Data center switch anomaly traffic detection method, apparatus, device, and medium
By calculating the traffic hop ratio and path latency difference in data center switches and combining multi-dimensional indicators to identify abnormal traffic paths, the problem of accurately detecting network jitter and protocol anomalies in existing technologies has been solved, achieving more accurate abnormal traffic detection and device attribution aggregation.
Patent Information
- Application Number
- CN202511192012.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-25
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-08-25
AI Technical Summary
Existing abnormal traffic detection methods for data center switches struggle to accurately identify sudden traffic spikes caused by network link jitter or protocol anomalies when faced with multi-path forwarding and abnormal communication behavior, leading to false alarms and missed detections, especially in dynamic network environments.
By acquiring adjacent periodic traffic data of uplink and downlink ports of data center switches, calculating the traffic jump ratio and filtering ports that exceed the dynamic threshold, and combining port traffic response latency and multi-dimensional indicators of continuous path nodes, abnormal traffic paths with delay offset are identified, abnormal traffic paths with composite characteristics are statistically analyzed, and traced back to the device granularity to achieve the detection of abnormal traffic paths with link disturbance.
It significantly enhances the granularity and accuracy of abnormal traffic identification, enabling closed-loop diagnosis from transient anomalies to path-level and then to device attribution, thereby improving the clarity and perception capabilities of abnormal traffic detection in data center switches.
Smart Images

Figure CN120729756B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of flow monitoring, in particular to a data center switch abnormal flow detection method, device, equipment and medium. BACKGROUND
[0002] The technical field of flow monitoring involves real-time or offline monitoring, analysis and management of data streams transmitted in computer networks, including data stream collection, classification, measurement, identification and anomaly detection. Raw flow data is obtained through collection devices or software components deployed on network nodes, and data packets or connection behaviors are processed in combination with specific rules or pattern recognition methods to identify potential security risks, resource usage anomalies or service quality problems. Among them, the traditional data center switch abnormal flow detection method refers to a method of identifying abnormal communication behavior by statistically analyzing port flow data from the switch interface in a data center network environment. In order to assist managers to discover potential network faults or security threats, the method usually adopts a flow statistical strategy based on a preset threshold, analyzes the rate change, protocol distribution and connection number of switch port flow, and combines the set judgment conditions to preliminarily judge the possible abnormal behavior.
[0003] In the existing switch flow detection process, the core means is to judge the port rate change with a fixed threshold. In the face of multi-path forwarding, abnormal communication behavior with short cycle alternation or flow direction jumping, there is a problem of response lag. Since it relies on the change of single-dimensional indicators at the port level and lacks the cooperative extraction of path behavior chain and node interaction characteristics, it is difficult to accurately identify the burst flow phenomenon caused by network link jitter or protocol anomaly. In a dynamic network environment, it is easy to cause false positives and missed judgments. For example, when the port flow suddenly increases due to scheduling rather than attack behavior, it is difficult to effectively analyze the abnormal propagation path and device association between upstream and downstream nodes. SUMMARY
[0004] The purpose of the present application is to solve the problems existing in the prior art, and the data center switch abnormal flow detection method, device, equipment and medium are proposed.
[0005] In order to achieve the above purpose, the present application adopts the following technical scheme: a data center switch abnormal flow detection method, comprising the following steps:
[0006] S1: Obtain the adjacent period flow data of the uplink and downlink ports of the data center switch, calculate the flow jump ratio, and filter the ports exceeding the dynamic flow threshold to generate the number of burst abnormal flow ports;
[0007] S2: According to the burst abnormal traffic port quantity, the port traffic response delay of the path continuous switching node is extracted, the maximum value and the minimum value difference are calculated, the path first breaking through the network jitter tolerance is screened, and the delay offset abnormal traffic path is generated;
[0008] S3: According to the delay offset abnormal traffic path, the node port average flow rate, the inter-packet arrival time, the MAC address change frequency and the direction jump number are extracted, the number of paths simultaneously exceeding the corresponding baseline abnormal detection is counted, and the composite feature abnormal traffic path statistical result is generated;
[0009] S4: Based on the composite feature abnormal traffic path statistical result, the traffic channel with BGP route oscillation is detected and recorded, the total path chain number is counted, and the link disturbance type abnormal traffic path total number is generated;
[0010] S5: According to the link disturbance type abnormal traffic path total number, the corresponding communication path and node information are determined, the abnormal traffic chain attribution aggregation is completed in the device dimension, and the switch abnormal traffic detection result is generated.
[0011] As a further scheme of the application, the burst abnormal traffic port quantity includes abnormal port distribution record, port jump ratio interval, traffic change trend category, the delay offset abnormal traffic path includes path delay difference interval, abnormal path topology position, affected communication direction, the composite feature abnormal traffic path statistical result includes path correlation index item number, abnormal index combination type, path feature difference grade, the link disturbance type abnormal traffic path total number includes path oscillation frequency, direction alternation mode in period, potential BGP influence level, and the switch abnormal traffic detection result includes abnormal switch number, aggregated link number and abnormal port belonging category.
[0012] As a further scheme of the application, the burst abnormal traffic port quantity acquisition step is:
[0013] S111: Based on the SNMP polling data of the data center switch, the uplink and downlink traffic values of each key port in two adjacent periods at a set time point are obtained, data matching is performed on each port according to the polling interval, the port uplink and downlink total traffic data of the current period and the previous period are extracted, and a port period traffic value pair is generated.
[0014] S112: According to the port period traffic value pair, the uplink and downlink traffic change of the current period and the previous period is compared, the overall variation characteristics of each port in the adjacent period are identified, the unified variation information set is summarized, and a traffic jump ratio list is generated.
[0015] S113: Based on the flow jump ratio list, compare the jump characteristics of each port with the set dynamic flow threshold value, identify the ports whose jump characteristics exceed the threshold value and count the number, and obtain the number of burst abnormal flow ports.
[0016] As a further scheme of the present application, the step of obtaining the delay offset abnormal flow path is:
[0017] S211: Based on the identified port set in the burst abnormal flow port number, extract the communication path of each port, limit three consecutive switching nodes in each path, obtain the port flow response time between nodes in each path, extract the timestamp interval as the response delay data, and record the flow response time difference of the front and rear ports of each of the three nodes corresponding to each path respectively, and generate a path delay value list;
[0018] S212: According to the path delay value list, perform response difference analysis on the three delay values in each path, obtain the difference range between the maximum delay value and the minimum delay value in the current path, calculate the path delay offset difference value, judge whether it exceeds the network jitter tolerance, construct the to-be-screened path set, and obtain the out-of-limit path difference value set;
[0019] S213: Based on the out-of-limit path difference value set, identify the path that first breaks through the network jitter tolerance, perform screening operation, mark all paths that have never historically exceeded the limit and record the path number, and obtain the delay offset abnormal flow path.
[0020] As a further scheme of the present application, the step of obtaining the composite feature abnormal flow path statistical result is:
[0021] S311: Based on each path in the delay offset abnormal flow path number, sequentially count the average flow rate, packet inter-arrival time, MAC address change frequency and direction jump times of the node ports in the path in the current period, and generate a node feature time sequence list;
[0022] S312: According to the node feature time sequence list, respectively judge the numerical situation of the average flow rate, packet inter-arrival time, MAC address change frequency and direction jump times and the respective baseline level in the period, judge whether there are three or more indicators in the abnormal state in the path, and obtain the baseline condition satisfied path count value.
[0023] S313: Based on the baseline condition satisfied path count value, extract the path number that meets three or more features simultaneously abnormal, classify and organize the corresponding record period, path identifier and abnormal state to form a composite table item, and perform summary statistical processing, and obtain the composite feature abnormal flow path statistical result.
[0024] As a further scheme of the present application, the link disturbance type abnormal traffic path total number acquisition step is:
[0025] S411: Based on the identified paths in the composite feature abnormal traffic path statistical result, the communication traffic direction change of each path in the current analysis period is detected piece by piece, the forwarding direction information between the starting node and the target node corresponding to the path is extracted, the communication direction sequence sorted by time is established, the index position of each occurrence of direction flip is marked in turn, and the number of times of occurrence in the period is recorded to obtain the path direction switching number value;
[0026] S412: According to the path direction switching number value, whether the number of communication direction changes of each path in the analysis period satisfies the condition of reciprocating flip more than twice is judged in turn, if there is the case of alternating change of positive and negative directions more than twice, it is judged that the path has bidirectional oscillation behavior, the path number of the path satisfying the condition is archived and recorded, and a path number set with route oscillation characteristics is obtained;
[0027] S413: According to the path number set with route oscillation characteristics, the link segment number covered by the path is recorded, the number of oscillation paths carried on each link is counted, and the path number, link number and oscillation state are associated and mapped to obtain the total number of link disturbance type abnormal traffic paths.
[0028] As a further scheme of the present application, the switch abnormal traffic detection result acquisition step is:
[0029] S511: Based on the total number of link disturbance type abnormal traffic paths, the link numbers involved and the corresponding path structure are determined, the communication node device information traversed by each path is extracted piece by piece, the starting device number, the terminal device number and all relay switch numbers in the path are identified through the binding relationship between the path and the topology structure, and the mapping relationship between the path number and the device number is established to generate a path associated switch node number set;
[0030] S512: According to the path associated switch node number set, the port state information corresponding to each switch number in the current analysis period is extracted, and the association structure between the period identifier and the device port state record is established, whether the device has abnormal port state in the period is judged by aggregating the index record of the ports contained by the device number, the abnormal device is marked, and the number and period identifier are recorded uniformly to obtain a period abnormal switch number set;
[0031] S513: According to the periodic abnormal switch number set, the total number of paths involved by each abnormal device is counted, and it is judged whether there is a multi-path cross aggregation phenomenon, the consistency of device traffic source and destination is judged in combination with the position and direction mark of the path in the network topology, the aggregation and division of each abnormal path at the device level are completed, the abnormal path attribution set is established with the device number as the index, and the switch abnormal traffic detection result is obtained.
[0032] The data center switch abnormal traffic detection device is used for executing the data center switch abnormal traffic detection method, comprising:
[0033] The identification port jump module is used for executing S1: obtaining the adjacent period traffic data of the data center switch uplink and downlink ports, calculating the traffic jump ratio and screening the ports exceeding the dynamic traffic threshold, and generating the number of burst abnormal traffic ports.
[0034] The analysis path delay module is used for executing S2: according to the number of burst abnormal traffic ports, extracting the port traffic response delay of the path continuous switching node, calculating the maximum value and minimum value difference, screening the path first breaking through the network jitter tolerance, and generating the delay offset abnormal traffic path.
[0035] The screening composite path module is used for executing S3: according to the delay offset abnormal traffic path, extracting the node port average flow rate, packet inter-arrival time, MAC address change frequency and direction jump times, counting the number of paths with any three indicators exceeding the corresponding baseline abnormal detection at the same time, and generating the composite feature abnormal traffic path statistical result.
[0036] The identification disturbance link module is used for executing S4: based on the composite feature abnormal traffic path statistical result, detecting the traffic channel recorded as having BGP route oscillation, counting the total path chain number, and generating the link disturbance type abnormal traffic path total number.
[0037] The abnormal detection output module is used for executing S5: according to the link disturbance type abnormal traffic path total number, determining the corresponding communication path and node information, completing the abnormal traffic chain attribution aggregation in the device dimension, and generating the switch abnormal traffic detection result.
[0038] Compared with the prior art, the advantages and positive effects of the present application are that:
[0039] In the application, the port mutation phenomenon is identified by the linkage of the jump ratio and the dynamic threshold, the identification logic of the initial offset of network jitter is established by combining the response delay difference of the path continuous node, the path level composite feature abnormality judgment is constructed by fusing the intersection behavior of multiple dimensions indicators, the potential path oscillation is identified according to the flow direction alternation in the period, and the chain attribution aggregation is realized to the equipment granularity, which can significantly enhance the granularity and accuracy of abnormal flow identification, realize the closed-loop abnormal diagnosis from transient anomaly to path level to equipment attribution, improve the perception ability in the complex link disturbance and multi-point abnormal collaborative scene, and improve the clarity of abnormal flow detection of the data center switch. BRIEF DESCRIPTION OF DRAWINGS
[0040] Figure 1 It is a main step flowchart of the application;
[0041] Figure 2 It is a burst abnormal flow port number acquisition flowchart of the application;
[0042] Figure 3 It is a delay offset abnormal flow path acquisition flowchart of the application;
[0043] Figure 4 It is a composite feature abnormal flow path statistical result acquisition flowchart of the application;
[0044] Figure 5 It is a link disturbance type abnormal flow path total number acquisition flowchart of the application;
[0045] Figure 6 It is a switch abnormal flow detection result acquisition flowchart of the application. DETAILED DESCRIPTION
[0046] In order to make the purpose, technical scheme and advantages of the application more clear and understandable, the application will be further described in detail below in combination with the drawings and examples. It should be understood that the specific examples described herein are only used to explain the application and not to limit the application.
[0047] In the description of the application, it should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the application and simplify the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, therefore it cannot be understood as a limitation of the application. In addition, in the description of the application, the meaning of "a plurality of" is two or more, unless otherwise specifically limited.
[0048] Please refer to Figure 1, a data center switch abnormal traffic detection method, comprising the following steps:
[0049] S1: Obtain the two adjacent period traffic data of the uplink and downlink key ports of the data center switch (SNMP polling period data, execute standard 30 second polling interval), compare the port total traffic values of the current period and the previous period, calculate the traffic jump ratio, compare the dynamic traffic threshold (meet the standard set 10% rate change rate), screen the ports exceeding the dynamic traffic threshold, and generate the number of burst abnormal traffic ports;
[0050] S2: According to the communication path involved in the number of burst abnormal traffic ports, extract the port traffic response delay of the three continuous switching nodes in each path, obtain the maximum value and the minimum value and perform difference calculation, compare with the network jitter tolerance (according to the standard set ±5ms), screen the path that first breaks through the network jitter tolerance, and generate the delay offset abnormal traffic path;
[0051] S3: According to each path in the number of delay offset abnormal traffic paths, extract the average flow rate, packet inter-arrival time, MAC address change frequency and direction jump times of the node port in the current period, count the number of paths in which any three indicators exceed the corresponding baseline abnormal detection (meet the digital evidence identification standard) at the same time, and generate the composite feature abnormal traffic path statistical result;
[0052] S4: Based on the identified path in the composite feature abnormal traffic path statistical result, detect whether there is communication traffic direction alternately changing more than twice in a period, if the condition is met, record as a traffic channel with BGP route oscillation (refer to the standard of Border Gateway Protocol), count the total path chain number, and generate the total number of link disturbance type abnormal traffic paths;
[0053] S5: According to the total number of link disturbance type abnormal traffic paths, determine the corresponding communication path and node information, backtrack the switching device number, port traffic and period state involved in the path, complete the abnormal traffic chain attribution aggregation in the device dimension (execute FlowSpecification mechanism of Network Traffic Classification), and generate the switching device abnormal traffic detection result.
[0054] The number of burst abnormal traffic ports includes abnormal port distribution record, port jump rate interval and traffic change trend category, the delay offset abnormal traffic path includes path delay difference interval, abnormal path topology position and affected communication direction, the composite feature abnormal traffic path statistical result includes path associated indicator item number, abnormal indicator combination type and path feature difference level, and the total number of link disturbance type abnormal traffic paths includes path oscillation frequency, direction alternation mode in a period and potential BGP influence level. The switching device abnormal traffic detection result includes abnormal switching device number, aggregated link number and abnormal port belonging category.
[0055] Referring to Figure 2 , the specific steps of S1 are as follows:
[0056] S111: Based on the SNMP polling data of the data center switch, the uplink and downlink traffic values of each key port in two adjacent periods at a set time point are obtained, data matching is performed on each port according to the polling interval, the total uplink and downlink traffic data of the current period and the previous period are extracted, and a port period traffic value pair is generated.
[0057] Based on the SNMP polling data of the data center switch, the uplink and downlink traffic of all key ports on the switch needs to be continuously collected and structured for two periods. This process first needs to initiate an SNMP request from a set management terminal, the target OID is ifHCInOctets and ifHCOutOctets, each polling period is 30 seconds, and the uplink and downlink data at the current time and the previous period are recorded, respectively, and are assembled into data items with port number as index. When executed, the time stamp is used to accurately locate the period boundary to avoid overlapping or missing. For example, the set time points are July 9, 2024, 14:00:00 and 13:59:30, which are the current and previous periods, respectively. When collecting the data of port 1, the current period uplink is 210000000 Byte (1680 Mbps), the downlink is 190000000 Byte (1520 Mbps), the previous period is 200000000 Byte (1600 Mbps) and 180000000 Byte (1440 Mbps), respectively. The uplink and downlink data of this port in the current polling period is [1680, 1600, 1520, 1440] Mbps. After collection, all port period data is collected and arranged as a structured array, where each row represents two period uplink and downlink data of a port, forming the following data table:
[0058] Table 1: Periodic traffic table of key ports of data center switch
[0059]
[0060] As shown in Table 1, the uplink and downlink traffic data of each port in two adjacent periods has been archived. This kind of table is directly derived from the original collection results of SNMP data polling, and after unit conversion and structure arrangement, it is convenient for subsequent traffic behavior difference identification operation. The final port period traffic value pair will be the basic analysis object for judging the behavior of key links in the data center.
[0061] S112: According to the port cycle traffic value pair, compare the uplink and downlink traffic changes of the current cycle and the previous cycle, identify the overall change characteristics of each port in the adjacent cycle, and aggregate the unified change information set to generate a traffic jump ratio list;
[0062] According to the generated port cycle traffic value pair, it is necessary to analyze the structure and jump behavior to identify the traffic fluctuation of each key port between two cycles. In the process, the total uplink and downlink traffic of the current and previous cycle in each group of data is first extracted and compared, for example, the current total traffic of port 1 is 1680+1520=3200Mbps, the previous cycle is 1600+1440=3040Mbps, and the change value is 160Mbps. In order to more accurately express the jump behavior characteristics, the offset influence of the upstream and downstream communication path also needs to be considered, for example, the communication data fluctuation of port 1 with port 2 and port 3 in this cycle is ±40Mbps and ±20Mbps respectively, which is considered as the overall communication influence factor of 60Mbps. This value is used as an auxiliary judgment parameter of jump feature together with the traffic difference value to form a jump feature description group. The corresponding items of each port are as follows:
[0063] Table 2 Port cycle traffic jump feature table
[0064]
[0065] As shown in Table 2, the traffic change value is calculated by the total traffic value of the current and previous cycle, and the communication path fluctuation influence factor is added, which can be used as the basis for determining whether the port behavior has a sudden change. After the construction of this structure information, a complete traffic jump ratio list is formed, which provides structural support for abnormal screening and jump ratio analysis.
[0066] S113: Based on the traffic jump ratio list, compare the jump characteristics of each port with the set dynamic traffic threshold, identify the ports whose jump characteristics exceed the threshold, and count the number to obtain the number of abnormal traffic ports;
[0067] Based on the constructed traffic jump ratio list, it is further necessary to judge which ports belong to abnormal jump behavior. The jump judgment takes 10% variation threshold as the basis, and marks the abnormal items for the difference between the current cycle total traffic and the previous cycle exceeding the proportion. In the specific operation, the jump ratio of each port variation value and the previous cycle traffic value is obtained by division operation, for example, port 1 jump ratio is 160 / 3040≈5.26%, which does not exceed the threshold; port 3 variation is 70 / 1930≈3.63%, which also does not exceed the threshold; if the jump ratio of a certain port is greater than 0.10, it is regarded as an abnormal port and enters the counting interval. In order to prevent misjudgment, ±0.5% tolerance interval is adopted, that is, less than 9.5% is not treated as abnormal. After counting the number of all ports meeting the jump conditions, it is taken as the final abnormal output index, as shown in Table 3:
[0068] Table 3 Jump ratio and abnormal judgment table
[0069]
[0070] As shown in Table 3, in the current example, all ports do not exceed the set jump threshold 10%, so the abnormal statistical result is 0. The number is the number of burst abnormal traffic ports in the data center switch corresponding to the current cycle, which is used to further judge whether there is a link severe fluctuation.
[0071] Please refer to Figure 3 , the specific steps of S2 are:
[0072] S211: Based on the identified port set in the number of burst abnormal traffic ports, extract the communication path of each port, and limit the three continuous switch nodes in each path, obtain the port traffic response time between the nodes in each path, extract the timestamp interval as the response delay data, and record the traffic response time difference of the front and rear ports of each path corresponding to the three nodes respectively, and generate a path delay value list;
[0073] Based on the port set extracted from the number of abnormal burst traffic ports, the communication path associated with each port needs to be identified one by one, and limited to a transmission path composed of three consecutive switching nodes. The path information can be automatically associated and located through the network topology relationship diagram and the link relationship table. After obtaining the path structure, the port response delay value between each switching node segment is collected. The response delay is defined as the time interval between the completion of data output by the upstream node interface and the completion of data reception by the downstream node interface, with the unit of milliseconds. The interface delay field of SNMP is used to cooperate with the clock synchronization mechanism for sampling, ensuring the consistency of timestamp analysis. During the data collection process, the response time of three consecutive node segments needs to be recorded for each path. For example, the three delay values of path P1 are 3.2 ms, 2.9 ms, and 3.5 ms, the three delay values of path P2 are 4.5 ms, 4.1 ms, and 5.0 ms, and the three delay values of path P3 are 5.1 ms, 6.0 ms, and 4.9 ms. After format verification and unit conversion, all path delay data are summarized to form the following structured table:
[0074] Table 4: Path delay collection table
[0075]
[0076] As shown in Table 4, the delay data are structured collection results with the unit of milliseconds. The path number and node segment delay value correspond to each other, which are used for subsequent path level delay variation calculation and screening logic judgment. The final result is a list of path delay values.
[0077] S212: According to the path delay value list, the response difference value of the three delay values in each path is analyzed to obtain the difference range between the maximum delay value and the minimum delay value in the current path. The formula is:
[0078]
[0079] The operation obtains the path delay offset difference value. It is judged whether it exceeds the network jitter tolerance. The to-be-screened path set is constructed, and the out-of-limit path difference value set is obtained, wherein, represents the delay offset difference value of path , with the unit of milliseconds (ms), respectively represent the port flow response delay of the three consecutive node segments of path , with the unit of milliseconds (ms), represents the arithmetic mean value of the three response delays of path , with the unit of milliseconds (ms), which is calculated as: ; represents the absolute deviation total amount between the three response delays of the path and the mean value, with the unit of milliseconds (ms), is the square root of the sum of squares of the three response delays of the path, with the unit of milliseconds (ms).
[0080] Based on the path delay value list, the comprehensive offset calculation is performed on the three response delay values of each path, the difference between the maximum and minimum response delay in the path is obtained in turn to form an initial range term, then the delay mean value is calculated, the offset of each delay from the mean value is taken as an absolute value and averaged to form an average offset term, and then the square root term is formed by squaring and summing each delay value and taking the square root. The absolute value of the sum of the three terms is taken as the path delay offset difference value, which is calculated using the formula.
[0081] Taking path P2 as an example, its delay data is 4.5ms, 4.1ms, 5.0ms, and the corresponding calculation process is as follows:
[0082] Range term: ;
[0083] Mean value: ;
[0084] Average deviation term: ;
[0085] Square root term: ;
[0086] Comprehensive difference value: ;
[0087] In this way, all paths are calculated, and the results are as follows:
[0088] Table 5 Path delay difference value and abnormality judgment table
[0089]
[0090] As shown in Table 5, the offset difference values of paths P2 and P3 have exceeded the ±5ms tolerance line, and path P1 is within the normal range. The final result is the path delay offset difference value.
[0091] The path delay offset difference value is a composite index for measuring the time delay fluctuation amplitude and distribution imbalance degree of a communication path in the network in the current period. It comprehensively reflects the maximum and minimum response delay difference between the three consecutive switching nodes on the path, the offset degree of each delay from the mean value, and the masking effect of the overall delay intensity on the jump trend. The larger the index value, the greater the time delay instability and delay change, which may be caused by network congestion, link fluctuation or node abnormality. When the value exceeds the preset network jitter tolerance threshold, it indicates that the path has an abnormal delay offset behavior, which should be considered as an important signal of potential transmission jitter or link failure risk in the network transmission layer.
[0092] The formula is developed around three dimensions of the difference, stability and absolute magnitude of the three segments of the path response delay. Firstly, the difference between the maximum value and the minimum value is used to build a range term to capture the fluctuation amplitude of the instantaneous jump in the path, reflecting the most direct and severe change degree of the delay. Secondly, the absolute value of the deviation of each delay value from its arithmetic mean is introduced, and the sum of the three is averaged to form the average deviation term. This term measures the uniformity of the overall delay. If the deviation is large, it means that the delay distribution is unstable. This term is introduced as a path stability indicator and is combined with the range term by addition to reflect the dispersion of the delay. Further, the square root of the sum of the squares of the three delay values is introduced to form the square root term. This term is essentially the Euclidean norm of the delay vector, which can reflect the response load of the path in the absolute value. Since it is the absolute magnitude feature that affects the overall delay trend, it is subtracted from the previous two terms to balance the interference between the deviation value and the inherent load of the path. The final overall structure adopts the combination form of adding first and then subtracting, and then taking the absolute value, to ensure that the path delay deviation value obtained is non-negative, and at the same time, the fluctuation degree, delay distribution uniformity and overall load intensity are considered, which reflects the multi-dimensional representation ability of the path jump behavior.
[0093] S213: Based on the set of ultra-limit path difference values, identify the path that first breaks through the network jitter tolerance limit, perform a screening operation, mark all paths that have not historically exceeded the limit and record the path number, and obtain the delay offset abnormal traffic path;
[0094] Based on the path delay offset difference value, compare with the fixed network jitter tolerance ±5ms, mark the path that first breaks through the threshold, use the first screening mechanism to avoid repeated recording, retrieve the offset record of the historical period in the path state table, if the current path has not occurred the limit behavior before, and the current period offset value is greater than 5ms, record the path as an abnormal path, for example, path P2 recorded 7.2ms in the 5th period, the current period is the 8th period, which is not the first jump, and is excluded; path P3 has not exceeded the limit in the past period, the current offset value is 7.73ms, which is the first jump, and is retained; the offset value of path P1 is 4.76ms, which is less than the threshold and is not processed, therefore, path P3 is finally recorded as a delay abnormal path in the structure table, and the result is the delay offset abnormal traffic path.
[0095] Please refer to Figure 4 , the specific steps of S3 are:
[0096] S311: Based on each path in the number of delay offset abnormal traffic paths, sequentially count the average flow rate, inter-packet arrival time, MAC address change frequency and direction jump times of the node port in the path in the current period, and generate a node feature time sequence list;
[0097] Based on each path in the abnormal traffic path number of delay offset, the average flow rate of the node port in the current period is extracted in turn, the inter-packet arrival time, the MAC address change frequency and the direction jump number, the average flow rate is obtained by detecting the total number of data bytes in the period and converting it into megabit units and then dividing by the period duration, for example, the transmission data amount of path P1 in 60 seconds period is 13.5MB, then its average flow rate is calculated as: 13.5*8 / 60=1.8Mbps, the inter-packet arrival time needs to extract the data packet timestamp of the current period and arrange in order, calculate the adjacent time interval, and take the average value as the inter-packet arrival time of the path, for example, the data packet arrival time of path P3 is 0.000s, 0.004s, 0.008s, 0.013s, 0.018s, then the adjacent time difference is 4ms, 4ms, 5ms, 5ms, and the average value is 4.5ms, the MAC address change frequency is obtained by counting the number of source MAC field changes in the data packet in the statistical period, and dividing by the total number of received data packets as the frequency index, if path P2 receives 200 data packets in the period, and the source MAC change frequency is 5 times, then the change frequency is 5 / 200=0.025 times / packet, the direction jump number is extracted based on the comparison of the source MAC and the destination MAC belonging to the layer 2 broadcast domain of the two consecutive data packets in the path, if there are 4 times of source and destination MAC corresponding broadcast domain change events in path P2 in the period, then it is recorded as 4 times of direction jump number, finally all the parameter collection results are summarized into a structured table, as shown in the following:
[0098] Table 6 Path node feature extraction table
[0099]
[0100] As shown in table 6, the node characteristic parameters corresponding to different path numbers have been extracted and summarized, and the node characteristic time series list is obtained.
[0101] S312: According to the node characteristic time series list, the values of the average flow rate, the inter-packet arrival time, the MAC address change frequency and the direction jump number are respectively judged with the baseline level in the period, whether there are three or more indicators in abnormal state in the path is judged, and the baseline condition satisfying path count value is obtained.
[0102] According to the node feature time sequence list, the average flow rate, packet inter-arrival time, MAC address change frequency and direction jump number in each path are determined in turn, the determination reference values are set to be 1.2 Mbps, 4 ms, 0.02 times / packet and 3 times respectively, and the judgment standard is whether each index exceeds the corresponding reference value. If it exceeds, mark this item as abnormal. The average flow rate in path P1 is 1.8 Mbps, which is higher than the reference value, and is abnormal. The packet inter-arrival time is 3.2 ms, which is lower than the reference value, and is normal. The MAC change frequency is 0.015 times / packet, which is lower than the reference value, and is normal. The direction jump number is 2 times, which is lower than the reference value, and is normal. P1 has only one abnormality. The average flow rate of path P2 is 1.1 Mbps, which is lower than the reference value, and is normal. The packet inter-arrival time is 5.0 ms, which is higher than the reference value, and is abnormal. The MAC change frequency is 0.025 times / packet, which is higher than the reference value, and is abnormal. The direction jump number is 4 times, which is higher than the reference value, and is abnormal. P2 has three abnormalities. The average flow rate of path P3 is 2.0 Mbps, which is abnormal. The packet inter-arrival time is 4.3 ms, which is abnormal. The MAC change frequency is 0.021 times / packet, which is abnormal. The direction jump number is 3 times, which is equal to the reference value, and is not determined as abnormal. Only three abnormalities, P2 and P3 finally meet the three or more abnormal conditions, and the baseline condition satisfying path count value is obtained.
[0103] S313: Based on the baseline condition satisfying path count value, extract the path number that meets three or more features and is abnormal at the same time, classify and organize its corresponding record period, path identifier and abnormal state to form a composite table item, and perform summary and statistical processing to obtain the composite feature abnormal flow path statistical result.
[0104] Based on the baseline condition satisfying the path count value, the path number set satisfying three or more index abnormalities in the node feature time sequence list is classified and summarized, and the abnormal index composition, path number, current analysis period number, and abnormal state of each index are structured and recorded. First, the P2 and P3 paths obtained in S312 are called as the path set that meets the conditions. The single abnormal index details of the path set are marked, for example, in path P2, the inter-packet arrival time is 5.0 ms, which exceeds the baseline of 4 ms, and is marked as “inter-packet arrival abnormality”. The MAC change frequency is 0.025 times per packet, which exceeds the baseline of 0.02 times per packet, and is marked as “MAC frequency abnormality”. The direction jump number is 4 times, which exceeds the baseline of 3 times, and is marked as “jump number abnormality”. In path P3, the average flow rate is 2.0 Mbps, which exceeds the baseline of 1.2 Mbps, and is marked as “flow rate abnormality”. The inter-packet arrival time is 4.3 ms, which exceeds the baseline of 4 ms, and is marked as “inter-packet arrival abnormality”. The MAC change frequency is 0.021 times per packet, which exceeds the baseline of 0.02 times per packet, and is marked as “MAC frequency abnormality”. In this way, the abnormal dimensions of each abnormal path are marked and counted, and a feature dimension mapping table of abnormal paths is constructed. In the path statistics process, the current period number is assigned as T8, and the abnormal dimension number, abnormal index type and corresponding parameter value of each path in the period are recorded. At the same time, an abnormal path statistics list is generated, for example as follows:
[0105] Table 7: Structured statistics table of composite abnormal path
[0106]
[0107] As shown in Table 7, path P2 and path P3 simultaneously satisfy three dimension index values exceeding the set baseline in the current period T8. The corresponding index name and specific value are recorded in the structured table, which facilitates subsequent path blocking judgment, abnormal feature clustering or correlation backtracking of the scheduling module. By counting the number of paths that meet the condition in the current period, a total of 2 paths reach the standard of three or more index abnormalities at the same time, and the composite feature abnormal flow path statistics result is obtained.
[0108] Please refer to Figure 5 The specific steps of S4 are as follows:
[0109] S411: Based on the identified paths in the composite feature abnormal flow path statistics result, the communication flow direction change of each path in the current analysis period is detected, the forwarding direction information between the starting node and the target node corresponding to the path is extracted, a time-ordered communication direction sequence is established, each occurrence of direction flip is marked with an index position, and the number of occurrences in the period is recorded to obtain the path direction switching number value.
[0110] Based on the identified paths in the composite feature abnormal traffic path statistics result, the communication direction change record of each path in the current analysis period is extracted. First, the order of data packets carried by each path in the period is obtained, and the source MAC and destination MAC fields of each data packet are extracted. Then, the MAC interface position and link mapping relationship are combined to convert it into a direction identifier, for example, the source MAC corresponds to SN1, and the destination MAC corresponds to SN2. The direction is recorded as SN1→SN2. After collecting the direction identifiers of all data packets, a time sequence direction sequence is constructed. The direction identifiers before and after are compared. If the direction is switched from X→Y to Y→X, or Y→X to X→Y, it is counted as a direction alternation event. The total number of direction flips of each path in the entire period is counted, and the following statistical table is constructed:
[0111] Table 8 Path communication direction alternation statistical table
[0112]
[0113] As shown in Table 8, the number of direction flips of paths P2 and P3 in period T9 reaches 2 times or more. The path direction switching number value is obtained.
[0114] S412: According to the path direction switching number value, the number of communication direction changes of each path in the analysis period is determined in turn. If there are two or more forward and reverse direction alternation changes, it is determined that the path has a bidirectional oscillation behavior. The path number that meets the condition is archived, and the path number set with routing oscillation characteristics is obtained;
[0115] According to the path direction switching number value, the direction change behavior of each path in period T9 is determined. The judgment standard is set as whether the number of direction switches in a single period reaches 2 times or more. If the condition is met, it is determined that the path has a communication direction oscillation phenomenon, and the path number is further archived. Path P1 has 0 direction change times in period T9, and the direction does not alternate, so it is not included in the path set. Path P2 has 3 direction flip times, which is greater than the threshold value, and meets the condition. Path P3 has 2 flip times, which is equal to the threshold value, and also meets the condition. Therefore, paths P2 and P3 are included in the direction oscillation path set at the same time. The period number, flip number and direction change mode are recorded, the initial identification structure of the oscillation path is established, and the path number set with routing oscillation characteristics is obtained.
[0116] S413: According to the path number set with routing oscillation characteristics, the link segment number covered by the path is recorded, the number of oscillation paths carried on each link is counted, and the path number, link number and oscillation state are associated and mapped to obtain the total number of link disturbance type abnormal traffic paths.
[0117] According to the path number set with the routing oscillation characteristics, the physical link structure mapped by each path is extracted. The path P2 passes through the link segments L1 (SN1→SN2), L2 (SN2→SN3), and L3 (SN3→SN4) in the topology structure in turn, and the path P3 passes through the link segments L2 (SN2→SN3), L3 (SN3→SN4), and L4 (SN4→SN5). After the path number is correspondingly bound with the link number, the link load mapping table is constructed, the number of times that each link is involved by the path with the routing oscillation characteristics is counted, and the result is as follows:
[0118] Table 9: Link disturbance path coverage statistical table
[0119]
[0120] As shown in Table 9, the link L2 and L3 are each covered by 2 paths, the link L1 and L4 are each covered by 1 path, 4 link path mappings are involved in total, and the total number of link disturbance type abnormal traffic paths is obtained.
[0121] Please refer to Figure 6 , the specific steps of S5 are as follows:
[0122] S511: Based on the total number of link disturbance type abnormal traffic paths, the link numbers involved and the corresponding path structures are determined, the communication node device information passed through by each path is extracted, the starting device number, the terminal device number, and all the relay switch numbers in the path are identified through the binding relationship between the path and the topology structure, the mapping relationship between the path number and the device number is established, the path associated switch node number set is generated, and the path associated switch node number set is generated.
[0123] Based on the total number of abnormal traffic path of link disturbance type, each path traversed in the current period is disassembled, the topology bound by each path is identified after the link number is determined, and the switching equipment involved in the path is matched based on the structure number mapped by the link. After the association between path number and link number is completed, the start device, end device and relay switch in the link topology are extracted as device number sequence to form the mapping of path to switch number, for example, path P2 maps link segments L1, L2, L3, which connect devices SW01→SW02, SW02→SW03, SW03→SW04 respectively, so the device number sequence of path P2 is SW01, SW02, SW03, SW04; Similarly, path P3 passes through link segments L2, L3, L4, which connect devices SW02→SW03, SW03→SW04, SW04→SW05, and the corresponding device numbers are SW02, SW03, SW04, SW05. After arranging the device numbers corresponding to each path in order, a structured list of path number and device node number is constructed, and is archived according to path period number, for example, paths P2 and P3 belong to period T9, and the corresponding device set is {SW01, SW02, SW03, SW04, SW05}, and the data structure is as follows:
[0124] Table 10 Path and switch node number relationship table
[0125]
[0126] As shown in Table 10, the complete mapping relationship between path number and corresponding switch node number can be obtained in period T9, and the path associated switch node number set is obtained.
[0127] S512: According to the path associated switch node number set, the port state information corresponding to each switch number in the current analysis period is extracted, and the association structure between period identifier and device port state record is established. By aggregating the index records of the ports contained in the device number, it is determined whether the device has abnormal port state in the period, and the abnormal device is marked, and the number and period identifier are recorded to obtain the period abnormal switch number set;
[0128] According to the path correlation switch node number set, the port running state data of each switch in the current period T9 is extracted, the uplink and downlink directions are matched according to the device port number, and the cumulative number of bytes transmitted, the number of data packets forwarded and the port bandwidth utilization in the current period are obtained, and the period port flow index table is formed by summarizing, for example, the switch SW02 sends 2.3GB data in the uplink port in the period T9, and receives 2.1GB data in the downlink port, and the average utilization rate is 74.5%, so the index column items are 2300MB, 2100MB and 74.5%; for SW03, the uplink is 2.8GB, the downlink is 2.4GB, and the utilization rate is 79.2%, and the record is as follows:
[0129] Table 11 Periodic port flow index collection table
[0130]
[0131] According to the flow index collected in the above table, the port load judgment standard is set, and the judgment standard is obtained by experimental statistics, when the average utilization rate of the device port is more than 75%, and the difference between the uplink and downlink data is more than 400MB, it is judged that the device port load fluctuation is abnormal, the utilization rate of SW02 is 74.5%, which is lower than the judgment standard, and is marked as normal, the utilization rate of SW03 is 79.2%, which is more than 75%, the difference between the uplink and downlink is 400MB, which meets the condition, and is marked as abnormal device, SW03 is recorded in the abnormal device identification list, and is combined with the current period number to record, and the period abnormal switch number set is obtained.
[0132] S513: According to the period abnormal switch number set, the total number of paths involved by each abnormal device is counted, and whether there is a multi-path cross aggregation phenomenon is judged, the consistency of the device flow source and destination is judged according to the position and direction of the path in the network topology, the aggregation and division of each abnormal path in the device level is completed, the abnormal path attribution set is established with the device number as the index, and the switch abnormal flow detection result is obtained;
[0133] According to the periodic abnormal switch number set, the path information associated with the abnormal device is retrieved, the path and device mapping relationship is referred to Table 10, the path number corresponding to the device is retrieved, for example, the path associated with SW03 is P2 and P3, which are located in the links L2 and L3 under the period T9, the path direction identifier is extracted, and it is obtained that P2 is in the SN1→SN4 direction and P3 is in the SN2→SN5 direction, the directions are different but both are aggregated on the switch SW03, the switch number is bound to the path, the number of paths is 2, the same steps are performed on SW04 to obtain the number of aggregated paths, the path aggregation of all abnormal device numbers is performed, the corresponding structure table of the device number and the number of aggregated paths is obtained, the one-way aggregation and the bidirectional mixed aggregation are distinguished according to the path direction, and finally the abnormal path attribution list of the device level is arranged, the summary structure content is extracted, and the switch abnormal flow detection result is obtained.
[0134] The data center switch abnormal flow detection device comprises:
[0135] The abnormal flow detection device comprises:
[0136] The abnormal flow detection device comprises:
[0137] The abnormal flow detection device comprises:
[0138] The abnormal flow detection device comprises:
[0139] The abnormal flow detection device comprises:
[0140] The above merely describes the preferred embodiments of the present application, and is not intended to limit the present application in other forms. Any skilled person in the art can modify or change the disclosed technical content into equivalent embodiments with equivalent changes, and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments according to the technical essence of the present application, without departing from the technical solution content of the present application, still falls within the protection scope of the present application.
Claims
1. A method for detecting abnormal traffic in a data center switch, the method comprising: The method comprises the following steps: S1: obtaining adjacent period traffic data of uplink and downlink ports of a data center switch, calculating traffic jump ratio and screening ports exceeding a dynamic traffic threshold to generate a number of burst abnormal traffic ports; S2: according to the number of burst abnormal traffic ports, extracting port traffic response delay of a path continuous switching node, calculating a maximum value and a minimum value difference, screening a path first breaking through a network jitter tolerance, and generating a delay offset abnormal traffic path; S3: according to the delay offset abnormal traffic path, extracting node port average flow rate, inter-packet arrival time, MAC address change frequency and direction jump times, counting the number of paths in which any three indicators exceed the corresponding baseline abnormal detection at the same time, and generating a composite feature abnormal traffic path statistical result; S4: based on the composite feature abnormal traffic path statistical result, detecting a traffic channel with BGP route oscillation, counting the total path chain number, and generating a total number of link disturbance type abnormal traffic paths; S5: according to the total number of link disturbance type abnormal traffic paths, determining the corresponding communication path and node information, completing abnormal traffic chain attribution aggregation in the device dimension, and generating a switch abnormal traffic detection result.
2. The data center switch anomaly traffic detection method of claim 1, wherein, The number of burst abnormal traffic ports includes abnormal port distribution records, port jump ratio intervals and traffic change trend categories, the delay offset abnormal traffic path includes path delay difference intervals, abnormal path topology positions and affected communication directions, the composite feature abnormal traffic path statistical result includes path associated indicator item numbers, abnormal indicator combination types and path feature difference levels, and the total number of link disturbance type abnormal traffic paths includes path oscillation frequencies, period direction alternation modes and potential BGP influence levels, and the switch abnormal traffic detection result includes abnormal switch numbers, aggregated link numbers and abnormal port categories.
3. The data center switch anomaly traffic detection method of claim 1, wherein, The acquisition step of the number of burst abnormal traffic ports is: S111: based on the SNMP polling data of the data center switch, obtaining the uplink and downlink traffic values of each key port in two adjacent periods at a set time point, matching the data of each port according to the polling interval, extracting the port uplink and downlink total traffic data of the current period and the previous period, and generating a port period traffic value pair; S112: according to the port period traffic value pair, comparing the uplink and downlink traffic changes of the current period and the previous period, identifying the overall variation characteristics of each port in the adjacent period, and generating a traffic jump ratio list by aggregating the unified variation information set; S113: based on the traffic jump ratio list, comparing the jump characteristics of each port with the set dynamic traffic threshold, identifying the ports with jump characteristics exceeding the threshold and counting the number of the ports, and obtaining the number of burst abnormal traffic ports.
4. The data center switch anomaly traffic detection method of claim 1, wherein, The acquisition step of the delay offset abnormal traffic path is: S211: Based on the identified port set in the burst abnormal traffic port quantity, the communication path of each port is extracted, and the three continuous switching nodes in each path are limited, the port traffic response time between the nodes in each path is obtained, the timestamp interval is extracted as the response delay data, and the traffic response time difference of the front and rear ports of each of the three nodes corresponding to each path is recorded respectively, and a path delay value list is generated; S212: According to the path delay value list, the response difference value analysis is performed on the three delay values in each path, the difference range between the maximum delay value and the minimum delay value in the current path is obtained, the path delay offset difference value is calculated, whether it exceeds the network jitter tolerance is judged, the path set to be screened is constructed, and the out-of-limit path difference value set is obtained; S213: Based on the out-of-limit path difference value set, the path that first breaks through the network jitter tolerance is identified, the screening operation is performed, all paths that have never historically exceeded the limit are marked and the path number is recorded, and the delay offset abnormal traffic path is obtained.
5. The data center switch anomaly traffic detection method of claim 1, wherein, The acquisition step of the composite feature abnormal traffic path statistical result is: S311: Based on each path in the delay offset abnormal traffic path quantity, the average flow rate, the inter-packet arrival time, the MAC address change frequency and the direction jump number of the node port in the path in the current period are sequentially counted, and a node feature time sequence list is generated; S312: According to the node feature time sequence list, the numerical situation of the average flow rate, the inter-packet arrival time, the MAC address change frequency and the direction jump number and the respective baseline level in the period are respectively distinguished, whether three or more indicators in the path are in an abnormal state is judged, and the baseline condition satisfied path count value is obtained; S313: Based on the baseline condition satisfied path count value, the path number that meets three or more features simultaneously abnormal is extracted, the corresponding record period, path identification and abnormal state are classified and arranged to form a composite table item, and the statistical processing is summarized, and the composite feature abnormal traffic path statistical result is obtained.
6. The data center switch anomaly traffic detection method of claim 1, wherein, The acquisition step of the link disturbance type abnormal traffic path total number is: S411: Based on the identified path in the composite feature abnormal traffic path statistical result, the communication traffic direction change of each path in the current analysis period is detected, the forwarding direction information between the starting node and the target node corresponding to the path is extracted, a time-ordered communication direction sequence is established, the index position of each occurrence of direction flip is marked in turn, and the number of times of occurrence in the period is recorded, and the path direction switching number value is obtained; S412: According to the path direction switching number value, whether the number of times of communication direction change of each path in the analysis period satisfies the condition of more than twice of reciprocating flip is judged in turn, if there are two times and more than two times of positive and negative direction alternation, it is judged that the path has bidirectional oscillation behavior, the path number that meets the condition is archived, and the path number set with route oscillation characteristics is obtained; S413: According to the path number set with the route oscillation characteristic, the link segment number covered by the path is recorded, the number of oscillation paths carried on each link is counted, and the path number, link number and oscillation state are associated and mapped to obtain the total number of link disturbance type abnormal traffic paths.
7. The data center switch anomaly traffic detection method of claim 1, wherein, The acquisition step of the switch abnormal traffic detection result is: S511: Based on the total number of link disturbance type abnormal traffic paths, the link number involved and the corresponding path structure are determined, the communication node device information traversed by each path is extracted, the starting device number, the terminating device number and all the relay switch numbers in the path are identified through the binding relationship between the path and the topology structure, the mapping relationship between the path number and the device number is established, and the path associated switch node number set is generated; S512: According to the path associated switch node number set, the port state information corresponding to each switch number in the current analysis period is extracted, and the association structure between the period identifier and the device port state record is established. By aggregating the index records of the ports contained by the device number, it is determined whether the device has abnormal port state in the period, the abnormal device is marked, and the number and the period identifier are recorded to obtain the period abnormal switch number set; S513: According to the period abnormal switch number set, the total number of paths involved by each abnormal device is counted, and it is judged whether there is a multi-path cross aggregation phenomenon. Combined with the position and direction identification of the path in the network topology, the consistency of the device traffic source and destination is judged, the aggregation and division of each abnormal path at the device level are completed, the abnormal path attribution set is established with the device number as the index, and the switch abnormal traffic detection result is obtained.
8. A data center switch anomaly traffic detection apparatus, characterized by, The data center switch abnormal traffic detection device is used to execute the data center switch abnormal traffic detection method in any one of claims 1 to 7, and the data center switch abnormal traffic detection device comprises: The identification port jump module is used to execute S1: obtaining the adjacent period traffic data of the data center switch uplink and downlink ports, calculating the traffic jump ratio and screening the ports exceeding the dynamic traffic threshold, and generating the number of burst abnormal traffic ports; The analysis path delay module is used to execute S2: according to the number of burst abnormal traffic ports, extracting the port traffic response delay of the path continuous switching node, calculating the difference between the maximum value and the minimum value, screening the path which first breaks through the network jitter tolerance, and generating the delay offset abnormal traffic path; The screening composite path module is used to execute S3: according to the delay offset abnormal traffic path, extracting the node port average flow rate, packet inter-arrival time, MAC address change frequency and direction jump times, counting the number of paths in which any three indicators exceed the corresponding baseline abnormal detection at the same time, and generating the composite feature abnormal traffic path statistical result; The identification disturbance link module is used to execute S4: based on the composite feature abnormal traffic path statistical result, detecting the traffic channel with BGP route oscillation, counting the total path chain number, and generating the total number of link disturbance type abnormal traffic paths; The identification disturbance link module is used to execute S4: based on the composite feature abnormal traffic path statistical result, detecting the traffic channel with BGP route oscillation, counting the total path chain number, and generating the total number of link disturbance type abnormal traffic paths; The anomaly detection output module is configured to perform S5: determining the corresponding communication path and node information according to the total number of link disturbance type anomaly traffic paths, completing anomaly traffic link attribution aggregation in the device dimension, and generating a switch anomaly traffic detection result.
9. A data center switch anomaly traffic detection device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor executes the computer program to implement the steps of the data center switch anomaly traffic detection method in any one of claims 1 to 7.
10. A computer readable medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the data center switch anomaly traffic detection method in any one of claims 1 to 7.
Citation Information
Patent Citations
Network monitoring method and device, equipment and storage medium
CN117278307A
Method and apparatus for monitoring network
JP2011114743A