Network traffic analysis method, electronic device, storage medium and program product
By calculating the interval window fill traffic ratio in network traffic analysis, combining Fourier series fitting and weighted mean algorithms, the problems of poor fitting effect and large calculation amount in the existing technology are solved, and more efficient and accurate traffic prediction is achieved.
Patent Information
- Application Number
- CN202510474301.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-22
AI Technical Summary
The existing network traffic prediction algorithms have problems with poor fitting effect, large amount of calculations and data lag, especially when the data prediction point and the fitting interval are too far away, the applicability of the fitting formula is reduced.
The interval window filling flow ratio is calculated based on the sampling window data, and the traffic data is fitted with the Fourier series fitting method, and the weighted mean value of adjacent sampling windows is obtained through the weighted mean algorithm for data filling.
It improves the accuracy and efficiency of network traffic analysis, solves the problems of data lag and large calculation volume, and ensures the accuracy of data calculations far away from the fitting interval.
Smart Images

Figure CN120358155A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network technology, and particularly relates to a network traffic analysis method, an electronic device, a storage medium, and a program product. Background Art
[0002] Network traffic prediction is a key technology that analyzes historical data to predict future network usage trends, thereby helping operators optimize network resource allocation, enhance user experience, and improve network reliability. This technology can also assist in network planning and business development, and at the same time provide data support for network management and security protection, with broad application prospects and important practical value. In the application scenario of predicting network traffic, existing technologies often use algorithms such as interpolation algorithms, neural network algorithms, and Fourier algorithms for data prediction.
[0003] The interpolation algorithm is a concept in mathematics used to estimate the values of unknown data points between a set of known data points. This algorithm has a wide range of applications in signal processing, computer graphics, numerical analysis, and various scientific and engineering fields. Common interpolation techniques include linear interpolation, which estimates by connecting two points with a straight line; polynomial interpolation, which fits data points using a polynomial function; Lagrange interpolation and Newton interpolation, both of which are special cases of polynomial interpolation but have different construction methods; piecewise interpolation, such as cubic spline interpolation, which uses polynomial segments and smoothly connects them at nodes; Chebyshev interpolation, which is known for its numerical stability; B-spline interpolation, which provides local control and smoothness; radial basis function interpolation, which is suitable for irregularly distributed data points; and spline curves, which generate smooth curves with specific smooth properties. Selecting an appropriate interpolation method requires considering various factors such as data characteristics, smoothness requirements, computational complexity, and application scenarios.
[0004] The neural network algorithm trains a neural network model through a large amount of data and uses the trained model to predict data. A neural network consists of many neurons (nodes) distributed between the input layer, hidden layer, and output layer. Its core idea is to simulate the way neurons in the human brain transmit information to achieve various complex tasks. Through multiple layers of neurons and complex connection methods, the neural network can process a large amount of complex data and tasks. This flexibility and powerful data processing ability have achieved remarkable results in fields such as image recognition, natural language processing, and predictive analysis.
[0005] Fourier series and Fourier transform are two core concepts in Fourier analysis, which are used to decompose signals into sine and cosine waves of different frequencies. Fourier series specifically deals with periodic signals, representing them as an infinite sum of trigonometric functions, while the Fourier transform is applicable to non-periodic or arbitrarily periodic signals, mapping them from the time domain to the frequency domain through an integral transform to reveal the frequency components of the signal. Although they differ in form and application, they both play a crucial role in fields such as signal processing, image analysis, and audio processing.
[0006] In the application scenario of predicting network traffic, the algorithms used in the existing technologies are mostly interpolation algorithms, neural networks, and Fourier algorithms. These algorithms all have some defects and limitations. For example:
[0007] Although interpolation algorithms are very useful for estimating unknown data points, they each have limitations. For example, linear interpolation may not be accurate enough in non-linear data, polynomial interpolation may produce the Runge phenomenon at high orders, the computational complexity and stability problems of Lagrange and Newton interpolation will intensify as the number of data points increases, piecewise interpolation may produce discontinuities near the piecewise points, and advanced interpolation methods such as cubic splines, Chebyshev, B-splines, and radial basis functions, although providing better smoothness and adaptability, have a high computational cost and may require more computational resources and storage space. Therefore, many factors need to be considered when choosing an interpolation algorithm, and overfitting and underfitting are likely to occur.
[0008] Although neural network algorithms have shown powerful capabilities in fields such as image recognition and natural language processing, they also have some disadvantages, including dependence on a large amount of data, high computational resource requirements, possible long training cycles, insufficient generalization ability, the black box problem of the model, sensitivity to data noise, complexity of hyperparameter tuning, resource waste caused by model complexity, and dependence on specific software frameworks. These challenges require careful consideration of data quality, model selection, training efficiency, and interpretability when designing and applying neural networks. And the trained data model has a certain lag, making it difficult to update in a timely manner, which will have a certain impact on the prediction results of the data.
[0009] The two core concepts of the Fourier algorithm are the Fourier series and the Fourier transform. Although the Fourier transform is extremely effective in signal analysis and can convert time-domain signals into the frequency domain for frequency feature analysis, it also has limitations. For example, it cannot accurately provide both the time and frequency information of a signal simultaneously, there is a contradiction in time-frequency resolution; the local characteristics of non-stationary signals are not analyzed sufficiently; the high computational complexity of traditional transforms; and the sensitivity to noise. The Fourier series has significant advantages in fitting periodic functions, but there are also some disadvantages. First, its main limitation is that it is only applicable to the fitting of periodic functions and is not effective for non-periodic functions. Second, the convergence rate of the Fourier series of some functions may be very slow, and many series terms are required to achieve sufficient accuracy.
[0010] In addition, for existing fitting methods, when the data prediction point is too far from the fitting interval, the applicability of the fitting formula may be reduced. Summary of the Invention
[0011] In view of the problems existing in the prior art, the present invention provides a network traffic analysis method, an electronic device, a storage medium, and a program product, which at least partially solve the problems of poor fitting effect, large amount of calculation, and data lag in the prior art.
[0012] In a first aspect, an embodiment of the present disclosure provides a network traffic analysis method, including:
[0013] Calculating the filling flow rate of the interval window based on the data of the obtained sampling window, where the interval window is the time window between two adjacent sampling windows;
[0014] Fitting the data in the sampling window, obtaining a flow fitting curve, and then filling the data at the boundary of the interval window by calculating the prediction interpolation according to the filling flow rate from the previous sampling window and the current sampling window;
[0015] Calling a weighted mean algorithm to obtain the weighted mean of the data in two adjacent sampling windows, and taking the mean as the filling data for the remaining flow in the interval window.
[0016] Optionally, the acquisition of the data in the sampling window includes capturing the data stream by using a packet capture technology that combines periodic sampling and random sampling.
[0017] Optionally, capturing the data stream includes separating packet capture from processing.
[0018] Optionally, the calculation of the filling flow rate of the interval window includes:
[0019] Calculating the filling flow rate of the interval window based on the obtained time T1, time T2, statistical quantity C1, and statistical quantity C2.
[0020] T1 is the duration of the linked data packet in the previous sampling window, T2 is the duration of the linked data packet in the current sampling window, C1 is the statistical quantity of the linked data packet in the previous sampling window, C2 is the statistical quantity of the linked data packet in the current sampling window, and the linked data packets are the same linked data packets.
[0021] Optionally, calculating the filling flow ratio of the interval window includes: calculating the packet capture rate V1 of the link in the previous sampling window and the packet capture rate V2 of the link in the current sampling window based on time T1, time T2, statistical quantity C1, and statistical quantity C2, and taking the average of rate V1 and rate V2 to obtain the average packet capture rate. Based on the average packet capture rate and the obtained interval window duration T3, obtain the statistical quantity C3 of the link of this data packet in the interval window; thus, the filling flow ratio is obtained as C1:C3:C2.
[0022] Optionally, fitting the data in the sampling window includes selecting the Fourier series fitting method to fit the traffic data.
[0023] The Fourier series fitting method includes determining the function period, selecting the truncation order, constructing the Fourier series equation, regression verification, and parameter tuning.
[0024] Determining the function period includes traversing all the data in the window, summing and calculating the mean value, using the mean value as the demarcation to distinguish the data peaks and valleys, and determining the function period through the distribution of the peaks and valleys.
[0025] Selecting the truncation order includes defining the first order as the initial truncation order, and performing error analysis on the calculation result of the Fourier series equation. If the error is large, gradually increase the truncation order until the error is adjusted to the set range.
[0026] Constructing the Fourier series equation includes randomly and uniformly extracting data at various positions as the verification samples for regression verification.
[0027] The regression verification includes substituting the verification samples into the Fourier series formula for regression calculation, performing error analysis on the calculated verification results, and performing parameter tuning if the error is not less than the set value.
[0028] The parameter tuning includes gradually increasing the truncation order, performing regression verification on the fitting formula after optimizing the parameters until the error is less than the set value. When the truncation order reaches the threshold, the fitting will stop and the fitting result with the smallest error in the previous regression test will be selected as the result of this fitting.
[0029] Optionally, the calling of a weighted mean algorithm to obtain a weighted mean of data from two adjacent sampling windows, and taking the mean as filling data for the remaining flow of the interval window, includes:
[0030] The data of two adjacent sampling windows are divided into multiple intervals, and a weight is assigned to each interval. The total amount of data in each interval is calculated and multiplied by the corresponding weight to obtain the weight score of the interval. The weight scores are summarized and calculated to obtain the weighted mean. The remaining flow data in the interval window is filled based on the weighted mean and the filling flow ratio.
[0031] In a second aspect, an embodiment of the present disclosure further provides an electronic device, the electronic device comprising:
[0032] at least one processor; and,
[0033] a memory communicatively connected to the at least one processor; wherein,
[0034] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the network traffic analysis method described in any one of the first aspects.
[0035] In a third aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any network traffic analysis method described in the first aspect.
[0036] In a fourth aspect, an embodiment of the present disclosure further provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements any network traffic analysis method described in the first aspect.
[0037] The present invention provides a network traffic analysis method, an electronic device, a storage medium and a program product, wherein the network traffic analysis method predicts the data at the edge of the fitting interval using the traffic curve obtained by fitting and the filling traffic ratio, while the data far away from the fitting interval is calculated using a weighted mean algorithm, considering that the fitting formula may not be applicable for evaluation calculation, which can accurately reflect the patterns and trends in the data set, thereby achieving the purpose of improving the accuracy and efficiency of network traffic analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The above and other objects, features and advantages of the present disclosure will become more apparent through a more detailed description of exemplary embodiments of the present disclosure in conjunction with the accompanying drawings, wherein like reference numerals generally represent like components throughout the exemplary embodiments of the present disclosure.
[0039] Figure 1Schematic diagram of the principle of sampling packet capture in the network traffic analysis method provided by the embodiments of the present disclosure;
[0040] Figure 2 Schematic diagram of the principle of separation between packet capture and processing in the network traffic analysis method provided by the embodiments of the present disclosure;
[0041] Figure 3 Schematic diagram of the principle of fill ratio calculation in the network traffic analysis method provided by the embodiments of the present disclosure;
[0042] Figure 4 Schematic diagram of the principle of calculation of fill mean in the network traffic analysis method provided by the embodiments of the present disclosure;
[0043] Figure 5 Schematic diagram of the principle of filling data with a fitted curve in the network traffic analysis method provided by the embodiments of the present disclosure;
[0044] Figure 6 Schematic block diagram of an electronic device provided by the embodiments of the present disclosure. Detailed implementation manners
[0045] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0046] It should be clear that the embodiments of the present disclosure are specifically illustrated by the following specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts belong to the scope of protection of the present disclosure.
[0047] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device can be implemented and this method can be practiced using other structures and / or functions in addition to one or more of the aspects described herein.
[0048] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present disclosure in a schematic manner. The diagrams only show the components related to the present disclosure, rather than being drawn according to the number, shape, and size of the components in actual implementation. The form, quantity, and proportion of each component in actual implementation can be arbitrarily changed, and the component layout form may also be more complex.
[0049] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0050] This embodiment aims to improve the accuracy and efficiency of network traffic analysis, make up for the disadvantages of other algorithms such as poor fitting effect, large computational amount, and data lag in the prediction process, and solve the phenomenon that the applicability of the fitting formula is reduced when the data prediction point is too far from the fitting interval.
[0051] This embodiment discloses a network traffic analysis method, including:
[0052] Calculating the filling flow ratio of the interval window based on the data of the obtained sampling window, where the interval window is the time window between two adjacent sampling windows;
[0053] Fitting the data in the sampling window, obtaining a flow fitting curve, and then calculating prediction interpolations from the previous sampling window and the current sampling window according to the filling flow ratio to fill the data at the boundary of the interval window;
[0054] Calling the weighted mean algorithm to obtain the weighted mean of the data of two adjacent sampling windows, and taking the mean as the filling data for the remaining flow of the interval window.
[0055] As Figure 1 shown, sampling and capturing the data stream will form an interval window without data between two sampling windows, and the flow data of this window needs to be compensated and calculated. Tracking and analyzing the data streams of two adjacent sampling windows, calling the algorithm to compensate for the missing flow, and finally realizing the restoration of the original scale of the flow, so as to obtain data closer to the actual flow.
[0056] This embodiment adopts a packet capture technology that combines periodic sampling and random sampling. By periodically performing packet capture operations on the data stream, the data stream within the sampling period is captured as an analysis sample. In actual operation, the sampling frequency and the size of the sampling window can be adjusted to adapt to different network environments and traffic conditions. At the same time, due to the uncertainty of the processing time, the sampling operation randomly determines the sampling starting point and interval, which can effectively avoid periodic deviation and make the sample more representative. For example, the time for capturing data packets is set to 10 seconds, the first capture process takes 10 seconds, and the subsequent processing process takes 2 seconds. Then, the next capture also takes 10 seconds, but the processing time is shortened to 1 second. This packet capture mode with a fixed capture time and an unfixed processing time shows a periodic characteristic as a whole, but there is also a certain degree of randomness locally, such as Figure 2 shown Figure 2 where T 抓包 is the time consumed by the program for packet capture, T 处理 is the time consumed by the program for processing, Flow 统计 is the traffic part counted during the packet capture process, Flow 缺失 is the traffic part missing during the processing process.
[0057] That is, the packet capture period is fixed, for example, packet capture is performed once every n seconds. However, due to different processing times, the sampling starting point and interval are different and have randomness. For example, when the processing time is 2 seconds, the sampling interval is 12 seconds; when the processing time is 1 second, the sampling interval is 11 seconds. Similarly, the sampling starting point also varies. Since this sampling method separates packet capture from processing and there is no direct association between the two, it leaves sufficient execution time for subsequent data processing and calculation.
[0058] For the calculation of the filling ratio, as Figure 3 shown, since there are many links within the same sampling window and their existence times are uneven, each link needs to be calculated separately to make the filling result more accurate. First, find the position where the data packet of this link first appears in the previous sampling window, record the time interval between its appearance time and the end time of the window statistics as T1, and count the number of times the data packet of this link is captured in this time window as C1; then, find the position where the data packet of this link finally appears in the current sampling window, record the time interval between the start time and the end time of this window statistics as T2, and count the number of times the data packet of this link is captured in this time window as C2. Finally, record the time interval between the start time and the end time of the interval window as T3. Figure 3Among them, T1 is the duration of the link data packet in the previous sampling window, T2 is the duration of the link data packet in the current sampling window, T3 is the duration of the interval window, C1 is the statistical quantity of the link data packet in the previous sampling window, C2 is the statistical quantity of the link data packet in the current sampling window, and C3 is the statistical quantity of the data packet link in the interval window.
[0059] Based on the above statistical parameters, C3 can be calculated. The specific calculation method is as follows: First, divide the statistical quantity by the duration to calculate the data packet capture rate V1 of the link in the previous sampling window and the data packet capture rate V2 of the current sampling window, and take the average of the two to obtain the average data packet capture rate. Multiply the calculation result by the interval window duration T3 to obtain the statistical quantity C3 of the data packet link in the interval window. The filling ratio of the three parts of the interval window is allocated according to the ratio of C1:C3:C2. That is, Figure 1 As shown in the figure, the interval window is divided into three parts, namely compensation flow 1, compensation flow 2, and compensation flow 3. The filling ratios of compensation flow 1, compensation flow 2, and compensation flow 3 are C1:C3:C2. A fitting curve is obtained by fitting based on the number of data items in sampling flow 1, and the data of compensation flow 1 is filled according to the fitting curve. Similarly, a fitting curve is obtained by fitting based on the data of sampling flow 2, and the data of compensation flow 3 is filled according to the fitting curve. The data of compensation flow 3 is filled based on the weighted average of the data of sampling flow 1 and sampling flow 2.
[0060] For the selection of the fitting formula, this module considers that when actually capturing network packets, requests and responses often show similar periodic characteristics of coming and going. Therefore, the Fourier series fitting method, which is more suitable for fitting periodic functions, is selected to fit the traffic data. It is divided into five steps: determining the function period, selecting the truncation order, constructing the Fourier series equation, regression verification, and parameter tuning.
[0061] 1) In the selection of the function period, traverse all the data in the window and sum to calculate the average value, and use the average value as the boundary to distinguish the data peaks and valleys. The appropriate function period can be determined through the distribution of peaks and valleys.
[0062] 2) In the selection of the truncation order, the first order can be simply defined as the initial truncation order. And in the subsequent calculations, error analysis is performed on the calculation results. If the error is large, the truncation order is gradually increased until the error is adjusted to an acceptable range.
[0063] 3) Construct the Fourier series equation. The basic form of the Fourier series is:
[0064]
[0065] Among them, the coefficient solution formula is:
[0066]
[0067] By calculating the above formula, the values of each Fourier coefficient can be obtained, and finally the Fourier series formula of the preliminary fitting can be obtained. Before calculation, some data need to be randomly and uniformly sampled at each position as the verification samples for regression verification.
[0068] 4) In the regression verification stage, the extracted verification samples are substituted into the obtained Fourier series formula for regression calculation, and the error analysis of the calculated verification results is carried out and recorded. If the error is small and within the acceptable range, the parameter tuning step is skipped; otherwise, parameter tuning is performed to make the fitted Fourier series formula closer to the data characteristics.
[0069] 5) When entering the parameter tuning stage, the calculation process will gradually increase the truncation order, and perform regression verification on the fitted formula after optimizing the parameters until the error verification result is reduced to the acceptable range. Since the order of the Fourier series has no theoretical upper limit and can increase without limit. However, considering factors such as the execution efficiency in actual operation, it is necessary to set an upper limit for the maximum fitting order. When the order reaches the threshold, the fitting will stop and the fitting result with the smallest error in the previous regression tests will be selected as the fitting result for this time.
[0070] (4) Calculation of the filling mean value:
[0071] As Figure 4 shown, by combining the obtained filling ratio and the fitting formula, the filled data interpolation can be obtained, and the calculated data interpolation is filled into the interval window boundary. Since the remaining unknown flow data in the interval window is far from the fitting interval, the prediction result may not be accurate. Therefore, in this embodiment, another weighted mean method is used to obtain the interpolation, and the mean value of this group of data is obtained by cumulatively summing the known data. However, considering that the influence of the edge data on the central data may not be as strong as that of other adjacent central data. Therefore, a weighting operation is also required to make the influence ratio of the adjacent data higher than that of the edge data. The specific operation method is: first divide the data into multiple intervals, and assign weights to each interval. Calculate the sum of the data amounts in each interval multiplied by the corresponding weight, which is the final weight score of this interval, and the weighted mean value can be obtained by aggregating and calculating the final weight scores.
[0072] In a specific application scenario, the network traffic analysis method mainly consists of three steps. First, calculate the filling flow ratio of the interval window based on data such as time interval and packet capture quantity. Second, fit the data in the sampling window according to the Fourier series algorithm, obtain the flow fitting curve, and calculate the predicted interpolation from the previous sampling window and the current sampling window by proportion to fill the data at the interval window boundary. Finally, it is necessary to call the weighted mean algorithm to calculate the weighted mean of the currently known data, and take the mean as the filling data for the remaining traffic. The key to the reliability of the above method lies in the determination of the filling ratio, the selection of the fitting formula, and the calculation of the filling mean.
[0073] For example, if the time of a sampling window is 10 seconds, and in the previous sampling window, a certain data connection lasted from appearance to end for 3 seconds in the previous sampling window, then T1 is 3 seconds, and the number of data entries in these three seconds is 300, so C1 is 300. The duration of the current sampling window is 2 seconds, and the number of captured data entries is 400, so T2 is 2 seconds, and C2 is 400. The intermediate interval processing time is 2 seconds, so T3 is 2 seconds. The calculation process of C3 is the average of the sampling speeds of the previous sampling window and the current sampling window, that is, (300 / 3 + 400 / 2) / 2 = 150 entries per second, and then multiply by the time T3, and the result of C3 is 300 entries. The filling ratio can be approximately considered as 300:300:400, and after simplification, it is 3:3:4. The first 3 refers to the influence interval of the previous window. In the example, it is 300 entries * 0.3 = 90 entries. In this interval window, the first 90 entries of data are taken from the fitting result of the previous window, and the result is the compensation flow 1. Similarly, the last 120 entries of data are taken from the fitting data of the current sampling window, and the result is the compensation flow 3. As Figure 5 shown. The middle 90 entries of data are obtained by calculating the mean. It can be understood as calculating the average data volume of the sampling windows near the current interval, then multiplying by the weight to obtain the weighted mean, and finally multiplying by the number of middle data entries, 90 entries, which is the middle compensation flow 2.
[0074] The calculated filling ratio is 3:3:4. The total number of data entries in the interval window obtained previously is 300 entries. Among them, the first 90 entries of data use the fitting curve of the previous sampling window, and the last 120 entries of data are taken from the fitting curve of the current window. The adjacent sampling intervals are divided into five intervals: 0 - 20%, 20% - 40%, 40% - 60%, 60% - 80%, 80% - 100%. That is, Figure 3 the data of the previous sampling window and the current sampling window in are divided into 5 intervals. The data within the corresponding interval is the data volume / number of entries, which is the average data volume of a single data entry in the current interval. Then multiply by the weight of this interval, and the sum of the results of the 10 intervals is divided by 10 to obtain the weighted mean. Finally, multiply by the previously calculated C3 ratio, which is the compensation flow 2.
[0075] The electronic device disclosed in this embodiment includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc.
[0076] The processor may be a central processing unit (CPU) or other forms of processing units with data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device to perform desired functions. In one embodiment of the present disclosure, the processor is used to run the computer-readable instructions stored in the memory, so that the electronic device executes all or part of the steps of the network traffic analysis method of the various embodiments of the present disclosure described above.
[0077] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain a good user experience effect, this embodiment may also include well-known structures such as communication buses, interfaces, etc., and these well-known structures should also be included in the protection scope of the present disclosure.
[0078] As Figure 6 is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of an electronic device suitable for implementing the electronic device in the embodiments of the present disclosure. Figure 6 The shown electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0079] As Figure 6 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in the read-only memory (ROM) or a program loaded from a storage device into the random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.
[0080] Generally, the following devices may be connected to the I / O interface: input devices including, for example, sensors or visual information acquisition devices; output devices including, for example, display screens; storage devices including, for example, magnetic tapes, hard disks, etc.; and communication devices. The communication device may allow the electronic device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 6An electronic device having various devices is shown, but it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0081] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from a network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processing device, all or part of the steps of the network traffic analysis method according to the embodiments of the present disclosure are performed.
[0082] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not described herein again.
[0083] The computer-readable storage medium disclosed in this embodiment stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by a processor, all or part of the steps of the network traffic analysis methods according to the foregoing embodiments of the present disclosure are performed.
[0084] The above-mentioned computer-readable storage medium includes but is not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or removable hard disks), media having built-in rewritable non-volatile memories (such as memory cards), and media having built-in ROMs (such as ROM cartridges).
[0085] For a detailed description of this embodiment, reference may be made to the corresponding descriptions in the foregoing embodiments, and details are not described herein again.
[0086] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, advantages, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, advantages, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-disclosed specific details are only for illustrative purposes and for ease of understanding, and are not limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.
[0087] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the term "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.
[0088] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a disjunctive listing. So, for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the examples described are preferred or better than other examples.
[0089] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.
[0090] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.
[0091] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.
[0092] The foregoing description has been presented for purposes of illustration and description. In addition, the description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those of skill in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.
Claims
1. A network traffic analysis method, characterized in that, Including: Calculating the filling flow ratio of the interval window based on the data of the obtained sampling window, where the interval window is the time window between two adjacent sampling windows; Fitting the data in the sampling window, obtaining a flow fitting curve, and then filling the data at the boundary of the interval window by calculating the prediction interpolation from the previous sampling window and the current sampling window according to the filling flow ratio; Invoking the weighted mean algorithm to calculate the weighted mean of the data in two adjacent sampling windows, and taking the mean as the filling data of the remaining flow in the interval window.
2. The network traffic analysis method according to claim 1, characterized in that Obtaining the data of the sampling window, including capturing the data stream by using a packet capture technology that combines periodic sampling and random sampling.
3. The network traffic analysis method according to claim 2, characterized in that, Capturing the data stream includes separating packet capture from processing.
4. The network traffic analysis method according to claim 1, wherein The calculating the filling flow ratio of the interval window includes: Calculating the filling flow ratio of the interval window based on the obtained time T1, time T2, statistical quantity C1, and statistical quantity C2, where T1 is the duration of the linked data packets in the previous sampling window, T2 is the duration of the linked data packets in the current sampling window, C1 is the statistical quantity of the linked data packets in the previous sampling window, C2 is the statistical quantity of the linked data packets in the current sampling window, and the linked data packets are the same linked data packets.
5. The network traffic analysis method according to claim 4, wherein The calculating the filling flow ratio of the interval window includes: calculating the capture rate V1 of the linked data packets in the previous sampling window and the capture rate V2 of the linked data packets in the current sampling window based on time T1, time T2, statistical quantity C1, and statistical quantity C2, taking the mean of the rates V1 and V2 to obtain the average packet capture rate V, and obtaining the statistical quantity C3 of the linked data packets in the interval window based on the average packet capture rate V and the obtained duration T3 of the interval window; thereby obtaining the filling flow ratio as C1:C3:C2.
6. The network traffic analysis method according to claim 1, wherein The fitting the data in the sampling window includes selecting the Fourier series fitting method to fit the flow data; The Fourier series fitting method includes determining the function period, selecting the truncation order, constructing the Fourier series equation, regression verification, and parameter tuning; The determining the function period includes traversing all the data in the window, summing and calculating the mean value, using the mean value as the demarcation to distinguish the data peaks and valleys, and determining the function period through the distribution of the peaks and valleys; The selecting the truncation order includes defining the first order as the initial truncation order, and performing error analysis on the calculation result of the Fourier series equation. If the error is large, gradually increase the truncation order until the error is adjusted to the set range; The constructing the Fourier series equation includes randomly and uniformly extracting data at each position as the verification samples for regression verification; The regression verification includes substituting the verification samples into the Fourier series formula for regression calculation, performing error analysis on the calculated verification results. If the error is not less than the set value, perform parameter tuning; The parameter tuning includes gradually increasing the truncation order, performing regression verification on the fitting formula after optimizing the parameters until the error is less than the set value. When the truncation order reaches the threshold, stop fitting and select the fitting result with the smallest error in the previous regression tests as the result of this fitting.
7. The network traffic analysis method according to claim 1, wherein The method of calling the weighted mean algorithm to obtain the weighted mean of the data of two adjacent sampling windows, and taking the mean as the filling data of the remaining flow of the interval window, includes: The data of two adjacent sampling windows are divided into multiple intervals, and a weight is assigned to each interval. The total amount of data in each interval is calculated and multiplied by the corresponding weight to obtain the weight score of the interval. The weight scores are summarized and calculated to obtain the weighted mean. The remaining flow data in the interval window is filled based on the weighted mean and the filling flow ratio.
8. An electronic device, characterized in that, The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the network traffic analysis method described in any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the network traffic analysis method described in any one of claims 1-7.
10. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by a processor, the network traffic analysis method described in any one of claims 1-7 is implemented.