Method and system for diagnosing and analyzing internet surfing quality of mobile phone based on large model
By employing large-scale model analysis methods, the problems of inaccurate data collection and weak root cause identification capabilities in mobile internet quality analysis have been solved, enabling precise anomaly diagnosis and optimization suggestions, thereby improving user experience and operator service quality.
Patent Information
- Application Number
- CN202511239745.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-01
- Publication Date
- 2025-12-05
AI Technical Summary
Existing mobile internet quality analysis tools suffer from poor compatibility, inaccurate data collection, weak root cause identification capabilities, and a lack of optimization measures, making it impossible to achieve a closed loop of business-level anomaly diagnosis and optimization.
The mobile internet quality diagnostic and analysis method based on a large model generates a standardized PCAP file by capturing packets on an Android terminal, uploads it to a cloud server in fragments using the QUIC protocol, reassembles the protocol stream using the Scapy library, and performs multi-protocol joint analysis through a large model based on the Transformer architecture to identify anomalies, locate root causes, and output a diagnostic report.
It enables intelligent and precise diagnosis of mobile internet quality, improving user experience and network operation and maintenance efficiency.
Smart Images

Figure CN121078468A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of communication and relates to a large model-based mobile phone online quality diagnosis and analysis method and system. BACKGROUND
[0002] With the deep popularization of mobile Internet, mobile application APP has become the core carrier for users to obtain information, develop social activities and carry out entertainment activities, and the service quality thereof directly depends on mobile phone online quality, and the pros and cons of the online quality significantly affect user experience and operator service satisfaction. However, the current mobile terminal APP service faces multiple technical challenges in the operator network environment, and the existing analysis means has obvious defects, as follows.
[0003] The round-trip time RTT of the mobile network significantly increases in weak signal areas, such as elevators, basements or network switching; the secondary operator needs to access the core resources of China Telecom / China Unicom across networks due to resource limitations, resulting in an increase of 30%-50% in the time delay; TCP head blocking (under HTTP / 2 protocol), DNS resolution delay (average 100-200 ms) directly slows down the first packet time of the service; cross-network resource scheduling is inefficient, 40% of the traffic is incorrectly scheduled to cross-network CDN nodes, and the core resources such as video and games in the mobile network are scarce, further amplifying the cross-network access delay.
[0004] Traditional signaling analysis tools, such as Wireshark and tcpdump, can only achieve mechanical analysis of protocol fields and cannot associate with service semantics; the rule engine relying on human experience is difficult to adapt to dynamically changing service scenarios, resulting in a disconnection between the analysis results and the actual service quality.
[0005] The existing service analysis scheme based on a multi-modal model has three key problems: data collection limitation: lacking the ability to dynamically capture user real service traffic through the terminal, it cannot obtain original data close to the actual use scenario. Root cause positioning missing: only data can be structurally analyzed, it is difficult to mine abnormalities through cross-protocol association, and it cannot realize root cause positioning of service-level abnormalities. Analysis closed loop is broken: only analysis results are output, and there is a lack of optimization measures based on data driving, resulting in a disconnection between abnormal detection and problem solving, and it cannot provide a practical service quality optimization scheme for operators.
[0006] In summary, the current mobile phone online quality analysis field has multiple technical problems such as complex network environment, poor adaptability of traditional tools, unrealistic data collection of existing schemes, weak root cause positioning ability and lack of optimization measures, and an urgent need for a technical scheme that can realize real data collection, deep protocol analysis, service-level abnormality diagnosis and optimization suggestion closed loop. SUMMARY
[0007] The application aims to solve the problems of complex network environment, poor adaptability of traditional tools, non-real data collection, weak root cause positioning ability and lack of optimization measures in the field of mobile Internet quality analysis in the prior art, and provides a mobile Internet quality diagnosis and analysis method and system based on a large model.
[0008] To achieve the above-mentioned purpose, the application adopts the following technical solutions:
[0009] The mobile Internet quality diagnosis and analysis method based on a large model comprises:
[0010] The business traffic of the Android terminal is captured, and the obtained PCAP data is desensitized for user identity information to generate a standardized PCAP file;
[0011] The standardized PCAP file is uploaded to a cloud server, the cloud server analyzes the received PCAP file, recombines the network protocol stream and extracts session information, and converts binary data into a structured business event sequence;
[0012] Based on the structured business event sequence, multi-protocol joint analysis is performed on domain name resolution DNS, transmission control protocol TCP, hypertext transfer protocol and peer-to-peer transmission, abnormal points are identified and root causes are located, and a diagnosis report containing optimization suggestions is output.
[0013] Further improvements of the application are as follows:
[0014] Further, the business traffic of the Android terminal is captured, specifically, a monitoring service is run in the background of the Android terminal, the monitoring service and packet capture are realized by using Binder and LocalBroadcastManager, and real-time indicators are stored; the PCAP data obtained is desensitized for user identity information, specifically, network traffic data of application UID is obtained in real time through the TrafficStats class; the / password and / token fields contained in the HTTP Body in the collected network traffic data are masked to avoid user identity information and privacy data leakage.
[0015] Further, the standardized PCAP file comprises a timestamp, an interface identifier and business metadata, wherein the timestamp is the specific time of capturing traffic data; the interface identifier is an identifier of the network interface corresponding to the traffic data; the business metadata is a business type identified by deep packet inspection DPI, and a network standard obtained by calling TelephonyManager.getNetworkType(), and wireless parameters extracted by calling SignalStrength.getCellSignalStrengths(), so that the PCAP file has business correlation analysis capability.
[0016] Further, the uploading of the standardized PCAP file to the cloud server comprises: the Android terminal establishes a connection with the cloud server through a QUIC protocol and adopts bidirectional certificate authentication; the PCAP file is divided into data blocks of a fixed size for fragmented uploading, the server returns an ACK after receiving, and retransmission is performed if the ACK is not confirmed within a timeout period; the server verifies data integrity by checking CRC32 values, decrypts and decompresses, and then combines into a complete PCAP file; wherein the Android terminal uses a device certificate, and the cloud server uses an OVSSL certificate.
[0017] Further, the cloud server parses the received PCAP file, specifically: using a Scapy library to recombine TCP streams and process IP fragments, associating scattered data packets into complete sessions; inputting protocol headers, payload metadata and extracted text information in the PCAP data into a fine-tuned Transformer architecture large model to obtain a structured business event sequence.
[0018] Further, the associating of scattered data packets into complete sessions comprises:
[0019] Through the Scapy library, the PCAP packets are preprocessed to extract key information in the scattered data packets, including source IP, source port, destination IP, destination port, protocol type, payload digest, timestamp and TCP stream sequence; wherein the protocol type includes DNS, TCP, HTTP / HTTPS and P2P;
[0020] For IP fragmented packets, the Scapy library's fragmentation recombination function is used to recombine fragmented packets belonging to the same IP datagram into a complete IP datagram;
[0021] Based on the extracted TCP stream sequence, source / destination IP and port information, the Scapy library is used to recombine TCP streams, and scattered data packets belonging to the same TCP connection are associated in time sequence and sequence number to restore the complete TCP session process;
[0022] Based on the protocol type and business context, data packets of different protocols are associated into complete business sessions.
[0023] Further, the inputting of the protocol header, payload metadata and extracted text information in the PCAP data into a fine-tuned Transformer architecture large model to obtain a structured business event sequence comprises:
[0024] The binary fields of the protocol header, the numerical features of the metadata and the text information are uniformly mapped into vector representations recognized by the model;
[0025] The self-attention mechanism and vector representation of the Transformer are used to capture the timing relationship between different protocol fields.
[0026] A protocol behavior knowledge base based on model training is used to re-analyze protocol fields into business semantics.
[0027] The timing relationship is an event flow logic sorted by timestamp, forming a complete business link, and marking events that do not conform to protocol specifications or business expectations; the event flow logic is DNS resolution, TCP connection, TLS handshake, and HTTP data transmission.
[0028] Further, the multi-protocol joint analysis includes a single protocol layer, an inter-protocol layer, and a business mapping layer; the single protocol layer is based on RFC standards for atomic anomaly detection, including DNS response delay, TCP retransmission rate, and HTTP stream interruption indicator extraction; the inter-protocol layer takes each protocol stage as a state node, implements state association through time constraints and event constraints, and constructs a protocol state transition graph; the business mapping layer is a quantitative influence model that establishes protocol anomaly features and APP business quality.
[0029] The atomic anomaly detection based on RFC standards is as follows:
[0030] DNS response delay = max(0, T_response - T_query);
[0031] CDN matching degree = 1 - (actual node distance / optimal node distance);
[0032] TCP retransmission rate = number of retransmitted packets / total number of packets;
[0033] Zero window event density = EWMA(zero window count, alpha = 0.7);
[0034] Where T_response is the response time, T_query is the request time, the optimal distance is intelligently assigned by CDN according to the request content initiated by the mobile phone, the actual node automatically scans all target addresses and performs Ping after the mobile phone initiates a request, and the CDN selects the optimal node for content distribution according to the results, the result obtained is the CDN matching degree; the zero window is the sliding window size of the TCP sender, which becomes 0, essentially because the receiving buffer of the TCP receiver is full and has no space to receive data; the EWMA is the zero window event density.
[0035] The state nodes are protocol phases, state association is realized through time constraints and event constraints, specifically: node definition is each protocol phase as a state node; edge transition condition is time constraint, state transition time is less than protocol timeout threshold, that is, time constraint is met; event constraint is that the previous state output matches the next state input.
[0036] Further, the positioning root cause outputs a diagnosis report containing optimization suggestions, specifically:
[0037] The root cause is realized through an association rule engine, including:
[0038] If the DNS delay is > 300 ms, the TCP retransmission rate is > 0.15, and the path hop count is > 8, it is determined that the network backbone is congested;
[0039] If the TLS failure rate is > 0.2, the HTTP / 2 stream interruption is > 3, and the certificate chain is abnormal, it is determined that the middleware is hijacked;
[0040] If the CDN matching degree is > 0.7, the HTTP / 2 first packet time is > 2000 ms, and the server load is < 30%, it is determined that the CDN scheduling is ineffective;
[0041] The path hop count refers to the number of intermediate routers that a data packet passes through from the source address to the destination address, the more the number, the longer the network path, and the worse the quality of service access;
[0042] The HTTP / 2 stream interruption usually refers to the abnormal termination of the underlying connection during transmission, resulting in the HTTP / 2 stream not being normally closed;
[0043] The HTTP / 2 first packet time is the HTTP / 2 communication response time, that is, the time consumed between sending a request and the server returning the first information;
[0044] The diagnosis report containing optimization suggestions specifically includes:
[0045] Based on the protocol anomaly weight of different protocol types, the root cause reliability index is obtained, and the protocol groups with reliability greater than 0.6 are jointly analyzed, and the prevention suggestions are output according to the fault type;
[0046] Wherein, the root cause reliability is:
[0047]
[0048] Wherein, W i is the protocol anomaly weight; k is the attenuation coefficient; the protocol anomaly weight of different protocol types is W1=DNS=0.3, W2=TCP=0.4, W3=HTTP=0.5; I(W i ) represents the number of different protocol types contained;
[0049] For CDN scheduling failure output node switching suggestion, for TCP zero window storm output traffic prediction expansion suggestion, for TLS certificate expiration output 7 days in advance alarm suggestion.
[0050] The mobile Internet quality diagnosis and analysis system based on a large model comprises:
[0051] The processing module performs service traffic packet capture on the Android terminal, performs user identity information desensitization processing on the obtained PCAP data, and generates a standardized PCAP file.
[0052] The analysis module uploads the standardized PCAP file to a cloud server, and the cloud server analyzes the received PCAP file, recombines network protocol streams and extracts session information, and converts binary data into a structured service event sequence.
[0053] The output module performs multi-protocol joint analysis on domain name resolution DNS, transmission control protocol TCP, hypertext transfer protocol and peer-to-peer transmission based on the structured service event sequence, identifies abnormal points and locates the root cause, and outputs a diagnosis report containing optimization suggestions.
[0054] Compared with the prior art, the present application has the following beneficial effects:
[0055] The present application protects user privacy by background packet capture and desensitization of the Android terminal, generates a standardized PCAP file containing time stamp, interface identifier, service metadata and wireless parameters, uploads in QUIC protocol fragments, guarantees efficient data transmission through CRC32 check, recombines protocol streams through Scapy library, converts binary data into structured service event sequence through Transformer architecture large model, accurately locates the root cause through multi-protocol joint analysis combined with association rule engine, outputs targeted optimization suggestions according to the root cause credibility index, and finally realizes intelligent, accurate and efficient mobile Internet quality diagnosis, improves user Internet experience and network operation efficiency. BRIEF DESCRIPTION OF DRAWINGS
[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0057] Figure 1 The flowchart of the mobile Internet quality diagnosis and analysis method based on a large model of the present application is shown.
[0058] Figure 2 A structural schematic diagram of a large model-based mobile phone online quality diagnosis and analysis system of the present application. DETAILED DESCRIPTION
[0059] To make the objects, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some but not all of the embodiments of the present application. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0060] Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0061] It should be noted that: similar reference numbers and letters represent similar items in the following drawings, therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0062] In the description of the embodiments of the present application, it should be noted that if the terms "upper", "lower", "horizontal", "inner" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship when the product of the present application is used, which is only for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the indicated device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application. In addition, the terms "first", "second" and the like are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0063] In addition, if the term "horizontal" appears, it does not mean that the component must be absolutely horizontal, but can be slightly inclined. For example, "horizontal" only means that its direction is relatively more horizontal than "vertical", and does not mean that the structure must be completely horizontal, but can be slightly inclined.
[0064] In the description of the embodiments of the application, it also needs to be explained that, unless explicitly defined and limited, if the terms "arrange", "install", "connect", "join" appear, they should be understood in a broad sense, for example, can be fixedly connected, can also be detachably connected, or integrally connected; can be mechanically connected, can also be electrically connected; can be directly connected, can also be indirectly connected through an intermediate medium, can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the application can be understood according to the specific circumstances.
[0065] The application will be further described in detail below with reference to the drawings:
[0066] Referring to Figure 1 The application discloses a mobile phone online quality diagnosis and analysis method based on a large model, comprising:
[0067] S101, the business traffic of the Android terminal is captured, the PCAP data obtained is desensitized for user identity information, and a standardized PCAP file is generated;
[0068] The business traffic of the Android terminal is captured, specifically: a monitoring service is run in the background of the Android terminal, Binder and LocalBroadcastManager are used to realize the monitoring service and the packet capture, and real-time indexes are stored; the PCAP data obtained is desensitized for user identity information, specifically: the network traffic data of the application UID is obtained in real time through the TrafficStats class; the / password and / token fields contained in the HTTP Body in the collected network traffic data are masked, so as to avoid the leakage of user identity information and private data.
[0069] The standardized PCAP file comprises a timestamp, an interface identifier and service metadata, wherein the timestamp is the specific time of recording the capture of traffic data; the interface identifier is the network interface corresponding to the traffic data; the service metadata is the service type identified by combining deep packet inspection (DPI), the network standard obtained by calling TelephonyManager.getNetworkType(), and the wireless parameters extracted by calling SignalStrength.getCellSignalStrengths(), so that the PCAP file has the service association analysis capability.
[0070] S102, the standardized PCAP file is uploaded to a cloud server, the cloud server analyzes the received PCAP file, recombines the network protocol stream and extracts session information, and converts binary data into a structured service event sequence;
[0071] The uploading of the standardized PCAP file to the cloud server comprises: the Android terminal establishes a connection with the cloud server through a QUIC protocol and adopts bidirectional certificate authentication; the PCAP file is divided into data blocks of a fixed size for fragmented uploading, and the server returns an ACK after receiving, and retransmits if not confirmed within a timeout; the server verifies data integrity by checking CRC32 values, decrypts and decompresses, and combines into a complete PCAP file; wherein the Android terminal uses a device certificate, and the cloud server uses an OVSSL certificate.
[0072] The cloud server parses the received PCAP file, specifically: using the Scapy library to recombine TCP streams and process IP fragments, associating scattered data packets into complete sessions; inputting the protocol header, payload metadata and extracted text information in the PCAP data into a fine-tuned Transformer architecture large model to obtain a structured business event sequence.
[0073] The scattered data packets are associated into complete sessions, specifically:
[0074] The PCAP packets are preprocessed by the Scapy library to extract key information in the scattered data packets, including source IP, source port, destination IP, destination port, protocol type, payload digest, timestamp and TCP stream sequence; wherein the protocol type includes DNS, TCP, HTTP / HTTPS and P2P;
[0075] For IP fragmented packets, the Scapy library's fragmentation recombination function is used to recombine fragmented packets belonging to the same IP datagram into complete IP datagrams;
[0076] Based on the extracted TCP stream sequence, source / destination IP and port information, the Scapy library is used to recombine TCP streams, and scattered data packets belonging to the same TCP connection are associated in time sequence and sequence number to restore the complete TCP session process;
[0077] Based on the protocol type and business context, data packets of different protocols are associated into complete business sessions.
[0078] The protocol header, payload metadata and extracted text information in the PCAP data are input into a fine-tuned Transformer architecture large model to obtain a structured business event sequence, specifically:
[0079] The binary fields of the protocol header, numerical features of the metadata and text information are uniformly mapped into vector representations recognized by the model;
[0080] The self-attention mechanism and vector representation of the Transformer are used to capture the timing relationship between different protocol fields;
[0081] Protocol behavior knowledge base based on model training, re-parsing protocol fields into business semantics;
[0082] Wherein, the time sequence relationship is an event flow transfer logic sorted by timestamp, forming a complete business link, and marking events that do not conform to protocol specifications or business expectations; wherein, the event flow transfer logic is DNS resolution, TCP connection, TLS handshake and HTTP data transmission.
[0083] S103, based on the structured business event sequence, multi-protocol joint analysis is performed on domain name resolution DNS, transmission control protocol TCP, hypertext transfer protocol and point-to-point transmission, abnormal points are identified and root causes are located, and a diagnosis report containing optimization suggestions is output.
[0084] The multi-protocol joint analysis includes a single protocol layer, an inter-protocol layer and a business mapping layer; wherein, the single protocol layer is based on RFC standard for atomic abnormality detection, including DNS response delay, TCP retransmission rate, HTTP flow interruption indicator extraction; the inter-protocol layer takes each protocol stage as a state node, realizes state association through time constraint and event constraint, and constructs a protocol state transition graph; the business mapping layer is a quantitative influence model of protocol abnormal feature and APP service quality;
[0085] Wherein, the atomic abnormality detection based on RFC standard is specifically:
[0086] DNS response delay = max(0, T_response-T_query);
[0087] CDN matching degree = 1-(actual node distance / optimal node distance);
[0088] TCP retransmission rate = number of retransmitted packets / total number of packets;
[0089] Zero window event density = EWMA(zero window count, alpha = 0.7);
[0090] Wherein, T_response is the response time; T_query is the request time; the optimal distance is intelligently allocated by CDN according to the request content initiated by the mobile phone, the actual node automatically scans all target addresses and performs Ping after the mobile phone initiates a request, and the CDN selects the optimal node for content distribution according to the result, and the result obtained is the CDN matching degree; the zero window is the sliding window size of the TCP sender becoming 0, which is essentially because the receiving buffer of the TCP receiver is full and has no space to receive data; the EWMA is the zero window event density;
[0091] The state nodes are protocol phases, state association is realized through time constraints and event constraints, specifically: node definition is each protocol phase as a state node; edge transition condition is time constraint, state transition time is less than protocol timeout threshold, that is, time constraint is met; event constraint is that the previous state output matches the next state input.
[0092] The positioning root cause outputs a diagnosis report containing optimization suggestions, specifically:
[0093] The root cause is realized through an association rule engine, including:
[0094] If DNS delay > 300 ms, TCP retransmission rate > 0.15, and path hop count > 8, it is determined that the network backbone is congested;
[0095] If TLS failure rate > 0.2, HTTP / 2 stream interruption > 3, and certificate chain anomaly, it is determined that the middleware is hijacked;
[0096] If CDN matching degree > 0.7, HTTP / 2 first packet time > 2000 ms, and server load < 30%, it is determined that the CDN scheduling is ineffective;
[0097] The path hop count refers to the number of intermediate routers that a data packet passes through from the source address to the destination address. The more the number, the longer the network path, and the worse the quality of service access;
[0098] The HTTP / 2 stream interruption usually refers to the abnormal termination of the underlying connection during transmission, resulting in the HTTP / 2 stream not being normally closed;
[0099] The HTTP / 2 first packet time is the HTTP / 2 communication response time, that is, the time consumed between sending a request and the server returning the first information;
[0100] The diagnosis report containing optimization suggestions, specifically:
[0101] Based on the protocol anomaly weight of different protocol types, the root cause reliability index is obtained, and the protocol groups with reliability greater than 0.6 are jointly analyzed, and the prevention suggestions are output according to the fault type;
[0102] Wherein, the root cause reliability is:
[0103]
[0104] Wherein, W i is the protocol anomaly weight; k is the attenuation coefficient; the protocol anomaly weight of different protocol types is W1 = DNS = 0.3, W2 = TCP = 0.4, W3 = HTTP = 0.5; I(W i ) represents the number of different protocol types contained;
[0105] For CDN scheduling failure output node switching suggestion, for TCP zero window storm output traffic prediction expansion suggestion, for TLS certificate expiration output 7 days in advance alarm suggestion.
[0106] Referring to Figure 2 The application discloses a mobile phone online quality diagnosis and analysis system based on a large model, comprising:
[0107] A processing module is configured to perform service traffic packet capturing on an Android terminal, perform user identity information desensitization processing on obtained PCAP data, and generate a standardized PCAP file.
[0108] An analysis module is configured to upload the standardized PCAP file to a cloud server, perform analysis on the received PCAP file, recombine network protocol streams and extract session information, and convert binary data into a structured service event sequence.
[0109] An output module is configured to perform multi-protocol joint analysis on domain name resolution DNS, transmission control protocol TCP, hypertext transfer protocol and peer-to-peer transmission based on the structured service event sequence, identify abnormal points and locate root causes, and output a diagnosis report containing optimization suggestions.
[0110] Embodiment:
[0111] The application discloses a mobile phone online quality diagnosis and analysis method based on a large model, comprising:
[0112] Step 1: Commercial Android terminal packet capturing, realizing lightweight collection of APP service data
[0113] First, run a monitoring service in the background of the Android terminal, and obtain application UID network traffic data in real time through the TrafficStats class. Mask fields such as / password and / token in the HTTP Body, and generate a cookie to store a standard PCAP file (containing metadata such as timestamps, interface identifiers and services)
[0114] For mobile phone app traffic collection, use Binder and LocalBroadcastManager to realize the monitoring service and packet capturing, and realize shared memory area storage of real-time indicators.
[0115] For enhanced PCAP metadata encapsulation, obtain the network standard through TelephonyManager.getNetworkType(), call SignalStrength.getCellSignalStrengths() to extract wireless parameters, and identify the service type based on deep packet inspection (DPI).
[0116] Storage optimization and security enhancement, using Zstandard dictionary compression: pre-training operator signaling dedicated dictionary, block compression strategy, each 10MB data block is compressed independently.
[0117] Step 2: PCAP packet upload analysis server
[0118] The terminal connects the cloud server through the QUIC protocol, adopts two-way certificate authentication, the terminal uses the device certificate, the cloud server uses the OV SSL certificate, and the PCAP file is divided into fixed data blocks for uploading. The server returns ACK immediately after receiving, and retransmits if it is not confirmed within the timeout. The server checks the CRC32 value to ensure data integrity, decrypts and decompresses, and merges into a complete PCAP file stored in the cloud server.
[0119] Step 3: Build large model deep analysis capability
[0120] Through large model analysis PCAP, low layer network data is converted into high layer semantic insight, using Scapy library to reorganize TCP flow, process IP fragmentation, and associate scattered packets into complete sessions. Such as HTTP file download + DNS resolution + TLS certificate exchange.
[0121] Through open source large model as intelligent analysis engine, input structured data of PCAP packet such as protocol header, payload metadata and extracted text / context information into large model. Use large model knowledge base such as protocol specification, attack pattern, network behavior characteristics for reasoning and correlation analysis.
[0122] Through Scapy for PCAP preprocessing and data extraction, the extracted content includes: source / destination IP, port, protocol type, payload digest, timestamp, TCP flow sequence, etc.
[0123] Deep analysis task, protocol behavior interpretation, locate connection failure reason; identify C2 communication mode from HTTP log, mark suspicious IP and URL.
[0124] Step 4: Multi-protocol anomaly diagnosis and problem solving suggestion
[0125] For multi-protocol anomaly diagnosis matrix, adopt three-layer analysis model, based on large model diagnosis result, build analysis rule, and then cross protocol root cause positioning.
[0126] Three-layer analysis model is single protocol layer, inter-protocol layer and business mapping layer; among them, single protocol layer is based on RFC standard atomization anomaly detection; inter-protocol layer is to build protocol state transition graph; business mapping layer is to establish protocol anomaly to business index quantitative influence model.
[0127] Single protocol anomaly feature extraction, specifically:
[0128] DNS response delay = max(0, T_response - T_query);
[0129] CDN matching degree = 1 - (actual node distance / optimal node distance);
[0130] TCP: retransmission rate = COUNT(retrans_packets) / COUNT(all_packets)
[0131] Zero window event density = EWMA(zero window count, a = 0.7)
[0132] Node definition in protocol state transition modeling: each protocol phase as a state node;
[0133] Edge transition conditions include: time constraints, specifically: T_transfer < protocol timeout threshold;
[0134] Event constraints are that the previous state output matches the next state input; for example, the DNS response IP must be consistent with the TCP destination IP.
[0135] Cross-protocol root cause positioning according to the association rule engine, as shown in Table 1.
[0136] Table 1 Association rule engine
[0137]
[0138] Build a prevention analysis model:
[0139]
[0140] wherein W i is the protocol anomaly weight, wherein DNS = 0.3, TCP = 0.4, HTTP = 0.5; K is the decay coefficient, default 0.5;
[0141] Dynamic adjustment of diagnosis priority, when the credibility is greater than 0.6, the protocol group is analyzed jointly, and the prevention suggestion is output according to the fault type. As shown in Table 2.
[0142] Table 2: Fault type level prevention method
[0143] Failure type Detection rate Positioning time Prevention method CDN scheduling failure 99.1% 37s 2h in advance to predict scheduling exception TCP zero window storm 97.3% 28s Expansion based on traffic prediction TLS certificate expiration 100% Instantly 7 days in advance warning
[0144] The above is only a preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A large model-based mobile phone Internet access quality diagnosis and analysis method, characterized in that, The application comprises the following steps: The user identity information of the PCAP data obtained by the business traffic packet capture of the Android terminal is desensitized, and a standardized PCAP file is generated; The standardized PCAP file is uploaded to a cloud server, the cloud server analyzes the received PCAP file, recombines the network protocol stream and extracts session information, and converts binary data into a structured business event sequence; Based on the structured business event sequence, the domain name resolution DNS, transmission control protocol TCP, hypertext transfer protocol and peer-to-peer transmission are jointly analyzed, the abnormal points are identified and the root cause is located, and a diagnosis report containing optimization suggestions is output.
2. The large model-based mobile Internet quality diagnosis and analysis method of claim 1, wherein, The business traffic packet capture of the Android terminal is specifically as follows: a monitoring service is run in the background of the Android terminal, Binder and LocalBroadcastManager are used to realize the monitoring service and packet capture, and real-time indicators are stored; the user identity information of the PCAP data obtained is desensitized, specifically: the network traffic data of the application UID is obtained in real time through the TrafficStats class; the / password and / token fields contained in the HTTP Body in the collected network traffic data are masked to avoid user identity information and privacy data leakage. 3.The large model-based mobile Internet quality diagnosis and analysis method of claim 2, wherein, The standardized PCAP file comprises a timestamp, an interface identifier and business metadata, wherein the timestamp is the specific time of recording the capture of traffic data; the interface identifier is an identifier of the network interface corresponding to the traffic data; the business metadata is a business type identified by deep packet inspection DPI, a network standard obtained by calling TelephonyManager.getNetworkType(), and wireless parameters extracted by calling SignalStrength.getCellSignalStrengths(), so that the PCAP file has business correlation analysis capability.
4. The large model-based mobile Internet quality diagnosis and analysis method of claim 3, wherein, The standardized PCAP file is uploaded to the cloud server, which comprises the following steps: the Android terminal establishes a connection with the cloud server through the QUIC protocol and adopts two-way certificate authentication; the PCAP file is divided into fixed-size data blocks for fragmented upload, the server returns ACK after receiving, and retransmits if it is not confirmed within a timeout period; the server verifies the data integrity by checking the CRC32 value, decrypts and decompresses, and combines into a complete PCAP file; wherein the Android terminal uses a device certificate, and the cloud server uses an OVSSL certificate.
5. The large model-based mobile Internet quality diagnosis and analysis method of claim 4, wherein, The cloud server analyzes the received PCAP file, specifically: TCP stream is recombined and IP fragmentation is processed using the Scapy library, and the scattered data packets are associated into complete sessions; the protocol header, payload metadata and extracted text information in the PCAP data are input into the fine-tuned Transformer architecture large model to obtain a structured business event sequence.
6. The large model-based mobile Internet quality diagnosis and analysis method of claim 5, wherein, The scattered data packets are associated into complete sessions, specifically: The key information in the scattered packets is extracted by preprocessing the PCAP packet through the Scapy library, including source IP, source port, destination IP, destination port, protocol type, payload digest, timestamp and TCP flow sequence; wherein, the protocol type includes DNS, TCP, HTTP / HTTPS and P2P; For IP fragmented packets, the fragmented packets belonging to the same IP datagram are recombined into a complete IP datagram through the fragmentation recombination function of the Scapy library; Based on the extracted TCP flow sequence, source / destination IP and port information, the TCP flow is recombined using the Scapy library, the scattered packets belonging to the same TCP connection are associated in time sequence and sequence number, and the complete TCP session process is restored; Based on the protocol type and service context, the packets of different protocols are associated into complete service sessions.
7. The large model-based mobile Internet quality diagnosis and analysis method of claim 6, wherein, The protocol header, payload metadata and extracted text information in the PCAP data are input into the fine-tuned Transformer architecture large model to obtain a structured service event sequence, specifically: The binary fields of the protocol header, the numerical features of the metadata and the text information are uniformly mapped into vector representations recognized by the model; The self-attention mechanism of the Transformer and the vector representation are used to capture the temporal relationship between different protocol fields; Based on the protocol behavior knowledge base trained by the model, the protocol fields are reanalyzed into business semantics; Wherein, the temporal relationship is the event flow transfer logic sorted by timestamp, forming a complete business link, and marking events that do not conform to the protocol specification or business expectations; wherein, the event flow transfer logic is DNS resolution, TCP connection, TLS handshake and HTTP data transmission. 8.The large model-based mobile Internet quality diagnosis and analysis method of claim 7, wherein, The multi-protocol joint analysis includes a single protocol layer, an inter-protocol layer and a business mapping layer; wherein, the single protocol layer is based on RFC standard for atomic anomaly detection, including DNS response delay, TCP retransmission rate, HTTP flow interruption indicator extraction; the inter-protocol layer takes each protocol phase as a state node, realizes state association through time constraint and event constraint, and constructs a protocol state transition graph; the business mapping layer is a quantitative influence model of protocol anomaly features and APP service quality; Wherein, the atomic anomaly detection based on the RFC standard is specifically: DNS response delay = max(0, T_response-T_query); CDN matching degree = 1-(actual node distance / optimal node distance); TCP retransmission rate = number of retransmitted packets / total number of packets; Zero window event density = EWMA(zero window count, alpha = 0.7); Wherein, T_response is the response time; T_query is the request time; the optimal distance is intelligently distributed by the CDN according to the request content initiated by the mobile phone, and the actual node will automatically scan all target addresses and perform Ping after the mobile phone initiates a request, and the CDN selects the optimal node for content distribution according to the result, and the result obtained is the CDN matching degree; the zero window is the sliding window size of the TCP sender, which becomes 0, and its essence is that the receiving buffer of the TCP receiver is full and has no space to receive data; the EWMA is the zero window event density; The state association is realized through time constraints and event constraints, specifically: the node is defined as each protocol phase as a state node; the edge transition condition is the time constraint, and the state transition time is less than the protocol timeout threshold, that is, the time constraint is satisfied; the event constraint is that the previous state output matches the state input. 9.The large model-based mobile Internet quality diagnosis and analysis method of claim 8, wherein, The positioning root cause outputs a diagnosis report containing optimization suggestions, specifically: The root cause is realized through an association rule engine, including: If the DNS delay is > 300ms, the TCP retransmission rate is > 0.15, and the path hop count is > 8, it is determined that the network backbone is congested; If the TLS failure rate is > 0.2, the HTTP / 2 stream interruption is > 3, and the certificate chain is abnormal, it is determined that the middleware is hijacked; If the CDN matching degree is > 0.7, the HTTP / 2 first packet time is > 2000ms, and the server load is < 30%, it is determined that the CDN scheduling is ineffective; The path hop count refers to the number of intermediate routers that the data packet passes through from the source address to the destination address, and the more the number, the longer the network path, and the worse the quality of business access; The HTTP / 2 stream interruption usually refers to the abnormal termination of the underlying connection in the transmission process, resulting in the HTTP / 2 stream not being normally closed; The HTTP / 2 first packet time is the HTTP / 2 communication response time, that is, the time consumed between sending a request and the server returning the first information; The diagnosis report containing optimization suggestions specifically includes: Based on the protocol anomaly weight of different protocol types, the root cause reliability index is obtained, and the protocol groups with a reliability greater than 0.6 are jointly analyzed, and the prevention suggestions are output according to the fault type; Wherein, the root cause reliability is: wherein W i is the protocol anomaly weight; k is the attenuation coefficient; the protocol anomaly weights of different protocol types are W1=DNS=0.3, W2=TCP=0.4, and W3=HTTP=0.5; I(W i ) represents the number of different protocol types contained. For CDN scheduling failure, output node switching suggestions, for TCP zero window storm, output traffic prediction expansion suggestions, and for TLS certificate expiration, output 7-day early warning suggestions.
10. A large model-based mobile phone Internet access quality diagnosis and analysis system, characterized in that, Including: The processing module performs business traffic packet capture on the Android terminal, performs user identity information desensitization processing on the obtained PCAP data, and generates a standardized PCAP file; The analysis module uploads the standardized PCAP file to the cloud server, the cloud server analyzes the received PCAP file, recombines the network protocol stream and extracts session information, and converts binary data into a structured business event sequence; The output module performs multi-protocol joint analysis on domain name resolution (DNS), transmission control protocol (TCP), hypertext transfer protocol (HTTP) and peer-to-peer transmission based on the structured service event sequence, identifies abnormal points and locates root causes, and outputs a diagnosis report containing optimization suggestions.