FTTR-B multi-tenant distributed anomaly detection method and device, equipment and medium

By dividing the FTTR-B network into sub-regions and setting personalized threshold adjustment strategies, the problems of misjudgment and missed detection in traditional detection methods when there are local traffic changes are solved, and more efficient anomaly detection is achieved.

CN121000641AActive Publication Date: 2025-11-21SICHUAN TIANYI COMHEART TELECOM
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511525371.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2025-11-21
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

Traditional anomaly detection methods in FTTR-B networks fail to detect dynamic changes in local traffic due to the use of globally uniform detection standards, leading to misjudgments or missed detections.

Method used

Based on the network topology of the area to be detected and the historical traffic data of each slave gateway, the FTTR-B network is divided into multiple sub-areas. The traffic change data of each sub-area is calculated, and a personalized threshold adjustment strategy is set for each sub-area to detect anomalies.

Benefits of technology

It dynamically adapts to local traffic changes, reduces false positives and false negatives, and ensures the accuracy and flexibility of network anomaly detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000641A_ABST
    Figure CN121000641A_ABST
Patent Text Reader

Abstract

The invention discloses an FTTR-B multi-tenant distributed anomaly detection method, device and equipment and a medium, and the method comprises the steps: dividing a to-be-detected region into a plurality of sub-regions based on the network topology of the to-be-detected region and the historical flow data of each slave gateway; calculating flow change data of each sub-region; setting a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; and performing anomaly detection on the to-be-detected area based on the threshold adjustment strategy of each sub-area. According to the method, the problem of misjudgment or missing detection when the local flow is changed due to the fact that a global unified detection standard is set in a traditional anomaly detection method is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of FTTR data anomaly detection, in particular to an FTTR-B multi-tenant distributed anomaly detection method, device, equipment and medium. BACKGROUND

[0002] As the core architecture of enterprise-level full optical network, Fiber to the Room (FTTR-B) realizes gigabit bandwidth, microsecond-level latency and high reliability connection by directly connecting office areas, machine rooms and production workshops through optical fibers, supporting cloud computing, industrial Internet of Things and other high-bandwidth low-latency businesses in multi-tenant scenarios. When network traffic is abnormal, precise detection is needed to ensure business continuity.

[0003] However, traditional anomaly detection methods rely on fixed thresholds, i.e., setting a global unified detection standard, which cannot perceive the dynamic changes of local traffic. When the enterprise network is frequently accessed due to business adjustment or temporarily video conference surges, the traditional anomaly detection method will have the risk of misjudgment or missed detection. SUMMARY

[0004] The main purpose of the present application is to provide an FTTR-B multi-tenant distributed anomaly detection method, device, equipment and medium, which aims to solve the technical problem of misjudgment or missed detection when local traffic changes due to setting a global unified detection standard in traditional anomaly detection methods.

[0005] To achieve the above purpose, the present application provides an FTTR-B multi-tenant distributed anomaly detection method, comprising: dividing a to-be-detected area into a plurality of sub-areas based on the network topology of the to-be-detected area and the historical traffic data of each slave gateway; calculating the traffic change data of each sub-area; setting a threshold adjustment strategy for each sub-area based on the traffic change data of each sub-area; and performing anomaly detection on the to-be-detected area based on the threshold adjustment strategy of each sub-area.

[0006] Optionally, the traffic change data is the difference between the traffic data at the current time point and the traffic data at the previous time point.

[0007] Optionally, dividing the to-be-detected area into a plurality of sub-areas based on the network topology of the to-be-detected area and the historical traffic data of each slave gateway comprises: determining the proximity between a target slave gateway and each other slave gateway based on the network topology; calculating the traffic approximation between the target slave gateway and each other slave gateway based on the historical traffic data of each slave gateway; and dividing the to-be-detected area into a plurality of sub-areas based on the proximity and the traffic approximation.

[0008] Optionally, the dividing the to-be-detected region into a plurality of sub-regions based on the proximity and the traffic approximation degree comprises: establishing a pattern similarity matrix based on the proximity and the traffic approximation degree and according to an order from small to large of the proximity and an order from large to small of the traffic approximation degree; and dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix.

[0009] Optionally, the dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix comprises: constructing a scatter plot based on each slave gateway, wherein each node in the scatter plot represents each slave gateway; connecting different nodes in the scatter plot based on the pattern similarity matrix and determining at least one connected component; and dividing the to-be-detected region into a plurality of sub-regions based on the connected component.

[0010] Optionally, each of the sub-regions comprises a plurality of slave gateways, and the setting a threshold adjustment strategy for each of the sub-regions based on the traffic change data of each of the sub-regions comprises: determining a traffic change anomaly factor of a target sub-region in all sub-regions; and setting a threshold adjustment strategy of the target sub-region based on the traffic change anomaly factor of the target sub-region.

[0011] Optionally, the determining the traffic change anomaly factor of the target sub-region comprises: obtaining a traffic data change trend of each slave gateway in the target sub-region; and determining the traffic change anomaly factor of the target sub-region based on the similarity of the traffic data change trends of different slave gateways in the target sub-region.

[0012] In addition, to achieve the above object, the present application also provides an FTTR-B multi-tenant distributed anomaly detection device, comprising: a region division module configured to divide a to-be-detected region into a plurality of sub-regions based on a network topology of the to-be-detected region and historical traffic data of each slave gateway; a traffic change calculation module configured to calculate traffic change data of each of the sub-regions; a threshold adjustment strategy setting module configured to set a threshold adjustment strategy for each of the sub-regions based on the traffic change data of each of the sub-regions; and an anomaly detection module configured to perform anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each of the sub-regions.

[0013] The present application also provides an FTTR-B multi-tenant distributed anomaly detection device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method in any of the possible implementation manners.

[0014] The application further provides a computer-readable storage medium, comprising a computer program stored therein, wherein the computer program, when executed by a processor, implements the FTTR-B multi-tenant distributed anomaly detection method.

[0015] The FTTR-B multi-tenant distributed anomaly detection method, device, equipment and medium provided by the application first divide the to-be-detected region into a plurality of sub-regions based on the network topology of the to-be-detected region and the historical traffic data of each slave gateway; then calculate the traffic change data of each sub-region and set a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; finally, perform anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each sub-region. The application solves the technical problem that the traditional anomaly detection method sets a global unified detection standard, and when the local traffic changes, false positives or missed detection occur. BRIEF DESCRIPTION OF DRAWINGS

[0016] Figure 1 The flowchart of the FTTR-B multi-tenant distributed anomaly detection method according to an embodiment of the application is shown; Figure 2 The structural block diagram of the FTTR-B multi-tenant distributed anomaly detection device according to an embodiment of the application is shown; Figure 3 The structural schematic diagram of the FTTR-B multi-tenant distributed anomaly detection equipment according to an embodiment of the application is shown.

[0017] The implementation, functional features and advantages of the application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0018] It should be understood that the specific embodiments described herein are only used to explain the application and not to limit the application.

[0019] In the FTTR-B scenario, the traditional anomaly detection method usually sets a global unified fixed threshold based on historical data, which cannot perceive the dynamic changes of local traffic, resulting in significant errors. For example, when the temporary video conference traffic of an enterprise suddenly increases, the fixed threshold fails to adapt dynamically, triggering false interception; for another example, at the end of the month, the network traffic of the financial area of an enterprise suddenly increases due to settlement data, and abnormal attack traffic may be hidden in normal traffic, which is missed by the system.

[0020] To solve the above problems, the application provides an FTTR-B multi-tenant distributed anomaly detection method, device, equipment and medium, and the application scheme is described in detail below.

[0021] Figure 1This is a flowchart illustrating an FTTR-B multi-tenant distributed anomaly detection method according to one embodiment of this application. This FTTR-B multi-tenant distributed anomaly detection method can be applied to an FTTR-B system. The FTTR-B system may include: an FTTR-B master gateway, multiple slave gateways, and an intelligent management platform. The operator's fiber optic access is provided to the master gateway. The master gateway distributes optical signals to each slave gateway via a fiber optic splitter. Each slave gateway connects to terminal devices in each room via wired or wireless means, providing them with network services. The intelligent management platform is used to monitor and optimize network traffic to ensure efficient network operation. (Refer to...) Figure 1 The FTTR-B multi-tenant distributed anomaly detection method may include the following steps: S11. Based on the network topology of the area to be detected and the historical traffic data of each slave gateway, the area to be detected is divided into multiple sub-areas.

[0022] Each sub-region represents a region with a different working mode within the region to be detected.

[0023] It is understandable that network topology can reflect the connection relationship between terminal devices and slave gateways within the area to be detected, as well as the connection relationship between each slave gateway and the master gateway. Historical traffic data of each slave gateway can characterize the working mode of each slave gateway. In this embodiment, by using the network topology of the area to be detected and the historical traffic data of each slave gateway, slave gateways with similar working modes and geographical locations can be divided into a sub-region, and the different sub-regions obtained can characterize different working modes.

[0024] In the specific implementation process, the network topology of the area to be detected is first obtained by using the FTTR master gateway and intelligent management platform, and then the historical traffic data of each slave gateway is obtained from the intelligent management platform.

[0025] Furthermore, based on the network topology of the area to be detected and the historical traffic data of each slave gateway, the area to be detected is divided into multiple sub-areas.

[0026] In one embodiment, step S11, dividing the area to be detected into multiple sub-areas based on the network topology of the area to be detected and the historical traffic data of each slave gateway, may specifically include: S111. Determine the proximity of the target from the gateway and each of the other gateways based on the network topology; S112. Calculate the degree of traffic approximation between the target slave gateway and each other slave gateway based on the historical traffic data of each slave gateway; S113. The area to be detected is divided into multiple sub-regions based on proximity and flow similarity.

[0027] In the implementation process, firstly, the proximity between the target slave gateway and each of the other slave gateways is determined according to the network topology, and the traffic approximation between the target slave gateway and each of the other slave gateways is calculated based on the historical traffic data of each slave gateway.

[0028] Exemplarily, the embodiment can determine the shortest distance between the target slave gateway and each of the other slave gateways using the shortest path algorithm on the network topology of the to-be-detected region, and take the shortest distance as the proximity between the target slave gateway and each of the other slave gateways. The embodiment can also determine the traffic approximation between the target slave gateway and each of the other slave gateways by calculating the DTW distance between the historical traffic data of the target slave gateway and the historical traffic data of each of the other slave gateways, and take the DTW distance as the traffic approximation between the target slave gateway and each of the other slave gateways.

[0029] It should be noted that, since the greater the DTW distance, the more dissimilar the data in the two groups of sequences, and then the embodiment linearly normalizes the calculated DTW distance and linearly maps it to the range of (0, 1], and then uses 1 minus the linearly normalized DTW distance as the traffic approximation between the target slave gateway and each of the other slave gateways. Correspondingly, since the smaller the shortest distance, the more similar the two slave gateways, and then the embodiment linearly normalizes the calculated shortest distance, and then uses the linearly normalized shortest distance as the proximity between the target slave gateway and each of the other slave gateways. It can be understood that, after linear processing and subtraction from the constant 1, the greater the traffic approximation, the more similar the working modes of the two slave gateways; after linear processing, the smaller the shortest distance, the more similar the physical connection installation positions of the two slave gateways.

[0030] In other embodiments, the maximum flow algorithm can also be used to determine the proximity between the target slave gateway and each of the other slave gateways, and in other embodiments, the correlation coefficient of the historical traffic data of the target slave gateway and each of the other slave gateways can also be used to determine the traffic approximation between the target slave gateway and each of the other slave gateways. The embodiment does not make specific limitation on the calculation methods of the proximity and the traffic approximation.

[0031] Further, the to-be-detected region is divided into a plurality of sub-regions based on the proximity and the traffic approximation.

[0032] It can be understood that, if the connection positions of two slave gateways are similar and the historical traffic data are similar, it indicates that the user terminals connected by the two slave gateways perform similar work contents, and the embodiment classifies the slave gateways performing similar work contents into a sub-region.

[0033] In an embodiment, the step S113 of dividing the to-be-detected region into a plurality of sub-regions based on the proximity degree and the traffic approximation degree can specifically include: S1131, establishing a pattern similarity matrix based on the proximity degree and the traffic approximation degree, and in accordance with the order of the proximity degree from small to large and the order of the traffic approximation degree from large to small; S1132, dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix.

[0034] In a specific implementation process, first, any two slave gateways are combined to form a gateway pair, and the proximity degrees of the gateway pairs are arranged in the order from small to large to form the first column of the pattern similarity matrix. The traffic approximation degrees of the slave gateways corresponding to the first column form the second column of the pattern similarity matrix. It can be understood that if there are three slave gateways, slave gateway a, slave gateway b, and slave gateway c, the gateway pairs include the first gateway pair (slave gateway a and slave gateway b), the second gateway pair (slave gateway a and slave gateway c), and the third gateway pair (slave gateway b and slave gateway c).

[0035] It should be noted that if the proximity degrees of two gateway pairs are the same, the two gateway pairs are arranged in the order of the traffic approximation degrees from large to small. For example, the proximity degrees of gateway pair A and gateway pair B are the same, and the traffic approximation degree of gateway pair A is greater than that of gateway pair B, so the arrangement order of gateway pair A is before that of gateway pair B.

[0036] In an embodiment, the step S1132 of dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix can specifically include: S11321, constructing a scatter plot based on each slave gateway, and each node in the scatter plot representing each slave gateway; S11322, connecting different nodes in the scatter plot based on the pattern similarity matrix, and determining at least one connected component; S11323, dividing the to-be-detected region into a plurality of sub-regions based on the connected component.

[0037] In a specific implementation process, first, a scatter plot is constructed, and each node in the scatter plot represents each slave gateway. It can be understood that the scatter plot only contains at least one node and does not contain the connection relationship (edge between nodes) between the nodes.

[0038] Further, in the mode similarity matrix, the first 50% of gateway pairs are selected from the first column as physical approximate gateway pairs, and if the traffic approximation degree of any physical approximate gateway pair is greater than a first preset threshold, an edge is added between the two nodes corresponding to the physical approximate gateway pair in the scatter plot, and finally an edge scatter plot is obtained. In this embodiment, the traffic approximation degrees are arranged in descending order, and the value corresponding to the last traffic approximation degree in the first 70% of traffic approximation degrees is set as the first preset threshold.

[0039] Further, using a priority search algorithm, all initial connected components in the edge scatter plot are determined, and at least one isolated node, i.e., a node that does not exist in connection with any node, is obtained. It can be understood that each initial connected component represents a number of nodes that exist in connection.

[0040] It should be noted that in this embodiment, one initial connected component can correspond to one sub-region, and one isolated node can correspond to one sub-region, and the to-be-detected region can be divided. In addition, the region merging of the isolated node can be completed according to the traffic approximation degree of the isolated node, i.e., if the traffic approximation degree of the isolated node and a node is greater than a second preset threshold, the isolated node is divided into the sub-region where the node is located, and finally each sub-region is obtained. In this embodiment, the traffic approximation degrees are arranged in descending order, and the value corresponding to the last traffic approximation degree in the first 50% of traffic approximation degrees is set as the second preset threshold.

[0041] S12, calculate the traffic change data of each sub-region; S13, set a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; S14, perform anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each sub-region.

[0042] In the specific implementation process, taking a target sub-region in all sub-regions as an example, the traffic change data of each slave gateway in the target sub-region is obtained in the intelligent management platform, and the traffic change data of the target sub-region is determined using the traffic change data of each slave gateway in the target sub-region. In this embodiment, the mean value of the traffic approximation degrees of each slave gateway and other slave gateways in the target sub-region can be calculated, and the traffic change data of the slave gateway with the smallest mean value is taken as the traffic change data of the target sub-region.

[0043] It can be understood that because the traffic change data of different sub-regions is different, the threshold adjustment strategies of different sub-regions are also different, and the threshold adjustment strategy for each sub-region needs to be set according to the traffic change data of each sub-region.

[0044] In the specific implementation process, first, the reference sub-region of the target sub-region is determined from all sub-regions based on the flow change data of the target sub-region, and then the threshold value set by the reference sub-region for the historical flow data for anomaly detection is used as the initial threshold value of the target sub-region.

[0045] Specifically, the similarity between the historical flow data of the target sub-region and other sub-regions can be calculated by using the DTW distance, and the sub-region with the highest similarity is used as the reference sub-region of the target sub-region. The reference sub-region can provide a reference for setting the initial threshold value for anomaly detection of the target sub-region.

[0046] It can be understood that the reference sub-region of the target sub-region, that is, the sub-region with similar flow change data in the historical flow data after the change of the target sub-region, can set the initial threshold value for anomaly detection of the target sub-region according to the threshold value setting method of the reference sub-region.

[0047] In an embodiment, the threshold value adjustment strategy of each sub-region is set based on the flow change data of each sub-region in step S13, which can specifically include: S131, determining the flow change anomaly factor of the target sub-region; S132, setting the threshold value adjustment strategy of the target sub-region based on the flow change anomaly factor of the target sub-region.

[0048] In the specific implementation process, first, the flow data change trend of each slave gateway in the target sub-region is obtained, and then the flow change anomaly factor of the target sub-region is determined based on the similarity of the flow data change trends of different slave gateways in the target sub-region.

[0049] Exemplarily, the flow change trend of each slave gateway can include: increase, decrease, and no change, and in this embodiment, no change and increase are classified as the same change trend, and then the number of slave gateways belonging to the same change trend in the target sub-region can be used to determine the threshold value adjustment strategy of the target sub-region.

[0050] Specifically, the threshold value adjustment strategy of the target sub-region is: if the flow change trend of the target sub-region at the current time point is increasing, that is, at the current time point, the flow change trend of more than 50% of the slave gateways in the target sub-region is increasing, then the initial threshold value needs to be increased; if only less than 20% of the slave gateways in the target sub-region at the current time point have an increasing flow change trend, then the initial threshold value is not changed.

[0051] In addition, if the traffic change trend of the target sub-region at the current time point is decreasing, that is, more than 50% of the traffic change trends of the slave gateways in the target sub-region at the current time point are decreasing, the initial threshold needs to be reduced; if only less than 20% of the traffic change trends of the slave gateways in the target sub-region at the current time point are decreasing, the initial threshold is not changed. It should be noted that the range of increasing or decreasing the initial threshold can be determined by the amplitude of the increase or decrease of the traffic data of each slave gateway in the target sub-region.

[0052] It can be understood that if the target sub-region has a business change, the traffic of each slave gateway included in the target sub-region will change, and at this time, the threshold needs to be adjusted. If only a small number of slave gateways in the target sub-region have traffic changes, it may be that the slave gateways have exceptions, and the threshold is not changed, so that the possible abnormal values can be obtained.

[0053] Further, the threshold adjustment strategy of each sub-region is used for abnormal detection of each sub-region, and the abnormal detection of the to-be-detected region is completed.

[0054] The FTTR-B multi-tenant distributed abnormal detection method provided in the embodiment of the application first divides the to-be-detected region into a plurality of sub-regions based on the network topology of the to-be-detected region and the historical traffic data of each slave gateway; then calculates the traffic change data of each sub-region and sets a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; finally, the to-be-detected region is detected based on the threshold adjustment strategy of each sub-region. The application solves the problem of misjudgment or missed detection of the traditional abnormal detection method when the local traffic changes due to the setting of a global unified detection standard. For example, when the temporary video conference traffic of an enterprise suddenly increases, the fixed threshold cannot dynamically adapt and triggers false interception. For another example, at the end of the month, the network traffic of the settlement data in the financial area of an enterprise suddenly increases, and abnormal attack traffic may be hidden in the normal traffic and missed by the system.

[0055] On the basis of the above-mentioned embodiments, Figure 2 The structure block diagram of the FTTR-B multi-tenant distributed abnormal detection device according to an embodiment of the application is shown in FIG. 2. The FTTR-B multi-tenant distributed abnormal detection device 200 can include a region division module 210, a traffic change calculation module 220, a threshold adjustment strategy setting module 230, and an abnormal detection module 240. Figure 2 The region division module 210 is configured to divide the to-be-detected region into a plurality of sub-regions based on the network topology of the to-be-detected region and the historical traffic data of each slave gateway. The traffic change calculation module 220 is configured to calculate the traffic change data of each sub-region. The threshold adjustment strategy setting module 230 is configured to set a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region. The threshold adjustment strategy setting module 230 is configured to set a threshold adjustment strategy for each sub-region based on the traffic variation data of the sub-region. The anomaly detection module 240 is configured to perform anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each sub-region.

[0056] In an example embodiment, the traffic variation data in the traffic variation calculation module 220 is the difference between the traffic data at the current time point and the traffic data at the previous time point.

[0057] In an example embodiment, the region division module 210 can also be configured to determine the proximity between the target slave gateway and each of the other slave gateways based on the network topology, calculate the traffic approximation between the target slave gateway and each of the other slave gateways based on the historical traffic data of each slave gateway, and divide the to-be-detected region into a plurality of sub-regions based on the proximity and the traffic approximation.

[0058] In an example embodiment, the region division module 210 can also be configured to establish a pattern similarity matrix based on the proximity and the traffic approximation, and in accordance with the order of the proximity from small to large and the order of the traffic approximation from large to small, and divide the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix.

[0059] In an example embodiment, the region division module 210 can also be configured to construct a scatter plot based on each slave gateway, wherein each node in the scatter plot represents each slave gateway, connect different nodes in the scatter plot based on the pattern similarity matrix, determine at least one connected component, and divide the to-be-detected region into a plurality of sub-regions based on the connected component.

[0060] In an example embodiment, the initial security detection model construction module 210 can also be configured to determine a reference sub-region of a target sub-region among all sub-regions, and set a threshold adjustment strategy for the target sub-region based on a preset anomaly threshold of the reference sub-region of the target sub-region.

[0061] In an example embodiment, the initial security detection model construction module 210 can also be configured to obtain the traffic data variation trend of each slave gateway in the target sub-region, and determine a traffic variation anomaly factor of the target sub-region based on the similarity of the traffic data variation trends of different slave gateways in the target sub-region.

[0062] Those skilled in the art should understand that the division of the various modules in the embodiments is merely a logical functional division. In actual applications, they can be fully or partially integrated onto one or more actual carriers. These modules can be implemented entirely in software through processing unit calls, entirely in hardware, or a combination of software and hardware. It should be noted that each module in the FTTR-B multi-tenant distributed anomaly detection device in this embodiment corresponds one-to-one with each step in the FTTR-B multi-tenant distributed anomaly detection method in the aforementioned embodiments. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned FTTR-B multi-tenant distributed anomaly detection method, which will not be repeated here.

[0063] Based on the above embodiments, Figure 3 This is a schematic diagram of the structure of an FTTR-B multi-tenant distributed anomaly detection device according to one embodiment of this application, as shown below. Figure 3 As shown, the electronic device may include a processor 310, a communication interface 320, a memory 330, and a communication bus 340, wherein the processor 310, the communication interface 320, and the memory 330 communicate with each other through the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute an FTTR-B multi-tenant distributed anomaly detection method. The method includes: dividing the area to be detected into multiple sub-areas based on the network topology of the area to be detected and the historical traffic data of each slave gateway; calculating the traffic change data of each sub-area; setting a threshold adjustment strategy for each sub-area based on the traffic change data of each sub-area; and performing anomaly detection on the area to be detected based on the threshold adjustment strategy of each sub-area.

[0064] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0065] On the basis of the above-mentioned embodiments, in another aspect, the present application also provides a computer program product, the computer program product comprising a computer program, the computer program being stored on a non-transitory computer-readable storage medium, and the computer program being executable by a processor to enable a computer to perform the FTTR-B multi-tenant distributed anomaly detection method provided by the above-mentioned methods, the method comprising: dividing a to-be-detected region into a plurality of sub-regions based on a network topology of the to-be-detected region and historical traffic data of each slave gateway; calculating traffic change data of each sub-region; setting a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; and performing anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each sub-region.

[0066] On the basis of the above-mentioned embodiments, in still another aspect, the present application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, the computer program being executable by a processor to implement the FTTR-B multi-tenant distributed anomaly detection method provided by the above-mentioned methods, the method comprising: dividing a to-be-detected region into a plurality of sub-regions based on a network topology of the to-be-detected region and historical traffic data of each slave gateway; calculating traffic change data of each sub-region; setting a threshold adjustment strategy for each sub-region based on the traffic change data of each sub-region; and performing anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each sub-region.

[0067] The above is only the preferred embodiments of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent process transformation using the content of the present application specification and drawings, or direct or indirect application in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. A multi-tenant distributed anomaly detection method for FTTR-B, characterized in that, The method comprises: dividing the to-be-detected region into a plurality of sub-regions based on network topology of the to-be-detected region and historical traffic data of each slave gateway; calculating traffic change data of each of the sub-regions; setting a threshold adjustment strategy for each of the sub-regions based on the traffic change data of each of the sub-regions; performing anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each of the sub-regions.

2. The method of claim 1, wherein, The traffic change data is a difference between traffic data at a current time point and traffic data at a previous time point.

3. The method of claim 1, wherein, The method of dividing the to-be-detected region into a plurality of sub-regions based on network topology of the to-be-detected region and historical traffic data of each slave gateway comprises: determining a proximity between a target slave gateway and each of other slave gateways based on the network topology; calculating a traffic approximation between the target slave gateway and each of other slave gateways based on the historical traffic data of each slave gateway; dividing the to-be-detected region into a plurality of sub-regions based on the proximity and the traffic approximation.

4. The method of claim 3, wherein, The method of dividing the to-be-detected region into a plurality of sub-regions based on the proximity and the traffic approximation comprises: establishing a pattern similarity matrix based on the proximity and the traffic approximation, and in accordance with an order of the proximity from small to large and an order of the traffic approximation from large to small; dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix.

5. The method of claim 4, wherein, The method of dividing the to-be-detected region into a plurality of sub-regions based on the pattern similarity matrix comprises: constructing a scatter plot based on each slave gateway, wherein each node in the scatter plot represents each slave gateway; connecting different nodes in the scatter plot based on the pattern similarity matrix, and determining at least one connected component; dividing the to-be-detected region into a plurality of sub-regions based on the connected component.

6. The method of claim 1, wherein, Each of the sub-regions comprises a plurality of slave gateways, and the method of setting a threshold adjustment strategy for each of the sub-regions based on traffic change data of each of the sub-regions comprises: determining a traffic change anomaly factor of a target sub-region in all sub-regions; setting a threshold adjustment strategy of the target sub-region based on the traffic change anomaly factor of the target sub-region.

7. The method of claim 6, wherein, The method of determining the traffic change anomaly factor of the target sub-region comprises: obtaining a traffic data change trend of each slave gateway in the target sub-region; determining a traffic change anomaly factor of the target sub-region based on similarity of the traffic data change trend of different slave gateways in the target sub-region.

8. An FTTR-B multi-tenant distributed anomaly detection apparatus, characterized in that, The method comprises: a region division module configured to divide the to-be-detected region into a plurality of sub-regions based on network topology of the to-be-detected region and historical traffic data of each slave gateway; a traffic change calculation module configured to calculate traffic change data of each of the sub-regions; a threshold adjustment strategy setting module configured to set a threshold adjustment strategy for each of the sub-regions based on the traffic change data of each of the sub-regions; an anomaly detection module configured to perform anomaly detection on the to-be-detected region based on the threshold adjustment strategy of each of the sub-regions.

9. An FTTR-B multi-tenant distributed anomaly detection device, characterized in that, The method comprises: at least one processor; and a memory communicatively connected with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, A computer program is stored, and the computer program is executed by a processor to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Zero-trust gateway-based application resource dynamic control access method

    CN117278329A

  • Cross-region communication method and device, equipment, storage medium and program product

    CN119583550A

  • Master-slave gateway equipment synchronization method and device based on FTTR

    CN120151702A

  • AI-based cloud desktop gateway flow intelligent prediction method

    CN120614260A

  • Anomaly detection method and device of power grid system and electronic equipment

    CN120728845A