Network traffic classification method and device, storage medium and computer equipment

By marking category weights for network traffic samples and dynamically building traffic feature vectors, and using the target traffic classification model for real-time monitoring, the problems of high false alarm rate and delay processing in traditional methods are solved, and fast and accurate traffic classification in the fields of finance and medical health are achieved.

CN120498864APending Publication Date: 2025-08-15PING AN PAY ELECTRONIC PAYMENT CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510846559.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-23
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Traditional network traffic classification methods are difficult to meet the high security and high real-time needs in the financial and medical health fields, especially in the face of dynamically changing attack methods and complex traffic types, resulting in high false positive rates and critical traffic delay processing.

Method used

By marking category weights for network traffic samples, dynamically constructing traffic feature vectors, using the trained target traffic classification model for real-time monitoring and classification, reducing the false alarm rate of key traffic and ensuring business security and continuity.

Benefits of technology

It has achieved rapid and accurate traffic classification in the fields of finance and medical health, reduced the false alarm rate of key traffic, met high real-time requirements, and ensured business security and continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498864A_ABST
    Figure CN120498864A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of internet, finance and medical health, and particularly discloses a network traffic classification method and device, a storage medium and computer equipment, and the method comprises the steps: obtaining a plurality of network traffic samples, and carrying out the data feature extraction of each network traffic sample, and obtaining the sample feature vector of the network traffic sample; training the initial traffic classification model by using the sample feature vector to obtain a target traffic classification model, a model loss value in the model training process being determined based on a sub-loss value of each network traffic sample, and the sub-loss value of each network traffic sample being determined based on a product of a category deviation and a category weight; and for each Pod in the target cluster, monitoring the traffic of the Pod through a cluster traffic monitoring tool, dynamically constructing a traffic feature vector of the Pod according to a monitoring result, and continuously determining the traffic category of the Pod through a target traffic classification model based on the dynamically constructed traffic feature vector.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of Internet, finance, and medical health technology, and in particular to a network traffic classification method and device, storage medium, and computer equipment. Background Art

[0002] With the acceleration of digital transformation, the scale and complexity of network traffic are increasing dramatically, especially in sectors like finance and healthcare, which have extremely high security and real-time requirements. Currently, systems in these sectors are often deployed using application clusters, and network traffic types are becoming more diverse and complex. In this context, traditional static traffic classification methods are unable to meet traffic classification needs.

[0003] For example, in the financial industry, the security and compliance of network traffic are directly related to the safety of user funds and business continuity. With the acceleration of financial digital transformation, network traffic generated by applications such as transaction systems, payment gateways, and mobile banking is growing exponentially, and traffic types are becoming increasingly complex (such as real-time transactions, batch transfers, and risk assessment requests). Traditional traffic classification methods based on rules or simple statistics are unable to cope with dynamically changing attack methods (such as DDoS spoofing and malicious API calls) and business traffic fluctuations, resulting in a high false alarm rate. For example, in high-frequency trading scenarios, the inability to quickly distinguish between normal transaction requests and abnormal traffic may lead to financial losses or regulatory compliance risks.

[0004] For example, the healthcare sector places extremely high demands on the real-time and accuracy of network traffic, especially in scenarios such as remote diagnosis and treatment, electronic medical record transmission, and medical device interconnection. Medical traffic involves sensitive data (such as patient medical records, imaging data, and real-time vital signs) and must strictly comply with privacy regulations such as HIPAA and GDPR. However, there are many types of heterogeneous traffic in medical networks (such as high-definition image transmission, low-latency control commands, and ordinary web page access). Traditional classification methods have difficulty balancing real-time and accuracy, resulting in delayed processing of critical traffic (such as emergency equipment data) or non-critical traffic occupying excessive bandwidth. For example, in remote surgery scenarios, if traffic classification errors lead to delayed control commands, it may endanger the patient's life. Summary of the Invention

[0005] In view of this, the present application provides a network traffic classification method and device, storage medium, and computer equipment. By marking category weights for network traffic samples, when performing model training, high-weight sample classification errors will cause the model loss value to change more, prompting the model to pay more attention to key traffic classification, thereby reducing the false alarm rate of key traffic and ensuring business security and continuity; through the cluster traffic monitoring tool, the traffic of each Pod is monitored in real time, the traffic feature vector is dynamically constructed, and then the trained target traffic classification model is used to continuously determine the traffic category, which can capture traffic changes in time, classify quickly and accurately, and meet high real-time requirements.

[0006] According to one aspect of the present application, a network traffic classification method is provided, which is applied to a target cluster. The method includes:

[0007] Acquire multiple network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true class label and a class weight determined based on the true class label;

[0008] The initial traffic classification model is trained using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein the model loss value during the model training process is determined based on the sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of the class deviation and the class weight, wherein the class deviation is the deviation between the predicted class label and the true class label;

[0009] For each Pod in the target cluster, the traffic of the Pod is monitored using a cluster traffic monitoring tool, and a traffic feature vector corresponding to the Pod is dynamically constructed based on the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined using the target traffic classification model.

[0010] According to another aspect of the present application, a network traffic classification device is provided, which is applied to a target cluster, and includes:

[0011] a feature vector extraction module, configured to obtain a plurality of network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true class label and a class weight determined based on the true class label;

[0012] A model training model is used to train an initial traffic classification model using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein a model loss value during the model training process is determined based on a sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of a class deviation and a class weight, where the class deviation is the deviation between the predicted class label and the true class label;

[0013] The traffic category determination module is used to monitor the traffic of each Pod in the target cluster through a cluster traffic monitoring tool, and dynamically construct a traffic feature vector corresponding to the Pod based on the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined through the target traffic classification model.

[0014] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the above-mentioned network traffic classification method is implemented.

[0015] According to another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned network traffic classification method when executing the program.

[0016] By means of the above technical solution, the present application provides a network traffic classification method and device, storage medium, and computer equipment. First, multiple network traffic samples can be obtained, wherein each network traffic sample can be marked with a true category label and a category weight. After obtaining the network traffic samples, data features can be further extracted from the network traffic samples to obtain a sample feature vector corresponding to each network traffic sample. Then, the sample feature vector corresponding to the above network traffic sample can be used to perform cyclic iterative training on the initial traffic classification model, and the model loss value is calculated after each round of iteration. Here, the model loss value is determined based on the sub-loss value of each sample feature vector. For one of the sample feature vectors, the category deviation value between the label value of the predicted category label and the label value of the true category label is calculated, and then the category deviation value is multiplied by the corresponding category weight. The product of the multiplication is the sub-loss corresponding to the sample feature vector. The ultimate goal of model training is that the model loss value is less than a preset loss threshold, or the number of iterations reaches a preset number, at which time the target traffic classification model is obtained. After determining the target traffic classification model, the target traffic classification model can be used to classify the network traffic of each Pod in the target cluster. Specifically, a cluster traffic monitoring tool can be used to capture the real-time traffic of each Pod, dynamically construct the traffic feature vector of each Pod, and then the target traffic classification model can be used to continuously determine the traffic category corresponding to each Pod in the target cluster. The embodiment of the present application marks the category weights for network traffic samples, so that when the model is trained, the classification error of high-weight samples will cause the model loss value to change more, prompting the model to pay more attention to the classification of key traffic, thereby reducing the false alarm rate of key traffic and ensuring business security and continuity; the cluster traffic monitoring tool monitors the traffic of each Pod in real time, dynamically constructs the traffic feature vector, and then uses the trained target traffic classification model to continuously determine the traffic category, which can capture traffic changes in time, classify quickly and accurately, and meet high real-time requirements.

[0017] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0019] Figure 1 A schematic diagram of a flow chart of a network traffic classification method provided in an embodiment of the present application is shown;

[0020] Figure 2 A schematic diagram of the structure of a target traffic classification model provided in an embodiment of the present application is shown;

[0021] Figure 3 A schematic diagram of the structure of a network traffic classification device provided in an embodiment of the present application is shown;

[0022] Figure 4 A schematic diagram of the device structure of a computer device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0023] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.

[0024] In this embodiment, a network traffic classification method is provided, which is applied to a target cluster, such as Figure 1 As shown, the method includes:

[0025] Step 101: obtain multiple network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true category label and a category weight determined based on the true category label.

[0026] Step 102: The initial traffic classification model is trained using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein the model loss value during the model training process is determined based on the sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of the category deviation and the category weight, where the category deviation is the deviation between the predicted category label and the true category label.

[0027] In step 103, for each Pod in the target cluster, the traffic of the Pod is monitored by a cluster traffic monitoring tool, and a traffic feature vector corresponding to the Pod is dynamically constructed according to the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined by the target traffic classification model.

[0028] A network traffic classification method provided in an embodiment of the present application can be applied to a target cluster (such as a Kubernetes cluster) and can dynamically monitor and classify the network traffic of each Pod in the target cluster.

[0029] First, a target traffic classification model can be pre-trained. This model can then be used to classify the network traffic of each pod. Specifically, multiple network traffic samples can be obtained, each labeled with a true class label and a class weight. The true class label indicates the true traffic category corresponding to the network traffic sample, such as HTTP, TCP, UDP, or database traffic. The class weight indicates the importance of network traffic samples of different traffic categories in the model training process. For example, traffic categories can be used to determine critical business traffic and ordinary traffic. Critical business traffic can be assigned a higher class weight, while ordinary traffic can be assigned a lower class weight to encourage the model to learn more about the characteristics of critical business traffic. For example, in the financial sector, the class weight of high-frequency trading traffic can be set to 10 (because every millisecond of delay can result in millions of dollars in losses); the class weight of batch clearing traffic can be set to 3 (needed to be completed but not in real time); the class weight of market data queries can be set to 1 (ordinary business); and the class weight of DDoS attack traffic can be set to 15 (prioritized for blocking). After obtaining network traffic samples, data feature extraction can be performed on the network traffic samples. Here, data feature extraction may include statistical feature extraction, time series feature extraction, and frequency feature extraction, etc., and a sample feature vector corresponding to the network traffic sample may be subsequently constructed based on these features.

[0030] Next, an initial traffic classification model can be constructed. The initial traffic classification model can employ a deep learning model (such as LSTM, Transformer) or a traditional machine learning model (such as Random Forest, XGBoost), without limitation. The model input is a sample feature vector, and the output is a predicted class label. Specifically, the initial traffic classification model can be iteratively trained using the sample feature vectors corresponding to the aforementioned network traffic samples, with a model loss value calculated after each iteration. Here, the model loss value is determined based on the sub-loss value of each sample feature vector. For example, taking the Nth iteration as an example, for the updated initial traffic classification model obtained after the Nth iteration, each sample feature vector can be input into the updated initial traffic classification model obtained after the Nth iteration, and the predicted class label corresponding to each sample feature vector is output. For each sample feature vector, the class deviation between the label value of the predicted class label and the label value of the true class label is calculated. This class deviation value is then multiplied by the corresponding class weight. The product of these multiplications is the sub-loss corresponding to that sample feature vector. The model loss after this iteration is the sum of all sub-loss values, ensuring that high class weights contribute more to the final model loss. For example, if financial transaction traffic (class weight = 10) is misclassified, its sub-loss value is 10 × class deviation, which is much higher than the sub-loss value of general traffic (class weight = 1). The ultimate goal of model training is to achieve a model loss value less than a preset loss threshold, or to reach a preset number of iterations, at which point the target traffic classification model is obtained.

[0031] Once the target traffic classification model is determined, it can be used to classify the network traffic of each pod in the target cluster. Specifically, cluster traffic monitoring tools (such as Hubble's traffic monitoring function) can be used to capture the real-time traffic of each pod. The captured traffic is then processed, and network traffic segments with a structure consistent with the network traffic sample are identified based on the network traffic sample construction method. Data features are extracted from the network traffic segments using the same extraction method as the sample feature vectors of the network traffic samples, generating traffic feature vectors with a structure consistent with the sample feature vectors. Since each pod continuously generates traffic, network traffic segments can be dynamically constructed over time. Based on these dynamically constructed network traffic segments, traffic feature vectors can be continuously generated. Subsequently, the target traffic classification model can be used to continuously determine the traffic category corresponding to each pod in the target cluster. Specifically, each time the traffic feature vector corresponding to a network traffic segment is input into the target traffic classification model, the target traffic classification model will output a predicted category label, which is the predicted traffic category. Network policies can then be dynamically adjusted based on the classification results. For example, if a Pod's traffic is classified as "remote surgical control instructions," its bandwidth priority is immediately increased.

[0032] By applying the technical solution of this embodiment, first, multiple network traffic samples can be obtained, wherein each network traffic sample can be marked with a true category label and a category weight. After obtaining the network traffic samples, further, data feature extraction can be performed on the network traffic samples to obtain a sample feature vector corresponding to each network traffic sample. Then, the sample feature vector corresponding to the above network traffic sample can be used to perform cyclic iterative training on the initial traffic classification model, and the model loss value is calculated after each round of iteration. Here, the model loss value is determined based on the sub-loss value of each sample feature vector. For one of the sample feature vectors, the category deviation value between the label value of the predicted category label and the label value of the true category label is calculated, and then the category deviation value is multiplied by the corresponding category weight. The product of the multiplication is the sub-loss corresponding to the sample feature vector. The ultimate goal of model training is that the model loss value is less than the preset loss threshold, or the number of iterations reaches the preset number, at which time the target traffic classification model is obtained. After determining the target traffic classification model, the target traffic classification model can be used to classify the network traffic of each Pod in the target cluster. Specifically, a cluster traffic monitoring tool can be used to capture the real-time traffic of each Pod, dynamically construct the traffic feature vector of each Pod, and then the target traffic classification model can be used to continuously determine the traffic category corresponding to each Pod in the target cluster. The embodiment of the present application marks the category weights for network traffic samples, so that when the model is trained, the classification error of high-weight samples will cause the model loss value to change more, prompting the model to pay more attention to the classification of key traffic, thereby reducing the false alarm rate of key traffic and ensuring business security and continuity; the cluster traffic monitoring tool monitors the traffic of each Pod in real time, dynamically constructs the traffic feature vector, and then uses the trained target traffic classification model to continuously determine the traffic category, which can capture traffic changes in time, classify quickly and accurately, and meet high real-time requirements.

[0033] In an embodiment of the present application, optionally, the step 101 of "extracting data features for each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample" includes: for each network traffic sample, determining the sample data packets contained in the network traffic sample, and respectively determining the traffic timestamp and data packet size corresponding to each sample data packet; calculating the statistical characteristics of the network traffic sample based on the data packet size of each sample data packet, wherein the statistical characteristics include at least one of the mean, variance, maximum and minimum values of the data packet size; calculating the timing characteristics and frequency characteristics of the network traffic sample based on the traffic timestamp and data packet size of each sample data packet, wherein the timing characteristics include the flow rate time series and / or the data packet size time series, and the frequency characteristics include the data packet reception frequency and / or the flow rate change rate; constructing the sample feature vector corresponding to the network traffic sample based on the statistical characteristics, timing characteristics and frequency characteristics.

[0034] In this embodiment, the core goal of feature extraction is to convert the original data packet sequence into a quantifiable feature vector so that the target traffic classification model can understand and learn the traffic pattern. Specifically, for each network traffic sample, statistical features, time series features, and frequency features can be calculated respectively, and then the sample feature vector corresponding to the network traffic sample is constructed based on these three features. Among them, statistical features reflect the overall load level of traffic; time series features reveal the dynamic behavior of traffic; frequency features quantify the rate of traffic arrival and change trend, which can be used to identify abnormal traffic (such as DDoS attacks).

[0035] For each network traffic sample, assuming network traffic sample A, multiple sample packets (such as TCP / UDP packets) are disassembled from the network traffic sample A. Then, the following fields are extracted from each sample packet: (1) Traffic timestamp: records the arrival time of each sample packet (such as 2023-10-01 10:00:00.123); (2) Packet size: records the payload size of each sample packet (such as 1500 bytes). One form of the extracted data can be [(timestamp1, size1), (timestamp2, size2), ...].

[0036] Next, based on the packet size of each sample packet of network traffic sample A, the statistical characteristics of network traffic sample A are calculated to characterize the distribution characteristics of packet size. Calculation method: (1) Mean: reflects the average load level. Formula: Mean = (size1 + size2 + ... + sizeN) / N. (2) Variance: measures the degree of fluctuation of packet size. Formula: Variance = Σ(sizei - Mean) 2 / N. (3) Maximum value (Max): Identify sudden large data packets (such as file transfers). (4) Minimum value (Min): Identify small data packets (such as heartbeat packets). For example, a remote surgery traffic sample contains 5 sample data packets with sizes of [1500, 1500, 100, 1500, 200]. Then the calculated statistical feature result can be: Mean = 960, Variance = 438400, Max = 1500, Min = 100, and the statistical feature can be expressed as [960, 438400, 1500, 100].

[0037] Based on the field extraction results for each sample packet of network traffic sample A, calculate the time series features of network traffic sample A. For example, a telesurgery traffic sample has a duration of 3 seconds and a time window of 1 second. The telesurgery traffic sample contains 5 sample packets with sizes [1500, 1500, 100, 1500, 200]. Assuming the first 3 packets arrive within 1 second, the 4th packet arrives at 2 seconds, and the 5th packet arrives at 3 seconds, calculate the total number of bytes in each time window: [1500, 1500, 100, 1500, 200] → [3100, 1500, 200], where each number represents the total number of bytes in the corresponding time window (in bytes / second). This sequence reflects the temporal trend of traffic flow, also known as a flow rate time series. [1500, 1500, 100, 1500, 200] can be called a packet size time series.

[0038] Based on the field extraction results of each sample data packet of network traffic sample A, the frequency characteristics of network traffic sample A are calculated. Frequency characteristics may include data packet reception frequency, flow rate change rate, etc. Data packet reception frequency: the number of data packets arriving per unit time. For example: 3 data packets arrive within 1 second → data packet reception frequency = 3Hz. Flow rate change rate: the difference in flow rates between adjacent time windows (such as (current flow rate - previous flow rate) / previous flow rate). For example: time window 1 flow rate = 3000 bytes / second, time window 2 flow rate = 100 bytes / second → flow rate change rate = -96.7%.

[0039] Finally, by concatenating the statistical, temporal, and frequency features into a vector, we can obtain the sample feature vector for network traffic sample A. For example, the statistical features of a telesurgery traffic sample are: [960, 438, 400, 1500, 100]; the temporal features (only the flow rate time series): [3100, 1500, 200]; and the frequency features (only the packet reception frequency): [3, 1, 1]. The final sample feature vector for this telesurgery traffic sample would be: [960, 438, 400, 1500, 100, 3100, 1500, 200, 3, 1, 1].

[0040] The embodiments of the present application capture traffic characteristics from three perspectives: distribution, time, and frequency, and consider more comprehensive dimensions. Through timing characteristics and frequency characteristics, it can reflect changes in traffic in real time, which helps to consider dynamic changes in traffic, thereby improving the model's ability to recognize complex traffic patterns.

[0041] In an embodiment of the present application, optionally, the target traffic classification model includes a convolution layer, a pooling layer, a fully connected layer, an LSTM layer, a Dropout layer, and a classification layer; the target traffic classification model determines the traffic category based on the following steps: inputting the traffic feature vector into the convolution layer, performing convolution operations on the traffic feature vector through each convolution kernel in the convolution layer, and obtaining a first feature corresponding to each convolution kernel; inputting the first feature corresponding to each convolution kernel into the pooling layer to obtain a second feature; inputting the second feature into the fully connected layer to obtain a third feature; and inputting the third feature and the P The historical features obtained after the previous traffic feature vector of od passes through the LSTM layer are input into the LSTM layer, and the first activation value of the forgetting gate, the second activation value of the input gate, and the candidate memory unit state value in the LSTM layer are calculated. According to the first activation value, the second activation value, and the candidate memory unit state value, an updated memory unit state value is obtained. According to the updated memory unit state value, a fourth feature is calculated; the fourth feature is input into the Dropout layer to obtain a fifth feature, and the fifth feature is input into the classification layer to obtain the traffic category corresponding to the traffic feature vector.

[0042] In this embodiment, Figure 2 As shown in the figure, the target traffic classification model structure includes: Convolutional Layer: extracting local features; Pooling Layer: reducing dimensions and retaining main features; Fully Connected Layer: integrating global information; LSTM Layer (Long Short-Term Memory Layer): processing temporal dependencies (combining historical traffic features); Dropout Layer: preventing overfitting; Classification Layer: outputting the final category.

[0043] Specifically, the convolutional layer is used to extract local patterns in the traffic feature vector (such as specific byte sequences or combinations of protocol header fields). The convolutional layer can include multiple convolution kernels (Filters), each of which slides over the traffic feature vector and calculates the weighted sum of the local area (convolution operation). The convolutional layer ultimately outputs multiple first features (Feature Maps), each of which corresponds to the perspective of a convolution kernel.

[0044] The pooling layer is used to reduce feature dimensions, retain key information, and reduce computational complexity. The pooling layer downsamples the output of the convolutional layer (e.g., max pooling takes the local maximum) to output a second feature (a compressed feature vector).

[0045] The fully connected layer is used to integrate global features and map local features to the classification space. The fully connected layer flattens the second feature output by the pooling layer, and outputs the third feature (a high-dimensional vector containing global information) through the weighted summation of the fully connected neurons in the fully connected layer.

[0046] The LSTM layer is used to process temporal dependencies and predict the current category based on historical traffic features. The input of the LSTM layer is: the current third feature + historical features (from the LSTM output of the previous moment). The LSTM layer includes a forget gate (ForgetGate), an input gate (Input Gate), and an output gate (Output Gate). The forget gate determines which historical information to discard. The calculation process is: the current third feature (h t ) and historical characteristics (h t-1 ) splicing, through the Sigmoid activation function: f t =σ(W f ·[h t-1 ,h t ]+b f ), get the first activation value f t The input gate determines which new information to update to the memory unit. The calculation process is: i t =σ(W i ·[h t-1 ,h t ]+b i ), get the second activation value i t ;Candidate memory cell state value C' t =tanh(W C ·[h t-1 ,h t ]+b C ); Combine the result of the forget gate, the result of the input gate and the state value of the candidate memory unit to update the long-term memory. The calculation process is: C t =f t ⊙C t-1 +i t⊙C' t , where ⊙ represents element-by-element multiplication, C t Represents the updated state value of the memory unit. Finally, the output gate obtains the fourth feature according to the updated state value of the memory unit. The calculation formula is: t =σ(W o ·[h t-1 ,h t ]+b o ), h t =o t ⊙tanh(C t ).h t The fourth feature.

[0047] The Dropout layer is used to randomly discard some neurons to prevent overfitting. The Dropout layer randomly blocks some neurons with a certain probability (such as 50%), forcing the model to learn redundant features and output the fifth feature (a sparse feature vector).

[0048] The classification layer is used to output traffic categories (such as normal / fraud, payment / query). The classification layer maps the fifth feature into a probability distribution through the Softmax function and selects the category with the highest probability as the final result.

[0049] The embodiment of the present application balances spatial feature extraction and temporal dependency modeling through convolutional layers and LSTM layers: the LSTM layer not only processes the current traffic feature (the third feature), but also integrates the previous traffic feature vector (historical state) of the Pod, which is suitable for processing traffic data with temporal dependencies; spatial features are extracted through convolution + full connection, and LSTM processes temporal features to achieve multi-dimensional feature joint modeling.

[0050] In an embodiment of the present application, optionally, the method also includes: when it is monitored that the traffic category corresponding to any Pod changes, based on the changed traffic category, determining the target bandwidth, target priority and target network policy corresponding to any Pod, and calling the cluster API interface, based on the target bandwidth, target priority and target network policy, through the cluster API interface, adjusting the preset configuration parameters corresponding to the any Pod in the target resource object of the target cluster.

[0051] In this embodiment, the traffic category of each Pod in the target cluster can be monitored at preset time intervals or in real time. When it is detected that the traffic category of any Pod has changed (such as from "normal query" to "large payment"), it indicates that the bandwidth requirements corresponding to the Pod have also changed. Therefore, the target bandwidth, target priority, target network policy, etc. corresponding to the Pod can be determined based on the changed traffic category. Among them, a mapping table of traffic category-bandwidth-priority-network policy can be pre-set. After determining the changed traffic category, the corresponding target bandwidth, target priority, and target network policy can be obtained by querying the mapping table. For example, in a financial scenario, the target network policy can be an encrypted transmission policy, etc. For example, the target network policy for the payment traffic category can be to enable encryption (TLS), while the target network policy for the log traffic category can be to allow non-encrypted transmission.

[0052] After determining the target bandwidth, target priority, and target network policy, you can call the cluster API interface (such as the Kubernetes API) and adjust the resources.limits (bandwidth), annotations (priority tags), and NetworkPolicy (network policy) in the preset configuration parameters corresponding to the Pod in the target resource object of the target cluster to the target bandwidth, target priority, and target network policy through the cluster API.

[0053] In an embodiment of the present application, optionally, the “determining the target bandwidth corresponding to any Pod based on the changed traffic category” includes: determining the bandwidth change type of any Pod based on the changed traffic category and the traffic category before the change; when the bandwidth change type of any Pod is a bandwidth increase type, determining the bandwidth increase demand of any Pod, obtaining the total bandwidth of the target cluster, and determining the bandwidth margin of the current target cluster based on the total bandwidth and the target resource object; if the bandwidth margin is less than the bandwidth increase demand corresponding to any Pod, obtaining a target Pod whose service priority is lower than a preset priority, and determining the allocated bandwidth corresponding to the target Pod; if the allocated bandwidth is not marked with a reduction label, calculating the product of a preset bandwidth reduction ratio and the allocated bandwidth, adjusting the allocated bandwidth according to the preset bandwidth reduction ratio, marking the adjusted allocated bandwidth with a reduction label, and increasing the bandwidth of any Pod based on the product result; if the allocated bandwidth is marked with a reduction label, adjusting the bandwidth of any Pod to meet the bandwidth increase demand based on the allocated bandwidth corresponding to the target Pod, setting a polling mechanism for the target Pod, and processing the network traffic of the target Pod based on the polling mechanism.

[0054] In this embodiment, by monitoring changes in traffic categories, changes in bandwidth requirements can be evaluated, and intelligent adjustments can be made when bandwidth resources are insufficient to ensure that high-priority services obtain sufficient bandwidth. Specifically, when monitoring discovers that the traffic category of a Pod has changed, first, the bandwidth change type of the Pod can be determined based on the traffic category after the change and the traffic category before the change. Among them, traffic category changes can include: changing from a low-priority service to a high-priority service (in this case, the bandwidth change type can specifically be a "bandwidth increase type"), changing from a high-priority service to a low-priority service (in this case, the bandwidth change type can specifically be a "bandwidth reduction type"), etc.

[0055] If it is found through monitoring that the bandwidth change type of a certain Pod is a bandwidth increase type, the total bandwidth of the target cluster can be obtained at this time, and the bandwidth margin of the current target cluster can be calculated: bandwidth margin = total bandwidth - allocated bandwidth of all Pods, where the allocated bandwidth of all Pods can be determined from the target resource object. The target resource object refers to the object in the target cluster used to configure the bandwidth and other related parameters of each Pod. In a specific embodiment, the Pod whose traffic category changes is a hedge fund Pod in a financial trading system. The traffic category of the hedge fund Pod before the change is "normal trading", and the traffic category after the change is "high-frequency trading". Therefore, the bandwidth change type of the hedge fund Pod is a bandwidth increase type. Assuming that the total bandwidth of the financial trading system is 500,000 transactions / second, and the currently allocated bandwidth of all Pods is 400,000 transactions / second, then the bandwidth margin is 100,000 transactions / second.

[0056] If the bandwidth margin is sufficient (≥ bandwidth increase requirement), the bandwidth required by the Pod can be directly allocated, that is, the bandwidth of the Pod can be directly increased to meet the requirement; if the bandwidth margin is insufficient (< bandwidth increase requirement), the reduction process can be entered later:

[0057] First, the system retrieves target pods whose service priorities are lower than a preset priority. Here, the preset priority can be "low" among "high," "medium," and "low," such as the priority corresponding to common services like email delivery. Next, the system determines the allocated bandwidth for these target pods, which is also the allocated bandwidth for pods serving common services.

[0058] Second, identify whether the allocated bandwidth is marked with a reduction tag. If so, it indicates that the allocated bandwidth has been reduced and is now less than the actual bandwidth required. If not, it indicates that the allocated bandwidth has not been reduced and is equal to the actual bandwidth required.

[0059] After identification, if it is found that the allocated bandwidth of these target Pods is not marked with a reduction label, then the product of the preset reduction ratio and the allocated bandwidth can be calculated, that is, the allocated bandwidth of each Pod is reduced according to the preset reduction ratio, wherein the preset reduction ratio can be a ratio determined based on experience that can release part of the bandwidth without seriously affecting the traffic transmission of the target Pod. In this way, each target Pod can release a part of the bandwidth to increase the bandwidth of the Pod whose bandwidth change type is the bandwidth increase type. It should be noted that after the allocated bandwidth of the target Pod is reduced, these allocated bandwidths can be marked with a reduction label to prevent subsequent reductions from affecting the traffic transmission of the target Pod.

[0060] After identification, if the allocated bandwidth of these target Pods is marked with a reduction label, the bandwidth of the Pods with the aforementioned bandwidth change type of bandwidth increase is directly adjusted to meet the demand. That is, the allocated bandwidth corresponding to the target Pod is directly released to match the bandwidth increase demand. At this time, the total allocated bandwidth of the target Pod is reduced. In order to meet the traffic transmission needs of the target Pod, a polling mechanism is set up for these reduced target Pods to handle their network traffic.

[0061] The embodiment of the present application distinguishes service priorities and only reduces bandwidth for low-priority Pods, ensuring that high-priority services obtain sufficient bandwidth resources; uses a preset reduction ratio instead of a fixed value for reduction, which makes reduction more flexible; avoids repeated reductions by marking reduction labels; adopts a polling mechanism for the target Pods that have been reduced to ensure that their services can still be processed; responds to changes in traffic categories in real time and dynamically adjusts bandwidth allocation, which makes dynamic adaptability stronger. The embodiment of the present application achieves efficient utilization and fair allocation of bandwidth resources within the target cluster through priority perception, dynamic reduction and polling guarantee mechanisms.

[0062] In an embodiment of the present application, optionally, the method also includes: monitoring the network delay rate and traffic packet loss rate corresponding to each Pod at preset time intervals, and obtaining the traffic category of the traffic corresponding to each Pod, and determining the target weight corresponding to each Pod according to the traffic category; calculating the network delay parameters of the target cluster according to the target weight and network delay rate corresponding to each Pod; and calculating the traffic packet loss parameters of the target cluster according to the target weight and traffic packet loss rate corresponding to each Pod; calculating the network performance parameters of the target cluster based on the network delay parameters and the traffic packet loss parameters, and judging whether the current network performance meets the preset performance requirements based on the network performance parameters.

[0063] In this embodiment, the network status of the target cluster can be captured in real time. Specifically, monitoring units can be deployed on each node of the target cluster. These units can automatically collect key data related to network performance at pre-set time intervals (e.g., at regular intervals). The collected data primarily includes: Network latency: This metric reflects the speed at which data packets are transmitted across the network. The monitoring unit can record the time required for a data packet to travel from the sender to the receiver and calculate the average latency per unit time. This is crucial for businesses that require fast responses, such as real-time transactions and online gaming. Packet loss rate: This measures the proportion of data packets lost during network transmission. Packet loss can result in incomplete data and affect the normal operation of the business. The monitoring unit can calculate the packet loss rate by counting the number of data packets that fail to reach the receiver per unit time. Therefore, the network latency and packet loss rate corresponding to each pod can be obtained from the monitoring unit of each node. In addition, the traffic category (the latest traffic category) of the network traffic corresponding to each pod can be obtained. Based on the different traffic categories, each pod is assigned a corresponding target weight, thereby reflecting the differentiated network performance requirements of different businesses. For example, critical businesses, such as payment processing in financial transaction systems and remote diagnosis in medical systems, have extremely high requirements for network stability and real-time performance, so they can be assigned higher target weights. This means that their network performance indicators (such as latency and packet loss rate) have a greater impact on the overall cluster network performance evaluation. Non-critical businesses, such as logging and background data synchronization, have relatively low requirements for network performance and can be assigned lower target weights. This way, when evaluating cluster network performance, fluctuations in their indicators have less impact on the overall results. This weight allocation mechanism can more reasonably reflect the importance of different businesses in the target cluster and their sensitivity to network performance, ensuring that subsequent performance evaluations are more aligned with actual business needs.

[0064] After obtaining the network delay rate, traffic packet loss rate, and corresponding target weight of each Pod, a weighted calculation is performed to obtain the network delay parameters and traffic packet loss parameters of the entire target cluster. Network delay parameters: Multiply the network delay rate of each Pod by its corresponding target weight, and then add up the weighted values of all Pods. The network delay parameters calculated in this way can comprehensively reflect the overall impact of different businesses in the target cluster on delay, highlighting the importance of key business delays to overall performance. Traffic packet loss parameters: The calculation method is similar to the network delay parameters. The traffic packet loss rate of each Pod is multiplied by its target weight and then summed up. This parameter can reflect the degree of impact of different business packet loss situations in the target cluster on the overall network quality. Through this weighted fusion method, the network performance indicators scattered on each Pod can be integrated into parameters that reflect the overall network performance of the target cluster, providing a unified standard for subsequent performance evaluation.

[0065] Furthermore, a comprehensive network performance parameter can be calculated based on the calculated network latency and packet loss parameters. This comprehensive parameter is a composite metric that takes into account multiple factors, such as latency and packet loss, and is used to comprehensively assess the network performance status of the target cluster. The calculated network performance parameter is then compared with pre-set performance requirement thresholds. If the network performance parameter meets the preset performance requirements, the target cluster network is operating normally, and monitoring can continue without any intervention. The current network status can be recorded for reference. If the network performance parameter does not meet the preset requirements, an alarm mechanism can be immediately triggered. Alarm methods can include sending text messages or email notifications to operations and maintenance personnel, or displaying prominent alarm messages on the monitoring platform. Furthermore, network optimization processes can be initiated based on pre-set rules, such as automatically adjusting bandwidth allocation and switching network paths, to quickly restore network performance.

[0066] For example, in a financial trading system built on a target cluster, trading services place extremely high demands on the real-time and stability of the network. This embodiment of the present application can assign a high target weight to trading services and a low target weight to general services, and monitor indicators such as network latency and packet loss rate in real time to determine whether the current network performance of the financial trading system meets the preset performance requirements, thereby ensuring that various services within the financial trading system can be completed quickly and accurately.

[0067] For example, in a medical diagnosis system built on a target cluster, telemedicine services place high demands on network reliability. This embodiment of the present application can assign a high target weight to telemedicine services and a low target weight to general services, focusing on network performance for telemedicine services such as remote surgery. This allows for timely detection and resolution of network latency or packet loss issues, ensuring accurate transmission of network traffic within the medical diagnosis system and improving medical quality and patient satisfaction.

[0068] The embodiments of the present application can assign different weights to network performance evaluation according to the characteristics and needs of different businesses, which makes the evaluation results closer to actual business scenarios and can accurately reflect the sensitivity of key businesses to network performance; it not only focuses on a single network performance indicator, but also comprehensively considers multiple key indicators such as network latency and traffic packet loss rate, and then reflects the quality and stability of the network from different angles, and integrates them into a comprehensive network performance parameter through weighted fusion, which can more comprehensively and accurately evaluate the network performance status of the target cluster; by regularly collecting network performance data and performing real-time calculation and evaluation, it can timely discover changes in network performance. Once it is detected that the network performance does not meet the preset requirements, it can quickly trigger an alarm and start the optimization process, realizing dynamic monitoring and real-time response to cluster network performance.

[0069] In an embodiment of the present application, after "determining whether the current network performance meets the preset performance requirements", the method also includes: if the current network performance does not meet the preset performance requirements, calling the preset large model, based on the traffic category, target weight, network delay rate and traffic packet loss rate corresponding to each Pod, through the preset large model, calculating the network adjustment strategy of the target cluster; based on the network adjustment strategy, adjusting the network policy parameters of the target cluster.

[0070] In this embodiment, if the current network performance does not meet the preset performance requirements, a preset large model can be invoked to calculate a network adjustment policy. This preset large model comprehensively considers information from multiple dimensions, including each pod's corresponding traffic category, target weight, network latency, and packet loss rate. This information is crucial for fully understanding the current network status of the target cluster. Different traffic categories have different network performance requirements. The target weight reflects the importance of the service, while the network latency and packet loss rate directly reflect current network issues. Based on this input information, the preset large model uses complex internal algorithms and logical reasoning to calculate a set of network adjustment policies suitable for the target cluster. In a specific embodiment, the preset large model analyzes the traffic category of each pod to understand the operational characteristics and requirements of different service types in the network. For example, services with high real-time requirements, such as online video conferencing, require lower latency and more stable network connections. Meanwhile, some backend data processing services may have relatively low latency requirements but certain requirements for bandwidth stability. Then, combined with the target weight, the preset large model can identify critical services that require priority network performance. Network issues affecting mission-critical businesses can have a serious impact on the entire business system, so more attention and resources are allocated to them in adjustment strategies. Furthermore, based on network latency and packet loss rates, the pre-set large model can locate problem areas and possible causes in the current network. For example, if the Pod latency in a certain area is generally high, it may be due to insufficient network bandwidth or network congestion in that area; if the packet loss rate is high, it may be due to network equipment failure or unstable network links. Based on these analyses, the pre-set large model can generate targeted adjustment strategies, such as adjusting bandwidth allocation, optimizing network routing, and repairing network equipment failures.

[0071] After calculating the network adjustment policy, the network policy parameters of the target cluster can be adjusted based on the policy. These network policy parameters include, but are not limited to, bandwidth limits, routing rules, and QoS (Quality of Service) settings. For example, if the network adjustment policy recommends increasing the bandwidth of a critical business, the network device configuration can be automatically adjusted to allocate more bandwidth resources to that business to ensure smooth network transmission. If the network adjustment policy requires optimizing routing rules, the data packet transmission path can be replanned to select a shorter, more stable path to reduce data transmission delays and packet loss.

[0072] The network environment is dynamic, and a single adjustment may not completely resolve all issues. Therefore, after implementing a network adjustment policy, you can continuously monitor changes in network performance. If the adjusted network performance still doesn't meet the preset requirements, or if new issues arise, you can re-use the pre-set large model, recalculate the adjustment policy based on the latest network data, and adjust the network policy parameters again. This dynamic adjustment and optimization mechanism ensures that the target cluster's network performance remains optimal and adapts to changing business needs and network environments.

[0073] The embodiment of the present application realizes the intelligence of network adjustment decision-making by calling a preset large model for policy calculation. The preset large model can comprehensively consider multiple factors, avoid the subjectivity and one-sidedness of manual decision-making, and improve the accuracy and scientificity of decision-making; when problems occur in network performance, the response process can be quickly started, the preset large model can be called to calculate the adjustment strategy and implement parameter optimization, quickly restore network performance, and reduce the impact on business; the dynamic adjustment and optimization mechanism can adapt to the ever-changing network environment and business needs, whether it is a sudden increase in business traffic or a failure of network equipment, timely adjustments can be made to ensure the stability of network performance.

[0074] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a network traffic classification device, which is applied to the target cluster, such as Figure 3 As shown, the device includes:

[0075] a feature vector extraction module, configured to obtain a plurality of network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true class label and a class weight determined based on the true class label;

[0076] A model training module is used to train an initial traffic classification model using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein a model loss value during the model training process is determined based on a sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of a class deviation and a class weight, where the class deviation is the deviation between the predicted class label and the true class label;

[0077] The traffic category determination module is used to monitor the traffic of each Pod in the target cluster through a cluster traffic monitoring tool, and dynamically construct a traffic feature vector corresponding to the Pod based on the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined through the target traffic classification model.

[0078] Optionally, the feature vector extraction module is used to:

[0079] For each network traffic sample, determine the sample data packets contained in the network traffic sample, and respectively determine the traffic timestamp and data packet size corresponding to each sample data packet;

[0080] Calculating statistical features of the network traffic sample based on the packet size of each sample packet, wherein the statistical features include at least one of a mean, a variance, a maximum value, and a minimum value of the packet size;

[0081] Calculate the time series characteristics and frequency characteristics of the network traffic sample based on the traffic timestamp and packet size of each sample data packet, wherein the time series characteristics include the flow rate time series and / or the packet size time series, and the frequency characteristics include the packet reception frequency and / or the flow rate change rate;

[0082] Based on statistical features, time series features and frequency features, a sample feature vector corresponding to the network traffic sample is constructed.

[0083] Optionally, the target traffic classification model includes a convolution layer, a pooling layer, a fully connected layer, an LSTM layer, a Dropout layer, and a classification layer; the target traffic classification model determines the traffic category based on the following steps:

[0084] Inputting the flow feature vector into the convolution layer, performing convolution operations on the flow feature vector through each convolution kernel in the convolution layer, and obtaining a first feature corresponding to each convolution kernel;

[0085] Inputting the first feature corresponding to each convolution kernel into the pooling layer to obtain the second feature;

[0086] Inputting the second feature into the fully connected layer to obtain a third feature;

[0087] The third feature and the historical feature obtained by passing the previous traffic feature vector of the Pod through the LSTM layer are input into the LSTM layer. The first activation value of the forget gate, the second activation value of the input gate, and the candidate memory unit state value in the LSTM layer are calculated. An updated memory unit state value is obtained based on the first activation value, the second activation value, and the candidate memory unit state value. The fourth feature is calculated based on the updated memory unit state value.

[0088] The fourth feature is input into the Dropout layer to obtain a fifth feature, and the fifth feature is input into the classification layer to obtain a traffic category corresponding to the traffic feature vector.

[0089] Optionally, the device further includes a monitoring module; the monitoring module is configured to:

[0090] When a change in the traffic category corresponding to any Pod is detected, the target bandwidth, target priority, and target network policy corresponding to the any Pod are determined based on the changed traffic category, and the cluster API interface is called. Based on the target bandwidth, target priority, and target network policy, the preset configuration parameters corresponding to the any Pod in the target resource object of the target cluster are adjusted through the cluster API interface.

[0091] Optionally, the monitoring module is further configured to:

[0092] Determine the bandwidth change type of any Pod based on the traffic category after the change and the traffic category before the change;

[0093] When the bandwidth change type of any Pod is a bandwidth increase type, determine the bandwidth increase requirement of any Pod, obtain the total bandwidth of the target cluster, and determine the bandwidth margin of the current target cluster based on the total bandwidth and the target resource object;

[0094] If the bandwidth margin is less than the bandwidth increase demand corresponding to any Pod, obtain a target Pod whose service priority is lower than the preset priority, and determine the allocated bandwidth corresponding to the target Pod;

[0095] If the allocated bandwidth is not marked with a reduction label, calculate the product of a preset bandwidth reduction ratio and the allocated bandwidth, adjust the allocated bandwidth according to the preset bandwidth reduction ratio, mark the adjusted allocated bandwidth with a reduction label, and increase the bandwidth of any Pod based on the product result;

[0096] In the case where the allocated bandwidth is marked with a reduction label, based on the allocated bandwidth corresponding to the target Pod, the bandwidth of any Pod is adjusted to meet the bandwidth increase demand, and a polling mechanism is set for the target Pod to process the network traffic of the target Pod based on the polling mechanism.

[0097] Optionally, the monitoring module is further configured to:

[0098] Monitor the network latency and packet loss rate of each Pod at preset time intervals, obtain the traffic category of each Pod, and determine the target weight of each Pod based on the traffic category.

[0099] Calculate the network delay parameter of the target cluster based on the target weight and network delay rate corresponding to each Pod; and calculate the traffic packet loss parameter of the target cluster based on the target weight and traffic packet loss rate corresponding to each Pod;

[0100] Based on the network delay parameter and the traffic packet loss parameter, the network performance parameter of the target cluster is calculated, and according to the network performance parameter, it is determined whether the current network performance meets the preset performance requirement.

[0101] Optionally, the device further includes a policy adjustment module; the policy adjustment module is configured to:

[0102] After determining whether the current network performance meets the preset performance requirements, if the current network performance does not meet the preset performance requirements, the preset large model is called to calculate the network adjustment strategy of the target cluster based on the traffic category, target weight, network delay rate and traffic packet loss rate corresponding to each Pod.

[0103] Based on the network adjustment policy, the network policy parameters of the target cluster are adjusted.

[0104] It should be noted that for other corresponding descriptions of the functional units involved in the network traffic classification device provided in the embodiment of the present application, please refer to Figures 1 to 2 The corresponding description in the method will not be repeated here.

[0105] The present application also provides a computer device, which can be a personal computer, a server, a network device, etc. Figure 4As shown, the computer device includes a bus, a processor, a memory, and a communication interface, and may also include an input / output interface and a display device. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the steps of each method embodiment are implemented.

[0106] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0107] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0108] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0109] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0110] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0111] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0112] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A network traffic classification method, characterized in that: Applied to the target cluster, the method includes: Acquire multiple network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true class label and a class weight determined based on the true class label; The initial traffic classification model is trained using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein the model loss value during the model training process is determined based on the sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of the class deviation and the class weight, wherein the class deviation is the deviation between the predicted class label and the true class label; For each Pod in the target cluster, the traffic of the Pod is monitored using a cluster traffic monitoring tool, and a traffic feature vector corresponding to the Pod is dynamically constructed based on the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined using the target traffic classification model.

2. The method according to claim 1, characterized in that The data feature extraction for each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample includes: For each network traffic sample, determine the sample data packets contained in the network traffic sample, and respectively determine the traffic timestamp and data packet size corresponding to each sample data packet; Calculating statistical features of the network traffic sample based on the packet size of each sample packet, wherein the statistical features include at least one of a mean, a variance, a maximum value, and a minimum value of the packet size; Calculate the time series characteristics and frequency characteristics of the network traffic sample based on the traffic timestamp and packet size of each sample data packet, wherein the time series characteristics include the flow rate time series and / or the packet size time series, and the frequency characteristics include the packet reception frequency and / or the flow rate change rate; Based on statistical features, time series features and frequency features, a sample feature vector corresponding to the network traffic sample is constructed.

3. The method according to claim 1, characterized in that The target traffic classification model includes a convolutional layer, a pooling layer, a fully connected layer, an LSTM layer, a Dropout layer, and a classification layer. The target traffic classification model determines the traffic category based on the following steps: Inputting the flow feature vector into the convolution layer, performing convolution operations on the flow feature vector through each convolution kernel in the convolution layer, and obtaining a first feature corresponding to each convolution kernel; Inputting the first feature corresponding to each convolution kernel into the pooling layer to obtain the second feature; Inputting the second feature into the fully connected layer to obtain a third feature; The third feature and the historical feature obtained by passing the previous traffic feature vector of the Pod through the LSTM layer are input into the LSTM layer. The first activation value of the forget gate, the second activation value of the input gate, and the candidate memory unit state value in the LSTM layer are calculated. An updated memory unit state value is obtained based on the first activation value, the second activation value, and the candidate memory unit state value. The fourth feature is calculated based on the updated memory unit state value. The fourth feature is input into the Dropout layer to obtain a fifth feature, and the fifth feature is input into the classification layer to obtain a traffic category corresponding to the traffic feature vector.

4. The method according to claim 1, wherein The method further comprises: When a change in the traffic category corresponding to any Pod is detected, the target bandwidth, target priority, and target network policy corresponding to the any Pod are determined based on the changed traffic category, and the cluster API interface is called. Based on the target bandwidth, target priority, and target network policy, the preset configuration parameters corresponding to the any Pod in the target resource object of the target cluster are adjusted through the cluster API interface.

5. The method according to claim 4, characterized in that Determining the target bandwidth corresponding to any Pod based on the changed traffic category includes: Determine the bandwidth change type of any Pod based on the traffic category after the change and the traffic category before the change; When the bandwidth change type of any Pod is a bandwidth increase type, determine the bandwidth increase requirement of any Pod, obtain the total bandwidth of the target cluster, and determine the bandwidth margin of the current target cluster based on the total bandwidth and the target resource object; If the bandwidth margin is less than the bandwidth increase demand corresponding to any Pod, obtain a target Pod whose service priority is lower than the preset priority, and determine the allocated bandwidth corresponding to the target Pod; If the allocated bandwidth is not marked with a reduction label, calculate the product of a preset bandwidth reduction ratio and the allocated bandwidth, adjust the allocated bandwidth according to the preset bandwidth reduction ratio, mark the adjusted allocated bandwidth with a reduction label, and increase the bandwidth of any Pod based on the product result; In the case where the allocated bandwidth is marked with a reduction label, based on the allocated bandwidth corresponding to the target Pod, the bandwidth of any Pod is adjusted to meet the bandwidth increase demand, and a polling mechanism is set for the target Pod to process the network traffic of the target Pod based on the polling mechanism.

6. The method according to claim 4, characterized in that The method further comprises: Monitor the network latency and packet loss rate of each Pod at preset time intervals, obtain the traffic category of each Pod, and determine the target weight of each Pod based on the traffic category. Calculate the network delay parameter of the target cluster based on the target weight and network delay rate corresponding to each Pod; and calculate the traffic packet loss parameter of the target cluster based on the target weight and traffic packet loss rate corresponding to each Pod; Based on the network delay parameter and the traffic packet loss parameter, the network performance parameter of the target cluster is calculated, and according to the network performance parameter, it is determined whether the current network performance meets the preset performance requirement.

7. The method according to claim 6, characterized in that After determining whether the current network performance meets the preset performance requirements, the method further includes: If the current network performance does not meet the preset performance requirements, the preset large model is called to calculate the network adjustment strategy of the target cluster based on the traffic category, target weight, network latency rate and traffic packet loss rate corresponding to each Pod. Based on the network adjustment policy, the network policy parameters of the target cluster are adjusted.

8. A network traffic classification device, characterized in that: Applied to a target cluster, the device includes: a feature vector extraction module, configured to obtain a plurality of network traffic samples and perform data feature extraction on each network traffic sample to obtain a sample feature vector corresponding to the network traffic sample, wherein each network traffic sample is marked with a true class label and a class weight determined based on the true class label; A model training module is used to train an initial traffic classification model using the sample feature vectors corresponding to each network traffic sample to obtain a target traffic classification model, wherein a model loss value during the model training process is determined based on a sub-loss value corresponding to each network traffic sample, and the sub-loss value corresponding to each network traffic sample is determined based on the product of a class deviation and a class weight, where the class deviation is the deviation between the predicted class label and the true class label; The traffic category determination module is used to monitor the traffic of each Pod in the target cluster through a cluster traffic monitoring tool, and dynamically construct a traffic feature vector corresponding to the Pod based on the monitoring results. Based on the dynamically constructed traffic feature vector, the traffic category corresponding to the Pod is continuously determined through the target traffic classification model.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Network traffic classification method, system and device, and storage medium

    CN120915687A