Intelligent analysis method and system for flow among different regional level networks of operator
By collecting, standardizing and aggregating traffic data from operators' regional networks, identifying service categories and optimizing billing, the accuracy and timeliness issues of cross-regional traffic analysis in existing technologies are resolved, enabling efficient and accurate cross-regional traffic billing.
Patent Information
- Application Number
- CN202511249260.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-09-03
AI Technical Summary
Existing technologies cannot accurately distinguish cross-regional traffic of different business types. Manual statistics are time-lagged and cannot dynamically adjust business strategies. Traditional IP analysis does not consider address drift, which leads to misjudgment of the location of ownership. It lacks multi-dimensional proportion analysis and is difficult to support billing negotiations.
Collect raw traffic data from multiple devices and nodes, perform standardization, anomaly cleaning and reorganization, and obtain a structured traffic record table; based on the structured traffic record table, identify IP geographic attribution, attribution credibility and business category, and generate a traffic label table; perform four-dimensional traffic aggregation, and perform billing and optimization according to the preset traffic billing strategy.
It realizes automatic and accurate differentiation of cross-regional traffic of different business types, solves the problem of address drift, and realizes efficient and accurate cross-regional traffic billing.
Smart Images

Figure CN120751059A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of traffic analysis, and in particular relates to a method and system for intelligently analyzing traffic between networks at different regional levels of an operator. Background Art
[0002] To cope with changes in billing rules between operators' regions and inter-regional settlement, it is necessary to analyze one's own business traffic and count the out-of-region traffic of each business. Based on this data, communicate with the business party to reduce the out-of-region traffic, and perform additional billing based on this data to reduce losses. The inter-regional settlement of operators adopts a traffic tiered pricing model. At the same time, it also adopts a night-time off-peak traffic discount rule, and cross-regional traffic needs to be counted by business type and time period.
[0003] Existing technologies for analyzing cross-regional traffic often have the following flaws: 1. Existing tools cannot accurately distinguish cross-regional traffic by service type (such as video, cloud services, or regular Internet access); 2. Manual statistics have a time lag (more than T+3 days), making it impossible to dynamically adjust service policies; 3. Traditional IP analysis does not account for address drift (such as misjudgment of the location of ownership due to dynamic node switching); 4. The lack of multi-dimensional proportion analysis (service / time period / target area) makes it difficult to support billing negotiations. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide a method and system for intelligently analyzing traffic between different regional-level networks of an operator, aiming to solve the problems raised in the background technology.
[0005] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions: A method for intelligently analyzing traffic between different regional networks of an operator, the method specifically comprising the following steps: Collecting raw traffic data from multiple devices and nodes, and standardizing, cleaning abnormalities, and reorganizing the raw traffic data to obtain a structured traffic record table; Based on the structured traffic record table, identify the IP geographical attribution, attribution credibility and service category of each traffic flow, and record the traffic label table; Based on the structured traffic record table and the traffic label table, performing four-dimensional traffic aggregation on the original traffic data to obtain a four-dimensional traffic portrait structure; According to the preset traffic billing strategy, traffic billing and optimization are performed on the four-dimensional traffic portrait structure to obtain traffic billing data.
[0006] As a further limitation of the technical solution of the embodiment of the present invention, the collecting of raw traffic data of multiple devices and nodes, and standardizing, cleaning abnormalities, and reorganizing the raw traffic data to obtain a structured traffic record table specifically includes the following steps: Receive traffic analysis requests; Identifying the traffic analysis request, and determining a sampling frequency, a plurality of devices, and nodes; Sampling multiple devices and nodes at the sampling frequency to obtain raw traffic data; Performing protocol standardization and field unification on the original traffic data; Performing abnormality cleaning and traffic reorganization on the original traffic data; Get the structured traffic record table.
[0007] As a further limitation of the technical solution of the embodiment of the present invention, based on the structured traffic record table, the IP geographical attribution, attribution credibility and service category identification of each traffic flow are performed, and the traffic label table is recorded, specifically including the following steps: Based on the preset BGP / ASN database, an IP geographic mapping library is constructed, and a probability weight model is established; Performing IP geographical attribution identification on each flow in the structured flow record table through the IP geographical mapping library, and recording the attribution identification result; Performing an attribution credibility analysis on each flow in the structured flow record table using the probability weight model to obtain an attribution credibility result; Extracting quintuples and behavior features based on the structured traffic record table; Identify the service category of each flow according to the five-tuple and the behavior characteristics, and record the service category identification result; The attribution identification result, the attribution credibility result and the service category identification result are integrated to generate a traffic label table.
[0008] As a further limitation of the technical solution of the embodiment of the present invention, the service category identification result includes multiple service types, specifically video service, cloud service and ordinary Internet service.
[0009] As a further limitation of the technical solution of the embodiment of the present invention, the four-dimensional traffic aggregation of the original traffic data based on the structured traffic record table and the traffic label table to obtain the four-dimensional traffic portrait structure specifically includes the following steps: Based on the structured flow record table and the flow label table, the original flow data is aggregated according to the service type and region affiliation to construct a service-region-flow matrix table; Based on the business-region-traffic matrix table, obtain the time period partitioning strategy; The original traffic data is divided according to the time period partitioning strategy, and four-dimensional traffic aggregation is performed on the basis of the business-region-traffic matrix table to generate a four-dimensional traffic portrait structure.
[0010] As a further limitation of the technical solution of the embodiment of the present invention, the flow billing and optimization of the four-dimensional flow profile structure according to the preset flow billing strategy, and the acquisition of flow billing data specifically include the following steps: Loading preset traffic billing strategies, including cross-region pricing strategies, time zone pricing strategies, and tiered pricing strategies; Perform cross-regional traffic billing on the four-dimensional traffic profile structure according to the cross-regional pricing strategy, and obtain cross-regional billing data; According to the time period zoning pricing strategy, based on the cross-regional billing data, the four-dimensional traffic profile structure is optimized for zoning pricing to obtain cross-regional billing data; According to the tiered pricing strategy, based on the cross-regional billing data, the four-dimensional traffic portrait structure is optimized for tiered pricing to obtain traffic billing data.
[0011] An intelligent traffic analysis system between operators' regional networks, comprising a traffic data collection unit, a traffic identification and processing unit, a four-dimensional traffic aggregation unit, and a traffic billing optimization unit, wherein: A flow data collection unit is used to collect raw flow data from multiple devices and nodes, and to standardize, clean up abnormalities, and reorganize the raw flow data to obtain a structured flow record table; A traffic identification processing unit, configured to identify the IP geographical attribution, attribution credibility and service category of each traffic flow based on the structured traffic record table, and record a traffic label table; A four-dimensional traffic aggregation unit is used to perform four-dimensional traffic aggregation on the original traffic data based on the structured traffic record table and the traffic label table to obtain a four-dimensional traffic portrait structure; The traffic billing optimization unit is used to perform traffic billing and optimization on the four-dimensional traffic portrait structure according to a preset traffic billing strategy and obtain traffic billing data.
[0012] As a further limitation of the technical solution of the embodiment of the present invention, the flow data collection unit specifically includes: A request receiving module, used for receiving traffic analysis requests; a request identification module, configured to identify the traffic analysis request and determine a sampling frequency, a plurality of devices, and nodes; A traffic sampling module, configured to sample multiple devices and nodes at the sampling frequency to obtain raw traffic data; A standardization and field unification module, configured to perform protocol standardization and field unification on the original traffic data; An abnormality cleaning and traffic reassembly module, used for performing abnormality cleaning and traffic reassembly on the original traffic data; The structured flow record table acquisition module is used to obtain the structured flow record table.
[0013] As a further limitation of the technical solution of the embodiment of the present invention, the traffic identification processing unit specifically includes: An IP geographic mapping library construction module is used to construct an IP geographic mapping library based on a preset BGP / ASN database and establish a probability weight model; An IP geographic attribution identification module is used to perform IP geographic attribution identification on each flow in the structured flow record table through the IP geographic mapping library and record the attribution identification result; an attribution credibility analysis module, configured to perform attribution credibility analysis on each flow in the structured flow record table using the probability weight model to obtain an attribution credibility result; A feature extraction module, configured to extract quintuples and behavior features based on the structured traffic record table; A service category identification module, configured to identify the service category of each flow according to the five-tuple and the behavior characteristics, and record the service category identification result; The flow label table generating module is used to generate a flow label table by integrating the attribution identification result, the attribution credibility result and the service category identification result.
[0014] As a further limitation of the technical solution of the embodiment of the present invention, the traffic billing optimization unit specifically includes: A policy loading module is used to load preset traffic billing policies, including cross-region pricing policies, time zone pricing policies, and tiered pricing policies; A cross-regional traffic billing module is used to perform cross-regional traffic billing on the four-dimensional traffic profile structure according to the cross-regional pricing strategy and obtain cross-regional billing data; A partition pricing optimization module is used to optimize the partition pricing of the four-dimensional traffic profile structure based on the cross-regional billing data according to the time period partition pricing strategy, and obtain the cross-regional billing data; The tiered pricing optimization module is used to perform tiered pricing optimization on the four-dimensional traffic portrait structure based on the cross-regional billing data in accordance with the tiered pricing strategy to obtain traffic billing data.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The embodiment of the present invention collects raw traffic data from multiple devices and nodes to obtain a structured traffic record table; identifies each traffic flow based on its IP geographic attribution, attribution credibility, and service category, and records a traffic label table; performs four-dimensional traffic aggregation on the raw traffic data to obtain a four-dimensional traffic profile structure; and performs traffic billing and optimization on the four-dimensional traffic profile structure according to a preset traffic billing strategy to obtain traffic billing data. The system is capable of identifying IP geographic attribution, attribution credibility, and service category, obtaining a four-dimensional traffic profile structure, performing traffic billing and optimization, and thereby automatically and accurately distinguishing cross-regional traffic flows of different service types, resolving the problem of address drift, and achieving efficient and accurate cross-regional traffic billing. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention.
[0017] Figure 1 A flow chart of a method provided by an embodiment of the present invention is shown.
[0018] Figure 2 A flow chart of obtaining a structured traffic record table in a method provided by an embodiment of the present invention is shown.
[0019] Figure 3 The application architecture diagram of the system provided by the embodiment of the present invention is shown.
[0020] Figure 4 A structural block diagram of a traffic identification processing unit in a system provided by an embodiment of the present invention is shown.
[0021] Figure 5 The structure block diagram of the traffic billing optimization unit in the system provided by the embodiment of the present invention is shown. DETAILED DESCRIPTION
[0022] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0023] Understandably, existing technologies for analyzing cross-regional traffic often suffer from the following flaws: 1. Existing tools cannot accurately distinguish cross-regional traffic by service type (e.g., video / cloud services / regular Internet access); 2. Manual statistics are time-delayed (more than T+3 days), making it impossible to dynamically adjust service policies; 3. Traditional IP analysis does not account for address drift (e.g., misjudgment of the location of ownership due to dynamic node switching); 4. The lack of multi-dimensional proportion analysis (service / time period / target area) makes it difficult to support billing negotiations.
[0024] To solve the above problems, the embodiment of the present invention collects the original traffic data of multiple devices and nodes, and performs standardization, anomaly cleaning and traffic reorganization on the original traffic data to obtain a structured traffic record table; based on the structured traffic record table, the IP geographical attribution, attribution credibility and service category identification are performed for each traffic, and a traffic label table is recorded; based on the structured traffic record table and the traffic label table, the original traffic data is subjected to four-dimensional traffic aggregation to obtain a four-dimensional traffic portrait structure; according to the preset traffic billing strategy, the four-dimensional traffic portrait structure is subjected to traffic billing and optimization to obtain traffic billing data. It is capable of performing IP geographical attribution, attribution credibility and service category identification, obtaining a four-dimensional traffic portrait structure, performing traffic billing and optimization, thereby automatically and accurately distinguishing cross-regional traffic of different business types, and solving the problem of address drift, thereby achieving efficient and accurate cross-regional traffic billing.
[0025] Figure 1 A flow chart of a method provided by an embodiment of the present invention is shown.
[0026] Specifically, the method for intelligently analyzing traffic between different regional networks of an operator includes the following steps: Step S101: collect original traffic data of multiple devices and nodes, and perform standardization, abnormality cleaning and traffic reorganization on the original traffic data to obtain a structured traffic record table.
[0027] In an embodiment of the present invention, a traffic analysis request uploaded by a management personnel is received, the traffic analysis request is identified, the sampling frequency, multiple devices and nodes are determined, and then the multiple devices and nodes are sampled according to the sampling frequency to obtain the original traffic data. After that, the original traffic data is subjected to protocol standardization and field unification (field standard mapping is performed, and the fields of heterogeneous devices are uniformly converted into internal common fields), and the original traffic data is subjected to abnormal cleaning and traffic reorganization (abnormal flows such as continuous 0-byte flows, too short connections, and scanning behavior flows are filtered, and the flow records are reconstructed into complete sessions to generate logical connections for subsequent identification), and a structured traffic record table is obtained.
[0028] Specifically, Figure 2A flow chart of obtaining a structured traffic record table in a method provided by an embodiment of the present invention is shown.
[0029] In a preferred embodiment of the present invention, the steps of collecting raw traffic data from multiple devices and nodes, standardizing the raw traffic data, cleaning abnormalities, and reorganizing the traffic to obtain a structured traffic record table specifically include the following steps: Step S1011, receiving a traffic analysis request; Step S1012: Identify the traffic analysis request and determine the sampling frequency, multiple devices, and nodes; Step S1013: sampling multiple devices and nodes according to the sampling frequency to obtain raw traffic data; Step S1014: performing protocol standardization and field unification on the original traffic data; Step S1015, performing abnormality cleaning and traffic reorganization on the original traffic data; Step S1016: Obtain a structured traffic record table.
[0030] Furthermore, the method for intelligently analyzing traffic between different regional networks of an operator further includes the following steps: Step S102: Based on the structured traffic record table, identify the IP geographical attribution, attribution credibility and service category of each traffic, and record the traffic label table.
[0031] In an embodiment of the present invention, based on a preset BGP / ASN database, an IP geographic mapping library is constructed (aggregating BGP routes, ASN tables, WHOIS registration information, and establishing an initial IP-region mapping), and a probability weight model is established. Through the IP geographic mapping library, IP geographic attribution identification is performed on each flow in the structured traffic record table, and the attribution identification result is recorded. Then, through the probability weight model, attribution credibility analysis is performed on each flow in the structured traffic record table to obtain the attribution credibility result. Based on the structured traffic record table, the five-tuple (SRC_IP, DST_IP, PORT, protocol, timing) and behavioral characteristics (such as packet interval, flow duration, jitter rate, etc.) are extracted. According to the five-tuple and behavioral characteristics, the service category of each flow is identified, and the service category identification result is recorded. Then, the attribution identification result, the attribution credibility result and the service category identification result are integrated to generate a traffic label table. The specific multiple service types include: video service, cloud service service and ordinary Internet service.
[0032] The SRC_IP in the quintuple represents the source IP address of the traffic, i.e., the IP address of the sender of the data packet, which is used to identify the network location of the initiating device or user of the traffic; The DST_IP in the quintuple represents the destination IP address of the traffic, i.e., the IP address of the receiver of the data packet, which is used to identify the network location of the target service or user of the traffic; The PORT in the quintuple represents the destination port number, which is used to distinguish different network services or applications; The protocol in the quintuple represents the network transport layer or application layer protocol type; The time sequence in the quintuple represents a time-related feature, which is used to analyze the time behavior pattern of traffic to assist in identifying real-time services and non-real-time services.
[0033] Among them, in the preferred embodiment provided by the present invention, the IP geographical attribution, attribution credibility and service category identification of each flow are performed based on the structured flow record table, and the flow label table is recorded, which specifically includes the following steps: Step S1021: Building an IP geography mapping library based on a preset BGP / ASN database and establishing a probability weight model; Step S1022: performing IP geographical attribution identification on each flow in the structured flow record table through the IP geographical mapping library, and recording the attribution identification result; Step S1023: performing attribution credibility analysis on each flow in the structured flow record table using the probability weight model to obtain an attribution credibility result; Step S1024: extracting quintuples and behavior features based on the structured traffic record table; Step S1025: Identify the service category of each flow according to the five-tuple and the behavior characteristics, and record the service category identification result; Step S1026 , generating a traffic label table by integrating the attribution identification result, the attribution credibility result and the service category identification result.
[0034] Specifically, the probability weight model is used to perform attribution credibility analysis on each flow in the structured flow record table to obtain an attribution credibility result. The specific steps are as follows: A time decay function is constructed based on the BGP route update timestamps recorded in the IP geo-mapping library. Based on the time decay function, the weight coefficient of historical routing information that exceeds a preset period is reduced, and the confidence weight of BGP update records is increased to obtain a dynamic weight model. Topology change intensity, temporal proximity, and routing stability indicators are obtained from BGP data. Based on a dynamic weight model, the operator's real-time network topology change time and BGP / ASN data are temporally and spatially correlated to obtain temporal and spatial correlation weights. Based on the temporal and spatial correlation weights, the IP geographic attribution identification results are obtained. Based on the IP geographic attribution identification results, topology change intensity, temporal proximity, and routing stability indicators, a multidimensional verification matrix is generated. A three-level decision tree is constructed based on the multi-dimensional verification matrix and the results of IP geographic attribution identification. The three-level decision tree is used to classify the attribution credibility of traffic into three levels to generate corresponding three-level credibility classification labels. Among them, the first-level decision of the three-level decision tree is as follows: when there is temporal and spatial overlap between BGP routing information and topology change records, the highest credibility label is directly assigned; the second-level decision is as follows: for IP segments with single-dimensional conflicts, historical router path backtracking analysis is initiated, and medium credibility labels are assigned based on the backtracking analysis results; the third-level decision is as follows: traffic behavior pattern matching is performed on IP segments that cross regional boundaries and compared with the extracted five-tuple features. If the match is successful, the credibility label is upgraded; otherwise, a low credibility label is assigned. The three-level credibility classification labels are associated with the business attributes of the traffic label table to construct an optimized probability weight model, and the attribution credibility result is obtained through the optimized probability weight model.
[0035] Furthermore, the present invention solves the problem of misjudgment of attribution caused by insufficient timeliness of BGP data by integrating the time decay function with the topology change record; by adopting a credibility grading mechanism that is adaptive to the service type, it reduces the computational overhead while ensuring the analysis accuracy; and by cross-validating the quintuple features and geographic credibility, it enhances the stealth of abnormal traffic detection.
[0036] Furthermore, the method for intelligently analyzing traffic between different regional networks of an operator further includes the following steps: Step S103: Based on the structured traffic record table and the traffic label table, four-dimensional traffic aggregation is performed on the original traffic data to obtain a four-dimensional traffic portrait structure.
[0037] In an embodiment of the present invention, based on a structured traffic record table and a traffic label table, the original traffic data is aggregated according to the business type and regional affiliation, and a business-region-traffic matrix table is constructed. Based on the business-region-traffic matrix table, a time period partitioning strategy is obtained (for example: off-peak hours are 0:00-6:00; busy hours are 6:00-24:00). Then, according to the time period partitioning strategy, the original traffic data is divided, and on the basis of the business-region-traffic matrix table, four-dimensional traffic aggregation is performed to generate a four-dimensional traffic portrait structure.
[0038] Specifically, in a preferred embodiment of the present invention, performing four-dimensional traffic aggregation on the original traffic data based on the structured traffic record table and the traffic label table to obtain a four-dimensional traffic portrait structure specifically includes the following steps: Step S1031: Based on the structured traffic record table and the traffic label table, the original traffic data is aggregated according to the service type and region, and a service-region-traffic matrix table is constructed; Step S1032: Based on the business-area-traffic matrix table, obtain a time period partitioning strategy; In step S1033, the original traffic data is divided according to the time period partitioning strategy, and four-dimensional traffic aggregation is performed based on the business-region-traffic matrix table to generate a four-dimensional traffic portrait structure.
[0039] Specifically, based on the structured flow record table and the flow label table, the original flow data is aggregated according to the service type and region affiliation to construct a service-region-flow matrix table. The specific steps are as follows: Based on the service category identification results, the real-time level is extracted. Based on the real-time level, the transmission stability index is calculated through the attribution credibility. The inter-regional traffic topology relationship diagram is constructed based on the IP geographic attribution identification results. The inter-regional traffic topology relationship diagram is used to obtain the historical transmission cost characteristics and timestamp-correlated service traffic fluctuations. The transmission stability index, historical transmission cost characteristics, and timestamp-correlated service traffic fluctuations are used to obtain a multi-dimensional feature vector. A trusted real-time comprehensive value is generated based on the attribution credibility and real-time level, and the trusted real-time comprehensive value is used as the key factor. A stability factor is calculated based on the key factor, and a cost sensitivity factor is constructed based on the stability factor and historical cost distribution. When resource utilization exceeds the preset resource utilization threshold, the cost sensitivity factor weight is increased, and a business-region association weight matrix is generated. Using feature-weighted clustering, we aggregate raw traffic data with similar multi-dimensional features into a business-region association weight matrix to generate an initial business-region-traffic matrix table. The historical distribution of the initial business-region-traffic matrix table is compared with the real-time traffic characteristics to identify abnormal units. The authenticity of the geographical attribution based on the abnormal units is verified using the attribution credibility. After verification, the multi-dimensional feature vector of the abnormal unit is reconstructed to obtain an optimized matrix table, which is used as the business-region-traffic matrix table.
[0040] Furthermore, the present invention improves the economic efficiency of cross-provincial traffic scheduling by dynamically associating weight factors with network status; and ensures the accuracy of the traffic matrix by combining anomaly detection mechanism with attribution credibility verification.
[0041] Specifically, based on the business-region-traffic matrix table, obtain the time period partitioning strategy. The specific steps are as follows: Based on the time dimension of historical traffic data in the business-region-traffic matrix table, the historical data is divided into preset periods, and the traffic fluctuation coefficient of each period is calculated based on the historical data to obtain the time period sensitivity coefficient. Based on the spatial dimension of the historical traffic data in the business-region-traffic matrix table, an inter-regional traffic transmission topology map is established, and the transmission intensity of the traffic between nodes in the inter-regional traffic transmission topology map is calculated to obtain the cross-regional transmission intensity. Based on the business-region-traffic matrix table, the business-related dimensions of historical traffic data are combined with the business category identification results to establish a mapping relationship between business types and spatiotemporal characteristics. Based on the time period sensitivity coefficient, cross-region transmission intensity, and the mapping relationship between business types and spatiotemporal characteristics, a spatiotemporal distribution feature map is obtained. Based on the spatiotemporal distribution feature map, a multi-task prediction model based on deep learning is constructed and used as a dynamic network load prediction model. Based on the service category identification results, real-time services and non-real-time services are classified. The cost distribution in cross-regional billing data is then combined to calculate the service type's sensitivity to transmission delay. Based on the service type's sensitivity to transmission delay, a correlation matrix is established between service type and time zone partitions to obtain a service time zone sensitivity grading table. Based on the prediction results of the dynamic network load prediction model and the priority data in the service time sensitivity classification table, a multi-objective optimization model is constructed. Based on the multi-objective optimization model, the NSGA-II multi-objective optimization algorithm is used to optimize the strategy and obtain the initial time partitioning strategy. The initial time period partitioning strategy is injected into historical traffic to build a simulation environment. The core period resource deviation is monitored in the simulation environment. When the core period resource deviation exceeds the preset threshold, the dynamic network load prediction model and the NSGA-II multi-objective optimization algorithm are incrementally trained based on the real-time traffic characteristics in the business-region-traffic matrix table to obtain the time period partitioning strategy.
[0042] Furthermore, the present invention enables the time period partitioning strategy to have self-optimization capabilities through the deviation monitoring mechanism in the strategy verification stage; and improves the accuracy of cross-provincial traffic scheduling by deeply coupling business characteristics with network load predictions.
[0043] Furthermore, the method for intelligently analyzing traffic between different regional networks of an operator further includes the following steps: Step S104: perform traffic billing and optimization on the four-dimensional traffic portrait structure according to the preset traffic billing strategy to obtain traffic billing data.
[0044] In an embodiment of the present invention, a preset traffic billing strategy including a cross-regional pricing strategy, a time period partition pricing strategy and a tiered pricing strategy is loaded, and cross-regional traffic billing is performed on the four-dimensional traffic portrait structure according to the cross-regional pricing strategy, and cross-regional billing data is obtained. Then, according to the time period partition pricing strategy, on the basis of the cross-regional billing data, the four-dimensional traffic portrait structure is optimized for partition pricing, and cross-regional billing data is obtained. Thereafter, according to the tiered pricing strategy, on the basis of the cross-regional billing data, the four-dimensional traffic portrait structure is optimized for tiered pricing, and traffic billing data is obtained.
[0045] Specifically, in a preferred embodiment of the present invention, performing traffic billing and optimization on the four-dimensional traffic profile structure according to a preset traffic billing strategy, and obtaining traffic billing data specifically include the following steps: Step S1041, loading a preset traffic billing strategy, wherein the traffic billing strategy includes a cross-region pricing strategy, a time zone pricing strategy, and a tiered pricing strategy; Step S1042: performing cross-regional traffic billing on the four-dimensional traffic profile structure according to the cross-regional pricing strategy, and obtaining cross-regional billing data; Step S1043: Optimizing the four-dimensional traffic profile structure for zone pricing based on the cross-regional billing data according to the time period zone pricing strategy to obtain cross-regional billing data; Step S1044: According to the tiered pricing strategy, based on the cross-regional billing data, the four-dimensional traffic portrait structure is optimized for tiered pricing to obtain traffic billing data.
[0046] Specifically, according to the tiered pricing strategy, based on the cross-regional billing data, the four-dimensional traffic profile structure is optimized for tiered pricing to obtain traffic billing data. The specific steps are as follows: A traffic baseline prediction model is constructed based on the cost distribution information of cross-regional billing data and the historical traffic characteristics of service type and regional combinations in the four-dimensional traffic profile structure. Based on the traffic baseline prediction model, the multi-dimensional deviation between the actual traffic volume during the billing period of the day and the predicted baseline is compared to construct the traffic threshold range for tiered pricing. Based on the traffic threshold range for tiered pricing, a threshold adaptive algorithm is used to restructure parameters for regional and service combinations with abnormal deviations to generate a dynamic tiered threshold parameter set. Based on the dynamic step threshold parameter group and the network resource load characteristics in the time period partitioning strategy, a broadband resource-step pricing association model is constructed. Through this broadband resource-step pricing association model, the resource occupancy coefficient is extracted from the four-dimensional traffic profile structure. The dynamic step threshold parameter group and the resource occupancy coefficient are coupled and calculated to obtain the resource weight allocation matrix. The resource weight factors in the resource weight allocation matrix are injected into the tiered pricing calculation engine, and a two-layer optimization algorithm is used to iterate the billing strategy to obtain an optimized tiered billing solution set. A billing effect evaluation model is constructed based on the original traffic features in the four-dimensional traffic portrait structure; the billing effect evaluation model is cross-validated using the optimized step billing scheme set to obtain a cross-validated billing effect evaluation model; and traffic billing data is obtained using the output of the cross-validated billing effect evaluation model.
[0047] Furthermore, the present invention deeply couples the traffic prediction model with the real-time billing strategy to achieve dynamic adaptation of the step threshold parameters and the network resource status, effectively balancing billing fairness and resource utilization; by adopting a multi-level cross-validation architecture, the mathematical rigor and engineering feasibility of the billing strategy are simultaneously guaranteed, forming a technical closed loop.
[0048] Further, Figure 3 The application architecture diagram of the system provided by the embodiment of the present invention is shown.
[0049] In another preferred embodiment of the present invention, a system for intelligently analyzing traffic between different regional networks of an operator includes: The flow data collection unit 101 is used to collect original flow data of multiple devices and nodes, and perform standardization, abnormality cleaning and flow reorganization on the original flow data to obtain a structured flow record table.
[0050] In an embodiment of the present invention, the traffic data collection unit 101 receives a traffic analysis request uploaded by a management personnel, identifies the traffic analysis request, determines the sampling frequency, multiple devices and nodes, and then samples the multiple devices and nodes according to the sampling frequency to obtain the original traffic data. After that, the original traffic data is subjected to protocol standardization and field unification (field standard mapping is performed, and the fields of heterogeneous devices are uniformly converted into internal common fields), and the original traffic data is subjected to abnormal cleaning and traffic reorganization (abnormal flows such as continuous 0-byte flows, too short connections, and scanning behavior flows are filtered, and the flow records are reconstructed into complete sessions to generate logical connections for subsequent identification) to obtain a structured traffic record table.
[0051] Specifically, in a preferred embodiment of the present invention, the flow data collection unit 101 specifically includes: A request receiving module, used for receiving traffic analysis requests; a request identification module, configured to identify the traffic analysis request and determine a sampling frequency, a plurality of devices, and nodes; A traffic sampling module, configured to sample multiple devices and nodes at the sampling frequency to obtain raw traffic data; A standardization and field unification module, configured to perform protocol standardization and field unification on the original traffic data; An abnormality cleaning and traffic reassembly module, used for performing abnormality cleaning and traffic reassembly on the original traffic data; The structured flow record table acquisition module is used to obtain the structured flow record table.
[0052] Furthermore, the traffic intelligent analysis system between different regional-level networks of the operator further includes: The traffic identification processing unit 102 is used to identify the IP geographical attribution, attribution credibility and service category of each traffic based on the structured traffic record table, and record the traffic label table.
[0053] In an embodiment of the present invention, the traffic identification processing unit 102 constructs an IP geographic mapping library (aggregating BGP routes, ASN tables, and WHOIS registration information to establish an initial IP-region mapping) based on a preset BGP / ASN database, and establishes a probability weight model. Through the IP geographic mapping library, the IP geographic attribution of each traffic in the structured traffic record table is identified, and the attribution identification result is recorded. Then, through the probability weight model, the attribution credibility analysis of each traffic in the structured traffic record table is performed to obtain the attribution credibility result. Based on the structured traffic record table, the quintuple (SRC_IP, DST_IP, PORT, protocol, timing) and behavioral characteristics (such as packet interval, flow duration, jitter rate, etc.) are extracted. According to the quintuple and behavioral characteristics, the service category of each traffic is identified, and the service category identification result is recorded. Then, the attribution identification result, the attribution credibility result, and the service category identification result are integrated to generate a traffic label table. The specific multiple service types include: video service, cloud service service, and ordinary Internet service.
[0054] Specifically, Figure 4 It shows a structural block diagram of the traffic identification processing unit 102 in the system provided by an embodiment of the present invention.
[0055] In a preferred embodiment of the present invention, the traffic identification and processing unit 102 specifically includes: An IP geographic mapping library construction module 1021 is used to construct an IP geographic mapping library based on a preset BGP / ASN database and establish a probability weight model; An IP geographic attribution identification module 1022 is configured to perform IP geographic attribution identification on each flow in the structured flow record table through the IP geographic mapping library and record the attribution identification result; The attribution credibility analysis module 1023 is configured to perform attribution credibility analysis on each flow in the structured flow record table using the probability weight model to obtain an attribution credibility result; A feature extraction module 1024 is configured to extract quintuples and behavior features based on the structured traffic record table; A service category identification module 1025 is configured to identify the service category of each flow according to the five-tuple and the behavior characteristics, and record the service category identification result; The traffic label table generating module 1026 is configured to generate a traffic label table by integrating the attribution identification result, the attribution credibility result and the service category identification result.
[0056] Furthermore, the traffic intelligent analysis system between different regional-level networks of the operator further includes: The four-dimensional traffic aggregation unit 103 is used to perform four-dimensional traffic aggregation on the original traffic data based on the structured traffic record table and the traffic label table to obtain a four-dimensional traffic portrait structure.
[0057] In an embodiment of the present invention, the four-dimensional traffic aggregation unit 103 summarizes the original traffic data based on the structured traffic record table and the traffic label table according to the business type and regional affiliation, constructs a business-region-traffic matrix table, and obtains the time period partitioning strategy (for example: off-peak time is 0:00-6:00; busy time is 6:00-24:00) based on the business-region-traffic matrix table, and then divides the original traffic data according to the time period partitioning strategy, and performs four-dimensional traffic aggregation on the basis of the business-region-traffic matrix table to generate a four-dimensional traffic portrait structure.
[0058] The traffic billing optimization unit 104 is used to perform traffic billing and optimization on the four-dimensional traffic portrait structure according to a preset traffic billing strategy and obtain traffic billing data.
[0059] In an embodiment of the present invention, the traffic billing optimization unit 104 loads preset traffic billing strategies including a cross-regional pricing strategy, a time period partition pricing strategy, and a step pricing strategy, and performs cross-regional traffic billing on the four-dimensional traffic portrait structure according to the cross-regional pricing strategy, obtains cross-regional billing data, and then performs partition pricing optimization on the four-dimensional traffic portrait structure based on the cross-regional billing data according to the time period partition pricing strategy, obtains cross-regional billing data, and then, performs step pricing optimization on the four-dimensional traffic portrait structure based on the cross-regional billing data according to the step pricing strategy, obtains traffic billing data.
[0060] Specifically, Figure 5 It shows a structural block diagram of the traffic billing optimization unit 104 in the system provided by an embodiment of the present invention.
[0061] In a preferred embodiment of the present invention, the traffic billing optimization unit 104 specifically includes: The policy loading module 1041 is used to load a preset traffic billing policy, which includes a cross-region pricing policy, a time zone pricing policy, and a tiered pricing policy; The cross-regional traffic billing module 1042 is configured to perform cross-regional traffic billing on the four-dimensional traffic profile structure according to the cross-regional pricing strategy and obtain cross-regional billing data; A zone pricing optimization module 1043 is configured to optimize zone pricing for the four-dimensional traffic profile structure based on the cross-regional billing data according to the time period zone pricing strategy, and obtain cross-regional billing data; The tiered pricing optimization module 1044 is used to perform tiered pricing optimization on the four-dimensional traffic profile structure based on the cross-regional billing data in accordance with the tiered pricing strategy to obtain traffic billing data.
[0062] It should be understood that, although the various steps in the flow chart of each embodiment of the present invention are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence according to the order indicated by the arrows. Unless otherwise specified herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0063] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When executed, the program can include the processes of the above-described method embodiments. Any reference to memory, storage, database, or other media used in the various embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct RAMbus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM).
[0064] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0065] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be determined by the appended claims.
[0066] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. The intelligent traffic analysis method between different regional networks of operators is characterized by: The method specifically comprises the following steps: Collecting raw traffic data from multiple devices and nodes, and standardizing, cleaning abnormalities, and reorganizing the raw traffic data to obtain a structured traffic record table; Based on the structured traffic record table, identify the IP geographical attribution, attribution credibility and service category of each traffic flow, and record the traffic label table; Based on the structured traffic record table and the traffic label table, performing four-dimensional traffic aggregation on the original traffic data to obtain a four-dimensional traffic portrait structure; According to the preset traffic billing strategy, traffic billing and optimization are performed on the four-dimensional traffic portrait structure to obtain traffic billing data.
2. The method for intelligent traffic analysis between different regional networks of an operator according to claim 1, characterized in that: The process of collecting raw traffic data from multiple devices and nodes, standardizing the raw traffic data, cleaning abnormalities, and reorganizing the traffic to obtain a structured traffic record table specifically includes the following steps: Receive traffic analysis requests; Identifying the traffic analysis request, and determining a sampling frequency, a plurality of devices, and nodes; Sampling multiple devices and nodes at the sampling frequency to obtain raw traffic data; Performing protocol standardization and field unification on the original traffic data; Performing abnormality cleaning and traffic reorganization on the original traffic data; Get the structured traffic record table.
3. The method for intelligent traffic analysis between different regional networks of an operator according to claim 1, characterized in that: Based on the structured traffic record table, identifying the IP geographical attribution, attribution credibility, and service category of each traffic flow, and recording the traffic label table specifically includes the following steps: Based on the preset BGP / ASN database, an IP geographic mapping library is constructed, and a probability weight model is established; Performing IP geographical attribution identification on each flow in the structured flow record table through the IP geographical mapping library, and recording the attribution identification result; Performing an attribution credibility analysis on each flow in the structured flow record table using the probability weight model to obtain an attribution credibility result; Extracting quintuples and behavior features based on the structured traffic record table; Identify the service category of each flow according to the five-tuple and the behavior characteristics, and record the service category identification result; The attribution identification result, the attribution credibility result and the service category identification result are integrated to generate a traffic label table.
4. The method for intelligent traffic analysis between different regional networks of an operator according to claim 3, characterized in that: Using the probability weight model, an attribution credibility analysis is performed on each flow in the structured flow record table to obtain an attribution credibility result. The specific steps are as follows: A time decay function is constructed based on the BGP route update timestamps recorded in the IP geo-mapping library. Based on the time decay function, the weight coefficient of historical routing information that exceeds a preset period is reduced, and the confidence weight of BGP update records is increased to obtain a dynamic weight model. Obtain BGP data packets and obtain topology change intensity, time proximity and routing stability indicators through BGP data packets; Based on a dynamic weight model, the operator's real-time network topology change time and BGP / ASN data are temporally and spatially correlated to obtain temporal and spatial correlation weights. Based on the time-space association weight, obtain the IP geographical attribution identification result; A multi-dimensional verification matrix is generated based on the IP geographic attribution identification results, topology change intensity, time proximity and routing stability indicators; A three-level decision tree is constructed based on the multi-dimensional verification matrix and the results of IP geographic attribution identification. The three-level decision tree is used to classify the attribution credibility of traffic into three levels to generate corresponding three-level credibility classification labels. Among them, the first-level decision of the three-level decision tree is as follows: when there is temporal and spatial overlap between BGP routing information and topology change records, the highest credibility label is directly assigned; the second-level decision is as follows: for IP segments with single-dimensional conflicts, historical router path backtracking analysis is initiated, and medium credibility labels are assigned based on the backtracking analysis results; the third-level decision is as follows: traffic behavior pattern matching is performed on IP segments that cross regional boundaries and compared with the extracted five-tuple features. If the match is successful, the credibility label is upgraded; otherwise, a low credibility label is assigned. The three-level credibility classification labels are associated with the business attributes of the traffic label table to construct an optimized probability weight model, and the attribution credibility result is obtained through the optimized probability weight model.
5. The method for intelligent traffic analysis between different regional networks of an operator according to claim 4 is characterized in that: The step of performing four-dimensional traffic aggregation on the original traffic data based on the structured traffic record table and the traffic label table to obtain a four-dimensional traffic portrait structure specifically includes the following steps: Based on the structured flow record table and the flow label table, the original flow data is aggregated according to the service type and region affiliation to construct a service-region-flow matrix table; Based on the business-region-traffic matrix table, obtain the time period partitioning strategy; The original traffic data is divided according to the time period partitioning strategy, and four-dimensional traffic aggregation is performed on the basis of the business-region-traffic matrix table to generate a four-dimensional traffic portrait structure.
6. The method for intelligent traffic analysis between different regional networks of an operator according to claim 5, characterized in that: Based on the structured traffic record table and the traffic label table, the raw traffic data is aggregated according to service type and region, and a service-region-traffic matrix table is constructed. The specific steps are as follows: Based on the service category identification results, the real-time level is extracted. Based on the real-time level, the transmission stability index is calculated through the attribution credibility. The inter-regional traffic topology relationship diagram is constructed based on the IP geographic attribution identification results. The inter-regional traffic topology relationship diagram is used to obtain the historical transmission cost characteristics and timestamp-correlated service traffic fluctuations. The transmission stability index, historical transmission cost characteristics, and timestamp-correlated service traffic fluctuations are used to obtain a multi-dimensional feature vector. A trusted real-time comprehensive value is generated based on the attributed credibility and real-time level, and the trusted real-time comprehensive value is used as a key factor; A stability factor is calculated based on key factors, and a cost sensitivity factor is constructed based on the stability factor and historical cost distribution. When resource utilization exceeds a preset resource utilization threshold, the cost sensitivity factor weight is increased, and a business-region association weight matrix is generated. Using feature-weighted clustering, we aggregate raw traffic data with similar multi-dimensional features into a business-region association weight matrix to generate an initial business-region-traffic matrix table. Compare the historical distribution of the initial business-region-traffic matrix with the real-time traffic characteristics to identify abnormal units; The authenticity of the geographic attribution of the abnormal unit is verified by using the attribution credibility. After the verification, the multi-dimensional feature vector of the abnormal unit is reconstructed to obtain an optimized matrix table, which is used as the business-region-traffic matrix table.
7. The method for intelligent traffic analysis between different regional networks of an operator according to claim 6, characterized in that: Based on the business-region-traffic matrix, obtain the time period partitioning strategy. The specific steps are as follows: Based on the time dimension of historical traffic data in the business-region-traffic matrix table, the historical data is divided into preset periods, and the traffic fluctuation coefficient of each period is calculated based on the historical data to obtain the time period sensitivity coefficient. Based on the spatial dimension of the historical traffic data in the business-region-traffic matrix table, an inter-regional traffic transmission topology map is established, and the transmission intensity of the traffic between nodes in the inter-regional traffic transmission topology map is calculated to obtain the cross-regional transmission intensity. Based on the business-region-traffic matrix table, the business-related dimensions of historical traffic data are combined with the business category identification results to establish a mapping relationship between business types and spatiotemporal characteristics. Based on the time period sensitivity coefficient, cross-regional transmission intensity, and the mapping relationship between business type and spatiotemporal characteristics, a spatiotemporal distribution feature map is obtained; Based on the spatiotemporal distribution feature map, a multi-task prediction model based on deep learning is constructed and used as a dynamic network load prediction model. Based on the service category identification results, real-time services and non-real-time services are classified. The cost distribution in cross-regional billing data is then combined to calculate the service type's sensitivity to transmission delay. Based on the service type's sensitivity to transmission delay, a correlation matrix is established between service type and time zone partitions to obtain a service time zone sensitivity grading table. Based on the prediction results of the dynamic network load prediction model and the priority data in the service period sensitivity classification table, a multi-objective optimization model is constructed; Based on the multi-objective optimization model, the NSGA-II multi-objective optimization algorithm is used to search for strategies to obtain the initial time period partitioning strategy; The initial time period partitioning strategy is injected into historical traffic to build a simulation environment. The core period resource deviation is monitored in the simulation environment. When the core period resource deviation exceeds the preset threshold, the dynamic network load prediction model and the NSGA-II multi-objective optimization algorithm are incrementally trained based on the real-time traffic characteristics in the business-region-traffic matrix table to obtain the time period partitioning strategy.
8. The method for intelligent traffic analysis between different regional networks of an operator according to claim 7, characterized in that: The method of performing traffic billing and optimizing the four-dimensional traffic profile structure according to the preset traffic billing strategy and obtaining traffic billing data specifically includes the following steps: Loading preset traffic billing strategies, including cross-region pricing strategies, time zone pricing strategies, and tiered pricing strategies; Perform cross-regional traffic billing on the four-dimensional traffic profile structure according to the cross-regional pricing strategy, and obtain cross-regional billing data; According to the time period zoning pricing strategy, based on the cross-regional billing data, the four-dimensional traffic profile structure is optimized for zoning pricing to obtain cross-regional billing data; According to the tiered pricing strategy, based on the cross-regional billing data, the four-dimensional traffic portrait structure is optimized for tiered pricing to obtain traffic billing data.
9. The method for intelligent traffic analysis between different regional networks of an operator according to claim 8, characterized in that: According to the tiered pricing strategy, based on the cross-regional billing data, the four-dimensional traffic profile structure is optimized for tiered pricing to obtain traffic billing data. The specific steps are as follows: A traffic baseline prediction model is constructed based on the cost distribution information of cross-regional billing data and the historical traffic characteristics of the service type and region combination in the four-dimensional traffic profile structure. Based on the traffic baseline prediction model, the traffic threshold range for tiered pricing is constructed by comparing the multi-dimensional deviation of the actual traffic volume during the billing period of the day with the predicted baseline. Based on the traffic threshold intervals for tiered pricing, a threshold adaptive algorithm is used to restructure parameters for region-service combinations with abnormal deviations to generate a dynamic tiered threshold parameter set. Based on the dynamic tiered threshold parameter set and the network resource load characteristics in the time zone partitioning strategy, a broadband resource-tiered pricing correlation model is constructed. Using the broadband resource-tiered pricing model, the resource occupancy coefficient is extracted from the four-dimensional traffic profile structure. The dynamic tiered threshold parameter set and the resource occupancy coefficient are then coupled and calculated to obtain a resource weight allocation matrix. The resource weight factors in the resource weight allocation matrix are injected into the tiered pricing calculation engine, and a two-layer optimization algorithm is used to iterate the billing strategy to obtain an optimized tiered billing solution set. A billing effect evaluation model is constructed based on the original traffic features in the four-dimensional traffic portrait structure; the billing effect evaluation model is cross-validated using the optimized step billing scheme set to obtain a cross-validated billing effect evaluation model; and traffic billing data is obtained using the output of the cross-validated billing effect evaluation model.
10. The intelligent traffic analysis system between operators' different regional networks is characterized by: The system applies the method for intelligent traffic analysis between different regional networks of an operator according to any one of claims 1 to 9, and includes a traffic data collection unit, a traffic identification and processing unit, a four-dimensional traffic aggregation unit, and a traffic billing optimization unit, wherein: A flow data collection unit is used to collect raw flow data from multiple devices and nodes, and to standardize, clean up abnormalities, and reorganize the raw flow data to obtain a structured flow record table; A traffic identification processing unit, configured to identify the IP geographical attribution, attribution credibility and service category of each traffic flow based on the structured traffic record table, and record a traffic label table; A four-dimensional traffic aggregation unit is used to perform four-dimensional traffic aggregation on the original traffic data based on the structured traffic record table and the traffic label table to obtain a four-dimensional traffic portrait structure; The traffic billing optimization unit is used to perform traffic billing and optimization on the four-dimensional traffic portrait structure according to a preset traffic billing strategy and obtain traffic billing data.
Citation Information
Patent Citations
5G charging method and device for attribution routing scene
CN113543056A
Network traffic classification method and system
CN116545944A
Traffic identification method, device and equipment based on micro-tag system, and medium
CN116760561A
Settlement method and settlement device for Internet cross-regional traffic, and electronic equipment
CN120378237A
Roaming cellular traffic policy and charging negotiation and enforcement entity
US10645230B1