An FTTR network security evaluation method, system, device and medium

By acquiring user terminal behavior data in the FTTR network and using deep learning models and fiber optic sensing systems for real-time security assessment, the problem of insufficient adaptability to dynamic network environments in existing technologies is solved, and more efficient network threat identification and protection are achieved.

CN120915594BActive Publication Date: 2025-12-12SICHUAN TIANYI COMHEART TELECOM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511394693.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2025-12-12
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

Existing FTTR network security assessment technologies are unable to respond promptly to rapidly evolving network threats, lack adaptability to dynamic network environments, and traditional methods cannot effectively monitor and identify new attack patterns. Furthermore, relying on known vulnerability databases cannot protect against unknown threats.

Method used

By acquiring current behavior data of each user terminal in the FTTR network, using deep learning models to predict performance and traffic indicators, and combining signal indicators of the fiber optic sensing system, evaluation results are generated based on a network security evaluation model, including abnormal transmission links and nodes, to achieve real-time security evaluation.

Benefits of technology

It improves the comprehensiveness and accuracy of cybersecurity assessments, possesses flexibility and strong adaptability to network environments, and can respond promptly to emerging threats and dynamic network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915594B_ABST
    Figure CN120915594B_ABST
Patent Text Reader

Abstract

The application discloses an FTTR network security evaluation method, system, device and medium, relates to the technical field of network, and the method comprises the following steps: acquiring current behavior data of each user terminal, and determining a predicted performance index according to the current behavior data, and determining a predicted traffic index according to the current behavior data; acquiring a current performance index and a current traffic index, and determining whether an exception exists in the network according to the predicted performance index, the predicted traffic index, the current performance index and the current traffic index, if yes, acquiring an optical fiber signal index between the network nodes through an optical fiber sensing system; determining a node security index according to the current performance index and the current traffic index, and determining a link security index according to the current traffic index and the optical fiber signal index; and generating an evaluation result based on a network security evaluation model. The application has the effect of improving the accuracy of network security evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of networks, in particular to an FTTR network security evaluation method, system, device and medium. BACKGROUND

[0002] With the popularity of Internet use and the increase of smart home devices, FTTR (Fiber To The Room) network as a new network architecture gradually becomes the preferred solution for home and enterprise networks; FTTR network provides high-speed and stable network service through fiber connection to each room, meeting the high requirements of users on bandwidth and connection stability. FTTRB is the enterprise version of FTTR (fiber to the room) technology, designed for small and medium-sized enterprises, with the characteristics of full-fiber coverage, ultra-gigabit bandwidth and intelligent operation and maintenance. Full-fiber coverage means using PON (passive optical network) technology, replacing traditional copper cable with fiber directly to each room or area of the enterprise; ultra-gigabit bandwidth means supporting Wi-Fi 6 / 7, providing end-to-end 2.5Gbps symmetric bandwidth to meet high concurrency requirements; intelligent operation and maintenance means realizing centralized management and control through a cloud management platform, supporting remote fault diagnosis and network optimization. In the process of using FTTR network by users, network security evaluation becomes particularly important. While enjoying high-quality network services, users are facing various network security threats, including malicious software attacks, data theft and network intrusion, etc.

[0003] Current security evaluation technology usually relies on regular vulnerability scanning and manual audit, aiming to identify and fix security vulnerabilities in the network. Although this method can to some extent discover potential risks, it often cannot respond to rapidly developing network threats in a timely manner. In addition, existing technologies often lack the ability to adapt to dynamic network environments. In FTTR networks, the variety of user devices and the constant changes in user behavior make it difficult for traditional security evaluation methods to effectively monitor and identify new attack patterns. In addition, vulnerability scanning tools rely on known vulnerability databases and cannot effectively protect against unknown threats, limiting the comprehensiveness and accuracy of security evaluation. Therefore, although existing technologies can improve network security protection capabilities to some extent, they still lack in dealing with emerging threats and dynamic network environments, and there is an urgent need for more advanced and flexible security evaluation solutions. SUMMARY

[0004] In order to improve the accuracy of network security evaluation, the application provides an FTTR network security evaluation method, system, device and medium.

[0005] In a first aspect, the application provides an FTTR network security evaluation method, which adopts the following technical solution:

[0006] A method for evaluating the security of an FTTR network, comprising:

[0007] Obtaining current behavior data of each user terminal in the FTTR network, and determining a predicted performance index of each network node according to the current behavior data, and determining a predicted traffic index of each network node according to the current behavior data, wherein the network nodes at least include a master optical modem and a slave optical modem;

[0008] Obtaining current performance indexes and current traffic indexes of the network nodes, and determining whether there is an anomaly in the FTTR network according to the predicted performance indexes, the predicted traffic indexes, the current performance indexes and the current traffic indexes, and if so, obtaining optical fiber signal indexes between the network nodes through an optical fiber sensing system;

[0009] Determining a node security index according to the current performance indexes and the current traffic indexes, and determining a link security index of each data transmission link in the FTTR network according to the current traffic indexes and the optical fiber signal indexes;

[0010] Generating an evaluation result based on a network security evaluation model and according to the link security indexes, the node security indexes and the current behavior data, wherein the evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link.

[0011] By adopting the technical scheme, the current behavior data of each user terminal in the FTTR network is acquired first, and the predicted performance indicators of each network node are determined according to the current behavior data, and the predicted traffic indicators of each network node are determined according to the current behavior data, wherein each network node at least includes a master optical modem and a slave optical modem, then the current performance indicators and the current traffic indicators of each network node are acquired, and whether the FTTR network is abnormal is determined according to the predicted performance indicators, the predicted traffic indicators, the current performance indicators and the current traffic indicators, if yes, the fiber signal indicators between each network node are acquired through the fiber sensing system, then the node security indicators are determined according to the current performance indicators and the current traffic indicators, and the link security indicators of each data transmission link in the FTTR network are determined according to the current traffic indicators and the fiber signal indicators, finally, the evaluation result is generated based on the network security evaluation model and according to the link security indicators, the node security indicators and the current behavior data, wherein the evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link; in the above method, when a user surfs the Internet or connects to a network, the FTTR network is safely evaluated from the network nodes and the transmission links in combination with the current performance indicators, the current traffic indicators and the fiber signal indicators, without relying on a vulnerability scanning tool, the comprehensiveness and accuracy of network security evaluation are improved, and the data can be collected in real time, so that the method has strong network environment adaptability and higher flexibility in the face of emerging threats and dynamic network environments.

[0012] Optionally, the step of determining the predicted performance indicators of each network node according to the behavior data comprises:

[0013] The first model training data is acquired, and the model training data is divided into a first training set and a first test set according to a preset ratio, wherein the first model training data includes historical behavior data and historical performance indicators of the network nodes;

[0014] The hyperparameters of a first deep learning model pre-constructed are set according to a random network search algorithm or a grid search algorithm, and a first evaluation indicator is determined;

[0015] The first deep learning model is trained according to the first training set, and a trained first deep learning model is obtained;

[0016] The trained first deep learning model is tested according to the first test set, and whether the corresponding error is within a preset range is judged according to the first evaluation indicator, if yes, the trained first deep learning model is taken as a performance indicator prediction model;

[0017] The predicted performance indicators of each network node are generated based on the performance indicator prediction model and according to the current behavior data.

[0018] By adopting the technical scheme, in order to determine the prediction performance indicators of the network nodes, first model training data is acquired, and the model training data is divided into a first training set and a first test set according to a preset ratio, wherein the first model training data includes historical behavior data and historical performance indicators of the network nodes, then the hyperparameters of a first deep learning model constructed in advance are set according to a random network search algorithm or a grid search algorithm, and a first evaluation indicator is determined, then the first deep learning model is trained according to the first training set, to obtain a trained first deep learning model, then the trained first deep learning model is tested according to the first test set, and whether the corresponding error is within a preset range is judged according to the first evaluation indicator, if yes, the trained first deep learning model is taken as a performance indicator prediction model, and finally, based on the performance indicator prediction model and according to current behavior data, prediction performance indicators of the network nodes are generated.

[0019] Optionally, the step of determining the prediction traffic indicators of the network nodes according to the behavior data comprises:

[0020] Second model training data is acquired, and the model training data is divided into a second training set and a second test set according to the preset ratio, wherein the second model training data includes the historical behavior data and historical performance indicators of the network nodes;

[0021] The hyperparameters of a second deep learning model constructed in advance are set according to a random network search algorithm or a grid search algorithm, and a second evaluation indicator is determined;

[0022] The second deep learning model is trained according to the second training set, to obtain a trained second deep learning model;

[0023] The trained second deep learning model is tested according to the second test set, and whether the corresponding error is within the preset range is judged according to the second evaluation indicator, if yes, the trained second deep learning model is taken as a traffic indicator prediction model;

[0024] Based on the traffic indicator prediction model and according to the current behavior data, prediction traffic indicators of the network nodes are generated.

[0025] By adopting the technical scheme, in order to determine the predicted traffic indicators of the network nodes, the second model training data is obtained, and the model training data is divided into a second training set and a second test set according to a preset ratio, wherein the second model training data includes historical behavior data and historical performance indicators of the network nodes, then the hyperparameters of the second deep learning model are set according to a random network search algorithm or a grid search algorithm, and a second evaluation indicator is determined, then the second deep learning model is trained according to the second training set, and a trained second deep learning model is obtained, then the trained second deep learning model is tested according to the second test set, and whether the corresponding error is within a preset range is determined according to the second evaluation indicator, if the error is within the preset range, the trained second deep learning model is taken as a traffic indicator prediction model, and finally, the traffic indicator prediction model is used to generate the predicted traffic indicators of the network nodes according to the current behavior data.

[0026] Optionally, the step of determining whether the FTTR network is abnormal according to the predicted performance indicators, the predicted traffic indicators, the current performance indicators and the current traffic indicators comprises:

[0027] determining a performance indicator deviation value of each network node according to the predicted performance indicators and the current performance indicators, and determining a traffic indicator deviation value of each network node according to the predicted traffic indicators and the current traffic indicators;

[0028] determining a performance indicator deviation average value, a performance indicator deviation maximum value and a performance indicator deviation minimum value according to the performance indicator deviation value, and determining a traffic indicator deviation average value, a traffic indicator deviation maximum value and a traffic indicator deviation minimum value according to the traffic indicator deviation value;

[0029] determining whether the performance indicator deviation average value, the performance indicator deviation maximum value and the performance indicator deviation minimum value satisfy a first preset condition, and determining whether the traffic indicator deviation average value, the traffic indicator deviation maximum value and the traffic indicator deviation minimum value satisfy a second preset condition, if all satisfy, it indicates that the FTTR network is normal, otherwise, it indicates that the FTTR network is abnormal.

[0030] By adopting the technical scheme, in order to determine whether the FTTR network is abnormal, the performance index deviation value of each network node is determined according to the predicted performance index and the current performance index, and the traffic index deviation value of each network node is determined according to the predicted traffic index and the current traffic index, then the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value are determined according to the performance index deviation value, and the traffic index deviation average value, the traffic index deviation maximum value and the traffic index deviation minimum value are determined according to the traffic index deviation value, then whether the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value meet the first preset condition is judged, and whether the traffic index deviation average value, the traffic index deviation maximum value and the traffic index deviation minimum value meet the second preset condition is judged, if all meet, it indicates that the FTTR network is normal, otherwise, it indicates that the FTTR network is abnormal.

[0031] Optionally, the step of determining the node security index according to the current performance index and the current traffic index comprises:

[0032] generating a performance index parameter set according to the current performance index, and generating a traffic index parameter set according to the current traffic index;

[0033] evaluating the mutual exclusion relationship of each parameter in the performance index parameter set according to the Bayesian conditional probability to determine a first mutual exclusion parameter group, and evaluating the mutual exclusion relationship of each parameter in the traffic index parameter set according to the Bayesian conditional probability to determine a second mutual exclusion parameter group;

[0034] linearly combining the first mutual exclusion parameter group to obtain a corresponding first combined parameter, and linearly combining the second mutual exclusion parameter group to obtain a corresponding second combined parameter;

[0035] generating the node security index based on the performance index parameter set and the traffic index parameter set, and according to the first combined parameter and the second combined parameter.

[0036] By adopting the technical scheme, in order to determine the node security index, a performance index parameter set is generated according to the current performance index, and a traffic index parameter set is generated according to the current traffic index, then the mutual exclusion relationship of each parameter in the performance index parameter set is evaluated according to the Bayesian conditional probability to determine a first mutual exclusion parameter group, and the mutual exclusion relationship of each parameter in the traffic index parameter set is evaluated according to the Bayesian conditional probability to determine a second mutual exclusion parameter group, then the first mutual exclusion parameter group is linearly combined to obtain a corresponding first combined parameter, and the second mutual exclusion parameter group is linearly combined to obtain a corresponding second combined parameter, and finally the node security index is generated based on the performance index parameter set and the traffic index parameter set, and according to the first combined parameter and the second combined parameter.

[0037] Optionally, the step of determining the link security indicators of each data transmission link in the FTTR network according to the current traffic indicators and the fiber signal indicators comprises:

[0038] generating a link security set according to the current traffic indicators and the fiber signal indicators;

[0039] evaluating the correlation of each parameter in the performance indicator parameter set according to the Bayesian conditional probability, and determining a correlation parameter group;

[0040] linearly combining the correlation parameter group to obtain a corresponding third combined parameter;

[0041] generating a link security indicator based on the link security set and according to the third combined parameter.

[0042] By adopting the above technical solution, in order to determine the link security indicators of each data transmission link in the FTTR network, first, a link security set is generated according to the current traffic indicators and the fiber signal indicators, then the correlation of each parameter in the performance indicator parameter set is evaluated according to the Bayesian conditional probability, and a correlation parameter group is determined, then the correlation parameter group is linearly combined to obtain a corresponding third combined parameter, and finally a link security indicator is generated based on the link security set and according to the third combined parameter.

[0043] Optionally, the network security evaluation model comprises an input layer, a first feature extraction layer, a second feature extraction layer, a third feature extraction layer, a splicing layer, and an output layer, and the step of generating an evaluation result based on the network security evaluation model and according to the link security indicators, the node security indicators, and the current behavior data comprises:

[0044] generating a first data feature vector through the input layer and according to the link security indicators;

[0045] generating a second data feature vector through the input layer and according to the node security indicators;

[0046] generating a third data feature vector through the input layer and according to the current behavior data;

[0047] generating a fourth data feature vector through the first feature extraction layer and according to the first data feature vector;

[0048] generating a fifth data feature vector through the second feature extraction layer and according to the second data feature vector;

[0049] generating a sixth data feature vector through the third feature extraction layer and according to the third data feature vector;

[0050] The fourth data feature vector, the fifth data feature vector and the sixth data feature vector are spliced by the splicing layer to obtain a seventh data feature vector.

[0051] An output matrix is generated by the output layer according to the seventh data feature vector, wherein the output matrix includes a first element and a second element, the first element is used to represent the abnormal transmission link, and the second element is used to represent the abnormal node.

[0052] In order to generate an evaluation result, a first data feature vector is generated by the input layer according to a link security index, a second data feature vector is generated by the input layer according to a node security index, and a third data feature vector is generated by the input layer according to current behavior data, then a fourth data feature vector is generated by the first feature extraction layer according to the first data feature vector, a fifth data feature vector is generated by the second feature extraction layer according to the second data feature vector, and a sixth data feature vector is generated by the third feature extraction layer according to the third data feature vector, then the fourth data feature vector, the fifth data feature vector and the sixth data feature vector are spliced by the splicing layer to obtain a seventh data feature vector, and finally an output matrix is generated by the output layer according to the seventh data feature vector, wherein the output matrix includes a first element and a second element, the first element is used to represent an abnormal transmission link, and the second element is used to represent an abnormal node.

[0053] In a second aspect, the application also provides an FTTR network security evaluation system, which adopts the following technical solution:

[0054] An FTTR network security evaluation system includes:

[0055] An index prediction module is configured to obtain current behavior data of each user terminal in an FTTR network, determine predicted performance indexes of each network node according to the current behavior data, and determine predicted traffic indexes of each network node according to the current behavior data, wherein the each network node at least includes a master optical modem and a slave optical modem;

[0056] A network anomaly judgment module is configured to obtain current performance indexes and current traffic indexes of the each network node, determine whether the FTTR network is abnormal according to the predicted performance indexes, the predicted traffic indexes, the current performance indexes and the current traffic indexes, and if so, obtain optical fiber signal indexes between the each network node by an optical fiber sensing system.

[0057] The security index determination module is configured to determine a node security index according to the current performance index and the current traffic index, and determine a link security index of each data transmission link in the FTTR network according to the current traffic index and the fiber signal index;

[0058] The evaluation result generation module is configured to generate an evaluation result based on a network security evaluation model and according to the link security index, the node security index and the current behavior data, wherein the evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link.

[0059] In a third aspect, the present application further provides a computer device, which adopts the technical scheme as follows:

[0060] The computer device comprises a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor implements the method in the first aspect when executing the computer program.

[0061] In a fourth aspect, the present application further provides a computer readable storage medium, which adopts the technical scheme as follows:

[0062] The computer readable storage medium stores a computer program capable of being loaded and executed by the processor to implement the method in the first aspect.

[0063] In summary, the present application at least includes the following beneficial technical effects: first, the current behavior data of each user terminal in the FTTR network is obtained, and the predicted performance indicators of each network node are determined according to the current behavior data, and the predicted traffic indicators of each network node are determined according to the current behavior data, wherein each network node at least includes a master optical modem and a slave optical modem; then, the current performance indicators and the current traffic indicators of each network node are obtained, and it is determined whether the FTTR network is abnormal according to the predicted performance indicators, the predicted traffic indicators, the current performance indicators and the current traffic indicators; if so, the optical fiber signal indicators between each network node are obtained through the optical fiber sensing system; then, the node security indicators are determined according to the current performance indicators and the current traffic indicators, and the link security indicators of each data transmission link in the FTTR network are determined according to the current traffic indicators and the optical fiber signal indicators; finally, based on the network security evaluation model, the evaluation results are generated according to the link security indicators, the node security indicators and the current behavior data, wherein the evaluation results include abnormal transmission links and abnormal nodes in the abnormal transmission links; in the above method, when the user is surfing the Internet or networking, the FTTR network is evaluated from the network nodes and the transmission links in combination with the current performance indicators, the current traffic indicators and the optical fiber signal indicators, without relying on a vulnerability scanning tool, thereby improving the comprehensiveness and accuracy of network security evaluation, and the data can be collected in real time, so that the method of the present application has strong network environment adaptability and stronger flexibility in the face of emerging threats and dynamic network environment. BRIEF DESCRIPTION OF DRAWINGS

[0064] Figure 1 is a whole flow schematic diagram of an embodiment of the present application.

[0065] Figure 2 is a structure schematic diagram of a system of the present application.

[0066] Figure 3 is a structure block diagram of a computer device of the present application. DETAILED DESCRIPTION

[0067] In order to make the purpose, technical scheme and advantages of the present application more clear, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application. Figures 1-3

[0068] Embodiments of the present application disclose a FTTR network security evaluation method.

[0069] With reference to Figure 1 , a FTTR network security evaluation method comprises:

[0070] ​Step S11, obtain the current behavior data of each user terminal in the FTTR network, and determine the predicted performance indicators of each network node according to the current behavior data, and determine the predicted traffic indicators of each network node according to the current behavior data.

[0071] Each network node includes at least a master optical cat and a slave optical cat.

[0072] It should be noted that the current behavior data refers to the usage mode and behavior of the user on the FTTR network, for example, the user's online time, the user's current access application (such as video streaming, social media, online games, etc.), data traffic (the amount of data currently uploaded and downloaded by the user); the predicted performance indicators are the predicted current performance indicators of each network node, for example, delay (i.e. the transmission time of data packets from source to target), bandwidth (the amount of data that each user or node can transmit within a certain period of time), packet loss rate, jitter, CPU utilization, memory utilization, error rate; the predicted traffic indicators are the predicted traffic indicators of each network node, for example, traffic, packet size, connection duration, traffic load balancing, traffic direction.

[0073] It should be further noted that each network node can also include an optical splitter, a network switch, a wireless router, etc.

[0074] Step S12, obtain the current performance indicators and current traffic indicators of each network node, and determine whether there is an anomaly in the FTTR network according to the predicted performance indicators, the predicted traffic indicators, the current performance indicators and the current traffic indicators, if so, obtain the optical fiber signal indicators between each network node through the optical fiber sensing system.

[0075] It can be understood that the current performance indicators and the current traffic indicators can be obtained through network monitoring tools, traffic analysis software, etc. The optical fiber sensing system is a system that uses optical fiber technology to monitor and measure various physical quantities (such as temperature, pressure, displacement, etc.). This system combines sensors and optical fibers to achieve high precision and high sensitivity detection. Optical fiber sensors usually use principles such as light interference and scattering to extract the required measurement information by analyzing changes in optical signals. In the optical fiber sensing system, the optical fiber signal indicators refer to various parameters and data obtained through optical fiber transmission. These indicators can help determine the state of the optical fiber and detect the monitored physical quantities. Common optical fiber signal indicators include light intensity, phase, wavelength, and time delay.

[0076] Step S13, determine the node security indicators according to the current performance indicators and the current traffic indicators, and determine the link security indicators of each data transmission link in the FTTR network according to the current traffic indicators and the optical fiber signal indicators.

[0077] In step S14, the evaluation result is generated based on the network security evaluation model and according to the link security indicators, the node security indicators and the current behavior data.

[0078] The evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link.

[0079] It should be noted that the evaluation result can also include an abnormal terminal and abnormal traffic.

[0080] In the above embodiment, the current behavior data of each user terminal in the FTTR network is first obtained, and the predicted performance indicators of each network node are determined according to the current behavior data, and the predicted traffic indicators of each network node are determined according to the current behavior data, wherein each network node at least includes a master optical modem and a slave optical modem. Then, the current performance indicators and the current traffic indicators of each network node are obtained, and whether the FTTR network is abnormal is determined according to the predicted performance indicators, the predicted traffic indicators, the current performance indicators and the current traffic indicators. If yes, the optical fiber signal indicators between each network node are obtained through the optical fiber sensing system, then the node security indicators are determined according to the current performance indicators and the current traffic indicators, and the link security indicators of each data transmission link in the FTTR network are determined according to the current traffic indicators and the optical fiber signal indicators. Finally, the evaluation result is generated based on the network security evaluation model and according to the link security indicators, the node security indicators and the current behavior data, wherein the evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link. In the above method, when the user is surfing the Internet or networking, the FTTR network is evaluated from the network nodes and the transmission links in combination with the current performance indicators, the current traffic indicators and the optical fiber signal indicators, without relying on a vulnerability scanning tool, thereby improving the comprehensiveness and accuracy of network security evaluation, and the above data can be collected in real time, so that the method has strong network environment adaptability and strong flexibility in the face of emerging threats and dynamic network environment.

[0081] As a further embodiment of the method, the step of determining the predicted performance indicators of each network node according to the behavior data comprises:

[0082] In step S21, the first model training data is obtained, and the model training data is divided into a first training set and a first test set according to a preset ratio.

[0083] The first model training data includes historical behavior data and historical performance indicators of each network node.

[0084] In step S22, the hyperparameters of the first deep learning model pre-constructed are set according to a random network search algorithm or a grid search algorithm, and a first evaluation indicator is determined.

[0085] It should be noted that the random network search algorithm is an optimization algorithm, which is usually used to find the best solution in a high-dimensional search space. In machine learning, RNS is often used for hyperparameter optimization, which experiments by randomly selecting parameter combinations and evaluates the results according to the model performance to guide the subsequent search. Grid search is a systematic and comprehensive hyperparameter optimization method that generates a grid on each predefined value of the hyperparameter and traverses all possible parameter combinations to find the best model. In addition, the first evaluation index of the present application is the root mean square error RMSE and the determination coefficient R 2 .

[0086] Step S23, training the first deep learning model according to the first training set to obtain the trained first deep learning model.

[0087] Step S24, testing the trained first deep learning model according to the first test set, and determining whether the corresponding error is within the preset range according to the first evaluation index. If yes, the trained first deep learning model is used as the performance index prediction model.

[0088] Step S25, generating the predicted performance index of each network node based on the performance index prediction model and according to the current behavior data.

[0089] In the above embodiment, in order to determine the predicted performance index of each network node, the first model training data is obtained, and the model training data is divided into a first training set and a first test set according to a preset ratio, wherein the first model training data includes historical behavior data and historical performance index of each network node. Then, the hyperparameters of the first deep learning model are set according to the random network search algorithm or the grid search algorithm, and the first evaluation index is determined. Then, the first deep learning model is trained according to the first training set to obtain the trained first deep learning model. Then, the trained first deep learning model is tested according to the first test set, and whether the corresponding error is within the preset range is determined according to the first evaluation index. If it is within the preset range, the trained first deep learning model is used as the performance index prediction model. Finally, the predicted performance index of each network node is generated based on the performance index prediction model and according to the current behavior data.

[0090] As a further embodiment of the method, the step of determining the predicted traffic index of each network node according to the behavior data comprises:

[0091] Step S31, obtaining second model training data and dividing the model training data into a second training set and a second test set according to a preset ratio.

[0092] The second model training data includes historical behavior data and historical performance index of each network node.

[0093] In step S32, the hyperparameters of the second pre-constructed deep learning model are set according to a random network search algorithm or a grid search algorithm, and a second evaluation index is determined.

[0094] It should be noted that the second evaluation index of the present application is the root mean square error RMSE and the coefficient of determination R 2 .

[0095] In step S33, the second deep learning model is trained according to the second training set, and a trained second deep learning model is obtained.

[0096] In step S34, the trained second deep learning model is tested according to the second test set, and it is determined whether the corresponding error is within a preset range according to the second evaluation index. If yes, the trained second deep learning model is used as a traffic index prediction model.

[0097] In step S35, the traffic index prediction model is used to generate predicted traffic indexes of each network node based on current behavior data.

[0098] In the above embodiment, in order to determine the predicted traffic index of each network node, the second model training data is obtained, and the model training data is divided into a second training set and a second test set according to a preset proportion, wherein the second model training data includes historical behavior data and historical performance indexes of each network node. Then, the hyperparameters of the second pre-constructed deep learning model are set according to a random network search algorithm or a grid search algorithm, and a second evaluation index is determined. Then, the second deep learning model is trained according to the second training set, and a trained second deep learning model is obtained. Then, the trained second deep learning model is tested according to the second test set, and it is determined whether the corresponding error is within a preset range according to the second evaluation index. If yes, the trained second deep learning model is used as a traffic index prediction model. Finally, the traffic index prediction model is used to generate predicted traffic indexes of each network node based on current behavior data.

[0099] As a further embodiment of the method, the step of determining whether the FTTR network is abnormal according to the predicted performance index, the predicted traffic index, the current performance index and the current traffic index comprises:

[0100] In step S41, the performance index deviation value of each network node is determined according to the predicted performance index and the current performance index, and the traffic index deviation value of each network node is determined according to the predicted traffic index and the current traffic index.

[0101] Step S42, determine the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value according to the performance index deviation values, and determine the flow index deviation average value, the flow index deviation maximum value and the flow index deviation minimum value according to the flow index deviation values.

[0102] Step S43, judge whether the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value meet the first preset condition, and judge whether the flow index deviation average value, the flow index deviation maximum value and the flow index deviation minimum value meet the second preset condition, if all meet, it indicates that the FTTR network is normal, otherwise, it indicates that the FTTR network is abnormal.

[0103] It should be noted that in step S43, when the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value meet the first preset condition, and the flow index deviation average value, the flow index deviation maximum value and the flow index deviation minimum value meet the second preset condition, it indicates that the FTTR network is normal, if there is a case that does not meet, it indicates that the FTTR network is abnormal.

[0104] In the above embodiment, in order to determine whether the FTTR network is abnormal, the performance index deviation values of each network node are determined according to the predicted performance index and the current performance index, and the flow index deviation values of each network node are determined according to the predicted flow index and the current flow index, then the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value are determined according to the performance index deviation values, and the flow index deviation average value, the flow index deviation maximum value and the flow index deviation minimum value are determined according to the flow index deviation values, then it is judged whether the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value meet the first preset condition, and whether the flow index deviation average value, the flow index deviation maximum value and the flow index deviation minimum value meet the second preset condition, if all meet, it indicates that the FTTR network is normal, otherwise, it indicates that the FTTR network is abnormal.

[0105] As a further embodiment of the method, the step of determining the node security index according to the current performance index and the current flow index comprises:

[0106] Step S51, generate a performance index parameter set according to the current performance index, and generate a flow index parameter set according to the current flow index.

[0107] Step S52, evaluate the mutual exclusion relationship of each parameter in the performance index parameter set according to the Bayesian conditional probability, determine a first mutual exclusion parameter group, and evaluate the mutual exclusion relationship of each parameter in the flow index parameter set according to the Bayesian conditional probability, determine a second mutual exclusion parameter group.

[0108] It should be noted that for the above step S52, the mutual exclusion relationship of any two performance indicator parameters in the performance indicator parameter set or the flow indicator parameter set is evaluated by the Bayesian conditional probability P(B|A)=(P(B|A)*P(A)) / (P(B)). Specifically, for any two performance indicators X and Y in the performance indicator parameter set or the flow indicator parameter set, the prior probabilities P(X) and P(Y) of the two parameters are calculated according to the historical data of the performance indicators X and Y, and the conditional probability P(X|Y) is calculated, wherein the prior probabilities P(X) and P(Y) are obtained by the respective frequencies of X and Y in the historical data, and the conditional probability P(X|Y) is obtained by the frequencies of X and Y in the historical data. Then, the conditional probability P(X|Y) is calculated according to the calculation formula of the prior probability, the joint probability and the Bayesian conditional probability, and then the mutual exclusion degree between the performance indicators X and Y is determined according to the size relationship between P(X|Y) and P(X). The difference between P(X|Y) and P(X) can be compared with the mutual exclusion threshold by setting a mutual exclusion threshold, and if the difference between P(X|Y) and P(X) is greater than the mutual exclusion threshold, it is determined that X and Y are mutually exclusive.

[0109] Step S53, linearly merging the first mutual exclusion parameter group to obtain the corresponding first merged parameter, and linearly merging the second mutual exclusion parameter group to obtain the corresponding second merged parameter.

[0110] It can be understood that the merging can be performed by weighted sum, multi-objective optimization, single indicator, etc.

[0111] Step S54, generating a node security indicator based on the performance indicator parameter set and the flow indicator parameter set, and according to the first merged parameter and the second merged parameter.

[0112] In the above embodiment, in order to determine the node security indicator, the performance indicator parameter set is generated according to the current performance indicator, and the flow indicator parameter set is generated according to the current flow indicator, then the mutual exclusion relationship of each parameter in the performance indicator parameter set is evaluated according to the Bayesian conditional probability, the first mutual exclusion parameter group is determined, and the mutual exclusion relationship of each parameter in the flow indicator parameter set is evaluated according to the Bayesian conditional probability, the second mutual exclusion parameter group is determined, then the first mutual exclusion parameter group is linearly merged to obtain the corresponding first merged parameter, and the second mutual exclusion parameter group is linearly merged to obtain the corresponding second merged parameter, and finally the node security indicator is generated based on the performance indicator parameter set and the flow indicator parameter set, and according to the first merged parameter and the second merged parameter.

[0113] As a further embodiment of the method, the step of determining the link security indicator of each data transmission link in the FTTR network according to the current flow indicator and the fiber signal indicator comprises:

[0114] Step S61, generating a link security set according to the current traffic index and the fiber signal index.

[0115] Step S62, evaluating the correlation between parameters in the performance index parameter set according to the Bayesian conditional probability, and determining a correlation parameter group.

[0116] It should be noted that the Bayesian conditional probability can evaluate the degree of mutual exclusion between two parameters, in other words, the Bayesian conditional probability can also be used to evaluate the degree of correlation between two parameters, specifically, a correlation threshold can be set, and the difference between P(X|Y) and P(X) is compared with the correlation threshold, if the difference between P(X|Y) and P(X) is less than the correlation threshold, it is determined that X and Y are correlated.

[0117] Step S63, linearly merging the correlation parameter group to obtain a corresponding third merged parameter.

[0118] Step S64, generating a link security index based on the link security set and according to the third merged parameter.

[0119] In the above embodiment, in order to determine the link security index of each data transmission link in the FTTR network, first, a link security set is generated according to the current traffic index and the fiber signal index, then the correlation between parameters in the performance index parameter set is evaluated according to the Bayesian conditional probability, and a correlation parameter group is determined, then the correlation parameter group is linearly merged to obtain a corresponding third merged parameter, and finally, a link security index is generated based on the link security set and according to the third merged parameter.

[0120] As a further embodiment of the method, the network security evaluation model includes an input layer, a first feature extraction layer, a second feature extraction layer, a third feature extraction layer, a splicing layer, and an output layer, and the step of generating an evaluation result based on the network security evaluation model and according to the link security index, the node security index, and the current behavior data includes:

[0121] Step S71, generating a first data feature vector through the input layer and according to the link security index.

[0122] Step S72, generating a second data feature vector through the input layer and according to the node security index.

[0123] Step S73, generating a third data feature vector through the input layer and according to the current behavior data.

[0124] It can be understood that the input layer is the first layer of an artificial neural network (ANN) and a deep learning model, which is responsible for receiving external input data and passing it to other layers of the network.

[0125] In step S74, a fourth data feature vector is generated from the first data feature vector by the first feature extraction layer.

[0126] In step S75, a fifth data feature vector is generated from the second data feature vector by the second feature extraction layer.

[0127] In step S76, a sixth data feature vector is generated from the third data feature tensor by the third feature extraction layer.

[0128] In step S77, the fourth data feature vector, the fifth data feature vector, and the sixth data feature vector are spliced by the splicing layer to obtain a seventh data feature vector.

[0129] It can be understood that the main function of the splicing layer is to connect multiple tensors or vectors along a certain dimension, and the splicing layer is usually used to process multi-modal data or fuse information between different parts of the model to improve the performance of the model.

[0130] In step S78, an output matrix is generated from the seventh data feature vector by the output layer.

[0131] The output matrix includes a first element and a second element, the first element is used to represent an abnormal transmission link, and the second element is used to represent an abnormal node.

[0132] It can be understood that the output layer is the terminal part of the neural network, which receives the data of the previous layer and converts these data into a specific output format according to the task requirements of the network, and is usually used for decision-making of the model.

[0133] In the above embodiment, in order to generate the evaluation result, the first data feature vector is generated from the link security index by the input layer, the second data feature vector is generated from the node security index by the input layer, and the third data feature vector is generated from the current behavior data by the input layer, then the fourth data feature vector is generated from the first data feature vector by the first feature extraction layer, the fifth data feature vector is generated from the second data feature vector by the second feature extraction layer, and the sixth data feature vector is generated from the third data feature tensor by the third feature extraction layer, then the fourth data feature vector, the fifth data feature vector, and the sixth data feature vector are spliced by the splicing layer to obtain the seventh data feature vector, and finally the output matrix is generated from the seventh data feature vector by the output layer, wherein the output matrix includes a first element and a second element, the first element is used to represent an abnormal transmission link, and the second element is used to represent an abnormal node.

[0134] The embodiment of the application also discloses an FTTR network security evaluation system.

[0135] Reference Figure 2 A FTTR network security evaluation system comprises:

[0136] An index prediction module is configured to acquire current behavior data of each user terminal in the FTTR network, and determine predicted performance indexes of each network node according to the current behavior data, and determine predicted traffic indexes of each network node according to the current behavior data, wherein each network node at least comprises a master optical modem and a slave optical modem.

[0137] A network anomaly judgment module is configured to acquire current performance indexes and current traffic indexes of each network node, and determine whether there is an anomaly in the FTTR network according to the predicted performance indexes, the predicted traffic indexes, the current performance indexes and the current traffic indexes, and if yes, acquire optical fiber signal indexes between each network node through an optical fiber sensing system.

[0138] A security index determination module is configured to determine node security indexes according to the current performance indexes and the current traffic indexes, and determine link security indexes of each data transmission link in the FTTR network according to the current traffic indexes and the optical fiber signal indexes.

[0139] An evaluation result generation module is configured to generate an evaluation result based on a network security evaluation model, and according to the link security indexes, the node security indexes and the current behavior data, wherein the evaluation result comprises an abnormal transmission link and an abnormal node in the abnormal transmission link.

[0140] The FTTR network security evaluation system can implement any one of the FTTR network security evaluation methods, and the specific working process of the FTTR network security evaluation system can refer to the corresponding process in the FTTR network security evaluation method.

[0141] The embodiment of the application further discloses a computer device.

[0142] Reference Figure 3 A computer device comprises a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor implements any one of the FTTR network security evaluation methods when executing the computer program.

[0143] The embodiment of the application further discloses a computer readable storage medium.

[0144] A computer readable storage medium stores a computer program capable of being loaded by a processor and executing any one of the FTTR network security evaluation methods.

[0145] Wherein, the computer readable storage medium can be any tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device; program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to wireless, wire line, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0146] The above are all preferred embodiments of the present application, and are not intended to limit the protection scope of the present application. Any feature disclosed in the specification (including the abstract and drawings) can be replaced by other equivalent or similar features, unless specifically stated otherwise. That is, each feature is only an example of a series of equivalent or similar features, unless specifically stated otherwise.

Claims

1. A method for FTTR network security evaluation, characterized in that, The method comprises the following steps: obtaining current behavior data of each user terminal in the FTTR network, and determining a predicted performance index of each network node according to the current behavior data, and determining a predicted traffic index of each network node according to the current behavior data, wherein the each network node at least comprises a master optical modem and a slave optical modem; obtaining current performance index and current traffic index of the each network node, and determining whether there is an exception in the FTTR network according to the predicted performance index, the predicted traffic index, the current performance index and the current traffic index, if yes, obtaining an optical fiber signal index between the each network node through an optical fiber sensing system; determining a node security index according to the current performance index and the current traffic index, and determining a link security index of each data transmission link in the FTTR network according to the current traffic index and the optical fiber signal index; generating an evaluation result based on a network security evaluation model and according to the link security index, the node security index and the current behavior data, wherein the evaluation result comprises an abnormal transmission link and an abnormal node in the abnormal transmission link; the step of determining the node security index according to the current performance index and the current traffic index comprises: generating a performance index parameter set according to the current performance index, and generating a traffic index parameter set according to the current traffic index; evaluating mutual exclusion relationship of each parameter in the performance index parameter set according to Bayesian conditional probability to determine a first mutual exclusion parameter group, and evaluating mutual exclusion relationship of each parameter in the traffic index parameter set according to Bayesian conditional probability to determine a second mutual exclusion parameter group; linearly combining the first mutual exclusion parameter group to obtain a corresponding first combined parameter, and linearly combining the second mutual exclusion parameter group to obtain a corresponding second combined parameter; generating a node security index based on the performance index parameter set and the traffic index parameter set, and according to the first combined parameter and the second combined parameter; the step of determining the link security index of each data transmission link in the FTTR network according to the current traffic index and the optical fiber signal index comprises: generating a link security set according to the current traffic index and the optical fiber signal index; determining a correlation parameter group according to Bayesian conditional probability to evaluate correlation relationship of each parameter in the performance index parameter set; linearly combining the correlation parameter group to obtain a corresponding third combined parameter; generating a link security index based on the link security set and according to the third combined parameter.

2. The FTTR network security evaluation method of claim 1, wherein, the step of determining the predicted performance index of each network node according to the behavior data comprises: obtaining first model training data, and dividing the model training data into a first training set and a first test set according to a preset proportion, wherein the first model training data comprises historical behavior data and historical performance index of the each network node; setting hyperparameters of a first deep learning model constructed in advance according to a random network search algorithm or a grid search algorithm, and determining a first evaluation index; training the first deep learning model according to the first training set, to obtain a trained first deep learning model; testing the trained first deep learning model according to the first test set, and determining whether the corresponding error is within a preset range according to the first evaluation index, if yes, taking the trained first deep learning model as a performance index prediction model; generating the predicted performance index of each network node based on the performance index prediction model and according to the current behavior data.

3. The FTTR network security evaluation method of claim 2, wherein, The step of determining the predicted traffic index of each network node according to the behavior data comprises: obtaining second model training data, and dividing the model training data into a second training set and a second test set according to the preset proportion, wherein the second model training data comprises the historical behavior data and historical performance index of each network node; setting the hyperparameters of a second deep learning model pre-constructed according to a random network search algorithm or a grid search algorithm, and determining a second evaluation index; training the second deep learning model according to the second training set, to obtain a trained second deep learning model; testing the trained second deep learning model according to the second test set, and determining whether the corresponding error is within the preset range according to the second evaluation index, if yes, taking the trained second deep learning model as a traffic index prediction model; generating the predicted traffic index of each network node based on the traffic index prediction model and according to the current behavior data.

4. The FTTR network security evaluation method of claim 1, wherein, The step of determining whether the FTTR network is abnormal according to the predicted performance index, the predicted traffic index, the current performance index and the current traffic index comprises: determining the performance index deviation value of each network node according to the predicted performance index and the current performance index, and determining the traffic index deviation value of each network node according to the predicted traffic index and the current traffic index; determining the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value according to the performance index deviation value, and determining the traffic index deviation average value, the traffic index deviation maximum value and the traffic index deviation minimum value according to the traffic index deviation value; determining whether the performance index deviation average value, the performance index deviation maximum value and the performance index deviation minimum value satisfy a first preset condition, and determining whether the traffic index deviation average value, the traffic index deviation maximum value and the traffic index deviation minimum value satisfy a second preset condition, if all yes, indicating that the FTTR network is normal, otherwise, indicating that the FTTR network is abnormal.

5. The FTTR network security evaluation method of claim 1, wherein, The network security evaluation model comprises an input layer, a first feature extraction layer, a second feature extraction layer, a third feature extraction layer, a splicing layer and an output layer, and the step of generating an evaluation result based on the network security evaluation model and according to the link security index, the node security index and the current behavior data comprises: generating a first data feature vector through the input layer and according to the link security index; generating a second data feature vector according to the node security index through the input layer; generating a third data feature vector according to the current behavior data through the input layer; generating a fourth data feature vector according to the first data feature vector through the first feature extraction layer; generating a fifth data feature vector according to the second data feature vector through the second feature extraction layer; generating a sixth data feature vector according to the third data feature vector through the third feature extraction layer; performing splicing processing on the fourth data feature vector, the fifth data feature vector and the sixth data feature vector through the splicing layer to obtain a seventh data feature vector; generating an output matrix according to the seventh data feature vector through the output layer, wherein the output matrix includes a first element and a second element, the first element is used to represent the abnormal transmission link, and the second element is used to represent the abnormal node.

6. An FTTR network security assessment system, characterized in that, comprise: an index prediction module, configured to acquire current behavior data of each user terminal in an FTTR network, and determine a predicted performance index of each network node according to the current behavior data, and determine a predicted traffic index of each network node according to the current behavior data, wherein the each network node at least includes a master optical modem and a slave optical modem; a network anomaly judgment module, configured to acquire a current performance index and a current traffic index of the each network node, and determine whether the FTTR network is abnormal according to the predicted performance index, the predicted traffic index, the current performance index and the current traffic index, and if so, acquire an optical fiber signal index between the each network node through an optical fiber sensing system; a security index determination module, configured to determine a node security index according to the current performance index and the current traffic index, and determine a link security index of each data transmission link in the FTTR network according to the current traffic index and the optical fiber signal index; an evaluation result generation module, configured to generate an evaluation result based on a network security evaluation model and according to the link security index, the node security index and the current behavior data, wherein the evaluation result includes an abnormal transmission link and an abnormal node in the abnormal transmission link; the step of determining a node security index according to the current performance index and the current traffic index comprises: generating a performance index parameter set according to the current performance index, and generating a traffic index parameter set according to the current traffic index; determining a first mutually exclusive parameter group according to the mutual exclusion relationship of each parameter in the performance index parameter set by Bayesian conditional probability, and determining a second mutually exclusive parameter group according to the mutual exclusion relationship of each parameter in the traffic index parameter set by Bayesian conditional probability; linearly combining the first mutually exclusive parameter group to obtain a corresponding first combined parameter, and linearly combining the second mutually exclusive parameter group to obtain a corresponding second combined parameter; generating a node security index based on the performance index parameter set and the traffic index parameter set, and according to the first combined parameter and the second combined parameter; The step of determining the link security indicators of each data transmission link in the FTTR network according to the current traffic indicators and the fiber signal indicators comprises: generating a link security set according to the current traffic indicators and the fiber signal indicators; evaluating the correlation of each parameter in the performance indicator parameter set according to Bayesian conditional probability, and determining a correlation parameter group; linearly combining the correlation parameter group to obtain a corresponding third combined parameter; generating a link security indicator based on the link security set and according to the third combined parameter.

7. A computer device, characterized by A computer program is stored on a memory and executable on a processor, and the processor executes the computer program to implement the method of any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, A computer program is stored on a memory and executable on a processor, and the processor executes the computer program to implement the method of any one of claims 1 to 5.

Citation Information

Patent Citations

  • Electric power optical fiber communication network risk quantitative evaluation method, system and equipment

    CN116562631A

  • Fault prediction method and system for IP network

    CN119583329A