks or congestion;
[0080] Verification decision function. The comprehensive scoring formula is: ; where: (time series similarity), measure the time series correlation between the current time point and historical anomaly events. In the formula is the time decay coefficient, is the timestamp of the historical anomaly event; , measure the similarity of the current traffic and historical anomalies in spatial features through cosine similarity, is the traffic spatial feature vector; is the adjustable weight coefficient.
[0081] In the verification decision function, introduce a dynamic weight adjustment algorithm with scenario awareness, and automatically optimize the weight coefficients in the time, space, and content dimensions by real-time analyzing traffic features and network environments; the specific process is as follows:
[0082] Extract the following environmental indicators: traffic type (Web, video stream, IoT device, etc.); network load rate (current bandwidth usage / total bandwidth); known threat intelligence matching degree (such as IP blacklist hit rate);
[0083] Map the environmental state to a feature vector: , where the traffic type uses one-hot encoding (such as Web = 001, video stream = 010, IoT = 100);
[0084] Build a lightweight neural network model (3-layer fully connected), with the input being the scenario feature vector , and the output being the weight coefficient: , where \(W\) and \(b\) are model parameters, trained with historical data, and the objective function is to minimize the validation error; the weights are recalculated every 5 minutes, and if the environmental state changes by more than a threshold (e.g., load rate fluctuation > 20%), the weight update is triggered immediately;
[0085] The constraint is: forced to satisfy , and the Lagrange multiplier method is used to ensure legal output; to avoid weight mutation, smoothing processing is adopted: , where is the smoothing factor, with an initial value of 0.7.
[0086] Step 3. Dynamic parameter correction, based on false alarm feedback and reinforcement learning to optimize the PID control parameters, combined with the exponentially decaying update mode library, to achieve efficient fusion of threshold self - adaptation and long - term / short - term traffic patterns, and improve the system robustness;
[0087] False alarm feature analysis, define the feature drift degree: , quantifying the degree to which the current feature deviates from the historical normal range, where is the current feature value, are the historical feature mean and standard deviation respectively; when the parameter update is triggered;
[0088] Adaptive threshold adjustment, using proportional - integral control: , where are the proportional and integral coefficients; the error term (target false alarm rate - actual value); the detection threshold is dynamically adjusted through PID control, automatically reducing the sensitivity when the false alarm rate is too high, and vice versa;
[0089] Mode library incremental update, update strategy: , where is the decay factor, ( hour time constant), is the current traffic pattern; the new and old patterns are fused according to exponential decay, retaining long - term patterns while quickly responding to short - term changes.
[0090] Introduce a parameter optimization module driven by reinforcement learning, which automatically optimizes the proportional coefficient and the integral coefficient through real - time feedback, and the specific steps are as follows:
[0091] Define the environmental state \(S_{env}\) to include: the current false alarm rate , the network load rate \(L=\) current bandwidth usage / total bandwidth, and the recent attack type distribution (such as the proportion of DDoS, port scanning, data leakage); define the action \(A\) as the adjustment of the PID parameters: , , limit the single - adjustment amplitude to avoid parameter mutation;
[0092] Multi - objective reward function: , where are weight coefficients, initially set to 0.5, 0.3, and 0.2 respectively; is the threshold adjustment amplitude (penalize drastic fluctuations);
[0093] Build a Deep Q - Network (DQN), with the input being the environmental state Senv and the output being the Q - values of each action A: , where Senv is the environmental state and A is the action space, are network parameters; store historical state - transition data , update the network parameters by sampling batch data every 10 minutes, and preferentially replay high - reward experiences; forcefully constrain the PID parameter range: , , prevent unreasonable values from being generated during the learning process; if the false - alarm rate increases by more than 5% after 3 consecutive adjustments, then automatically roll back to the previous stable parameter configuration.
[0094] An Internet - communication - based data traffic monitoring system, including a multi - dimensional feature modeling module, a real - time anomaly detection module, a decision verification module, a parameter dynamic optimization module, and a knowledge - base management module;
[0095] The multi - dimensional feature modeling module constructs a traffic feature tensor through a three - dimensional feature space (time dimension, space dimension, content dimension), and combines dynamic period detection and multi - scale fusion to generate a historical traffic pattern library;
[0096] The real - time anomaly detection module runs a threshold detector (based on the 3σ principle) and a prediction detector (LSTM time - series prediction) in parallel to capture traffic anomalies in real - time;
[0097] The decision verification module verifies the authenticity of anomalies through a scenario - aware dynamic weight adjustment algorithm, combined with multi - dimensional similarity scores of time series, space, and content;
[0098] The parameter dynamic optimization module uses reinforcement learning (DQN) to online optimize the PID control parameters, and automatically adjusts the detection threshold and the pattern - library update strategy in combination with false - alarm feedback;
[0099] The knowledge - base management module stores historical traffic patterns, anomaly feature vectors, and optimization parameters, and supports incremental updates and multi - version backtracking.
[0100] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments only. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and utilize the present invention well. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A data traffic monitoring method based on Internet communication, characterized in that, It includes the following steps: Q1. Historical feature spatio-temporal modeling: Construct a traffic pattern library through three-dimensional features, combine dynamic period detection and multi-scale fusion to extract normal periodic behaviors and abnormal patterns, and provide a benchmark model for subsequent detection; Q2. Real-time anomaly collaborative verification: Run the threshold detector and the prediction detector in parallel, and adjust the multi-dimensional score through scene-aware dynamic weight to distinguish real anomalies from false alarms; Q3. Dynamic parameter correction: Optimize the PID control parameters based on false alarm feedback and reinforcement learning, and combine the exponential decay to update the pattern library to achieve adaptive adjustment of the threshold and the fusion of long-term and short-term traffic patterns, improving the robustness of the system.
2. The data traffic monitoring method based on Internet communication according to claim 1, characterized in that The specific process of Q1 is as follows: Build a traffic feature tensor: Define a three-dimensional feature space , and comprehensively describe the time, space, and content characteristics of traffic through the three-dimensional feature space; Where: T is the time dimension, including hourly trends and minute-level fluctuations; S is the spatial dimension, based on the distribution entropy values of the source IP and the destination IP; C is the content dimension, the payload entropy , where represents entropy, represents the probability that the random variable x takes a specific value, x is a random variable, and log is the operation of taking the logarithm of the probability taking the logarithm operation; Construct a typical pattern library and extract periodic patterns: , through the periodic superposition of historical data; where is the periodic pattern function, Td is the flow period, is the global historical period number, is the eigenvalue at time point t in the k-th period; The abnormal mode clustering adopts an improved DBSCAN algorithm, and the density threshold is defined as: , is the mean of the neighborhood samples, is the standard deviation.
3. A method for monitoring data traffic based on Internet communication according to claim 2, characterized in that, In Q1, a dynamic period detection algorithm and a multi-scale feature fusion mechanism are added to the period pattern extraction, and the process is as follows: For historical traffic data Perform a fast Fourier transform: , extract the frequencies of the significant peaks in the amplitude spectrum , and calculate the candidate periods ; where is the Fourier transform result of the historical traffic data ; j is the ordinal unit, w is the angular function, and t is the time; Define the cycle stability index: , where M is the number of verification cycles, retaining cycles; where is the cycle stability index, m is the m-th verification cycle, is the correlation function, and Td is the flow cycle; If multiple valid cycles are detected , reconstruct the cycle pattern: , where is the number of historical cycles corresponding to each cycle, is the number of candidate cycles; Expand the time dimension T into a multi-scale structure: , and calculate the trend components at each scale respectively ; Dynamically fuse multi-scale features through the attention mechanism: , , are the attention weights for each time scale, is the trainable weight parameter, time scale type.
4. A data traffic monitoring method based on Internet communication according to claim 1, characterized in that The specific operation steps of Q2 are as follows: Multi-detector parallel computing, threshold detector: , detecting instantaneous anomalies based on the 3σ principle. If the current value exceeds three times the standard deviation of the historical mean, an alarm is triggered; where are the historical mean and the historical standard deviation respectively, and x is the current traffic characteristic value; The prediction detector uses an LSTM model, and the anomaly criterion is as follows: , where are the actual observed value and the predicted value of the LSTM model respectively, is the error tolerance threshold; by comparing the relative errors between the actual value and the predicted value, traffic anomalies caused by attacks or congestion are identified; Verify the decision function. The comprehensive scoring formula is as follows: ; Wherein: is the temporal similarity, measuring the temporal correlation between the current time point and historical abnormal events. In the formula is the time decay coefficient, is the timestamp of the historical abnormal event; , measuring the similarity between the current traffic and historical anomalies in spatial features through cosine similarity, is the traffic spatial feature vector; is the adjustable weight coefficient.
5. A data traffic monitoring method based on Internet communication according to claim 4, characterized in that, In the verification decision function of Q2, a scene-aware dynamic weight adjustment algorithm is introduced. By real-time analyzing traffic features and network environment, the weight coefficients in the time, space, and content dimensions are automatically optimized. The specific process is as follows: Extract the following environmental indicators: Traffic type; Network load rate; Known threat intelligence matching degree; Map the environmental state to a feature vector: , where the traffic type uses one-hot encoding; Build a lightweight neural network model with the input being the scene feature vector , and the output being the weight coefficients: , where W and b are model parameters, trained with historical data, and the objective function is to minimize the validation error; Recalculate the weights every 5 minutes. If the environmental state changes exceed the threshold, trigger the weight update immediately; The constraint is: forced to satisfy , and the Lagrange multiplier method is used to ensure legal output; To avoid sudden changes in weights, smoothing processing is adopted: , where is the smoothing factor.
6. A method for monitoring data traffic based on Internet communication according to claim 1, characterized in that, The specific operation steps of Q3 are as follows: False alarm feature analysis, defining the feature drift degree: , quantifying the degree to which the current feature deviates from the historical normal range, where is the current feature value, are the historical feature mean and standard deviation respectively; When the parameter update is triggered; Adaptive threshold adjustment, using proportional-integral control: , where are the proportional and integral coefficients; Error term That is, the target false alarm rate - the actual value; Dynamically adjust the detection threshold through PID control, automatically reduce the sensitivity when the false alarm rate is too high, and vice versa; Incremental update of the pattern library, update strategy: , where is the decay factor, , hour time constant, is the current traffic pattern.
7. A data traffic monitoring method based on Internet communication according to claim 6, characterized in that A parameter optimization module driven by reinforcement learning is introduced in Q3, and the proportional coefficient is automatically optimized through real-time feedback and the integral coefficient , and the specific operation steps are as follows: Define the environmental state Senv to include: the current false alarm rate , the network load rate L = the current bandwidth usage / the total bandwidth, and the recent attack type distribution; Define Action A as the adjustment of PID parameters: , , and limit the amplitude of single adjustment; Multi-objective reward function: , where is the weight coefficient; is the threshold adjustment range; Build a deep Q-network, with the environmental state Senv as the input and the Q-values of each action space A as the output: , where Senv is the environmental state and A is the action space, and are the network parameters; Store historical state transition data , sample batch data every 10 minutes to update network parameters, and preferentially replay high-reward experiences; Forcibly restrict the PID parameter range: , , to prevent unreasonable values from occurring during the learning process; if the false alarm rate increases by more than 5% after three consecutive adjustments, it will automatically roll back to the previous stable parameter configuration.
8. A system applied to the data traffic monitoring method based on Internet communication according to any one of claims 1-7, characterized in that, It includes: A multi-dimensional feature modeling module, which is used to construct a traffic feature tensor through a three-dimensional feature space, combine dynamic period detection and multi-scale fusion to generate a historical traffic pattern library; A real-time anomaly detection module, which is used to run the threshold detector and the prediction detector in parallel to capture traffic anomalies in real time; A decision verification module, which is used to verify the authenticity of anomalies through a scene-aware dynamic weight adjustment algorithm, combined with multi-dimensional similarity scores in time series, space, and content; A parameter dynamic optimization module, which is used to online optimize the PID control parameters using reinforcement learning, and automatically adjust the detection threshold and the pattern library update strategy combined with false alarm feedback; A knowledge base management module, which is used to store historical traffic patterns, anomaly feature vectors, and optimized parameters, and support incremental updates and multi-version backtracking.
Citation Information
Patent Citations
Anomaly traffic detection methods and device
CN109413071A
Industrial control network flow anomaly detection method and device based on deep learning
CN113162811A
Network traffic abnormity monitoring method and device based on BiLSTM-Att network
CN119232490A
Database adaptive data flow acquisition optimization method and system based on reinforcement learning
CN119719783A
Vortex shedding flowmeter monitoring method and device based on deep learning, medium and product
CN119884694A
Cited By
Wind speed monitoring identification method and system based on pattern matching
CN120492951A
Cache-aware data self-driven traffic anomaly online detection method and system, computer equipment and readable storage medium
CN120956538A
A cache-aware data self-driven traffic anomaly online detection method, system, computer device and readable storage medium
CN120956538B
Base station flow prediction method based on spatio-temporal characteristic joint representation
CN121463080A
Abnormal attack identification method and system based on flow data analysis
CN122027370A