Network fault flow optimization method and system based on security protocol scheduling
By setting up dial-up points in multiple geographical locations and utilizing a secure protocol mechanism to dispatch user traffic to a dynamic content distribution network in the event of a network failure, and switching back to the public network when normal operation is restored, the problems of untimely network failure detection and high DCDN costs are resolved, achieving efficient traffic dispatching and low-cost network operation.
Patent Information
- Application Number
- CN202510654757.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-09-05
AI Technical Summary
Existing network fault detection methods are not timely and accurate enough, resulting in the inability to quickly switch to backup network entrances when a network failure occurs, affecting business continuity and user experience. At the same time, the cost of dynamic content distribution network solutions is too high.
By setting up dial-up test points at multiple geographical locations, the network in the target area is monitored in real time. The security protocol mechanism is used to dispatch user traffic to the dynamic content distribution network in the event of a network failure. When the network returns to normal, the traffic is switched back to the public network through the load balancer, achieving flexible scheduling and reducing costs.
It achieves timely detection of network failures and flexible traffic scheduling, reduces network operation costs, improves business continuity and user experience, reduces manual intervention, and ensures network operation efficiency and reliability.
Smart Images

Figure CN120602124A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network communication technology, and in particular to a network fault flow optimization method and system based on security protocol scheduling. Background Art
[0002] With the continuous expansion of global business, enterprises often face network jitter during operations. In certain regions, network instability can be widespread due to carrier failures, leading to business interruptions and customer churn. To address this issue, enterprises often use dynamic content delivery network solutions from cloud vendors and other suppliers. This solution improves network availability and reduces latency through dedicated lines and line redundancy, but it comes at a high cost, more than double the cost of regular public network traffic.
[0003] While existing Dynamic Content Delivery Network (DCDN) solutions offer excellent availability and latency, their high cost presents a major technical drawback. Specifically, DCDN solutions utilize dedicated networks and line redundancy to ensure network stability, but this approach is prohibitively expensive for many businesses. Existing network fault detection methods are often inaccurate and inefficient, preventing rapid failover to backup network access points when a fault occurs. This impacts business continuity and negatively impacts the user experience.
[0004] Therefore, a network fault flow optimization method and system based on security protocol scheduling are proposed. Summary of the Invention
[0005] To solve the above technical problems, the present invention provides a network fault traffic optimization method and system based on security protocol scheduling, which is used to solve the problems of poor performance of existing network fault detection and traffic scheduling and high cost of dynamic content distribution network solutions, so as to improve business stability and user experience.
[0006] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising:
[0007] By setting up dial-up test points at multiple geographical locations, the network in the target area can be monitored in real time;
[0008] When a network failure in the target area is detected, user traffic is dispatched to the dynamic content distribution network based on a security protocol mechanism, and the user terminal device accesses the network link through the dynamic content distribution network;
[0009] When it is detected that the network in the target area has returned to normal, the user traffic is evenly distributed to multiple servers or network links through a load balancer based on a security protocol mechanism, and the use of the dynamic content distribution network is disconnected.
[0010] Preferably, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, the steps of which include: setting dial-up test points at multiple geographical locations to perform real-time monitoring of the network in the target area; and
[0011] Deploy dial-up test points at multiple geographical locations, each equipped with a corresponding dial-up test terminal.
[0012] The network monitoring terminal issues a dialing test task to the dialing test terminal, performs real-time detection on the network in the target area, and transmits the obtained dialing test results back to the network monitoring terminal; including:
[0013] The network monitoring terminal formulates a planned dialing test task according to the deployment status of the dialing test terminal and sends it to the dialing test terminal;
[0014] The dial test terminal parses and processes the planned dial test task to obtain a dial test start time, a dial test cycle, a dial test end time, and a polling number. When the current time period reaches the dial test start time, the dial test terminal is awakened to monitor the network of the target area based on the planned dial test task. When the current time period reaches the dial test end time, the dial test terminal transmits the terminal monitoring result back to the network monitoring terminal and controls the dial test terminal to enter a dormant state.
[0015] The network monitoring end analyzes and processes the terminal monitoring results transmitted back, and when it is detected that there is no abnormality in the network, uses the terminal monitoring results as the dial test results; when it is detected that there is an abnormality in the network, an immediate dial test task is sent to the dial test terminal of the network in the monitoring target area through the network monitoring end, and the network in the target area is monitored simultaneously. The dial test results are obtained based on the immediate test results transmitted back by each dial test terminal.
[0016] Preferably, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, the steps of: when a network fault in a target area is detected, scheduling user traffic to a dynamic content distribution network based on a security protocol mechanism, and allowing a user terminal device to access a network link through the dynamic content distribution network; including:
[0017] When a network failure in the target area is detected, the request information and destination address are obtained based on user traffic analysis, and the request information and destination address are encapsulated into an information request packet using an encryption protocol based on a security protocol mechanism;
[0018] transmitting the information request packet to a protocol parser via the dynamic content delivery network;
[0019] Performing security detection on the information request packet through the monitoring port on the protocol analyzer to obtain the request detection result;
[0020] After determining that the information request packet has passed the security detection, the received information request packet is parsed and processed to obtain the request information and the destination address, and the request information is transmitted to the target server according to the destination address.
[0021] Preferably, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, wherein the step of transmitting the information request packet to the protocol parser via the dynamic content distribution network comprises:
[0022] According to the information request packet, obtaining a network server cluster with corresponding processing capabilities in the dynamic content distribution network;
[0023] Establishing a search area based on the network server cluster, by setting a number of search points, randomly selecting initial positions of the search points in the search area, and updating the spatial positions according to the performance evaluation values of the network servers, to obtain a sub-search area for each search point;
[0024]
[0025] in, is the updated position of the i-th search point, R best is the currently obtained optimal position, a is the position change parameter, K j is the sinusoidal mapping parameter, R m is the current average distribution position of all search points, is the current position of the i-th search point;
[0026]
[0027] Among them, c j is a random parameter in the parameter interval [0, C], K j-1 is the sinusoidal mapping parameter of the last updated position;
[0028] The search point updates a position in the sub-search area using a first search path to obtain a first optimized network server;
[0029]
[0030] in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the first search path, w i is the perturbation parameter value corresponding to the i-th search point, rand is a random parameter, For the i-th search point in the corresponding sub-search area z i The optimal position obtained by the first search path, Δx is the lateral displacement of the search point based on the current position and the updated position, and Δy is the longitudinal displacement of the search point based on the current position and the updated position;
[0031] The search point updates its position in the sub-search area using a second search path to obtain a second optimized network server;
[0032]
[0033] in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the maximum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the minimum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The current location obtained by the second search path;
[0034] Comparing the first and second performance evaluation values corresponding to the first and second optimized network servers to obtain the optimal network server;
[0035] When the optimal network server is obtained, the transmission distance between the optimal network server and the user terminal device is evaluated, and when the transmission distance meets a threshold requirement, the information request packet is transmitted through the optimal network server.
[0036] Preferably, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, the steps of: establishing a search area based on the network server cluster, setting a plurality of search points, randomly selecting initial positions in the search area, and updating spatial positions according to the working performance evaluation value of the network server to obtain a sub-search area for each search point; comprising:
[0037] Obtaining a performance evaluation value of the network server based on the operating status of the network server and the network quality;
[0038] S i =μ1*(α d *d i +α c *ci +α m *m i )+μ2*(σ t *t i +σ p *p i )
[0039] Among them, S i is the performance evaluation value of the i-th network server, μ1 is the first weight parameter, and μ2 is the second weight parameter; d i is the bandwidth surplus rate of the i-th network server, α d is the corresponding bandwidth weight value, c i is the computing resource surplus rate of the i-th network server, α c is the corresponding resource weight value, m i The memory remaining rate of the i-th network server, α m is the corresponding memory weight value; t i is the transmission delay for communicating with the i-th network server, σ t is the corresponding delay weight value, p i is the packet loss rate of the i-th network server, σ p is the corresponding packet loss weight value.
[0040] Preferably, the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, the steps of: performing security detection on the information request packet through the monitoring port on the protocol analyzer to obtain the request detection result; comprising:
[0041] Obtaining the transmission delay, transmission direction, and data length of the information request packet, and constructing a detection sequence;
[0042] Preprocessing and shaping the detection sequence according to the model detection requirements, adjusting the dimension of the detection sequence, arranging the continuous features of the information request packet in the horizontal direction, and arranging the information requests of the information request packet at different times in the vertical direction, to construct a preprocessed detection sequence;
[0043] Extracting spatial feature information of the preprocessed detection sequence through a convolutional neural network model, extracting temporal feature information of the preprocessed detection sequence through a long short-term memory network model, and extracting key feature information of the preprocessed detection sequence through a multi-attention mechanism network model, performing feature mapping through a fully connected layer, and obtaining detection feature information;
[0044] Constructing a safety detection model, adding sample labels to the sample detection sequence, training the safety detection model based on a loss function, and optimizing the control parameters of the safety detection model;
[0045]
[0046] Among them, θ i ′ is the control parameter obtained by optimizing the detection sequence of the i-th sample, θ 0 is the initial control parameter of the security detection model, γ is the learning rate on the sample detection sequence, L i (θ 0 ) is the initial control parameter θ 0 Set the security detection model to calculate the loss function value obtained by the i-th sample detection sequence;
[0047] Optimizing the control parameters of the safety detection model through all sample detection sequences to obtain optimized control parameters;
[0048]
[0049] Among them, θ is the optimized control parameter of the safety detection model, and there are n sample detection sequences in total;
[0050] The detection feature information is input into the security detection model for detection to obtain a corresponding request detection result. When it is detected that the detection sequence is a malicious access, shielding measures are executed to prohibit the protocol parser from parsing and processing the information request packet.
[0051] Preferably, the present invention provides a method for optimizing network failure traffic based on security protocol scheduling, the method comprising: when monitoring that the network in the target area has returned to normal, evenly distributing user traffic to multiple servers or network links through a load balancer based on a security protocol mechanism, and disconnecting the use of the dynamic content distribution network; comprising:
[0052] The load balancer receives user traffic transmitted by the user terminal device and parses it to obtain the request information and destination address;
[0053] The load balancer obtains a public network server capable of processing the request information according to the request information, and builds the public network server pool;
[0054] By obtaining processor resources of the public network servers in the public network server pool, calculating the response time of the public network servers to the request information, and calculating the information transmission time according to the transmission route between the load balancer and the public network servers, and obtaining the static processing response time according to the response time and the information transmission time;
[0055] Obtaining the real-time task processing status of the public network server in the current public network server pool, and obtaining the dynamic processing response time of the public network server to the request information;
[0056] Based on the static processing response time and the dynamic processing response time, the processing response time corresponding to each public network server is obtained. The load balancer selects the public network server with the shortest processing response time as the request processing server, and modifies the destination address to the access address of the request processing server, and transmits the user traffic to the request processing server.
[0057] Preferably, the present invention provides a network fault flow optimization method based on security protocol scheduling, comprising:
[0058] The load balancer provides a unique access entrance for the user terminal device to receive the user traffic;
[0059] The security protocol mechanism caches the access entrances of the load balancer and the dynamic content distribution network, and automatically switches the access entrances of the load balancer and the dynamic content distribution network according to the network operation status of the target area;
[0060] The user terminal device caches an access entry of the dynamic content distribution network. When a network request fails, the user terminal device automatically retry the network access through the access entry of the dynamic content distribution network.
[0061] The present invention provides a network fault flow optimization system based on security protocol scheduling, comprising:
[0062] The network monitoring module is used to monitor the network in the target area in real time by setting up dial-up test points at multiple geographical locations;
[0063] A network scheduling module is used to schedule user traffic to a dynamic content distribution network based on a security protocol mechanism when a network failure is detected in a target area, and the user terminal device accesses the network link through the dynamic content distribution network;
[0064] The network scheduling module is also used to evenly distribute user traffic to multiple servers or network links through a load balancer based on a security protocol mechanism when it is monitored that the network in the target area has returned to normal, and disconnect the use of the dynamic content distribution network.
[0065] Compared with traditional technologies, the beneficial effects of the present invention are: a network fault traffic optimization method and system based on security protocol scheduling realizes real-time automatic fault monitoring of the target area network by setting dial-up test points at multiple geographical locations, and when a network fault is detected, user traffic is dispatched to the dynamic content distribution network based on the security protocol mechanism to ensure the continuity of user services, and when the network returns to normal, it switches back to normal public network use, realizing flexible scheduling of user traffic and avoiding unnecessary network cost expenditure; the above technical solution reduces network operating costs by using the dynamic content distribution network only during network faults, avoiding the problem of high costs of long-term use of the dynamic content distribution network, and at the same time, intelligently switching between the public network and the dynamic content distribution network based on the security protocol mechanism reduces manual intervention, improves network operating efficiency and reliability, ensures business continuity, and enhances user experience.
[0066] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.
[0067] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] Figure 1 A schematic diagram of the flow chart of a network fault flow optimization method based on security protocol scheduling provided by the present invention;
[0069] Figure 2 This is a structural diagram of a network fault flow optimization system based on security protocol scheduling provided by the present invention. DETAILED DESCRIPTION
[0070] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0071] Example 1:
[0072] The embodiment of the present invention provides a network fault flow optimization method based on security protocol scheduling, referring to Figure 1 ,include:
[0073] By setting up dial-up test points at multiple geographical locations, the network in the target area can be monitored in real time;
[0074] When a network failure is detected in the target area, user traffic is dispatched to the dynamic content distribution network based on the security protocol mechanism, and the user terminal device accesses the network link through the dynamic content distribution network;
[0075] When it is detected that the network in the target area has returned to normal, the user traffic is evenly distributed to multiple servers or network links through the load balancer based on the security protocol mechanism, and the use of the dynamic content distribution network is disconnected.
[0076] In the above embodiments, by setting up dial-up test points at multiple geographical locations, the network of the target area is monitored in real time. When a network failure in the target area is detected, user traffic is dispatched to the dynamic content distribution network based on a security protocol mechanism, and the user terminal device accesses the network link through the dynamic content distribution network. When the network in the target area is detected to be restored to normal, the user traffic is evenly distributed to multiple servers or network links through a load balancer based on a security protocol mechanism, and the use of the dynamic content distribution network is disconnected.
[0077] In the above embodiments, the security protocol mechanism is implemented as the DOH (DNS-over-HTTPS) protocol, which uses the HTTPS protocol to encrypt and transmit DNS query requests. By encapsulating the DNS query in HTTPS, the problem of user DNS query requests in the original DNS protocol being eavesdropped or modified is avoided, thereby enhancing the security and privacy of DNS queries.
[0078] In the above embodiments, the Dynamic Content Delivery Network (DCDN) is a network used to accelerate the transmission of dynamic content. It not only caches static content but also reduces the distance between users and the source server by optimizing the paths of dynamic requests, intelligent scheduling, and edge computing, thereby improving the transmission efficiency of dynamic content. It is mainly used to accelerate dynamic content such as database query results, API request responses, personalized pages, and other real-time generated content.
[0079] In the above embodiments, a load balancer (LB) is a device or software used to evenly distribute network traffic or computing tasks across multiple servers or network links. It provides a single external access point through a proxy server and forwards requests to an internal server cluster based on request characteristics and a pre-set algorithm, thereby improving system concurrency, availability, and responsiveness.
[0080] The beneficial effects of the above technology are: by setting up dial-up test points at multiple geographical locations, real-time automatic fault monitoring of the target area network is achieved, and when a network failure is detected, user traffic is dispatched to the dynamic content distribution network based on the security protocol mechanism to ensure the continuity of user services. When the network returns to normal, it switches back to normal public network use, achieving flexible scheduling of user traffic and avoiding unnecessary network cost expenditure; compared with traditional technologies, the above method reduces network operating costs by only using the dynamic content distribution network during network failures, avoiding the high cost of long-term use of the dynamic content distribution network, and at the same time, intelligently switching between the public network and the dynamic content distribution network based on the security protocol mechanism reduces manual intervention, improves network operating efficiency and reliability, ensures business continuity, and enhances user experience.
[0081] Example 2:
[0082] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising the steps of: setting dial-up test points at multiple geographical locations to perform real-time monitoring of the network in the target area; and
[0083] Deploy dial-up test points at multiple geographical locations, each equipped with a corresponding dial-up test terminal.
[0084] The network monitoring terminal issues a dial test task to the dial test terminal, performs real-time network testing on the target area, and transmits the obtained dial test results back to the network monitoring terminal. This includes:
[0085] The network monitoring end formulates a planned dial test task based on the deployment of the dial test terminal and sends it to the dial test terminal;
[0086] The dial test terminal parses the planned dial test task and obtains the dial test start time, dial test cycle, dial test end time, and polling number. When the current time period reaches the dial test start time, the dial test terminal is awakened to monitor the network of the target area based on the planned dial test task. When the current time period reaches the dial test end time, the dial test terminal transmits the terminal monitoring result back to the network monitoring terminal and controls the dial test terminal to enter a dormant state.
[0087] The network monitoring end parses and processes the terminal monitoring results transmitted back. When no network anomalies are detected, the terminal monitoring results are used as the dial test results. When a network anomaly is detected, an immediate dial test task is sent to the dial test terminal in the target area network through the network monitoring end, and the network in the target area is monitored simultaneously. The dial test results are obtained based on the immediate test results transmitted back by each dial test terminal.
[0088] In the above embodiments, dial-up test points are deployed at multiple geographical locations, each of which is equipped with a corresponding dial-up test terminal. The network monitoring terminal issues a dial-up test task to the dial-up test terminal, performs real-time detection on the network in the target area, and transmits the obtained dial-up test results back to the network monitoring terminal.
[0089] In the above embodiment, the network monitoring end sends the planned dial test task to the dial test terminal. The dial test terminal parses and processes the planned dial test task to obtain the dial test start time, dial test cycle, dial test end time, and polling number. When the current time period reaches the dial test start time, the dial test terminal is awakened to perform network monitoring of the target area based on the planned dial test task. When the current time period reaches the dial test end time, the dial test terminal transmits the terminal monitoring result back to the network monitoring end and controls the dial test terminal to enter a dormant state.
[0090] In the above embodiments, the network monitoring terminal parses and processes the terminal monitoring results transmitted back. When a network anomaly is detected, the network monitoring terminal sends an immediate dialing test task to the dialing test terminal of the target area network, monitors the network in the target area simultaneously, and obtains the dialing test results based on the immediate test results transmitted back by each dialing test terminal.
[0091] The beneficial effects of the above technology are: by issuing planned dial-up test tasks to the dial-up test terminals through the network monitoring terminal, each dial-up test terminal can realize polling monitoring of the target area network, avoiding the problem of multiple dial-up test terminals continuously monitoring the network for a long time and consuming resources. In addition, when any dial-up test terminal detects a network anomaly, all dial-up test terminals are awakened to perform real-time network monitoring and obtain the dial-up test results. The above technical solution can detect network failures in a timely and accurate manner, providing a basis for subsequent traffic scheduling. While realizing network monitoring in the target area, it effectively reduces the power consumption required for monitoring.
[0092] Example 3:
[0093] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising the following steps: when a network fault in a target area is detected, user traffic is scheduled to a dynamic content distribution network based on a security protocol mechanism, and a user terminal device accesses a network link through the dynamic content distribution network; the method comprises:
[0094] When a network failure in the target area is detected, the system obtains the request information and destination address based on user traffic analysis, and encapsulates the request information and destination address into an information request packet using an encryption protocol based on the security protocol mechanism;
[0095] Transmitting the information request packet to the protocol parser via the dynamic content delivery network;
[0096] Perform security detection on the information request packet through the monitoring port on the protocol analyzer to obtain the request detection result;
[0097] After determining that the information request packet has passed the security detection, the received information request packet is parsed and processed to obtain the request information and the destination address, and the request information is transmitted to the target server according to the destination address.
[0098] In the above embodiments, when a network failure in the target area is detected, the request information and destination address are obtained based on user traffic analysis, and the request information and destination address are encapsulated into an information request packet using an encryption protocol based on a security protocol mechanism. The information request packet is transmitted to the protocol parser through the dynamic content distribution network. After the monitoring port on the protocol parser performs a security check on the information request packet and passes it, the received information request packet is parsed and processed to obtain the request information and destination address, and the request information is transmitted to the target server according to the destination address.
[0099] In the above embodiment, the security check of the information request packet is implemented through the monitoring port on the protocol analyzer, and the parsing process of the information request packet is stopped when the security check fails.
[0100] The beneficial effects of the above technology are: through the dynamic content distribution network, user traffic scheduling and processing are realized when a network failure occurs, user traffic is parsed and encapsulated as an information request packet based on a security protocol mechanism and encrypted protocol and transmitted to the protocol parser, and the request information is transmitted to the target server according to the destination address, realizing the data transmission function of the dynamic content distribution network, and setting a monitoring port to detect the information request packet, avoiding the processing of the information request packet containing virus files, and effectively improving the security of information transmission.
[0101] Example 4:
[0102] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising the steps of: transmitting an information request packet to a protocol parser via a dynamic content distribution network; and
[0103] Obtaining a network server cluster with corresponding processing capabilities in a dynamic content distribution network according to the information request packet;
[0104] A search area is established based on a network server cluster. Several search points are set up, and the search points randomly select initial positions in the search area. The spatial positions are updated according to the performance evaluation values of the network servers to obtain a sub-search area for each search point.
[0105]
[0106] in, is the updated position of the i-th search point, R best is the currently obtained optimal position, a is the position change parameter, Kj is the sinusoidal mapping parameter, R m is the current average distribution position of all search points, is the current position of the i-th search point;
[0107]
[0108] Among them, c j is a random parameter in the parameter interval [0, C], K j-1 is the sinusoidal mapping parameter of the last updated position;
[0109] The search point updates its position in the sub-search area using the first search path to obtain a first optimized network server;
[0110]
[0111] in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the first search path, w i is the perturbation parameter value corresponding to the i-th search point, rand is a random parameter, For the i-th search point in the corresponding sub-search area z i The optimal position obtained by the first search path, Δx is the lateral displacement of the search point based on the current position and the updated position, and Δy is the longitudinal displacement of the search point based on the current position and the updated position;
[0112] The search point updates its position in the sub-search area using a second search path to obtain a second optimized network server;
[0113]
[0114] in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the maximum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the minimum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The current location obtained by the second search path;
[0115] Comparing the first and second performance evaluation values corresponding to the first and second optimized network servers to obtain the optimal network server;
[0116] When the optimal network server is obtained, the transmission distance between the optimal network server and the user terminal device is evaluated, and when the transmission distance meets the threshold requirement, the information request packet is transmitted through the optimal network server.
[0117] In the above embodiments, the dynamic content distribution network obtains a network server cluster with corresponding processing capabilities in the dynamic content distribution network based on the information request packet, selects the optimal network server in the network server cluster, and when the transmission distance between the optimal network server and the user terminal device meets the threshold requirement, the information request packet is transmitted to the target server through the optimal network server.
[0118] In the above embodiments, for the selection of the optimal network server, a search area is established based on the network server cluster. By setting a number of search points, the search points randomly select initial positions in the search area, and update the spatial positions according to the work performance evaluation values of the network servers to obtain a sub-search area for each search point; the search points update their positions in the sub-search areas using the first search path and the second search path respectively to obtain the first optimized network server and the second optimized network server, and the optimal network server is obtained according to the corresponding work performance evaluation.
[0119] In the above embodiment, the sub-search area of the search point is obtained by adding a sine mapping parameter based on the current position and the currently obtained optimal position of the search point. The setting of the sine mapping parameter effectively improves the global search capability of the search point.
[0120] In the above embodiment, the search point updates its position in the sub-search area using the first search path, and by adding random perturbations, the convergence speed of the algorithm is accelerated, while the risk of falling into local optimality during the search process is reduced, thereby obtaining the first optimized network server in the sub-search area.
[0121] In the above embodiment, the search point updates its position in the sub-search area using the second search path, and seeks the optimal solution in the sub-search area by introducing a reverse learning strategy, thereby effectively improving the optimization accuracy of the algorithm.
[0122] The beneficial effects of the above technology are: by obtaining a network server cluster that can process information request packets, setting a search point to search for the optimal network server in the network server cluster, and when the transmission distance meets the threshold requirement, transmitting the information request packet to the target server through the optimal network server, it is realized that the optimal network server is intelligently selected for the transmission of information request packets in the dynamic content distribution network, and the threshold requirement of the transmission distance is set, thereby further improving the processing rate of the dynamic content distribution network for user traffic.
[0123] Example 5:
[0124] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising the following steps: establishing a search area based on a network server cluster, setting a number of search points, randomly selecting initial positions within the search area, and updating the spatial positions based on the performance evaluation values of the network servers to obtain a sub-search area for each search point; and comprising:
[0125] Obtaining a performance evaluation value of the network server based on the network server's operating status and network quality;
[0126] S i =μ1*(α d *d i +α c *c i +α m *m i )+μ2*(τ t *t i +τ p *p i )
[0127] Among them, S i is the performance evaluation value of the i-th network server, μ1 is the first weight parameter, and μ2 is the second weight parameter; d i is the bandwidth surplus rate of the i-th network server, α d is the corresponding bandwidth weight value, c i is the computing resource surplus rate of the i-th network server, α c is the corresponding resource weight value, m i The memory remaining rate of the i-th network server, α m is the corresponding memory weight value; t i is the transmission delay for communicating with the i-th network server, σ t is the corresponding delay weight value, p i is the packet loss rate of the i-th network server, σ p is the corresponding packet loss weight value.
[0128] In the above embodiments, the local working performance of the network server is calculated by obtaining the bandwidth surplus rate, computing resource surplus rate, and memory surplus rate of the network server, and the transmission status performance of the network server is calculated by obtaining the transmission delay and packet loss rate of the network server for communication. By dynamically allocating weights, the network server working performance evaluation value is obtained.
[0129] The beneficial effect of the above technology is that by analyzing the operating status of the network server and the network quality, the working performance evaluation value of the network server is obtained, thereby providing a reliable basis for searching for the optimal network server in the network server cluster.
[0130] Example 6:
[0131] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising the steps of: performing security detection on an information request packet through a monitoring port on a protocol analyzer to obtain a request detection result; and comprising:
[0132] Obtain the transmission delay, transmission direction and data length of the information request packet and construct a detection sequence;
[0133] Preprocess and shape the detection sequence according to the model detection requirements, adjust the dimension of the detection sequence, arrange the continuous features of the information request packet in the horizontal direction, and arrange the information requests of the information request packet at different times in the vertical direction to construct a preprocessed detection sequence;
[0134] The spatial feature information of the preprocessed detection sequence is extracted through the convolutional neural network model, the temporal feature information of the preprocessed detection sequence is extracted through the long short-term memory network model, and the key feature information of the preprocessed detection sequence is extracted through the multi-attention mechanism network model. Feature mapping is performed through the fully connected layer to obtain detection feature information;
[0135] Build a security detection model, add sample labels to the sample detection sequence, train the security detection model based on the loss function, and optimize the control parameters of the security detection model;
[0136]
[0137] Among them, θ i ′ is the control parameter obtained by optimizing the detection sequence of the i-th sample, θ 0 is the initial control parameter of the security detection model, γ is the learning rate on the sample detection sequence, L i (θ 0 ) is the initial control parameter θ 0 Set the security detection model to calculate the loss function value obtained by the i-th sample detection sequence;
[0138] Optimize the control parameters of the safety detection model through all sample detection sequences to obtain optimized control parameters;
[0139]
[0140] Among them, θ is the optimized control parameter of the safety detection model, and there are n sample detection sequences in total;
[0141] The detection feature information is input into the security detection model for detection to obtain the corresponding request detection result. When it is detected that the detection sequence is a malicious access, shielding measures are executed to prohibit the protocol parser from parsing and processing the information request packet.
[0142] In the above embodiments, the transmission delay, transmission direction and data length of the information request packet are obtained to construct a detection sequence; the detection sequence is preprocessed and shaped according to the model detection requirements to construct a preprocessed detection sequence; the spatial feature information of the preprocessed detection sequence is extracted through a convolutional neural network model, the temporal feature information of the preprocessed detection sequence is extracted through a long short-term memory network model, and the key feature information of the preprocessed detection sequence is extracted through a multi-attention mechanism network model, and feature mapping is performed through a fully connected layer to obtain detection feature information; the detection feature information is input into a security detection model for detection to obtain corresponding request detection results, and when it is detected that the detection sequence is a malicious access, shielding measures are executed to prohibit the protocol parser from parsing and processing the information request packet.
[0143] In the above embodiments, the preprocessing of the detection sequence is shaped by adjusting the dimension of the detection sequence, arranging the continuous features of the information request packet in the horizontal direction, and arranging the information requests of the information request packet at different times in the vertical direction to construct a preprocessing detection sequence; the content of the obtained preprocessing detection sequence data remains unchanged, only the shape of the data dimension is changed, so that the convolution kernel movement in the subsequent step model can capture more comprehensive data feature relationships.
[0144] In the above embodiments, sample labels are added to the sample detection sequence, the security detection model is trained based on the loss function, the control parameters of the security detection model are optimized, and the optimized security detection model is used for security detection of the preprocessing detection sequence.
[0145] In the above embodiments, the loss function is constructed based on the cross-entropy loss function, and is trained through multiple sample detection sequences so that the control parameters of the security detection model obtain the most universal optimization direction, thereby improving the generalization performance of the model in security detection tasks.
[0146] The beneficial effects of the above technology are: obtaining the transmission delay, transmission direction and data length of the information request packet, constructing a detection sequence, and performing preprocessing shaping to obtain a preprocessed detection sequence for use in convolutional neural network models, long short-term memory network models, and multi-attention mechanism network models to extract detection feature information, and performing security detection through a security detection model to obtain request detection results, thereby realizing security detection of information request packets by the monitoring port, avoiding the dynamic content distribution network from forwarding and parsing maliciously accessed data, thereby affecting the normal operation of the server, and improving the security protection of the server while realizing security detection of user traffic.
[0147] Example 7:
[0148] An embodiment of the present invention provides a method for optimizing network failure traffic based on security protocol scheduling, comprising the following steps: when it is detected that the network in the target area has returned to normal, user traffic is evenly distributed to multiple servers or network links through a load balancer based on a security protocol mechanism, and the use of a dynamic content distribution network is disconnected; the method comprises:
[0149] The load balancer receives user traffic transmitted by the user terminal device and parses it to obtain the request information and destination address;
[0150] The load balancer obtains a public network server capable of processing the request information based on the request information and builds a public network server pool;
[0151] By obtaining the processor resources of the public network server in the public network server pool, calculating the response time of the public network server to the request information, and calculating the information transmission time based on the transmission route between the load balancer and the public network server, the static processing response time is obtained based on the response time and the information transmission time;
[0152] Obtain the real-time task processing status of the public network servers in the current public network server pool, and obtain the dynamic processing response time of the public network servers to the request information;
[0153] Based on the static processing response time and the dynamic processing response time, the corresponding processing response time of each public network server is obtained. The load balancer selects the public network server with the shortest processing response time as the request processing server, modifies the destination address to the access address of the request processing server, and transmits the user traffic to the request processing server.
[0154] In the above embodiment, the load balancer receives user traffic transmitted by the user terminal device and parses it to obtain request information and destination address; the load balancer obtains a public network server capable of processing request information based on the request information, selects the public network server with the shortest processing response time as the request processing server, and modifies the destination address to the access address of the request processing server, and transmits the user traffic to the request processing server.
[0155] In the above embodiment, the processing response time of the public network server is obtained by calculating the static processing response time and the dynamic processing response time. The static processing response time is calculated based on the response time of the public network server to the request information processing and the information transmission time required for the transmission route between the load balancer and the public network server; the dynamic processing response time is obtained based on the real-time task processing status of the current public network server.
[0156] The beneficial effect of the above technology is that: when it is monitored that the network in the target area has returned to normal, the load balancer is used to obtain the response time of each public network server in the public network server pool for request information processing, and the public network server with the shortest processing response time is selected as the request processing server to process the request information, and the destination address is modified to the access address of the request processing server, thereby improving the processing speed of the request information, realizing rapid scheduling and processing of the request information, and effectively improving the user-side network access experience.
[0157] Example 8:
[0158] An embodiment of the present invention provides a method for optimizing network fault traffic based on security protocol scheduling, comprising:
[0159] The load balancer provides a unique access point for user-end devices to receive user traffic;
[0160] The security protocol mechanism caches the access entries of the load balancer and the dynamic content distribution network, and automatically switches the access entries of the load balancer and the dynamic content distribution network according to the network operation status of the target area;
[0161] The user terminal device caches the access entry of the dynamic content distribution network. When the network request fails, the user terminal device automatically retry the network access through the access entry of the dynamic content distribution network.
[0162] In the above embodiments, when the network in the target area has no faults, the user terminal device is connected to the load balancer through a unique access portal, and the load balancer schedules user traffic.
[0163] In the above embodiments, the security protocol mechanism automatically switches the access portals of the load balancer and the dynamic content distribution network according to the network failure situation, thereby realizing intelligent scheduling of user traffic.
[0164] In the above embodiment, by caching the access entry of the dynamic content distribution network in the user terminal device, when a network request through the public network fails, the network access is automatically retried through the access entry of the dynamic content distribution network.
[0165] The beneficial effects of the above technology are: through the load balancer, user traffic is scheduled when the target area network is fault-free; through the dynamic content distribution network, user traffic is processed when the target area network fails; based on the security protocol mechanism, the two network scheduling methods are intelligently switched, effectively ensuring the normal processing of user traffic and avoiding the impact of network failures on user network access; and the access entrance of the dynamic content distribution network is cached at the user-end device, and automatically switched when the network request fails, effectively improving the user's network access experience.
[0166] Example 9:
[0167] The embodiment of the present invention provides a network fault flow optimization system based on security protocol scheduling, referring to Figure 2 ,include:
[0168] The network monitoring module is used to monitor the network in the target area in real time by setting up dial-up test points at multiple geographical locations;
[0169] The network scheduling module is used to schedule user traffic to the dynamic content distribution network based on the security protocol mechanism when a network failure is detected in the target area. The user terminal device accesses the network link through the dynamic content distribution network;
[0170] The network scheduling module is also used to evenly distribute user traffic to multiple servers or network links through a load balancer based on a security protocol mechanism when it is detected that the network in the target area has returned to normal, thereby disconnecting the use of the dynamic content distribution network.
[0171] In the above embodiments, the network monitoring module sets up dial-up test points at multiple geographical locations to perform real-time monitoring of the network in the target area. When the network scheduling module detects that a network failure has occurred in the target area, the network scheduling module dispatches user traffic to the dynamic content distribution network based on the security protocol mechanism, and the user terminal device accesses the network link through the dynamic content distribution network. When the network in the target area is detected to be restored to normal, the user traffic is evenly distributed to multiple servers or network links through the load balancer based on the security protocol mechanism, and the use of the dynamic content distribution network is disconnected.
[0172] The beneficial effects of the above technology are: by setting up dial-up test points in multiple geographical locations, real-time automatic fault monitoring of the target area network is achieved, and when a network failure is detected, user traffic is dispatched to the dynamic content distribution network based on the security protocol mechanism to ensure the continuity of user services. When the network returns to normal, it switches back to normal public network use, achieving flexible scheduling of user traffic and avoiding unnecessary network cost expenditure; compared with traditional technologies, the above system reduces network operating costs by only using the dynamic content distribution network during network failures, avoiding the high cost of long-term use of the dynamic content distribution network, and at the same time, intelligently switching between the public network and the dynamic content distribution network based on the security protocol mechanism reduces manual intervention, improves network operating efficiency and reliability, ensures business continuity, and enhances user experience.
[0173] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A network fault flow optimization method based on security protocol scheduling, characterized in that: include: By setting up dial-up test points at multiple geographical locations, the network in the target area can be monitored in real time; When a network failure in the target area is detected, user traffic is dispatched to the dynamic content distribution network based on a security protocol mechanism, and the user terminal device accesses the network link through the dynamic content distribution network; When it is detected that the network in the target area has returned to normal, the user traffic is evenly distributed to multiple servers or network links through a load balancer based on a security protocol mechanism, and the use of the dynamic content distribution network is disconnected.
2. A network fault flow optimization method based on security protocol scheduling according to claim 1, characterized in that: The steps of setting up dial-up test points at multiple geographical locations to monitor the network in the target area in real time include: Deploy dial-up test points at multiple geographical locations, each equipped with a corresponding dial-up test terminal. The network monitoring terminal issues a dialing test task to the dialing test terminal, performs real-time detection on the network in the target area, and transmits the obtained dialing test results back to the network monitoring terminal; including: The network monitoring terminal formulates a planned dialing test task according to the deployment status of the dialing test terminal and sends it to the dialing test terminal; The dial test terminal parses and processes the planned dial test task to obtain a dial test start time, a dial test cycle, a dial test end time, and a polling number. When the current time period reaches the dial test start time, the dial test terminal is awakened to monitor the network of the target area based on the planned dial test task. When the current time period reaches the dial test end time, the dial test terminal transmits the terminal monitoring result back to the network monitoring terminal and controls the dial test terminal to enter a dormant state. The network monitoring end analyzes and processes the terminal monitoring results transmitted back, and when it is detected that there is no abnormality in the network, uses the terminal monitoring results as the dial test results; when it is detected that there is an abnormality in the network, an immediate dial test task is sent to the dial test terminal of the network in the monitoring target area through the network monitoring end, and the network in the target area is monitored simultaneously. The dial test results are obtained based on the immediate test results transmitted back by each dial test terminal.
3. The method for optimizing network fault traffic based on security protocol scheduling according to claim 1, characterized in that: The step of dispatching user traffic to a dynamic content distribution network based on a security protocol mechanism when a network failure in a target area is detected, and allowing a user terminal device to access a network link through the dynamic content distribution network, includes: When a network failure in the target area is detected, the request information and destination address are obtained based on user traffic analysis, and the request information and destination address are encapsulated into an information request packet using an encryption protocol based on a security protocol mechanism; transmitting the information request packet to a protocol parser via the dynamic content delivery network; Performing security detection on the information request packet through the monitoring port on the protocol analyzer to obtain the request detection result; After determining that the information request packet has passed the security detection, the received information request packet is parsed and processed to obtain the request information and the destination address, and the request information is transmitted to the target server according to the destination address.
4. The method for optimizing network fault traffic based on security protocol scheduling according to claim 3 is characterized in that: The step of transmitting the information request packet to the protocol analyzer via the dynamic content distribution network includes: According to the information request packet, obtaining a network server cluster with corresponding processing capabilities in the dynamic content distribution network; Establishing a search area based on the network server cluster, by setting a number of search points, randomly selecting initial positions of the search points in the search area, and updating the spatial positions according to the performance evaluation values of the network servers, to obtain a sub-search area for each search point; in, is the updated position of the i-th search point, R best is the currently obtained optimal position, a is the position change parameter, K j is the sinusoidal mapping parameter, R m is the current average distribution position of all search points, is the current position of the i-th search point; Among them, c j is a random parameter in the parameter interval [0, C], K j-1 is the sinusoidal mapping parameter of the last updated position; The search point updates a position in the sub-search area using a first search path to obtain a first optimized network server; in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the first search path, w i is the perturbation parameter value corresponding to the i-th search point, rand is a random parameter, For the i-th search point in the corresponding sub-search area z i The optimal position obtained by the first search path, Δx is the lateral displacement of the search point based on the current position and the updated position, and Δy is the longitudinal displacement of the search point based on the current position and the updated position; The search point updates its position in the sub-search area using a second search path to obtain a second optimized network server; in, For the i-th search point in the corresponding sub-search area z i The updated position obtained by the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the maximum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The location of the network server corresponding to the minimum work performance evaluation value obtained by searching the second search path, For the i-th search point in the corresponding sub-search area z i The current location obtained by the second search path; Comparing the first and second performance evaluation values corresponding to the first and second optimized network servers to obtain the optimal network server; When the optimal network server is obtained, the transmission distance between the optimal network server and the user terminal device is evaluated, and when the transmission distance meets a threshold requirement, the information request packet is transmitted through the optimal network server.
5. The method for optimizing network fault traffic based on security protocol scheduling according to claim 4, characterized in that: The step of establishing a search area based on the network server cluster, setting a plurality of search points, randomly selecting initial positions of the search points in the search area, and updating the spatial positions according to the working performance evaluation values of the network servers to obtain a sub-search area for each search point includes: Obtaining a performance evaluation value of the network server based on the operating status of the network server and the network quality; S i =μ1*(a d *d i +a c *c i +a m *m i )+μ2*(σ t *t i +s p *p i ) Among them, S i is the performance evaluation value of the i-th network server, μ1 is the first weight parameter, and μ2 is the second weight parameter; d i is the bandwidth surplus rate of the i-th network server, α d is the corresponding bandwidth weight value, c i is the computing resource surplus rate of the i-th network server, α c is the corresponding resource weight value, m i The memory remaining rate of the i-th network server, α m is the corresponding memory weight value; t i is the transmission delay for communicating with the i-th network server, σ t is the corresponding delay weight value, p i is the packet loss rate of the i-th network server, σ p is the corresponding packet loss weight value.
6. The method for optimizing network fault traffic based on security protocol scheduling according to claim 3, characterized in that: The step of performing security detection on the information request packet through the monitoring port on the protocol analyzer to obtain the request detection result includes: Obtaining the transmission delay, transmission direction, and data length of the information request packet, and constructing a detection sequence; Preprocessing and shaping the detection sequence according to the model detection requirements, adjusting the dimension of the detection sequence, arranging the continuous features of the information request packet in the horizontal direction, and arranging the information requests of the information request packet at different times in the vertical direction, to construct a preprocessed detection sequence; Extracting spatial feature information of the preprocessed detection sequence through a convolutional neural network model, extracting temporal feature information of the preprocessed detection sequence through a long short-term memory network model, and extracting key feature information of the preprocessed detection sequence through a multi-attention mechanism network model, performing feature mapping through a fully connected layer, and obtaining detection feature information; Constructing a safety detection model, adding sample labels to the sample detection sequence, training the safety detection model based on a loss function, and optimizing the control parameters of the safety detection model; Among them, θ′ i is the control parameter obtained by optimizing the detection sequence of the i-th sample, θ 0 is the initial control parameter of the security detection model, γ is the learning rate on the sample detection sequence, L i (θ 0 ) is the initial control parameter θ 0 Set the security detection model to calculate the loss function value obtained by the i-th sample detection sequence; Optimizing the control parameters of the safety detection model through all sample detection sequences to obtain optimized control parameters; Among them, θ is the optimized control parameter of the safety detection model, and there are n sample detection sequences in total; The detection feature information is input into the security detection model for detection to obtain a corresponding request detection result. When it is detected that the detection sequence is a malicious access, shielding measures are executed to prohibit the protocol parser from parsing and processing the information request packet.
7. The method for optimizing network fault traffic based on security protocol scheduling according to claim 1, characterized in that: The step: when it is detected that the network in the target area has returned to normal, evenly distributing user traffic to multiple servers or network links through a load balancer based on a security protocol mechanism, and disconnecting the use of the dynamic content distribution network; includes: The load balancer receives user traffic transmitted by the user terminal device and parses it to obtain the request information and destination address; The load balancer obtains a public network server capable of processing the request information according to the request information, and builds the public network server pool; By obtaining processor resources of the public network servers in the public network server pool, calculating the response time of the public network servers to the request information, and calculating the information transmission time according to the transmission route between the load balancer and the public network servers, and obtaining the static processing response time according to the response time and the information transmission time; Obtaining the real-time task processing status of the public network server in the current public network server pool, and obtaining the dynamic processing response time of the public network server to the request information; Based on the static processing response time and the dynamic processing response time, the processing response time corresponding to each public network server is obtained. The load balancer selects the public network server with the shortest processing response time as the request processing server, and modifies the destination address to the access address of the request processing server, and transmits the user traffic to the request processing server.
8. The method for optimizing network fault traffic based on security protocol scheduling according to claim 1, characterized in that: include: The load balancer provides a unique access entrance for the user terminal device to receive the user traffic; The security protocol mechanism caches the access entrances of the load balancer and the dynamic content distribution network, and automatically switches the access entrances of the load balancer and the dynamic content distribution network according to the network operation status of the target area; The user terminal device caches an access entry of the dynamic content distribution network. When a network request fails, the user terminal device automatically retry the network access through the access entry of the dynamic content distribution network.
9. A network fault flow optimization system based on security protocol scheduling, characterized in that: include: The network monitoring module is used to monitor the network in the target area in real time by setting up dial-up test points at multiple geographical locations; A network scheduling module is used to schedule user traffic to a dynamic content distribution network based on a security protocol mechanism when a network failure is detected in a target area, and the user terminal device accesses the network link through the dynamic content distribution network; The network scheduling module is also used to evenly distribute user traffic to multiple servers or network links through a load balancer based on a security protocol mechanism when it is monitored that the network in the target area has returned to normal, and disconnect the use of the dynamic content distribution network.