Network flow control equipment and security policy configuration method and system thereof

By setting up enterprise traffic monitoring points in network traffic control equipment, performing dyeing positioning management and throughput processing, combined with network security management during the update cycle, the problems of network traffic management and security defense are solved, and network performance and security are improved.

CN120498739AInactive Publication Date: 2025-08-15NANTONG ZHONGXINYI DATA TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510585076.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network traffic control devices are difficult to effectively manage complex network traffic, optimize network performance, prevent network congestion, and on this basis, defend against network threats such as DDoS attacks and data leakage.

Method used

By setting up enterprise traffic monitoring points, establishing enterprise delivery channels, performing dyeing positioning management, performing flux processing and table trace processing, and conducting network security management according to the update cycle, and using dyeing factor and homologous factor to optimize network resource utilization and security strategies.

Benefits of technology

It realizes efficient management of network traffic, optimizes resource utilization, enhances network controllability and adaptability, improves network performance and security, and prevents potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
Patent Text Reader

Abstract

The invention discloses a network flow control device and a security policy configuration method and system thereof, and relates to the field of network flow security, and the method comprises the following steps: setting an enterprise flow monitoring point, and building an enterprise carrying channel according to enterprise network information data; setting a network security management contract, performing dyeing positioning management on the traffic operation network channel according to the network security management contract to obtain a dyeing factor, and managing the enterprise carrying channel according to the dyeing factor; obtaining enterprise flux information data according to the enterprise network information data, and performing surface trace processing on the enterprise flux information data through the enterprise transportation and dyeing channel; setting an updating period, acquiring updated enterprise network information data according to the updating period, acquiring enterprise homologous information data according to the updated enterprise network information data, acquiring a homologous factor according to the enterprise homologous information data, and performing network security management according to the homologous factor and an enterprise transportation and dyeing channel; according to the invention, the security and stability of network operation are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network traffic security, and in particular to a network traffic control device and a security policy configuration method and system thereof. Background Art

[0002] With the development of the Internet and the rapid growth of network traffic, the types and scale of data traffic in the network have become increasingly complex. Enterprises and service providers need effective traffic management tools to optimize network performance, reduce latency, and prevent network congestion. At the same time, as the frequency and complexity of network attacks increase, traffic control devices need to be combined with security policies to ensure that while managing traffic, they can effectively defend against various network threats such as DDoS attacks, malware propagation, and data leakage. To this end, a network traffic control device and its security policy configuration method and system are now provided. Summary of the Invention

[0003] In order to solve the above technical problems, the present invention aims to provide a network traffic control device and a security policy configuration method thereof, comprising the following steps: Step S1: Set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transport channels based on the enterprise network information data; Step S2: Setting up a network security management contract, performing location management on the traffic operation network channel according to the network security management contract, obtaining a location factor, managing the enterprise transport channel according to the location factor, and obtaining the enterprise transport channel; Step S3: performing flux processing on the enterprise network information data to obtain enterprise flux information data, and performing trace processing on the enterprise flux information data through the enterprise transport channel to obtain enterprise trace information data; Step S4: Set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and the enterprise infection channels.

[0004] Furthermore, the process of setting up enterprise traffic monitoring points, obtaining enterprise network information data, and establishing enterprise transport channels based on the enterprise network information data includes: The enterprise network information data includes flow information data, bandwidth information data and load information data; the flow information data includes enterprise flow value and enterprise flow timestamp; the enterprise flow value includes internal flow, external flow, upstream flow and downstream flow; the enterprise flow timestamp includes start time, end time and duration; the bandwidth information data includes actual bandwidth value and total bandwidth value; the load information data includes enterprise network load information data, enterprise network load end quantity, enterprise network load value, load peak value and load fluctuation time; Set a monitoring cycle, and the enterprise traffic monitoring point obtains enterprise network information data according to the monitoring cycle; According to the enterprise network load end quantity, the enterprise network grouping is set; according to the enterprise network load information data and the corresponding actual bandwidth value, the load bandwidth value of each enterprise network load end is obtained; according to the load bandwidth value of each enterprise network load end, the enterprise network grouping and the enterprise network load information data, the enterprise transport channel is established.

[0005] Furthermore, a network security management contract is set up, and the traffic operation network channel is managed according to the network security management contract. The process of obtaining the positioning factor includes: The network security management contract includes an identity authentication contract, an external network security management contract, and an internal network security management contract; the identity authentication contract includes identity authentication of external network enterprise staff and identity authentication of internal network enterprise staff; the external network security management contract includes identity authentication of external network enterprise staff and external traffic management value; the internal network security management contract includes identity authentication of internal network enterprise staff and internal traffic management value; Authenticate the identities of those accessing the enterprise network according to the network security management contract, screen out outsiders, and mark them as prohibited from passing; obtain internal factors and external factors based on the enterprise traffic value, enterprise traffic timestamp, internal traffic, and external traffic in the traffic information data; obtain the number of intra-enterprise transport channels based on the internal factors, the number of operating network channels, and the internal traffic management value; obtain the number of extra-enterprise transport channels based on the external factors, the number of operating network channels, and the external traffic management value; and obtain the upstream traffic level and the downstream traffic level based on the obtained number of intra-enterprise transport channels, the number of extra-enterprise transport channels, the upstream traffic, the downstream traffic, and the corresponding durations; and obtain the identification factor based on the upstream traffic level, the downstream traffic level, the corresponding internal factors, and the external factors; Manage the enterprise's transportation channels according to the dyeing factors and obtain the enterprise's transportation channels.

[0006] Furthermore, the process of performing flux processing on the enterprise network information data to obtain the enterprise flux information data includes: The bandwidth utilization rate is obtained based on the actual bandwidth value and the total bandwidth value in the bandwidth information data; the uplink coefficient and the downlink coefficient are set; the comprehensive traffic value is obtained based on the uplink coefficient, the downlink coefficient, the uplink traffic and the downlink traffic in the traffic information data; the bandwidth utilization rate, the comprehensive traffic value and the enterprise network load value are used to obtain the flux value, and the flux value is associated with the corresponding enterprise network information data to obtain the enterprise flux information data.

[0007] Furthermore, the enterprise flux information data is subjected to trace processing through the enterprise transport channel, and the process of obtaining the enterprise trace information data includes: According to the dyeing factors associated with the enterprise's dyeing channels, a continuous dyeing interval is set; the continuous dyeing interval is composed of various continuous dyeing intervals; the dyeing interval includes an upper limit value and a lower limit value; the upper limit value and the lower limit value are continuous dyeing factors; according to the flux value and the dyeing interval associated with the enterprise flux information data, the enterprise flux information data corresponding to the flux value is recorded as the same group of data, and the flux values and dyeing intervals associated with all enterprise flux information data are limited to obtain the enterprise trace information data.

[0008] Furthermore, an update cycle is set, and updated enterprise network information data is obtained according to the update cycle. The updated enterprise network information data is monitored and compared to obtain enterprise homologous information data, and the enterprise homologous information data is organized and processed. The process of obtaining homologous factors includes: Based on the updated network information data and the enterprise network information data, a network similarity value is obtained; the network similarity value includes a network traffic similarity value, a network broadband similarity value, and a network load similarity value; a similarity threshold is set; based on the similarity threshold and the network similarity value, a homology factor is obtained; the homology factor includes a homology traffic factor, a homology broadband factor, and a homology load factor.

[0009] Furthermore, based on homologous factors and enterprise infection channels, the process of network security management for updating enterprise network information data includes: If the homologous flow factor is greater than 0, the enterprise's dyeing channel corresponding to the homologous flow factor and other enterprise's dyeing channels associated with the enterprise's dyeing channel will be urgently closed; If the homologous flow factor is less than or equal to 0, the homologous broadband factor and the homologous load factor are determined. If the ratio of the homologous broadband factor to the homologous load factor is greater than zero, the channel limit is set according to the dyeing factor associated with the enterprise's dyeing channel. When the flow data exceeds the channel limit, the excess part will be sent a second time. When the flow data does not exceed the channel limit, there is no need to send it multiple times. If the ratio of the homologous broadband factor to the homologous load factor is less than zero, the network behavior is normal.

[0010] In another embodiment of the present invention, the present invention further discloses a network traffic control device and a security policy configuration system thereof, including a management center, wherein the management center is communicatively connected to a traffic information collection module, a traffic information analysis module, a traffic information processing module, and a network security management module; The traffic information collection module is used to set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transportation channels based on the enterprise network information data; The traffic information analysis module is used to set up a network security management contract, perform location management on the traffic operation network channel according to the network security management contract, obtain the location factor, manage the enterprise transportation channel according to the location factor, and obtain the enterprise transportation channel; The flow information processing module is used to perform flux processing on the enterprise network information data to obtain enterprise flux information data, and perform trace processing on the enterprise flux information data through the enterprise transmission channel to obtain enterprise trace information data; The network security management module is used to set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and enterprise infection channels.

[0011] Compared with the prior art, the beneficial effects of the present invention are: establishing an enterprise transport channel based on enterprise network information data can optimize resource management and ensure efficient use of network resources; managing the enterprise transport channel according to the specified factors to obtain the enterprise transport channel, which can enhance the controllability and adaptability of the network; performing flux processing on the enterprise network information data to obtain enterprise flux information data, which can enhance the controllability and adaptability of the network, and performing trace processing on the enterprise flux information data through the enterprise transport channel to obtain enterprise trace information data, which can monitor, filter, limit and optimize network data traffic; organizing and processing the enterprise homologous information data to obtain homologous factors, which can improve network performance, and according to the homologous factors and the enterprise transport channel, it is possible to improve network performance, ensure network security and prevent potential security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 This is a flowchart of a network traffic control device and a security policy configuration method thereof according to an embodiment of the present application.

[0013] Figure 2 This is a schematic diagram of a network traffic control device and its security policy configuration system according to an embodiment of the present application. DETAILED DESCRIPTION

[0014] like Figure 1 As shown, a network traffic control device and a security policy configuration method thereof include the following steps: Step S1: Set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transport channels based on the enterprise network information data; Step S2: Setting up a network security management contract, performing location management on the traffic operation network channel according to the network security management contract, obtaining a location factor, managing the enterprise transport channel according to the location factor, and obtaining the enterprise transport channel; Step S3: performing flux processing on the enterprise network information data to obtain enterprise flux information data, and performing trace processing on the enterprise flux information data through the enterprise transport channel to obtain enterprise trace information data; Step S4: Set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and the enterprise infection channels.

[0015] It should be further explained that, in the specific implementation process, the process of setting up enterprise traffic monitoring points, obtaining enterprise network information data, and establishing enterprise transport channels based on the enterprise network information data includes: The enterprise traffic monitoring point is set at the enterprise egress gateway; the enterprise egress gateway is used to connect the enterprise internal network and the external Internet; It should be further explained that, in the specific implementation process, the external Internet is the enterprise public network and is used for external use. The internal network is only used by internal personnel. External personnel need to conduct access testing and are not open to the public. The enterprise network information data includes flow information data, bandwidth information data and load information data; The traffic information data includes enterprise traffic value and enterprise traffic timestamp; the enterprise traffic value includes internal traffic, external traffic, upstream traffic and downstream traffic; the enterprise traffic timestamp includes start time, end time and duration; The bandwidth information data includes an actual bandwidth value and a total bandwidth value; The load information data includes enterprise network load information data, enterprise network load end quantity, enterprise network load value, load peak value and load fluctuation time; It should be further explained that, in the specific implementation process, the upstream traffic is the amount of data received by the load end, the downstream traffic is the amount of data sent by the load end, the internal traffic is the total traffic between the enterprise intranet network, and the external traffic is the total traffic of the enterprise external Internet; Set a monitoring cycle, and the enterprise traffic monitoring point obtains enterprise network information data according to the monitoring cycle; According to the enterprise network load end quantity, enterprise network groups are set; enterprise network load information data is matched with its corresponding actual bandwidth value to obtain the load bandwidth value of each enterprise network load end; enterprise transport channels are established based on the load bandwidth value of each enterprise network load end, the enterprise network group, and the enterprise network load information data, wherein the enterprise transport channels include an internal transport channel and an external transport channel, each of which includes a plurality of internal transport sub-channels and external transport sub-channels, each of which contains a sin state and a cos state; It should be further explained that, in the specific implementation process, an enterprise transport channel in the sin state means that the traffic direction within the enterprise transport channel is in the receiving direction, and an enterprise transport channel in the cos state means that the traffic direction within the enterprise transport channel is in the sending direction, and the sin state and cos state of the enterprise transport channel can exist at the same time.

[0016] It should be further explained that, during the specific implementation process, a network security management contract is set up, and traffic operation network channels are managed according to the network security management contract to obtain the positioning factor. Enterprise transport channels are managed according to the positioning factor. The process of obtaining the enterprise transport channel includes: The network security management contract includes an identity authentication contract, an external network security management contract, and an internal network security management contract; The identity authentication contract includes the identity authentication of external network enterprise staff and the identity authentication of internal network enterprise staff; the external network security management contract includes the identity authentication of external network enterprise staff and the external traffic management value; the internal network security management contract includes the identity authentication of internal network enterprise staff and the internal traffic management value; Conduct infection location management on the traffic operation network channel according to the network security management contract to obtain the infection location factor; It needs to be further explained that, in the specific implementation process, the specific process of conducting infection and positioning management of traffic operation network channels according to the network security management contract is as follows: authenticate the identity of enterprise network access personnel according to the network security management contract, screen out outsiders, and mark outsiders as prohibited from passing; match the enterprise traffic value and enterprise traffic timestamp in the traffic information data, calculate the proportion of internal traffic and external traffic, and obtain the proportion of internal traffic to the total enterprise traffic and the proportion of external traffic to the total enterprise traffic, which are recorded as internal factors and external factors; divide the enterprise's internal transport channels and the enterprise's external transport channels in the traffic operation network channel into internal and external proportions according to the external traffic management value, internal traffic management value, internal factors and external factors, calculate the product of the internal factor and the number of operating network channels, and obtain the internal and external factors. The product calculation result of the internal traffic management value is calculated by ratio calculation to obtain the number of intra-enterprise transport channels, the external factor is calculated by product calculation to the number of operating network channels, the product calculation result is calculated by ratio calculation to the external traffic management value to obtain the number of extra-enterprise transport channels, and the intra-enterprise transport channels and extra-enterprise transport channels are respectively reallocated according to the obtained number of intra-enterprise transport channels and the number of extra-enterprise transport channels; the uplink traffic and the downlink traffic are respectively calculated by ratio calculation to the corresponding duration to obtain the uplink traffic level and the downlink traffic level; the traffic is divided into levels according to each of the uplink traffic level and the downlink traffic level, and the uplink traffic level and the downlink traffic level are respectively multiplied by the corresponding internal factor or external factor to obtain the coloring factor; the traffic is divided into layers according to the coloring factor; Manage the enterprise's transportation channels according to the dyeing factors and obtain the enterprise's transportation channels; It needs to be further explained that, in the specific implementation process, the specific process of managing the enterprise transport channels according to the dyeing factors is: according to each dyeing factor, the enterprise transport channels are allocated, each enterprise transport channel is matched one by one with each dyeing factor, and the enterprise transport channels are queued according to the increasing order of the dyeing factors, and the dyeing factors are associated with the corresponding enterprise transport channels to obtain the enterprise transport channels.

[0017] It should be further explained that, in the specific implementation process, the enterprise network information data is subjected to flux processing to obtain the enterprise flux information data, and the enterprise flux information data is subjected to trace processing through the enterprise transport channel. The process of obtaining the enterprise trace information data includes: Performing flux processing on enterprise network information data to obtain enterprise flux information data; It should be further explained that, in a specific implementation, the process of flux processing the enterprise network information data is as follows: calculating the ratio of the actual bandwidth value and the total bandwidth value in the bandwidth information data to obtain bandwidth utilization; setting an uplink coefficient and a downlink coefficient; calculating the uplink flow and the downlink flow in the flow information data based on the uplink coefficient and the downlink coefficient, and adding the product of the uplink coefficient and the uplink flow, and the downlink coefficient and the downlink flow, respectively, to obtain a comprehensive flow value; matching the bandwidth utilization, the comprehensive flow value, and the enterprise network load value, calculating the difference between the comprehensive flow value and the enterprise network load value, and multiplying the obtained difference calculation result by the bandwidth utilization to obtain a flux value, and associating the flux value with the corresponding enterprise network information data to obtain enterprise flux information data; And the enterprise flux information data is processed through the enterprise transportation channel to obtain the enterprise trace information data; It should be further explained that, in the specific implementation process, the process of tracing the enterprise flux information data through the enterprise dyeing channel is as follows: according to the dyeing factors associated with the enterprise dyeing channel, a continuous dyeing interval is set; the continuous dyeing interval is composed of each continuous dyeing interval; the dyeing interval includes an upper limit value and a lower limit value; the upper limit value and the lower limit value are continuous dyeing factors; when the flux value associated with the enterprise flux information data is within one of the dyeing intervals, the enterprise flux information data corresponding to the flux value is recorded as the same group of data, and the flux values associated with all enterprise flux information data are limited to the dyeing interval to obtain the enterprise trace information data.

[0018] It should be further explained that, in the specific implementation process, an update cycle is set, and updated enterprise network information data is obtained according to the update cycle. The updated enterprise network information data is monitored and compared to obtain enterprise homologous information data, and the enterprise homologous information data is organized and processed to obtain homologous factors. Based on the homologous factors and enterprise infection channels, the process of network security management of the updated enterprise network information data includes: The updated enterprise network information data is real-time enterprise network information data; Perform similarity processing on the updated network information data and the enterprise network information data to obtain a network similarity value; The network similarity values include network traffic similarity values, network bandwidth similarity values, and network load similarity values; the network similarity values are processed to set similarity thresholds; the similarity thresholds are differenced with the network similarity values to obtain dissimilarities between the updated enterprise network information data and the enterprise network information data, which are recorded as homology factors; the homology factors include homology traffic factors, homology bandwidth factors, and homology load factors; It should be further explained that, in the specific implementation process, the network similarity value can have positive, negative and zero values; If the homologous flow factor is greater than 0, the enterprise's dyeing channel corresponding to the homologous flow factor and other enterprise's dyeing channels associated with the enterprise's dyeing channel will be urgently closed; If the homologous flow factor is less than or equal to 0, the homologous broadband factor and the homologous load factor are determined. If the ratio of the homologous broadband factor to the homologous load factor is greater than zero, the channel limit is set according to the dyeing factor associated with the enterprise's dyeing channel. When the flow data exceeds the channel limit, the excess part will be sent a second time. When the flow data does not exceed the channel limit, there is no need to send it multiple times. If the ratio of the homologous broadband factor to the homologous load factor is less than zero, the network behavior is normal.

[0019] like Figure 2 As shown, in another embodiment of the present invention, the present invention further discloses a network traffic control device and a security policy configuration system thereof, including a management center, wherein the management center is communicatively connected to a traffic information collection module, a traffic information analysis module, a traffic information processing module, and a network security management module; The traffic information collection module is used to set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transportation channels based on the enterprise network information data; The traffic information analysis module is used to set up a network security management contract, perform location management on the traffic operation network channel according to the network security management contract, obtain the location factor, manage the enterprise transportation channel according to the location factor, and obtain the enterprise transportation channel; The flow information processing module is used to perform flux processing on the enterprise network information data to obtain enterprise flux information data, and perform trace processing on the enterprise flux information data through the enterprise transmission channel to obtain enterprise trace information data; The network security management module is used to set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and enterprise infection channels.

[0020] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A network traffic control device and a security policy configuration method thereof, characterized in that: The following steps are involved: Step S1: Set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transport channels based on the enterprise network information data; Step S2: Setting up a network security management contract, performing location management on the traffic operation network channel according to the network security management contract, obtaining a location factor, managing the enterprise transport channel according to the location factor, and obtaining the enterprise transport channel; Step S3: performing flux processing on the enterprise network information data to obtain enterprise flux information data, and performing trace processing on the enterprise flux information data through the enterprise transport channel to obtain enterprise trace information data; Step S4: Set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and the enterprise infection channels.

2. A network traffic control device and security policy configuration method thereof according to claim 1, characterized in that: The process of setting up enterprise traffic monitoring points, obtaining enterprise network information data, and establishing enterprise transport channels based on the enterprise network information data includes: The enterprise network information data includes flow information data, bandwidth information data and load information data; the flow information data includes enterprise flow value and enterprise flow timestamp; the enterprise flow value includes internal flow, external flow, upstream flow and downstream flow; the enterprise flow timestamp includes start time, end time and duration; the bandwidth information data includes actual bandwidth value and total bandwidth value; the load information data includes enterprise network load information data, enterprise network load end quantity, enterprise network load value, load peak value and load fluctuation time; Set a monitoring cycle, and the enterprise traffic monitoring point obtains enterprise network information data according to the monitoring cycle; According to the enterprise network load end quantity, the enterprise network grouping is set; according to the enterprise network load information data and the corresponding actual bandwidth value, the load bandwidth value of each enterprise network load end is obtained; according to the load bandwidth value of each enterprise network load end, the enterprise network grouping and the enterprise network load information data, the enterprise transport channel is established.

3. A network traffic control device and security policy configuration method thereof according to claim 2, characterized in that: Set up a network security management contract and perform location management on the traffic operation network channel according to the network security management contract. The process of obtaining the location factor includes: The network security management contract includes an identity authentication contract, an external network security management contract, and an internal network security management contract; the identity authentication contract includes identity authentication of external network enterprise staff and identity authentication of internal network enterprise staff; the external network security management contract includes identity authentication of external network enterprise staff and external traffic management value; the internal network security management contract includes identity authentication of internal network enterprise staff and internal traffic management value; Authenticate the identities of those accessing the enterprise network according to the network security management contract, screen out outsiders, and mark them as prohibited from passing; obtain internal factors and external factors based on the enterprise traffic value, enterprise traffic timestamp, internal traffic, and external traffic in the traffic information data; obtain the number of intra-enterprise transport channels based on the internal factors, the number of operating network channels, and the internal traffic management value; obtain the number of extra-enterprise transport channels based on the external factors, the number of operating network channels, and the external traffic management value; and obtain the upstream traffic level and the downstream traffic level based on the obtained number of intra-enterprise transport channels, the number of extra-enterprise transport channels, the upstream traffic, the downstream traffic, and the corresponding durations; and obtain the identification factor based on the upstream traffic level, the downstream traffic level, the corresponding internal factors, and the external factors; Manage the enterprise's transportation channels according to the dyeing factors and obtain the enterprise's transportation channels.

4. A network traffic control device and security policy configuration method thereof according to claim 3, characterized in that: The process of performing flux processing on enterprise network information data and obtaining enterprise flux information data includes: The bandwidth utilization rate is obtained based on the actual bandwidth value and the total bandwidth value in the bandwidth information data; the uplink coefficient and the downlink coefficient are set; the comprehensive traffic value is obtained based on the uplink coefficient, the downlink coefficient, the uplink traffic and the downlink traffic in the traffic information data; the bandwidth utilization rate, the comprehensive traffic value and the enterprise network load value are used to obtain the flux value, and the flux value is associated with the corresponding enterprise network information data to obtain the enterprise flux information data.

5. A network traffic control device and security policy configuration method thereof according to claim 4, characterized in that: The process of processing the enterprise flux information data through the enterprise transport channel to obtain the enterprise trace information data includes: According to the dyeing factors associated with the enterprise's dyeing channels, a continuous dyeing interval is set; the continuous dyeing interval is composed of various continuous dyeing intervals; the dyeing interval includes an upper limit value and a lower limit value; the upper limit value and the lower limit value are continuous dyeing factors; according to the flux value and the dyeing interval associated with the enterprise flux information data, the enterprise flux information data corresponding to the flux value is recorded as the same group of data, and the flux values and dyeing intervals associated with all enterprise flux information data are limited to obtain the enterprise trace information data.

6. A network traffic control device and security policy configuration method thereof according to claim 5, characterized in that: Set an update cycle, obtain and update enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, and organize and process the enterprise homologous information data. The process of obtaining homologous factors includes: Based on the updated network information data and the enterprise network information data, a network similarity value is obtained; the network similarity value includes a network traffic similarity value, a network broadband similarity value, and a network load similarity value; a similarity threshold is set; based on the similarity threshold and the network similarity value, a homology factor is obtained; the homology factor includes a homology traffic factor, a homology broadband factor, and a homology load factor.

7. A network traffic control device and security policy configuration method thereof according to claim 6, characterized in that: Based on homologous factors and enterprise infection channels, the process of network security management for updating enterprise network information data includes: If the homologous flow factor is greater than 0, the enterprise's dyeing channel corresponding to the homologous flow factor and other enterprise's dyeing channels associated with the enterprise's dyeing channel will be urgently closed; If the homologous flow factor is less than or equal to 0, the homologous broadband factor and the homologous load factor are determined. If the ratio of the homologous broadband factor to the homologous load factor is greater than zero, the channel limit is set according to the dyeing factor associated with the enterprise's dyeing channel. When the flow data exceeds the channel limit, the excess part will be sent a second time. When the flow data does not exceed the channel limit, there is no need to send it multiple times. If the ratio of the homologous broadband factor to the homologous load factor is less than zero, the network behavior is normal.

8. A network traffic control device and a security policy configuration system thereof, specifically applied to a network traffic control device and a security policy configuration method thereof according to any one of claims 1 to 7, comprising a management center, characterized in that: The management center is communicatively connected to a flow information collection module, a flow information analysis module, a flow information processing module, and a network security management module; The traffic information collection module is used to set up enterprise traffic monitoring points, obtain enterprise network information data, and establish enterprise transportation channels based on the enterprise network information data; The traffic information analysis module is used to set up a network security management contract, perform location management on the traffic operation network channel according to the network security management contract, obtain the location factor, manage the enterprise transportation channel according to the location factor, and obtain the enterprise transportation channel; The flow information processing module is used to perform flux processing on the enterprise network information data to obtain enterprise flux information data, and perform trace processing on the enterprise flux information data through the enterprise transmission channel to obtain enterprise trace information data; The network security management module is used to set an update cycle, obtain updated enterprise network information data according to the update cycle, monitor and compare the updated enterprise network information data, obtain enterprise homologous information data, organize and process the enterprise homologous information data, obtain homologous factors, and perform network security management on the updated enterprise network information data based on the homologous factors and enterprise infection channels.