Traffic data scheduling method and device, nonvolatile storage medium and electronic equipment
By extracting multiple traffic features in PCDN and using machine learning and graph neural networks for traffic classification and malicious node detection, combined with reinforcement learning and blockchain technology, the problems of insufficient identification and unintelligent scheduling in PCDN traffic management are solved, and efficient, transparent and secure traffic management is achieved.
Patent Information
- Application Number
- CN202510639398.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-18
AI Technical Summary
The existing technology cannot accurately identify traffic data of peer content distribution network (PCDN) which leads to the inability to efficiently manage PCDN traffic data, and there are problems such as insufficient traffic classification accuracy, limitations of malicious node detection, insufficient intelligence in traffic scheduling, and lack of transparency in governance mechanisms.
By extracting various characteristics of traffic data, such as statistical features, timing behavior characteristics and protocol fingerprint features, using machine learning models for traffic classification and malicious node detection, combining graph neural network to analyze traffic interaction diagrams, using reinforcement learning optimization scheduling strategies, and trustworthy supervision through blockchain technology to achieve efficient management of PCDN.
It improves the accuracy of PCDN traffic recognition, enhances the detection capabilities of malicious nodes, optimizes bandwidth utilization, improves the transparency and credibility of governance, and ensures the rationality and security of traffic scheduling.
Smart Images

Figure CN120342964A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular, to a traffic data scheduling method, apparatus, non-volatile storage medium, and electronic device. Background Art
[0002] At present, PCDN (Peer-to-Peer Content Delivery Network) traffic has been widely used in communication systems. However, in related technologies, it is impossible to accurately identify PCDN traffic data from various types of traffic data in the communication system, resulting in the inability to manage PCDN traffic data.
[0003] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0004] Embodiments of the present application provide a traffic data scheduling method, apparatus, non-volatile storage medium, and electronic device, so as to at least solve the technical problem that in related technologies, due to the inability to accurately identify peer-to-peer content delivery network traffic data, the traffic data of the peer-to-peer content delivery network cannot be efficiently scheduled and managed.
[0005] According to one aspect of the embodiments of the present application, a traffic data scheduling method is provided, including: determining multiple traffic characteristics of each traffic data in the original traffic dataset, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; identifying target traffic data from the original traffic dataset according to the multiple traffic characteristics, where the target traffic data is peer-to-peer content delivery network traffic data; determining a target traffic interaction graph according to the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer-to-peer content delivery network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; and scheduling and managing the peer-to-peer content delivery network according to the target traffic interaction graph.
[0006] Optionally, identifying target traffic data from the original traffic dataset according to the multiple traffic characteristics includes: determining the classification probability of each traffic data in the original traffic dataset through a first classification model, where the classification probability is the probability that the type of each traffic data is peer-to-peer content delivery network traffic data; and determining that the traffic data with the corresponding classification probability greater than the preset probability threshold is the target traffic data.
[0007] Optionally, the method further includes: adding a random offset to the traffic behavior characteristics of the target node to obtain test traffic data, where the target node is any node in the target traffic interaction graph, and the value range of the random offset is within a preset range; determining the traffic data type corresponding to the traffic behavior characteristics of the target node identified according to the second classification model; training the linear interpretable model based on the test traffic data and the traffic data type, so as to determine the feature weights of various traffic features; determining the importance ranking of various traffic features according to the feature weights.
[0008] Optionally, according to the target traffic interaction graph, scheduling and managing the peer-to-peer content distribution network includes: according to the target traffic interaction graph, determining the embedding representation of each node in the target traffic interaction graph, where the embedding representation is used to reflect the interaction relationship between the node and its adjacent nodes, and the adjacent nodes of the node are the nodes that have edge connections with the node; processing the embedding representation of each node through the second classification model, and obtaining the malicious node probability corresponding to each node, where the malicious node probability is the probability that the node is a malicious node, and the malicious node is a node with a violation; determining the nodes with corresponding malicious node probabilities greater than the preset probability threshold as malicious nodes; adjusting the scheduling and management strategy of the peer-to-peer content distribution network according to the malicious nodes in the target traffic interaction graph, where the scheduling and management strategy includes the bandwidth allocation strategy and node permissions.
[0009] Optionally, according to the target traffic interaction graph, determining the embedding representation of each node in the target traffic interaction graph includes: for each node in the target traffic interaction graph, iteratively updating the node feature vector of each node according to the node feature vectors of its adjacent nodes, so as to obtain the embedding representation of each node, where in the first round of iteration, the node feature vector is used to reflect the traffic information of the node, and the traffic information includes traffic behavior information and bandwidth usage.
[0010] Optionally, according to the target traffic interaction graph, scheduling and managing the peer-to-peer content distribution network includes: determining the state space, action space and reward function of the peer-to-peer content distribution network, where the state space includes the network topology structure, bandwidth utilization and node user request status of the state space, the action space includes the action strategies that the agent can take, and the action strategies include the data flow path selection strategy. The agent is used to schedule the data traffic of the peer-to-peer content distribution network, and the reward function is used to determine the state evaluation value of the peer-to-peer content distribution network, and the higher the state evaluation value, the better the state of the peer-to-peer content distribution network; training the agent according to the state space, action space and reward function, and after the training is completed, using the agent to schedule and manage the peer-to-peer content distribution network based on the target traffic interaction graph.
[0011] Optionally, scheduling and managing the peer-to-peer content distribution network according to the target traffic interaction diagram includes: determining each peer content distribution network node in the peer-to-peer content distribution network according to the target traffic interaction diagram; determining the behavior data of each peer content distribution network node, where the behavior data includes at least one of the following: traffic forwarding behavior records, content request logs, bandwidth usage, and reputation scores; determining the behavior hash values corresponding to the behavior data of the peer content distribution network nodes, and storing the behavior hash values in the blockchain ledger; reading the behavior hash values of each peer content distribution network node recorded in the blockchain ledger according to a preset period, and determining the traffic scheduling priorities of each peer content distribution network node according to the behavior hash values.
[0012] Optionally, the reputation score is determined in the following manner: determining the normal traffic forwarding ratio, the number of violations punishment times, and the bandwidth contribution rate of the peer content distribution network node; determining the reputation score of the peer content distribution network node according to the normal traffic forwarding ratio, the number of violations punishment times, and the bandwidth contribution rate of the peer content distribution network node.
[0013] Optionally, the statistical features include the mean packet size and the traffic directionality ratio.
[0014] Optionally, the time-series behavior features include the traffic burstiness and the coefficient of variation of traffic intervals. Among them, the traffic burstiness is used to reflect the degree of change in the packet size of traffic data, and the coefficient of variation of traffic intervals is used to reflect the fluctuation of the arrival time intervals of traffic packets in traffic data.
[0015] Optionally, the protocol fingerprint features include the transport layer security protocol handshake features and the request-response mode features.
[0016] According to another aspect of the embodiments of the present application, there is also provided a traffic data scheduling device, including: a first processing module, configured to determine various traffic features of each traffic data in the original traffic dataset, where the traffic features include statistical features, time-series behavior features, and protocol fingerprint features; a second processing module, configured to identify target traffic data from the original traffic dataset according to the various traffic features, where the target traffic data is peer-to-peer content distribution network traffic data; a third processing module, configured to determine a target traffic interaction diagram according to the target traffic data, where the target traffic interaction diagram includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; a fourth processing module, configured to schedule and manage the peer-to-peer content distribution network according to the target traffic interaction diagram.
[0017] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided. A program is stored in the non-volatile storage medium. When the program runs, it controls the device where the non-volatile storage medium is located to execute the traffic data scheduling method.
[0018] According to another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory and a processor. The processor is used to run the program stored in the memory. When the program runs, it executes the traffic data scheduling method.
[0019] According to another aspect of the embodiments of the present application, a computer program product is further provided, including a computer program. When the computer program is executed by a processor, it implements the traffic data scheduling method.
[0020] In the embodiments of the present application, multiple traffic characteristics of each traffic data in the original traffic dataset are determined. Among them, the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; target traffic data is identified from the original traffic dataset based on the multiple traffic characteristics. The target traffic data is peer content distribution network traffic data; a target traffic interaction graph is determined based on the target traffic data. The target traffic interaction graph includes nodes and edges. The nodes are peer content distribution network nodes, and the edges are used to reflect the traffic transmission relationship between different nodes. The weight of the edge is used to reflect the data exchange frequency between different nodes; the method of scheduling and managing the peer content distribution network based on the target traffic interaction graph, by determining the type of traffic data according to multiple traffic characteristics, achieves the purpose of accurately identifying peer content distribution network traffic data from the traffic data, thereby realizing the technical effect of efficiently managing the peer content distribution network traffic data, and further solving the technical problem that the traffic data of the peer content distribution network cannot be efficiently scheduled and managed due to the inability to accurately identify the peer content distribution network traffic data in the related art. Description of the Drawings
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0022] Figure 1 is a schematic structural diagram of a computer terminal (mobile terminal) provided according to an embodiment of the present application;
[0023] Figure 2 is a schematic flowchart of a traffic data scheduling method provided according to an embodiment of the present application;
[0024] Figure 3 is a schematic flowchart of a traffic data scheduling process provided according to an embodiment of the present application;
[0025] Figure 4 It is a schematic flowchart of a traffic data scheduling interaction process provided according to an embodiment of the present application;
[0026] Figure 5 It is a schematic structural diagram of a traffic data scheduling device provided according to an embodiment of the present application. Detailed implementation manners
[0027] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0028] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these process, method, product or device.
[0029] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:
[0030] PCDN (Peer-to-Peer Content Delivery Network, peer content delivery network): PCDN is a hybrid architecture that combines P2P (peer-to-peer) technology and CDN (content delivery network) technology, allowing user devices (such as PCs, smartphones, set-top boxes) to act as both content consumers and content distribution nodes, thereby improving content distribution efficiency and reducing server pressure. However, due to the distributed characteristics of PCDN, traffic governance faces challenges, such as bandwidth abuse, malicious node attacks, etc.
[0031] Traffic Feature Modeling: Traffic feature modeling refers to the extraction and construction of key features of PCDN traffic through statistical analysis, machine learning, or deep learning methods to distinguish normal and abnormal traffic. For example, traffic patterns can be composed of dimensions such as bandwidth occupancy, packet size, P2P connection frequency, and traffic direction to help detect abnormal behaviors such as node abuse or illegal content distribution.
[0032] Multi-Modal Traffic Analysis: Multi-modal traffic analysis refers to a method of performing high-precision traffic classification by integrating multiple dimensions (such as time-series features, statistical features, behavior patterns, etc.). Traditional PCDN traffic governance usually performs traffic screening based on IP, port, and protocol type, while multi-modal analysis introduces machine learning and deep learning, combines traffic patterns, content features, and historical behaviors for more accurate traffic detection, effectively improving the ability to detect anomalies.
[0033] Reinforcement Learning-based Traffic Scheduling: Reinforcement learning (RL) is an adaptive optimization strategy that continuously optimizes traffic scheduling based on a reward feedback mechanism. This application applies RL in PCDN governance to intelligently adjust traffic allocation, node selection, and rate-limiting strategies to prevent malicious nodes from over-consuming resources and improve the overall network efficiency. For example, a scheduling algorithm based on reinforcement learning can dynamically optimize the traffic distribution strategy of PCDN nodes to maximize the throughput of compliant traffic while suppressing malicious traffic.
[0034] GNN (Graph Neural Network): GNN is a neural network specifically designed to process graph-structured data. In PCDN traffic governance, it can be used to analyze the traffic interaction relationships between nodes and discover malicious traffic patterns. For example, a PCDN network can be modeled as a weighted graph, where nodes represent PCDN terminals and edges represent traffic transmission paths. GNN can identify suspicious nodes with abnormally high-frequency interconnections to help detect malicious P2P traffic abuse.
[0035] Blockchain-based Trust Authentication: Blockchain is a decentralized distributed ledger technology. This application uses blockchain to ensure the credibility of PCDN nodes. By recording the historical behaviors, reputation scores, and traffic contributions of nodes through smart contracts, a transparent, secure, and immutable PCDN access control system can be constructed to prevent malicious nodes from forging identities or hijacking traffic.
[0036] Explainable AI (XAI): Explainable AI (XAI) is an artificial intelligence method that can provide readable decision-making bases. During the traffic governance process of this application, methods such as SHAP (Shapley Additive Explanations) and LIME (Local Interpretable Model-agnostic Explanations) are adopted to enable the system to clearly display the bases for traffic classification decisions, making the governance strategy more transparent and adjustable by manual auditors.
[0037] Reputation Scoring Mechanism: The reputation scoring mechanism is a dynamic credit system used to evaluate the behaviors of PCDN nodes. It calculates the node credibility by combining multiple dimensions such as traffic contribution rate, historical behaviors, and violation records. In PCDN governance, the reputation score is used to: reduce the weights of malicious nodes and restrict their traffic distribution permissions; reward high-quality nodes and increase their content distribution priorities; dynamically adjust node access policies to ensure the efficient utilization of PCDN resources and reduce the impacts of bad behaviors simultaneously.
[0038] With the rapid development of Internet technologies, the high-bandwidth service demands such as video streaming media, online live broadcast, cloud storage, and online games have increased significantly, putting huge bandwidth costs and traffic scheduling pressures on traditional content delivery networks (CDNs, Content Delivery Networks). To alleviate the bottleneck problems of the CDN centralized architecture and improve data distribution efficiency, the PCDN (Peer-to-Peer Content Delivery Network) technology based on the P2P (Peer-to-Peer) architecture emerged as the times require. PCDN combines the advantages of CDN and P2P, enabling user devices to not only be content consumers but also serve as content distribution nodes, forming a decentralized content delivery network, reducing the dependence on central servers, thereby reducing bandwidth costs, improving content transmission efficiency, and enhancing the anti-pressure ability of the system.
[0039] The core mechanism of PCDN lies in using the idle bandwidth and storage resources of user terminal devices for data distribution, and at the same time selecting the optimal transmission path through intelligent scheduling algorithms to achieve the efficient distribution of content. Currently, PCDN is widely applied in scenarios such as streaming media platforms (such as online videos, live broadcasts), online game updates, large file distributions (such as system patch updates), cloud storage sharing, etc., and has become an important supplementary technology for modern Internet content distribution.
[0040] However, although PCDN has significant advantages in improving bandwidth utilization and reducing server load, its decentralized architecture and P2P traffic characteristics also bring challenges in various aspects such as traffic control, content security, prevention of malicious nodes, and intelligent scheduling, which affect the governance effect and application promotion of PCDN. In response to these problems, although relevant technologies have proposed strategies such as traffic identification, reputation mechanism, and intelligent scheduling for optimization, there are still many technical bottlenecks and urgent improvements are needed.
[0041] There are at least the following problems in the related technologies:
[0042] 1. The accuracy of existing traffic classification methods is insufficient, and it is difficult to accurately identify PCDN traffic
[0043] Currently, the governance of PCDN traffic usually relies on traditional traffic identification methods based on IP, port, and protocol type. However, with the popularity of encrypted traffic (such as HTTPS and QUIC protocols), traditional DPI (Deep Packet Inspection) methods face the following limitations:
[0044] High false alarm rate: Static rule matching methods are difficult to distinguish between legitimate P2P traffic and abnormal traffic, such as malware or botnet traffic.
[0045] Difficulty in dealing with encrypted traffic: More and more PCDN data transmissions adopt end-to-end encryption (such as TLS1.3 and DoH), rendering traditional DPI detection methods ineffective.
[0046] Poor adaptability: Existing machine learning-based traffic classification methods often only use a single feature and are difficult to cope with complex traffic pattern changes.
[0047] Therefore, the accuracy and adaptability of existing technologies in PCDN traffic identification are insufficient, resulting in incorrect traffic classification and affecting the effectiveness of governance strategies.
[0048] 2. The existing PCDN malicious node detection mechanism has limitations and is difficult to effectively suppress malicious behaviors
[0049] Malicious nodes in the PCDN network may forge identities, abuse bandwidth, or even act as DDoS attack sources or spread illegal content. Existing detection schemes mainly rely on reputation scoring mechanisms or blacklist mechanisms, but there are still the following problems:
[0050] Reputation scores are easily deceived: Malicious nodes can improve their own reputation by forging traffic or deceptive data contributions, thus evading detection.
[0051] The blacklist mechanism has a lag in updating: Malicious nodes can frequently change their IP and MAC addresses, rendering blacklist-based detection strategies ineffective.
[0052] Traditional anomaly detection methods have poor robustness: Existing anomaly detection methods based on threshold setting are difficult to adapt to new types of attacks, such as low-speed DDoS and covert P2P abuse.
[0053] Therefore, existing malicious node detection solutions cannot effectively and accurately identify malicious behaviors in the PCDN network, leading to an increase in network governance difficulty.
[0054] 3. Existing PCDN traffic scheduling is not intelligent enough and difficult to optimize bandwidth utilization
[0055] Current PCDN traffic scheduling mainly relies on static policies or bandwidth threshold setting, resulting in the following problems:
[0056] Lack of adaptability of scheduling strategies: In the face of bursty traffic (such as hot videos, live events), existing scheduling mechanisms cannot adjust dynamically, resulting in some nodes being overloaded while other nodes' resources are not fully utilized.
[0057] Fairness issue: Some PCDN nodes may bear high-load tasks for a long time, while other nodes hardly participate in data transmission, resulting in uneven distribution of system resources.
[0058] Hotspot congestion problem: When certain content becomes a hotspot in a short period of time, existing scheduling algorithms cannot respond quickly, leading to a decline in user experience.
[0059] Existing PCDN traffic scheduling lacks intelligence, adaptability, and fairness, and cannot fully optimize the utilization of bandwidth resources, affecting the overall performance of the system.
[0060] 4. Existing PCDN governance mechanisms lack transparency and are difficult to conduct effective auditing and compliance management
[0061] Since PCDN adopts a decentralized architecture, its traffic distribution path is difficult to supervise, resulting in a lack of transparency in governance rules and implementation processes, and the following problems exist:
[0062] Illegitimate content is difficult to trace: In PCDN, illegal content (such as pirated videos, malware) may be transmitted through multiple nodes, making it difficult to trace the source, posing challenges to supervision.
[0063] Governance rules are difficult to adjust dynamically: Current PCDN governance strategies are mostly static rules and cannot flexibly optimize governance strategies in combination with the real-time network environment.
[0064] The decision-making of black-box AI is not interpretable: Some PCDN governance solutions use machine learning algorithms for traffic identification or scheduling. However, due to the lack of interpretability of AI models, it is difficult for managers to understand their decision-making logic, reducing controllability and credibility.
[0065] The transparency and traceability of existing PCDN governance solutions are insufficient, affecting network compliance and governance effectiveness, and urgent optimization is needed.
[0066] In summary, although PCDN technology can effectively improve content distribution efficiency and reduce bandwidth costs, due to its decentralized architecture and P2P traffic characteristics, the existing governance solutions still have the following four major technical problems:
[0067] 1. The accuracy of traffic classification methods is insufficient, making it difficult to accurately identify PCDN traffic and affecting the implementation effect of governance strategies.
[0068] 2. The malicious node detection mechanism has limitations, making it difficult to effectively prevent problems such as identity forgery, DDoS attacks, and bandwidth abuse.
[0069] 3. Traffic scheduling is not intelligent enough, making it difficult to dynamically optimize bandwidth resources and affecting system fairness and stability.
[0070] 4. The governance mechanism lacks transparency, making it difficult to trace illegal content and affecting regulatory compliance and system credibility.
[0071] To solve the above problems, relevant solutions are provided in the embodiments of this application, which are described in detail below.
[0072] According to the embodiments of this application, a method embodiment of a traffic data scheduling method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0073] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing the traffic data scheduling method is shown. As Figure 1 shown, the computer terminal 10 (or mobile device 10) may include one or more (shown as 102a, 102b,..., 102n in the figure) processors 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand, Figure 1The structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may also include more or fewer components than those shown in Figure 1 or have a different configuration from that shown in Figure 1 .
[0074] It should be noted that one or more of the above-mentioned processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in software, hardware, firmware or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0075] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the traffic data scheduling method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned traffic data scheduling method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely provided relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network and combinations thereof.
[0076] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include the wireless network provided by the communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0077] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of the computer terminal 10 (or mobile device).
[0078] Under the above operating environment, the embodiments of the present application provide a traffic data scheduling method, asFigure 2 As shown in the figure, the method includes the following steps:
[0079] Step S202: Determine various traffic characteristics of each piece of traffic data in the original traffic dataset, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics;
[0080] In the technical solution provided in step S202, the statistical characteristics include the average packet size and the traffic directionality ratio. The temporal behavior characteristics include the traffic burstiness and the coefficient of variation of traffic intervals. Among them, the traffic burstiness is used to reflect the degree of change in the packet size of traffic data, and the coefficient of variation of traffic intervals is used to reflect the fluctuation of the arrival time intervals of traffic packets. The protocol fingerprint characteristics include the transport layer security protocol handshake characteristics and the request-response mode characteristics.
[0081] As an alternative implementation, let the traffic dataset to be classified be X = {x1, x2,..., x n}, then each traffic sample x i contains the following three main feature categories:
[0082] (1) Traffic statistical characteristics
[0083] The traffic statistical characteristics quantify the basic attributes of each packet and reflect the overall distribution characteristics of the traffic. They mainly include:
[0084] Average packet size μ s :
[0085]
[0086] where s i is the size of the i-th packet, and N is the total number of packets.
[0087] Traffic directionality ratio r d :
[0088]
[0089] where N uplink and N downlink are the number of uplink and downlink packets respectively. PCDN traffic usually shows a relatively high proportion of downlink traffic.
[0090] (2) Temporal behavior characteristics
[0091] The temporal behavior characteristics are used to capture the temporal patterns of traffic and reflect the changing trend of the packet arrival time. They mainly include:
[0092] Traffic burstiness σ s :
[0093]
[0094] This feature is used to evaluate the degree of change in the size of data packets. PCDN traffic usually exhibits a strong bursty transmission pattern.
[0095] Coefficient of variation of traffic interval CV t :
[0096]
[0097] where μ t and σ t are the mean and standard deviation of the arrival time intervals of traffic packets respectively. PCDN traffic has greater volatility in time intervals compared to traditional CDN traffic.
[0098] (3) Protocol fingerprint features
[0099] Protocol fingerprint features capture the unique protocol behavior patterns of PCDN by analyzing the application layer protocols of data packets. These include:
[0100] TLS (Transport Layer Security) handshake features: Based on information such as the SNI (Server Name Indication) field and the ALPN (Application-Layer Protocol Negotiation) protocol list, different PCDN implementations (such as PCDN provided by different applications) can be effectively distinguished.
[0101] Request-response pattern: PCDN traffic usually has a short-time and high-frequency request and response pattern, which is significantly different from the traditional P2P traffic pattern.
[0102] In this way, by adopting various types of traffic features, PCDN traffic data can be identified more accurately.
[0103] Step S204, identify target traffic data from the original traffic dataset according to various traffic features, where the target traffic data is peer content distribution network traffic data;
[0104] In the technical solution provided in step S204, the steps of identifying target traffic data from the original traffic dataset according to various traffic features include: determining the classification probability of each traffic data in the original traffic dataset through a first classification model, where the classification probability is the probability that the type of each traffic data is peer content distribution network traffic data; determining that the traffic data corresponding to the classification probability greater than the preset probability threshold is the target traffic data.
[0105] As an alternative implementation, the probability function for traffic classification can be defined as:
[0106] P(y|X) = f(WX + b)
[0107] Where: W is the feature weight matrix, b is the bias term, and f(·) is the classification function (such as Softmax), which is used to output the probability of each type of traffic.
[0108] After that, the first classification model can be trained, and the trained model can be used to identify the type of traffic data. Among them, the first classification model can be a model that combines a convolutional neural network (CNN) and a long short-term memory network (LSTM). During the process of training the model, the following cross-entropy loss function can be used to minimize the prediction error:
[0109]
[0110] Where, y i is the true class, is the predicted class probability. The model parameters are continuously updated through the backpropagation algorithm, and finally an efficient and accurate traffic classification model is obtained.
[0111] When officially using the first classification model to identify the type of traffic data, first extract the above statistical features, temporal behavior features, and protocol fingerprint features from the captured network traffic data. Then, input these features into the trained classification model to calculate the classification probability of each traffic type. If the probability P(PCDN|X) of a certain traffic's PCDN category is greater than the set threshold θ, then this traffic is determined to be PCDN traffic.
[0112] In some embodiments of the present application, the complete process of identifying the traffic data type includes:
[0113] The first step, traffic data collection: Capture traffic data for a certain period of time from the network to generate a dataset X.
[0114] The second step, feature extraction: Extract statistical features, temporal features, and protocol fingerprint features from the traffic dataset.
[0115] The third step, model training: Use historical traffic data and labels to train a deep learning model to obtain a classification model.
[0116] The fourth step, traffic identification: Input real-time traffic data into the classification model to determine the traffic type.
[0117] The fifth step, feedback scheduling: For the data identified as PCDN traffic, it can be managed in combination with other network governance strategies (such as traffic scheduling, bandwidth management).
[0118] In the process of PCDN (Peer-to-Peer Content Delivery Network) governance, traffic scheduling and malicious node detection usually rely on deep learning and traditional rule engines. However, due to the black-box nature of deep learning models, the governance decisions lack interpretability, making it difficult to accurately understand the influencing factors and resulting in difficulties in policy optimization. The embodiment of this application proposes a PCDN governance analysis method based on explainable AI (XAI). By means such as feature visualization and decision path analysis, the PCDN governance decisions are made more transparent and verifiable, improving the reliability of governance.
[0119] As an alternative implementation, in order to improve the interpretability of the first classification model and determine the influence degree of various traffic features on the traffic data type, a random offset can also be added to the traffic behavior features of the target node to obtain test traffic data, where the target node is any node in the target traffic interaction graph, and the value range of the random offset is within a preset range; determine the traffic data type corresponding to the traffic behavior features of the target node identified according to the second classification model; train the linear interpretable model based on the test traffic data and the traffic data type, so as to determine the feature weights of various traffic features; determine the importance ranking of various traffic features according to the feature weights.
[0120] Optionally, the SHAP (Shapley Additive Explanations) algorithm can be used to calculate the contribution degree of each traffic feature to the PCDN governance decision, and combined with the Local Interpretable Model-agnostic Explanation (LIME) to perform visual analysis on the detected malicious node behavior. Through this solution, the manager can clearly understand which traffic features affect the determination of malicious nodes, so as to accurately optimize the PCDN governance strategy, reduce the false alarm rate, and improve the overall governance effect of the system.
[0121] In order to quantify the importance of each traffic feature in PCDN governance and traffic data type recognition, in some embodiments of this application, the SHAP value is used to calculate the contribution degree of each feature, which is defined as follows:
[0122]
[0123] Where: φ i is the contribution degree of feature i to the model decision; N is the set of all features; S is the feature subset; v(S) is the model output when only using the feature subset S for PCDN governance decision; by calculating the SHAP value, the most influential features can be identified and the PCDN governance strategy can be optimized.
[0124] In some embodiments of the present application, a LIME (Local Interpretable Model-Agnostic Explanations) method is also provided for local interpretable analysis of the decisions of a single PCDN node. The specific process includes the following steps:
[0125] In the first step, a PCDN traffic detection model (the first classification model) is selected, and the traffic data of a certain node is predicted.
[0126] In the second step, similar traffic data is randomly sampled around the node to generate a local dataset. Randomly sampling similar traffic data around the node means adding random offsets to various feature indicators based on the node traffic data.
[0127] In the third step, a linear interpretable model is trained to approximate the local behavior of the deep learning model, and the feature weights are calculated. During the training process, the prediction results output by the PCDN traffic detection model can be used as labels.
[0128] In the fourth step, the importance ranking of traffic features is output, and a visual explanation is provided to help the administrator understand the governance decision.
[0129] The linear interpretable model trained in the above manner can explain the traffic prediction results of the PCDN traffic monitoring model for the selected node.
[0130] To verify the technical effects of the method provided in the embodiments of the present application, a test network containing 5000 PCDN nodes was deployed in a PCDN environment, and the interpretable AI method of the embodiments of the present application was used for traffic governance analysis. During the experiment, first, the LSTM+CNN model was used to classify the traffic behavior of PCDN nodes, and the SHAP algorithm was used to calculate the contribution degree of each traffic feature to the determination of malicious traffic. The experiment found that traffic burstiness, abnormal port usage, and packet size changes are the three key factors affecting malicious traffic detection. In addition, for some false alarm nodes, the LIME method was used for local decision analysis, and it was found that some normal traffic patterns were misclassified as malicious traffic due to feature similarity. Based on this analysis result, the governance strategy was optimized, improving the accuracy of PCDN malicious node detection.
[0131] The experimental results show that after adopting the interpretable AI method of the embodiments of the present application, the transparency of the PCDN governance decision-making has been greatly improved, and the managers' understanding of malicious traffic determination has increased by 30%. By optimizing the detection strategy, the false alarm rate of the PCDN has been reduced by 15%, and the overall governance efficiency has been increased by more than 20%. In addition, the visualization and interpretation function provided by the embodiments of the present application enables the administrator to monitor and adjust the governance strategy in real time to ensure the rationality of traffic scheduling. Compared with the traditional black box model, the governance method of the embodiments of the present application is more interpretable, effectively enhancing the security and stability of the PCDN environment.
[0132] The embodiments of the present application construct an intelligent, efficient, and secure PCDN governance solution through five major modules: traffic feature extraction, malicious node detection, intelligent scheduling, trusted supervision, and interpretable AI analysis, improving the bandwidth utilization rate, traffic recognition accuracy, malicious node detection ability, supervision transparency, and policy credibility, and providing a more optimized governance means for the PCDN network.
[0133] Step S206: Determine a target traffic interaction graph according to the target traffic data, where the target traffic interaction graph includes nodes and edges. The nodes are peer content distribution network nodes, and the edges are used to reflect the traffic transmission relationship between different nodes. The weight of the edge is used to reflect the data exchange frequency between different nodes.
[0134] In some embodiments of the present application, in order to detect malicious nodes in the PCDN, it is first necessary to construct a PCDN traffic interaction graph. Assume that the PCDN network consists of several nodes V = {v1, v2,..., v n}, where each node represents a PCDN participant. The connection edges E = {e ij} between the nodes represent the data transmission relationship between node v i and node v j . The weight e ij represents the data exchange frequency. The specific construction process includes:
[0135] Node representation: Each node v i is represented as a feature vector h i , which contains attributes such as the traffic behavior and bandwidth usage of the node.
[0136] Edge weight calculation: The edge weight e ij between the nodes is calculated according to the data transmission frequency between the two nodes. Nodes with a higher data transmission frequency have a greater impact on other nodes and a larger weight.
[0137] The target traffic interaction graph can be represented as an undirected graph G = (V, E), where V is the set of nodes and E is the set of edges.
[0138] Step S208: scheduling and managing the peer-to-peer content distribution network according to the target traffic interaction graph.
[0139] Scheduling and managing a peer-to-peer content distribution network includes adjusting a traffic transmission path in the peer-to-peer content distribution network, including the traffic borne by each node and whether to include certain nodes in the traffic transmission path.
[0140] In the technical solution provided in step S208, the step of scheduling and managing the peer-to-peer content distribution network based on the target traffic interaction graph includes: determining the embedded representation of each node in the target traffic interaction graph based on the target traffic interaction graph, wherein the embedded representation is used to reflect the interaction relationship between the node and the adjacent nodes of the node, and the adjacent nodes of the node are nodes that have edge connections with the node; processing the embedded representation of each node through the second classification model, and obtaining the malicious node probability corresponding to each node, wherein the malicious node probability is the probability that the node is a malicious node, and the malicious node is a node with illegal behavior; determining that the node whose corresponding malicious node probability is greater than a preset probability threshold is a malicious node; and adjusting the scheduling management strategy of the peer-to-peer content distribution network based on the malicious nodes in the target traffic interaction graph, wherein the scheduling management strategy includes a bandwidth allocation strategy and node authority.
[0141] In some embodiments of the present application, when training the second classification model, a federated learning technology can be used between multiple PCDN nodes, so that each node can collaboratively train a malicious traffic detection model without sharing original data, thereby improving detection accuracy while protecting user data privacy.
[0142] As an optional implementation, based on the target traffic interaction graph, the step of determining the embedded representation of each node in the target traffic interaction graph includes: for each node in the target traffic interaction graph, iteratively updating the node feature vector of each node based on the node feature vectors of its adjacent nodes to obtain the embedded representation of each node, wherein, in the first round of iteration, the node feature vector is used to reflect the traffic information of the node, and the traffic information includes traffic behavior information and bandwidth usage.
[0143] In some embodiments of the present application, after constructing the target traffic interaction graph, the graph neural network GNN can be used to update the node features of each node in the target traffic interaction graph to obtain an embedded representation of the node. The calculation process of the GNN model is as follows:
[0144] The features of each node are updated through the features of its neighboring nodes in each iteration. The specific update formula is:
[0145]
[0146] Wherein: is the feature representation of node v after the t-th round of iteration; N(v) is the set of neighbor nodes of node v; W and b are model parameters, which are the weight matrix and bias term respectively; σ is the activation function, usually ReLU or other non-linear activation functions.
[0147] This formula indicates that the features of each node will depend on the weighted sum of the features of all neighbor nodes in its neighbor node set N(v). After being transformed by the weight matrix W and bias b, it undergoes a non-linear mapping through the activation function σ.
[0148] In some embodiments of the present application, by updating node features through multiple rounds of iteration, the GNN model can effectively capture the mutual relationships and data transmission patterns between nodes, and finally obtain the feature representation of each node where T is the number of iterations. Next, by classifying the node features, it can be determined whether a node is a malicious node.
[0149] The basis for identifying malicious nodes is the output value of their feature vectors in the classification model. A threshold θ can be set to determine whether a node is a malicious node. In this way, if then node v is determined to be a malicious node. Otherwise, node v is determined to be a normal node.
[0150] In some embodiments of the present application, the complete process of identifying malicious nodes and scheduling the PCDN network includes the following steps:
[0151] The first step, data collection: Collect traffic data from the PCDN network and establish the initial feature representation of each node.
[0152] The second step, constructing a graph model: Construct a PCDN traffic interaction graph according to the traffic relationship between nodes.
[0153] The third step, GNN training: Use the existing malicious node labels to perform supervised learning to train the GNN model.
[0154] The fourth step, traffic monitoring: Update node features in real time and perform iterative calculations to detect malicious nodes in the network.
[0155] The fifth step, feedback adjustment: Based on the detection results, adjust the bandwidth allocation strategy, node permissions, etc. of the PCDN network to enhance network security.
[0156] To verify the technical effects of the malicious node detection and scheduling method provided in the embodiments of the present application, assume that in a PCDN network, there are 100 nodes, and the traffic characteristics of each node include bandwidth usage, data transmission frequency, etc. First, traffic data is collected from the network, and the feature representation is initialized for each node. Then, a graph is constructed, where the edges in the graph represent the data transmission relationship between nodes, and the edge weights are the transmission frequencies. Next, a graph neural network is used to train these features, and through multiple rounds of iteration, the node features are gradually optimized.
[0157] After the training is completed, when new traffic data enters the network, the GNN model will be updated in real time according to the interaction graph of the nodes and the traffic characteristics. Finally, a classification model is used to determine whether each node is a malicious node, and malicious behaviors are discovered and isolated in a timely manner, thereby improving the security of the PCDN network.
[0158] After the above experimental verification, the malicious node detection method based on graph neural network provided in the embodiments of the present application can accurately identify more than 85% of malicious nodes, and the false positive rate is reduced by more than 25% compared with traditional methods. This method has high adaptability and accuracy, and shows strong robustness especially in the face of complex traffic and encrypted environments.
[0159] It can be seen that the method provided in the embodiments of the present application can not only identify common malicious behaviors such as bandwidth abuse and forged identities, but also accurately detect more complex attack types such as DDoS attacks and illegal content dissemination, improving the overall security protection ability of the PCDN network.
[0160] In some embodiments of the present application, the steps of scheduling and managing the peer-to-peer content distribution network according to the target traffic interaction graph include: determining the state space, action space, and reward function of the peer-to-peer content distribution network, where the state space includes the network topology structure, bandwidth utilization, and node user request status of the state space, the action space includes the action strategies that the agent can take, and the action strategies include data flow path selection strategies. The agent is used to schedule the data traffic of the peer-to-peer content distribution network, and the reward function is used to determine the state evaluation value of the peer-to-peer content distribution network, and the higher the state evaluation value, the better the state of the peer-to-peer content distribution network; training the agent according to the state space, action space, and reward function, and after the training is completed, using the agent to schedule and manage the peer-to-peer content distribution network based on the target traffic interaction graph.
[0161] It should be noted that the traffic scheduling methods in the related art are usually based on static rules or preset policies, lacking the ability to respond to network changes in real time, resulting in uneven bandwidth utilization and network congestion problems. To solve this problem and improve the flexibility and efficiency of the network, in the embodiments of the present application, by introducing reinforcement learning technology, the traffic scheduling can be dynamically adjusted according to the network state, so as to achieve higher bandwidth utilization, lower transmission delay and better traffic balance.
[0162] In some embodiments of the present application, a traffic scheduling model based on reinforcement learning is constructed, which mainly includes the following three parts:
[0163] State space S: Represents the current status of the PCDN network. The state space includes the following aspects:
[0164] Network topology structure: Includes information such as the distribution of nodes, bandwidth, and delay.
[0165] Bandwidth utilization: The current bandwidth occupancy of each node.
[0166] User request status: Request density, traffic demand, etc. of each node.
[0167] It can be expressed as the state vector S = {s1, s2,..., s m}, where m is the dimension of the state.
[0168] Action space A: Represents the actions that the agent can take, mainly to select different PCDN nodes for data transmission to optimize the bandwidth utilization of the network. The action space contains all possible data flow path selections, that is, the traffic transmission directions of each node in the network.
[0169] It can be expressed as the action vector A = {a1, a2,..., a n}, where n is the total number of actions.
[0170] Reward function RRR: Used to evaluate the effect of each action and guide the agent to learn. The reward function is calculated by considering three key indicators: bandwidth utilization U, transmission delay D, and load balance degree BR.
[0171] The formula of the reward function is as follows:
[0172] R = w1·U + w2·(1 - D) + w3·BR
[0173] Where: w1, w2, w3 are weight coefficients used to balance the importance of each indicator. U is the bandwidth utilization, representing the usage of the current network's bandwidth resources; D is the average delay, representing the delay situation of data transmission, the lower the better; BR is the load balance degree, representing the balance degree of traffic distribution between different nodes, the higher the better.
[0174] Through reinforcement learning, the agent (traffic scheduler) continuously explores and learns in the network to maximize the total reward. The reinforcement learning process includes the following steps:
[0175] Initialization: Initialize the state space S, action space A, and assign initial values to each action.
[0176] Interaction with the environment: At each time step t, the agent selects an action a t to adjust the traffic transmission path, based on the current state s t and the reward function R t to evaluate the effect of this action.
[0177] Policy update: Based on the reward signal R t , the agent updates the policy through algorithms such as Q-learning or Deep Q-Network (DQN) to improve future decision-making effects. The update rules are as follows:
[0178]
[0179] where: Q(s t , a t ) is the Q-value of taking action a t in state s t ; α is the learning rate, which determines the learning rate of new information; γ is the discount factor, indicating the degree of emphasis on future rewards. denotes selecting the action that maximizes Q(s t+1 , a) from all possible action sets, which can be used to estimate the maximum future benefit that can be obtained in the next state.
[0180] Iterative update: Through multiple iterations, the agent gradually learns the optimal traffic scheduling policy to achieve efficient bandwidth utilization and data transmission optimization.
[0181] In some embodiments of the present application, after training is completed, the deployed agent can continuously monitor the current state of the PCDN network, obtain information such as network topology, bandwidth utilization, and user request conditions. And it can select a suitable action according to the current state, that is, select a suitable node for data transmission. Additionally, it can calculate the reward based on the real-time feedback of the network (such as bandwidth utilization, transmission delay, and load balancing degree) after the agent is deployed, provide it to the agent for learning. And according to the reward feedback, update the traffic scheduling policy and provide a reference for future decision-making.
[0182] In some embodiments of the present application, the complete process of training and deploying the agent to schedule traffic data includes the following steps:
[0183] Step 1, Data Collection: First, collect the real-time status data of the network, including the bandwidth utilization rate, request status, etc. of each node.
[0184] Step 2, Model Training: Train the reinforcement learning model with historical data and continuously optimize it.
[0185] Step 3, Traffic Scheduling: According to the trained policy, intelligently schedule traffic and dynamically adjust the data transmission path.
[0186] Step 4, Feedback Adjustment: Continuously adjust the policy according to the feedback of the traffic scheduling effect to achieve the best scheduling effect.
[0187] To further verify the technical effects of the intelligent agent training and PCDN network traffic scheduling method provided by the embodiments of the present application, assume that in a PCDN network, there are 100 nodes, and the intelligent traffic scheduling system monitors the bandwidth utilization rate, traffic request volume, etc. of these nodes in real time. Through the reinforcement learning algorithm, the system can automatically select the optimal transmission path to balance the bandwidth load between each node.
[0188] For example, when the bandwidth utilization rate of some nodes is too high, the system will automatically select nodes with relatively idle bandwidth for data transmission, thereby improving the overall bandwidth utilization rate of the network. After multiple rounds of learning, the system can adapt to different network states and dynamically adjust the traffic path to cope with burst traffic and network congestion.
[0189] In the above experiment, by conducting experiments in a real PCDN environment, the intelligent traffic scheduling method based on reinforcement learning significantly improved the bandwidth utilization rate by more than 30%, and at the same time reduced the transmission delay by 15%-20%. In addition, the system also showed strong adaptability, could effectively cope with network traffic fluctuations and burst traffic, and optimized the overall performance of the network.
[0190] It can be seen that after adopting the method provided by the embodiments of the present application, the PCDN network can achieve more efficient and flexible traffic scheduling, not only improving the bandwidth utilization rate, but also enhancing the stability and response speed of the network.
[0191] As an optional implementation method, in order to perform trusted supervision on each PCDN node, the step of scheduling and managing the peer content distribution network according to the target traffic interaction graph includes: determining each peer content distribution network node in the peer content distribution network according to the target traffic interaction graph; determining the behavior data of each peer content distribution network node, the behavior data including at least one of the following: traffic forwarding behavior record, content request log, bandwidth usage and reputation score; determining the behavior hash value corresponding to the behavior data of the peer content distribution network node, and storing the behavior hash value in the blockchain ledger; reading the behavior hash value of each peer content distribution network node recorded in the blockchain ledger according to a preset period, and determining the traffic scheduling priority of each peer content distribution network node according to the behavior hash value.
[0192] As an optional implementation method, the behavior characteristics of each node can be determined according to the behavior hash value, so as to distinguish malicious nodes such as DDoS attack nodes and bandwidth abuse nodes.
[0193] In some embodiments of the present application, the decentralized, tamper-proof, and traceable characteristics of blockchain can be used to implement behavior evidence and compliance supervision of PCDN nodes. This solution records the traffic forwarding logs of PCDN nodes through smart contracts, and combines decentralized identity authentication (DID) to ensure the integrity and credibility of the data, thereby improving the transparency of PCDN content supervision and reducing the illegal behavior of malicious nodes.
[0194] Optionally, a blockchain ledger can be used to record the behavior data of PCDN nodes, including traffic forwarding records, content request logs, bandwidth usage, reputation scores and other key indicators. When forwarding traffic, each PCDN node will package the behavior data and generate a hash value H. i , and then submitted to the blockchain ledger to ensure the data cannot be tampered with.
[0195] Assume D i is the behavior data of the i-th PCDN node. The hash calculation formula is as follows:
[0196] H i =Hash(D i )
[0197] Where Hash(·) is a cryptographic hash function (such as SHA-256). All hash values H i Form a time series chain and store it in the blockchain ledger.
[0198] As an alternative implementation, the reputation score is determined as follows: Determine the normal traffic forwarding ratio, the number of penalty times for violation behaviors, and the bandwidth contribution rate of the peer content distribution network node; Determine the reputation score of the peer content distribution network node based on the normal traffic forwarding ratio, the number of penalty times for violation behaviors, and the bandwidth contribution rate of the peer content distribution network node.
[0199] In some embodiments of the present application, the reputation score can be used to incentivize good nodes and punish bad nodes. The reputation score S of the PCDN node i is determined by multiple factors, including the normal traffic forwarding ratio T i , the penalty coefficient P for violation behaviors i , and the bandwidth contribution degree B i . The reputation score calculation formula is as follows:
[0200] S i = w1·T i - w2·P i + w3·B i
[0201] where: w1, w2, w3 are weight parameters; T represents the ratio of the traffic forwarding tasks successfully completed by the node; P i represents the number of times the node has been punished for violation behaviors; B i represents the bandwidth resource contribution degree provided by the node.
[0202] The reputation score S i will directly affect the task allocation weight of the PCDN node. Nodes with higher reputation will be preferentially allocated more traffic tasks, while nodes with too low reputation will be restricted or removed.
[0203] In some embodiments of the present application, a decentralized identity authentication (DID) mechanism is also provided. Optionally, the identity authentication of the PCDN node adopts decentralized identity authentication (DID) to ensure that the identity information of the node is verifiable and non-forgeable. The identity credential ID of each node i i consists of the following information:
[0204] ID i = {PK i , SK i , Sign i}
[0205] where: PK i : the public key of the node; SK i : the private key of the node; Sign i = Sign(H i , SK i ): the signature of the node behavior data to ensure the legitimacy of the identity.
[0206] All DID identity information is stored in the blockchain and managed by smart contracts to ensure the security and decentralization of the identity authentication process.
[0207] To further verify the technical effects of the method provided in the embodiments of the present application, 100 PCDN nodes are deployed in a simulated PCDN environment, including normal traffic forwarding nodes and malicious nodes, and a blockchain evidence storage and reputation scoring mechanism is used for supervision. The experiment uses Hyperledger Fabric as the underlying blockchain architecture, and the Ethereum Virtual Machine (EVM) executes smart contracts, with the initial reputation score set to 50. During the experiment, all PCDN nodes will record the traffic forwarding on the chain and generate hash values for evidence storage. The smart contract automatically calculates the reputation score every 30 minutes, adjusts the task allocation according to the node behavior, high-reputation nodes receive more traffic tasks, while low-reputation nodes are restricted or even blocked. At the same time, decentralized identity authentication (DID) is used to ensure the authenticity and credibility of the node identity and prevent malicious behaviors with forged identities.
[0208] The experimental results show that the evidence storage mechanism ensures the integrity and immutability of the PCDN traffic data. The reputation scoring mechanism increases the traffic task volume of high-reputation nodes by 35% and reduces the traffic of malicious nodes by 80%, effectively suppressing illegal behaviors. In addition, the DID identity authentication improves the content credibility by 85%, enhancing the security and transparency of the system. Through the blockchain+PCDN supervision mechanism of the embodiments of the present application, a trustworthy, transparent, and manageable PCDN network environment is achieved, effectively reducing the risk of malicious traffic attacks and improving the compliance and overall service quality of PCDN nodes.
[0209] According to the embodiments of the present application, there is also provided a traffic data scheduling process as Figure 3 shown, including the following steps:
[0210] Step S302, collect PCDN traffic data and extract traffic features, then use a deep learning model to determine whether the PCDN traffic data is abnormal data, and jump to step S304 when it is determined to be abnormal data, and jump to step S308 when it is determined to be non-abnormal data;
[0211] Step S304, perform interpretable AI analysis on the deep learning model to determine the importance of each feature in the judgment process, and calculate the reputation scores of each node involved in the traffic data. Jump to step S306 when it is determined that the reputation score is lower than the preset threshold, and jump to step S308 when the reputation score is not lower than the preset threshold;
[0212] Step S306, restrict or isolate malicious nodes, and store relevant information in the blockchain, then jump to step S310;
[0213] Step S308, execute the normal traffic scheduling program;
[0214] Step S310, store the relevant governance results and optimize the PCDN traffic scheduling process.
[0215] In some embodiments of the present application, there is also provided a traffic data scheduling interaction process as Figure 4 shown.
[0216] As can be seen from Figure 4 , this process includes:
[0217] First step, the user sends a content request to the PCDN node;
[0218] Second step, the traffic monitoring module collects traffic data from the PCDN node;
[0219] Third step, the deep learning analysis and AI determination module extracts traffic features from the data collected by the traffic monitoring module and performs analysis;
[0220] Fourth step, the deep learning analysis and AI determination module performs traffic classification and anomaly detection according to the analysis results;
[0221] Fifth step, the reputation evaluation system calculates the reputation scores of each node according to the detection results;
[0222] Sixth step, the reputation evaluation system feeds back the reputation scores and governance suggestions to the governance decision-making and scheduling module;
[0223] Seventh step, the governance decision-making and scheduling module asks the deep learning analysis and AI determination module whether the traffic data is abnormal traffic data;
[0224] Eighth step, in the case of determining that the traffic data is abnormal traffic data, the governance decision-making and scheduling module determines malicious nodes according to the abnormal traffic data and performs restriction or isolation processing on the malicious nodes.
[0225] Ninth step, in the case of determining that the traffic data is not abnormal traffic data, the governance decision-making and scheduling module schedules the PCDN nodes according to the normal traffic scheduling strategy;
[0226] Tenth step, the governance decision-making and scheduling module stores the governance records in the blockchain evidence deposit;
[0227] Eleventh step, the blockchain evidence deposit feeds back the governance results to the user.
[0228] By adopting various traffic characteristics of each traffic data in the original traffic dataset, where the traffic characteristics include statistical characteristics, time-series behavior characteristics, and protocol fingerprint characteristics; identifying target traffic data from the original traffic dataset based on the various traffic characteristics, where the target traffic data is peer content delivery network traffic data; determining a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content delivery network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; and a method for scheduling and managing the peer content delivery network according to the target traffic interaction graph, by determining the type of traffic data according to various traffic characteristics, the purpose of accurately identifying peer content delivery network traffic data from the traffic data is achieved, thereby realizing the technical effect of efficiently managing the peer content delivery network traffic data, and further solving the technical problem that the traffic data of the peer content delivery network cannot be efficiently scheduled and managed due to the inability to accurately identify the peer content delivery network traffic data in the related art.
[0229] In addition, the method provided by the embodiments of the present application also realizes intelligent extraction and classification of traffic characteristics, anomaly behavior determination based on interpretable AI, node reputation evaluation and adaptive regulation, blockchain-based trusted deposit, and federated learning collaborative governance. And it has the following beneficial effects:
[0230] 1. Precise traffic anomaly detection: By adopting deep learning combined with interpretable AI technology, the accuracy of malicious traffic detection is improved, the false alarm rate and missed alarm rate are effectively reduced, and normal traffic is ensured to be unaffected.
[0231] 2. Intelligent governance strategy optimization: Through the reputation scoring and adaptive regulation mechanism, the dynamic management of PCDN nodes is realized, ensuring that high-reputation nodes obtain more traffic tasks, while malicious nodes are restricted or isolated, thereby improving the overall service quality of PCDN.
[0232] 3. Enhanced data security and traceability: Based on blockchain technology, the integrity and immutability of PCDN governance data are guaranteed, preventing malicious nodes from forging traffic history or tampering with reputation scores, and improving the transparency and trust of the governance system.
[0233] 4. Privacy protection and distributed collaborative governance: By adopting federated learning technology, multiple PCDN nodes can collaboratively optimize the traffic governance model on the premise of protecting privacy, effectively improving the detection ability, and at the same time avoiding the privacy leakage risk caused by traditional centralized data analysis.
[0234] 5. Adaptive Governance and Efficient Resource Allocation: By integrating reputation assessment, malicious behavior detection, and intelligent regulation, the fairness and rationality of PCDN traffic allocation are improved, bandwidth abuse is reduced, the utilization rate of network resources is optimized, and the overall operating cost is lowered.
[0235] In summary, the method provided by the embodiments of this application not only improves the governance accuracy and security of the PCDN network, but also enhances the transparency and interpretability of governance decisions, ensuring reasonable, efficient, and secure traffic scheduling.
[0236] The embodiments of this application provide a traffic data scheduling device. Figure 5 This is a schematic structural diagram of the device. As can be seen from Figure 5 it, the device includes: a first processing module 50, configured to determine multiple traffic characteristics of each traffic data in the original traffic dataset, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; a second processing module 52, configured to identify target traffic data from the original traffic dataset based on the multiple traffic characteristics, where the target traffic data is peer content distribution network traffic data; a third processing module 54, configured to determine a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; a fourth processing module 56, configured to perform scheduling management on the peer content distribution network based on the target traffic interaction graph.
[0237] In some embodiments of this application, the statistical characteristics include the mean packet size and the traffic directionality ratio.
[0238] In some embodiments of this application, the temporal behavior characteristics include the traffic burstiness and the coefficient of variation of traffic intervals. Among them, the traffic burstiness is used to reflect the degree of change in the packet size of traffic data, and the coefficient of variation of traffic intervals is used to reflect the fluctuation of the arrival time interval of traffic packets in traffic data.
[0239] In some embodiments of this application, the protocol fingerprint characteristics include the transport layer security protocol handshake characteristics and the request-response mode characteristics.
[0240] In some embodiments of this application, the steps for the second processing module 52 to identify target traffic data from the original traffic dataset based on the multiple traffic characteristics include: determining the classification probability of each traffic data in the original traffic dataset through a first classification model, where the classification probability is the probability that the type of each traffic data is peer content distribution network traffic data; and determining that the traffic data with a corresponding classification probability greater than a preset probability threshold is the target traffic data.
[0241] In some embodiments of the present application, the second processing module 52 is further configured to: add a random offset to the traffic behavior characteristics of the target node to obtain test traffic data, where the target node is any node in the target traffic interaction graph, and the value range of the random offset is within a preset range; determine the traffic data type corresponding to the traffic behavior characteristics of the target node identified according to the second classification model; train the linear interpretable model based on the test traffic data and the traffic data type, so as to determine the feature weights of various traffic features; determine the importance ranking of various traffic features according to the feature weights.
[0242] In some embodiments of the present application, the steps for the fourth processing module 56 to schedule and manage the peer-to-peer content distribution network according to the target traffic interaction graph include: according to the target traffic interaction graph, determine the embedding representation of each node in the target traffic interaction graph, where the embedding representation is used to reflect the interaction relationship between the node and its adjacent nodes, and the adjacent nodes of the node are the nodes connected by edges to the node; process the embedding representation of each node through the second classification model, and obtain the malicious node probability corresponding to each node, where the malicious node probability is the probability that the node is a malicious node, and the malicious node is a node with a violation; determine the nodes with a corresponding malicious node probability greater than the preset probability threshold as malicious nodes; adjust the scheduling and management strategy of the peer-to-peer content distribution network according to the malicious nodes in the target traffic interaction graph, where the scheduling and management strategy includes a bandwidth allocation strategy and node permissions.
[0243] In some embodiments of the present application, the steps for the fourth processing module 56 to determine the embedding representation of each node in the target traffic interaction graph according to the target traffic interaction graph include: for each node in the target traffic interaction graph, iteratively update the node feature vector of each node according to the node feature vectors of the adjacent nodes of each node, so as to obtain the embedding representation of each node, where in the first round of iteration, the node feature vector is used to reflect the traffic information of the node, and the traffic information includes traffic behavior information and bandwidth usage.
[0244] In some embodiments of the present application, the steps for the fourth processing module 56 to schedule and manage the peer-to-peer content distribution network according to the target traffic interaction graph include: determining the state space, action space, and reward function of the peer-to-peer content distribution network, where the state space includes the network topology structure of the state space, bandwidth utilization, and node user request status, the action space includes the action strategies that the agent can take, and the action strategies include data flow path selection strategies. The agent is used to schedule the data traffic of the peer-to-peer content distribution network, and the reward function is used to determine the state evaluation value of the peer-to-peer content distribution network. The higher the state evaluation value, the better the state of the peer-to-peer content distribution network; training the agent according to the state space, action space, and reward function, and after the training is completed, using the agent to schedule and manage the peer-to-peer content distribution network based on the target traffic interaction graph.
[0245] In some embodiments of the present application, the steps for the fourth processing module 56 to schedule and manage the peer-to-peer content distribution network according to the target traffic interaction graph include: determining each peer-to-peer content distribution network node in the peer-to-peer content distribution network according to the target traffic interaction graph; determining the behavior data of each peer-to-peer content distribution network node, where the behavior data includes at least one of the following: traffic forwarding behavior records, content request logs, bandwidth usage, and reputation scores; determining the behavior hash value corresponding to the behavior data of the peer-to-peer content distribution network node, and storing the behavior hash value in the blockchain ledger; reading the behavior hash values of each peer-to-peer content distribution network node recorded in the blockchain ledger at a preset period, and determining the traffic scheduling priority of each peer-to-peer content distribution network node according to the behavior hash value.
[0246] In some embodiments of the present application, the fourth processing module 56 is further used to determine the reputation score in the following manner: determining the normal traffic forwarding ratio, the number of penalty times for violation behaviors, and the bandwidth contribution rate of the peer-to-peer content distribution network node; determining the reputation score of the peer-to-peer content distribution network node according to the normal traffic forwarding ratio, the number of penalty times for violation behaviors, and the bandwidth contribution rate of the peer-to-peer content distribution network node.
[0247] It should be noted that each module in the above traffic data scheduling device can be a program module (for example, a set of program instructions that implement a specific function), or a hardware module. For the latter, it can be presented in the following forms, but not limited to this: the manifestation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.
[0248] According to an embodiment of the present application, there is also provided a non-volatile storage medium storing a program, wherein when the program runs, it controls a device where the non-volatile storage medium is located to execute the following traffic data scheduling method: determining multiple traffic characteristics of each traffic data in the original traffic data set, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; identifying target traffic data from the original traffic data set based on the multiple traffic characteristics, where the target traffic data is peer content distribution network traffic data; determining a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; and scheduling and managing the peer content distribution network based on the target traffic interaction graph.
[0249] According to an embodiment of the present application, there is also provided an electronic device, including: a memory and a processor, where the processor is used to run a program stored in the memory, and when the program runs, it executes the following traffic data scheduling method: determining multiple traffic characteristics of each traffic data in the original traffic data set, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; identifying target traffic data from the original traffic data set based on the multiple traffic characteristics, where the target traffic data is peer content distribution network traffic data; determining a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; and scheduling and managing the peer content distribution network based on the target traffic interaction graph.
[0250] According to an embodiment of the present application, there is also provided a computer program product including a computer program, which when executed by a processor implements the following traffic data scheduling method: determining multiple traffic characteristics of each traffic data in the original traffic data set, where the traffic characteristics include statistical characteristics, temporal behavior characteristics, and protocol fingerprint characteristics; identifying target traffic data from the original traffic data set based on the multiple traffic characteristics, where the target traffic data is peer content distribution network traffic data; determining a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; and scheduling and managing the peer content distribution network based on the target traffic interaction graph.
[0251] In the above embodiments of the present application, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0252] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in electrical or other forms.
[0253] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0254] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0255] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical disks, and other various media that can store program codes.
[0256] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A traffic data scheduling method, characterized in that, Including: Determine various traffic characteristics of each traffic data in the original traffic dataset, where the traffic characteristics include statistical characteristics, time-series behavior characteristics, and protocol fingerprint characteristics; Identify target traffic data from the original traffic dataset based on the various traffic characteristics, where the target traffic data is peer content distribution network traffic data; Determine a target traffic interaction graph based on the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; Schedule and manage the peer content distribution network based on the target traffic interaction graph.
2. The traffic data scheduling method according to claim 1, wherein Identifying target traffic data from the original traffic dataset based on the various traffic characteristics includes: Determine the classification probability of each traffic data in the original traffic dataset through a first classification model, where the classification probability is the probability that the type of each traffic data is the peer content distribution network traffic data; Determine that the traffic data with a corresponding classification probability greater than a preset probability threshold is the target traffic data.
3. The traffic data scheduling method according to claim 2, wherein The method further includes: Add a random offset to the traffic behavior characteristics of the target node to obtain test traffic data, where the target node is any node in the target traffic interaction graph, and the value range of the random offset is within a preset range; Determine the traffic data type corresponding to the traffic behavior characteristics of the target node identified according to the first classification model; Train a linear interpretable model based on the test traffic data and the traffic data type to determine the feature weights of various traffic characteristics; Determine the importance ranking of various traffic characteristics according to the feature weights.
4. The traffic data scheduling method according to claim 1, wherein Scheduling and managing the peer content distribution network based on the target traffic interaction graph includes: Determine the embedding representation of each node in the target traffic interaction graph based on the target traffic interaction graph, where the embedding representation is used to reflect the interaction relationship between the node and its adjacent nodes, and the adjacent nodes of the node are the nodes connected to the node by an edge; Process the embedding representation of each node through a second classification model and obtain the malicious node probability corresponding to each node, where the malicious node probability is the probability that the node is a malicious node, and the malicious node is a node with a violation; Determine that the node with a corresponding malicious node probability greater than a preset probability threshold is the malicious node; Adjust the scheduling and management strategy of the peer content distribution network based on the malicious nodes in the target traffic interaction graph, where the scheduling and management strategy includes a bandwidth allocation strategy and node permissions.
5. The traffic data scheduling method according to claim 4, wherein Determining the embedding representation of each node in the target traffic interaction graph based on the target traffic interaction graph includes: For each node in the target traffic interaction graph, the node feature vectors of each node are iteratively updated based on the node feature vectors of the adjacent nodes of each node to obtain the embedding representation of each node. Among them, in the first round of iteration, the node feature vectors are used to reflect the traffic information of the nodes, and the traffic information includes traffic behavior information and bandwidth usage.
6. The traffic data scheduling method according to claim 1, wherein According to the target traffic interaction graph, the scheduling and management of the peer-to-peer content distribution network includes: Determining the state space, action space and reward function of the peer-to-peer content distribution network, where the state space includes the network topology structure, bandwidth utilization and node user request status of the state space, the action space includes the action strategies that the agent can take, the action strategies include data flow path selection strategies, the agent is used to schedule the data traffic of the peer-to-peer content distribution network, the reward function is used to determine the state evaluation value of the peer-to-peer content distribution network, and the higher the state evaluation value, the better the state of the peer-to-peer content distribution network; Training the agent according to the state space, the action space and the reward function, and using the agent to schedule and manage the peer-to-peer content distribution network based on the target traffic interaction graph after the training is completed.
7. The traffic data scheduling method according to claim 1, wherein According to the target traffic interaction graph, the scheduling and management of the peer-to-peer content distribution network includes: Determining each peer content distribution network node in the peer-to-peer content distribution network according to the target traffic interaction graph; Determining the behavior data of each peer content distribution network node, where the behavior data includes at least one of the following: traffic forwarding behavior records, content request logs, bandwidth usage and reputation scores; Determining the behavior hash value corresponding to the behavior data of the peer content distribution network node, and storing the behavior hash value in the blockchain ledger; Reading the behavior hash values of each peer content distribution network node recorded in the blockchain ledger at a preset period, and determining the traffic scheduling priority of each peer content distribution network node according to the behavior hash value.
8. The traffic data scheduling method according to claim 7, wherein, The reputation score is determined by the following method: Determining the normal traffic forwarding ratio, the number of violations punished and the bandwidth contribution rate of the peer content distribution network node; Determining the reputation score of the peer content distribution network node according to the normal traffic forwarding ratio, the number of violations punished and the bandwidth contribution rate of the peer content distribution network node.
9. The traffic data scheduling method according to claim 1, wherein The statistical features include the average packet size and the traffic directionality ratio.
10. The traffic data scheduling method according to claim 1, wherein The temporal behavior features include the traffic burstiness and the traffic interval coefficient of variation, where the traffic burstiness is used to reflect the change degree of the packet size of the traffic data, and the traffic interval coefficient of variation is used to reflect the fluctuation of the traffic packet arrival time interval of the traffic data.
11. The traffic data scheduling method according to claim 1, wherein The protocol fingerprint features include the transport layer security protocol handshake features and the request-response mode features.
12. A traffic data scheduling device, characterized in that Including: A first processing module, configured to determine multiple traffic features of each traffic data in the original traffic dataset, where the traffic features include statistical features, temporal behavior features and protocol fingerprint features; A second processing module, configured to identify target traffic data from the original traffic dataset according to the multiple traffic characteristics, where the target traffic data is peer content distribution network traffic data; A third processing module, configured to determine a target traffic interaction graph according to the target traffic data, where the target traffic interaction graph includes nodes and edges, the nodes are peer content distribution network nodes, the edges are used to reflect the traffic transmission relationship between different nodes, and the weights of the edges are used to reflect the data exchange frequency between different nodes; A fourth processing module, configured to perform scheduling management on the peer content distribution network according to the target traffic interaction graph.
13. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, where when the program runs, it controls the device where the non-volatile storage medium is located to execute the traffic data scheduling method according to any one of claims 1 to 12.
14. An electronic device, characterized in that, Including: A memory and a processor, the processor is configured to run the program stored in the memory, where when the program runs, it executes the traffic data scheduling method according to any one of claims 1 to 12.
15. A computer program product, characterized in that, Including a computer program, which realizes the traffic data scheduling method according to any one of claims 1 to 7 when executed by a processor.