Traffic anomaly processing method and device, electronic equipment and storage medium

By adjusting bandwidth and mapping the network topology when monitoring sudden changes in network traffic, the target traffic path is determined, which solves the problems of insufficient real-time performance and path optimization in existing technologies, and achieves efficient network traffic management and stable transmission.

CN121098711BActive Publication Date: 2026-06-23国网思极网安科技(北京)有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
国网思极网安科技(北京)有限公司
Filing Date
2025-08-04
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing methods for detecting network traffic anomalies are slow and lack real-time performance when faced with complex and ever-changing network environments. They also have shortcomings in traffic distribution mapping and path optimization in network topology, making it impossible to effectively manage and control network traffic.

Method used

By monitoring sudden changes in network traffic data, abnormal traffic ranges can be identified, and network link bandwidth can be adjusted according to bandwidth thresholds. The bandwidth change values ​​can be recorded, the network topology can be mapped, the target traffic path can be determined, and the traffic transmission path can be optimized.

Benefits of technology

It improves network transmission efficiency and stability, enables precise control and visualization of abnormal traffic, and optimizes network traffic paths.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098711B_ABST
    Figure CN121098711B_ABST
Patent Text Reader

Abstract

The present disclosure provides a traffic anomaly processing method and device, electronic equipment and storage medium. In response to monitoring that the traffic data of a monitoring network has a mutation, a traffic anomaly interval is determined. A preset bandwidth threshold is obtained, the network link bandwidth in the traffic anomaly interval is adjusted according to the bandwidth threshold, and a bandwidth adjustment change value is recorded. A network topology graph corresponding to the monitoring network is obtained, the network topology graph is mapped and processed according to the bandwidth adjustment change value, and a traffic mapping network topology is obtained. A target traffic path is determined according to the traffic mapping network topology, and the traffic transmission is controlled according to the target traffic path, wherein the target traffic path is a path from the starting position of the traffic anomaly interval to the end position of the traffic anomaly interval. The present disclosure optimizes the network traffic path when there is abnormal traffic, and improves the transmission efficiency and stability of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of traffic analysis, and in particular to a method, apparatus, electronic device, and storage medium for handling traffic anomalies. Background Technology

[0002] Traditional methods for detecting network traffic anomalies primarily rely on rule matching and statistical analysis. However, these methods have many limitations when dealing with complex and ever-changing network environments. For example, they often suffer from slow processing speeds and poor real-time performance when handling large-scale network traffic.

[0003] In addition, existing systems are inadequate in terms of traffic distribution mapping and traffic path optimization in network topology, and cannot effectively manage and control network traffic. Summary of the Invention

[0004] In view of this, the purpose of this disclosure is to provide a method, apparatus, electronic device and storage medium for handling traffic anomalies in order to solve the current problems.

[0005] To achieve the above objectives, a first aspect of this disclosure provides a method for handling traffic anomalies, the method comprising:

[0006] In response to a sudden change in traffic data detected in the monitored network, the abnormal traffic range is determined;

[0007] Obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value;

[0008] Obtain the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology;

[0009] The target traffic path is determined based on the traffic mapping network topology, and traffic transmission is controlled based on the target traffic path, wherein the target traffic path is the path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval.

[0010] Based on the same inventive concept, a second aspect of this disclosure proposes a flow anomaly processing device, comprising:

[0011] The monitoring module is configured to determine the abnormal traffic range in response to a sudden change in the traffic data of the monitored network;

[0012] The adjustment module is configured to obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value.

[0013] The mapping module is configured to acquire the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology.

[0014] The path determination module is configured to determine a target traffic path based on the traffic mapping network topology and control traffic transmission based on the target traffic path, wherein the target traffic path is a path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval.

[0015] Based on the same inventive concept, a third aspect of this disclosure proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the traffic anomaly handling method as described above when executing the computer program.

[0016] Based on the same inventive concept, a fourth aspect of this disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the traffic anomaly handling method described above.

[0017] As can be seen from the above, this disclosure proposes a method, apparatus, electronic device, and storage medium for handling traffic anomalies. If a sudden change in traffic data of the monitored network is detected, it indicates the presence of abnormal traffic in the monitored network, and an abnormal traffic interval is determined. The network link bandwidth within the abnormal traffic interval is adjusted according to a bandwidth threshold to limit the spread of abnormal traffic. The bandwidth adjustment change value is recorded, and the network topology is mapped based on the bandwidth adjustment change value to obtain a traffic-mapped network topology. A traffic distribution mapping label is formed on the network topology map, allowing administrators to intuitively see the distribution and trend of abnormal traffic in the network. A target traffic path is determined based on the traffic-mapped network topology, wherein the target traffic path is the path from the start position to the end position of the abnormal traffic interval. Traffic transmission is controlled according to the target traffic path. By determining the target traffic path, the network traffic path is optimized, improving the network transmission efficiency and stability. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in this disclosure or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart of a traffic anomaly handling method according to an embodiment of this disclosure;

[0020] Figure 2 This is a schematic diagram of the workflow of the traffic anomaly handling system according to an embodiment of the present disclosure;

[0021] Figure 3 This is a structural block diagram of the traffic anomaly handling device according to an embodiment of the present disclosure;

[0022] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of this disclosure clearer, the following detailed description is provided in conjunction with specific embodiments and the accompanying drawings.

[0024] It should be noted that, unless otherwise defined, the technical or scientific terms used in the embodiments of this disclosure should have the ordinary meaning understood by one of ordinary skill in the art to which this disclosure pertains. The terms "first," "second," and similar terms used in the embodiments of this disclosure do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Terms such as "comprising" or "including" mean that the element or object preceding the word encompasses the elements or objects listed following the word and their equivalents, without excluding other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. Terms such as "upper," "lower," "left," and "right" are used only to indicate relative positional relationships; when the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0025] The following are definitions of terms used in this disclosure:

[0026] A* Algorithm: The A* algorithm is a classic heuristic search algorithm widely used in path planning, graph search, and artificial intelligence. It combines the advantages of Dijkstra's algorithm (guaranteeing to find the shortest path) and greedy algorithms (heuristic search to improve efficiency), and can efficiently find the optimal path from the starting point to the destination.

[0027] RRT*: The RRT* (Rapidly-exploring Random Tree Star) algorithm is an improved version of the RRT (Rapidly-exploring Random Tree) algorithm, designed to address the problem of low-quality paths generated by RRT. The RRT* algorithm introduces a path optimization mechanism to find paths closer to the optimal path while ensuring path feasibility.

[0028] Traditional methods for detecting network traffic anomalies primarily rely on techniques such as rule matching and statistical analysis. However, these methods have many limitations when facing complex and ever-changing network environments. For example, rule matching methods require the pre-definition of a large number of rules and often fail to detect new types of abnormal traffic in a timely manner; statistical analysis methods, on the other hand, are heavily dependent on statistical models of normal traffic, and are prone to false positives or false negatives when the network environment changes.

[0029] With the widespread application of deep learning technology in various fields, its application in network traffic anomaly detection has become a research hotspot. However, existing deep learning-based network traffic anomaly detection systems still have some problems in practical applications. For example, in terms of traffic feature extraction, they often fail to extract key traffic features comprehensively and accurately; and in determining abnormal intervals and executing intervention operations, there is a lack of effective strategies and methods, resulting in low detection efficiency and accuracy.

[0030] Existing network traffic anomaly detection systems often suffer from slow processing speed and poor real-time performance when dealing with large-scale network traffic. This is because traditional detection methods have high computational complexity when processing large amounts of data, making it difficult to meet the requirements of real-time detection. Furthermore, existing systems also have shortcomings in network topology mapping of traffic distribution and traffic path optimization, failing to effectively manage and control network traffic.

[0031] Existing network traffic anomaly detection systems lack flexible intervention strategies and effective dynamic correction mechanisms for anomaly intervention. When abnormal traffic is detected, they often adopt fixed intervention methods, failing to adjust according to the actual situation, resulting in poor intervention effects. Furthermore, the inability to dynamically correct output indicators in real time during intervention further impacts the performance of the detection system.

[0032] Therefore, this embodiment proposes a method for handling traffic anomalies, such as... Figure 1 As shown, the method includes:

[0033] Step 101: In response to the detection of a sudden change in the traffic data of the monitoring network, determine the abnormal traffic range.

[0034] Step 102: Obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value.

[0035] Step 103: Obtain the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology.

[0036] Step 104: Determine the target traffic path according to the traffic mapping network topology, and control traffic transmission according to the target traffic path, wherein the target traffic path is the path from the starting position of the traffic anomaly interval to the ending position of the traffic anomaly interval.

[0037] In practice, traffic data from the monitoring network is collected in real time. If a sudden change in traffic data is detected, i.e., a sudden change occurs, the abnormal traffic range is determined. The abnormal traffic range refers to the location and extent of the anomaly when traffic is abnormal.

[0038] In this embodiment, traffic data can be collected in real time by sensors, and the traffic data at the next moment can be compared with the traffic data at the current moment. When the difference between the two is greater than a preset threshold, it is determined that a sudden change has occurred in the traffic data.

[0039] A preset bandwidth threshold is obtained, and the network link bandwidth within the abnormal traffic range is adjusted according to the bandwidth threshold. For example, if the bandwidth threshold is 800Mbps and the network link bandwidth within the current abnormal traffic range is 1Gbps, then the original 1Gbps bandwidth of the link is temporarily adjusted to 800Mbps to limit the spread of abnormal traffic.

[0040] During bandwidth adjustment, the bandwidth adjustment changes are recorded in real time. For example, for normal traffic in an office subnet, the upper limit of its bandwidth strength parameter is preset to 700Mbps, and the lower limit to 500Mbps. When the collected bandwidth strength parameter exceeds this preset constraint threshold, such as detecting a traffic bandwidth strength of 850Mbps, exceeding the upper limit of 700Mbps, the link bandwidth is further adjusted to limit it to the preset upper limit of 700Mbps, ensuring that the traffic bandwidth strength does not exceed this threshold, thereby preventing abnormal traffic from causing greater impact on the network. Simultaneously, starting at 10:05, traffic transmission values ​​are recorded every 10 seconds, resulting in a series of data, i.e., bandwidth adjustment changes, such as 750Mbps at 10:05:00, 720Mbps at 10:05:10, and 710Mbps at 10:05:20.

[0041] A network topology map corresponding to the monitored network is obtained. This network topology map is a visual representation of the entire network structure, including devices, links, and their connections. The network topology map is mapped based on the bandwidth adjustment change value to obtain a traffic-mapped network topology. This results in a traffic distribution mapping on the network topology map, allowing administrators to visually observe the distribution and trends of abnormal traffic within the network.

[0042] The target traffic path is determined based on the traffic mapping network topology, and traffic transmission is controlled based on the target traffic path, wherein the target traffic path is the path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval.

[0043] The above scheme identifies a sudden change in network traffic data, indicating abnormal traffic. An abnormal traffic range is then determined. The network link bandwidth within this range is adjusted based on a bandwidth threshold to limit the spread of abnormal traffic. The bandwidth adjustment change is recorded, and the network topology is mapped using this value to obtain a traffic-mapped network topology. This creates a traffic distribution map on the network topology, allowing administrators to visually observe the distribution and trends of abnormal traffic. A target traffic path is then determined based on the traffic-mapped network topology, extending from the beginning to the end of the abnormal traffic range. Traffic transmission is controlled according to this target path, optimizing network traffic paths and improving network transmission efficiency and stability.

[0044] In some embodiments, step 101, in response to detecting a sudden change in traffic data of the monitored network, determines the abnormal traffic range, specifically including:

[0045] Step 1011: In response to the detection of a sudden change in the traffic data of the monitored network, determine the time of the sudden change;

[0046] Step 1012: Determine the time for the flow data to recover from the sudden change to the normal flow parameter range;

[0047] Step 1013: Determine the abnormal flow range based on the time of the mutation and the parameter recovery time.

[0048] In practice, network traffic data can be continuously monitored in real time through a traffic acquisition module. This data includes parameters such as traffic volume, transmission rate, and number of data packets. When a sudden change in network traffic data is detected, a change recording mechanism is immediately triggered. The system generates a timestamp of the time of the change, which is the exact time of the change. This timestamp is accurate to the millisecond level and records the specific moment of the traffic change. The timestamp generation is based on an internal clock module that synchronizes with a standard time source via the Network Time Protocol (NTP) to ensure accuracy and consistency.

[0049] The process involves determining the recovery time of the traffic data from the abrupt change to the normal traffic parameter range. Specifically, after recording the timestamp data, the traffic parameters are continuously monitored to find the critical point at which the parameters recover from the abnormal state to the normal state, i.e., the parameter recovery critical point. Here, the normal state refers to the normal traffic parameter range preset by the system, which is obtained through statistical analysis of historical normal traffic data.

[0050] The system compares the real-time monitored parameters with the normal range. When the parameter gradually falls back from outside the normal range and enters the normal range, the parameter recovery critical point can be determined. After determining this critical point, the system records the cycle number of the recovery moment. The cycle number is set to identify the position of the parameter recovery moment within the entire monitoring cycle. The monitoring cycle can be set according to actual needs, such as 1 minute, 5 minutes, etc. At the beginning of each monitoring cycle, the cycle number is reset to facilitate the differentiation and management of parameter recovery in different cycles.

[0051] The abnormal traffic range is determined based on the occurrence time of the mutation and the recovery time of the parameters. Specifically, mutation coordinates and recovery coordinates are generated based on timestamp data and period numbers. The timestamp data and period numbers need to be converted into spatial location information. Specifically, the timestamp data can be mapped to a time axis in spatial coordinates, while the period number can be combined with the length of the monitoring period to convert it into a specific time segment on the time axis. Then, the mutation and recovery times on the time axis are combined with the spatial location information in the network topology to generate mutation coordinates and recovery coordinates. This spatial location information includes the location of the traffic acquisition module in the network topology, the deployment location of the traffic control module, and the connection relationships of network links.

[0052] A closed interval is formed by spatially correlating the mutation coordinates, recovery coordinates, and the location of the traffic acquisition module. The location of the traffic acquisition module in the network topology is known; its connections and relative positions with other network devices can be determined using the network topology map. Spatially correlating the mutation and recovery coordinates with the location of the traffic acquisition module involves finding the connections and spatial range between these three points in the network topology map. Through spatial geometric calculations, a closed interval is formed with the mutation coordinates, recovery coordinates, and the location of the traffic acquisition module as vertices. The formation of this closed interval needs to consider the actual connectivity of network links to ensure that the interval can accurately identify areas in the network where traffic anomalies occur.

[0053] After a closed interval is formed, it is marked as an anomalous interval. This marking process is implemented through the visualization interface of the intelligent analysis platform, using specific colors or symbols to annotate the anomalous intervals on the network topology map, allowing administrators to intuitively see the location and extent of the anomaly. Simultaneously, the system stores relevant information about the anomalous intervals, such as mutation coordinates, recovery coordinates, and formation time, in a database for subsequent querying and analysis.

[0054] The above scheme accurately records and processes periods of traffic surges and parameter recovery, ensuring the accuracy and reliability of anomaly identification. Precise recording of timestamp data and cycle numbers accurately reflects the time points of traffic anomalies and their recovery. By combining time information with spatial location information, the system accurately identifies the areas where anomalies occur, providing precise target locations for subsequent anomaly intervention and traffic control. Furthermore, the system backs up recorded timestamp data, cycle numbers, surge coordinates, and recovery coordinates to prevent data loss and ensure that this data can be retrieved and used whenever needed.

[0055] In some embodiments, step 103, which maps the network topology map according to the bandwidth adjustment change value to obtain a traffic-mapped network topology, specifically includes:

[0056] Step 1031: Based on the bandwidth change adjustment value, a variational autoencoder is used to generate a dynamic traffic feature map;

[0057] Step 1032: Extract multiple key feature points from the traffic dynamic feature map according to a preset time interval;

[0058] Step 1033: Map the network topology graph according to the multiple key feature points to obtain the traffic-mapped network topology.

[0059] In practice, a variational autoencoder (VAE) is used to generate a dynamic traffic feature map based on the bandwidth change adjustment value. A VAE is a deep learning model capable of dimensionality reduction encoding of high-dimensional data and reconstructing its features. The bandwidth change adjustment value is input into a pre-trained VAE model, which automatically learns the latent feature representations of the traffic data and then reconstructs a dynamic traffic feature map based on these features. In the generated dynamic traffic feature map, the horizontal axis represents time, and the vertical axis represents the feature dimension of the traffic. The curves or color blocks in the map reflect the feature changes of the traffic at different time points. For example, the map might show that between 10:05 and 10:10, the traffic features exhibit a high-frequency fluctuation pattern, which contrasts sharply with the stable characteristics of normal traffic.

[0060] A preset time interval is obtained, and multiple key feature points are extracted from the traffic dynamic feature map according to the preset time interval. That is, a number of key feature points are extracted from the traffic dynamic feature map at equal time intervals, and the number of key feature points is proportional to the duration of the map. For example, if the duration of the map is 5 minutes, and one key feature point is extracted every 30 seconds, a total of 10 key feature points are extracted. Each key feature point contains the traffic feature vector at that time point, such as traffic volume, frequency domain characteristics, and change trend. The purpose of extracting key feature points is to simplify the map data while retaining the main features of traffic changes, which facilitates subsequent traffic distribution mapping of the network topology.

[0061] Traffic distribution mapping and annotation are performed on the network topology map based on extracted key feature points. The network topology map is a visual representation of the entire network structure, including devices, links, and their connections. The extracted key feature points are mapped to specific locations on the network topology map, i.e., the links and devices where abnormal intervals occur.

[0062] Specifically, based on the bandwidth adjustment change value, a variational autoencoder is used to generate a dynamic traffic feature map. This map, through learning and reconstructing the bandwidth adjustment change data, can reflect the characteristic changes in traffic at different time points. At preset time intervals, multiple key feature points are extracted from the dynamic traffic feature map. These key feature points contain traffic feature vectors for the corresponding time points, such as traffic volume and trend information. Based on the extracted key feature points, they are mapped to the links and devices where abnormal intervals are located in the network topology map, performing traffic distribution mapping and annotation. This completes the mapping process of the network topology map, resulting in a traffic-mapped network topology.

[0063] For example, in the network topology diagram, the key characteristic point at 10:05 AM is marked on the link from the core switch to the Layer 3 switch in the office subnet, and different colors or icons are used to represent the traffic characteristic intensity at that time. In this way, a traffic distribution mapping is formed on the network topology diagram, allowing administrators to intuitively see the distribution and changing trends of abnormal traffic in the network.

[0064] The generated traffic feature maps and mapping labels are updated in real time using the above method, enabling the generation of more effective control strategies. Furthermore, the system backs up all data generated during processing, including sets of changing parameters, key feature points, and traffic feature maps, to prevent data loss and facilitate subsequent querying and analysis. This approach achieves precise control and visualization of abnormal traffic, providing strong support for the detection and intervention of network traffic anomalies.

[0065] In some embodiments, determining the target traffic path based on the traffic mapping network topology in step 104 specifically includes:

[0066] Step 1041: Obtain the start and end positions corresponding to the abnormal traffic interval, and determine the access position of the target abnormal interval based on the traffic mapping network topology, the start position, and the end position;

[0067] Step 1042: Perform parameter synchronization processing on the starting position, the ending position, and the target abnormal interval access position;

[0068] Step 1043: In response to the completion of parameter synchronization, the target traffic path is determined to be from the starting position, through the target abnormal interval access position, to the ending position.

[0069] In specific implementation, the starting and ending positions corresponding to the abnormal traffic interval are obtained, and the target abnormal interval access position is determined based on the traffic mapping network topology, the starting position, and the ending position. For example, in the current network topology, the starting position corresponding to the abnormal traffic interval is router A, and the ending position of the abnormal interval, i.e., the next-hop forwarding node, is the aggregation router B. The target abnormal interval access position is determined to be backup link D based on the traffic mapping network topology, the starting position, and the ending position.

[0070] The starting position, the ending position, and the target abnormal interval access position are synchronized. After synchronization is complete, the abnormal interval is entered from the access position to obtain the target traffic path. That is, the target traffic path is from the starting position, through the target abnormal interval access position, to the ending position.

[0071] Based on the above example, the target traffic path is determined to be from router A to backup link D, and finally to aggregation router B.

[0072] In some embodiments, determining the target abnormal interval access location based on the traffic mapping network topology, the starting location, and the ending location in step 1041 includes:

[0073] Step 10411: Based on the traffic mapping network topology, find multiple initial network paths from the starting position to the ending position;

[0074] Step 10412: Determine the number of network hops and the latency parameter corresponding to each initial network path, and determine the comprehensive index value corresponding to each initial network path based on the number of network hops and the latency parameter;

[0075] Step 10413: Select the initial network path with the largest comprehensive index value as the target network path, and take the node positions in the target network path other than the starting position and the ending position as the target abnormal interval access positions.

[0076] In specific implementation, multiple initial network paths from the initial position to the endpoint position are found according to the traffic mapping network topology. Among these multiple initial network paths, the network path currently used corresponding to the current abnormal interval is not included.

[0077] The network hop count and latency parameters corresponding to each initial network path are determined, and a comprehensive index value corresponding to each initial network path is determined based on the network hop count and latency parameters. The following describes the specific method for determining the comprehensive index value for each initial network path:

[0078] Step A: Determine the initial two-dimensional evaluation matrix based on the network hop count and latency parameters corresponding to the initial network path;

[0079] Step B: Normalize the initial two-dimensional evaluation matrix to obtain a two-dimensional evaluation matrix, wherein the two-dimensional evaluation matrix includes the normalized network hop count and the normalized delay parameter.

[0080] Step C: Obtain a preset weight value, and perform weighted processing on the normalized network hop count and normalized delay parameter according to the preset weight value to obtain the comprehensive index value corresponding to the initial network path.

[0081] In practice, a comprehensive evaluation is performed based on network hop count and latency parameters to establish an initial two-dimensional evaluation matrix containing the number of operation steps and latency values. This initial two-dimensional evaluation matrix is ​​then normalized by converting the network hop count and latency into values ​​between 0 and 1. This results in a two-dimensional evaluation matrix that includes normalized network hop count and normalized latency parameters.

[0082] Obtain preset weight values, which include a first weight value corresponding to the normalized network hop count and a second weight value corresponding to the normalized delay parameter. Perform weighted processing on the normalized network hop count and the normalized delay parameter according to the preset weight values ​​to obtain a comprehensive index value corresponding to the initial network path.

[0083] The initial network path with the largest comprehensive index value is selected as the target network path, and the node positions in the target network path other than the starting position and the ending position are selected as the target abnormal interval access positions.

[0084] The following is a specific example to illustrate this:

[0085] In the current network topology, the next-hop forwarding node in the abnormal section is the aggregation router B. Its subsequent switchable forwarding paths include bypassing to the target server cluster via router C or directly connecting via backup link D. Going via router C requires 5 steps with a delay of 15ms, while going via backup link D requires 3 steps with a delay of 8ms. The normalized network hop count is 0.6 (router C) and 0.4 (backup link D), and the normalized delay parameters are 0.4 (router C) and 0.6 (backup link D).

[0086] Linear discriminant analysis (LDA) is used to extract the first principal component (PPC) as the comprehensive evaluation index. LDA determines the weighting coefficients for the number of operation steps and the delay value based on their importance in the evaluation. These weighting coefficients are derived from the statistical regularities of the impact of operation complexity and delay on network performance in historical network operation data. For the path through router C, its normalized operation process value and normalized delay value each correspond to certain values. The comprehensive evaluation index for this path is calculated using the weighting coefficients of the first principal component. For the backup link D, the same calculation is performed based on its normalized operation process value and normalized delay value, combined with the same weighting coefficients. Because the combination of the normalized results and weighting coefficients for the number of operation steps and the delay value is more effective for backup link D, its calculated comprehensive evaluation index value is greater than that of the path through router C. Therefore, the comprehensive evaluation index value for backup link D is larger.

[0087] In some embodiments, after determining the network hop count and latency parameters corresponding to each initial network path, when determining the target network path from multiple initial network paths, a path planning algorithm can also be used, specifically including:

[0088] Path planning algorithms are search algorithms for finding the optimal path. They guide the search direction by comprehensively considering the actual cost and estimated cost of the path, in order to efficiently find the optimal solution. These path planning algorithms include Dijkstra's algorithm, A* algorithm, Hybrid A* algorithm, or RRT* algorithm, etc.

[0089] Dijkstra's algorithm is a classic breadth-first search algorithm suitable for shortest path search in static environments. It finds the global optimum by traversing all possible paths, but it is computationally expensive and suitable for small-scale graphs. A* combines Dijkstra's algorithm with heuristic search, improving search efficiency through an evaluation function (such as Manhattan distance). It can quickly find a path, but the path may not be globally optimal. Hybrid A* adds vehicle kinematic constraints to A, making it suitable for scenarios such as autonomous driving where direction and turning radius need to be considered. RRT* rapidly expands the search tree through random sampling, suitable for path planning in high-dimensional spaces. It can progressively optimize the path, but its convergence speed is slow.

[0090] Specifically, when calculating feasible access locations for each anomalous interval using path planning algorithms, factors such as network link hop count, latency, and bandwidth are considered to evaluate the cost of each feasible access location. The actual cost may include the number of operational steps required to reach that location, i.e., network hop count, while the estimated cost may involve parameters such as latency to the target node. After calculating the total cost of each feasible access location based on these factors, a comprehensive evaluation is performed in conjunction with operational procedures and latency parameters. This provides a basis for selecting the access location for the anomalous interval with the shortest operational procedure and the lowest latency.

[0091] For example, a path planning algorithm is used to calculate the feasible access locations for each abnormal interval. The path planning algorithm takes into account factors such as the number of hops, latency, and bandwidth of the network link. For example, the total cost of the path through router C is calculated to be (3 hops, 15ms latency), and the total cost of the path through backup link D is calculated to be (2 hops, 8ms latency).

[0092] In some embodiments, step 1042, which involves parameter synchronization processing of the starting position, the ending position, and the target abnormal interval access position, specifically includes:

[0093] Step 10421: Obtain the first routing information corresponding to the starting position, the second routing information corresponding to the ending position, and the third routing information corresponding to the target abnormal interval access position;

[0094] Step 10422: Compare the first routing information, the second routing information, and the third routing information to determine that the comparison result is consistent with the routing table, and obtain the network parameters corresponding to the access location of the target abnormal interval;

[0095] Step 10423: Compare the network parameters with a preset parameter threshold. In response to the network parameters being within the preset parameter threshold range, parameter synchronization is completed.

[0096] In practice, the first step is to negotiate a routing protocol with the network device at the access location of the target abnormal interval. Specifically, routing information can be exchanged via the BGP protocol. This involves obtaining the first routing information corresponding to the starting location, the second routing information corresponding to the ending location, and the third routing information corresponding to the access location of the target abnormal interval, and then comparing these three sets of information.

[0097] When the comparison result shows that the routing table is consistent, the network parameters corresponding to the access location of the target abnormal interval are obtained, wherein the network parameters include the current bandwidth utilization, latency, packet loss rate, etc.

[0098] The network parameters are compared with a preset parameter threshold, where the preset parameter threshold is a preset normal parameter range. In response to the network parameters falling within the preset parameter threshold range, parameter synchronization is confirmed.

[0099] In some embodiments, when controlling traffic transmission according to the target traffic path, the traffic path from the starting point to the ending point is changed to the target traffic path by modifying routing table entries. Based on the foregoing example, the original traffic path from core router A to aggregation router B is switched to core router A → backup link D → aggregation router B.

[0100] Simultaneously, traffic in abnormal ranges can be rate-limited, for example, by limiting the bandwidth of that link to 800Mbps and enabling traffic shaping technology to ensure that sudden traffic surges do not cause network congestion. The system continuously monitors the traffic status in abnormal ranges and provides real-time feedback.

[0101] The algorithm acquires real-time output metrics for traffic anomalies after adopting the target traffic path and dynamically corrects these metrics using the RMSprop optimization algorithm. Output metrics include traffic transmission rate, latency, and packet loss rate. For example, real-time monitoring might show a link latency of 10ms and a packet loss rate of 0.5% after a switchover. The RMSprop optimization algorithm adjusts traffic control parameters based on historical and real-time data, such as dynamically adjusting rate limiting thresholds or queue lengths for traffic shaping, to adapt to changes in network conditions. For instance, if the packet loss rate is detected to be rising to 1%, the algorithm will automatically adjust the rate limiting threshold from 800Mbps to 750Mbps to reduce link load.

[0102] After each continuous forwarding operation is completed within a traffic anomaly interval, the traffic control module pauses output and exits the anomaly interval, then re-determines the access location for the target anomaly interval. For example, when traffic is successfully forwarded from core router A to aggregation router B via backup link D, completing one continuous forwarding operation, traffic transmission to that anomaly interval is temporarily stopped, and the current intervention state is exited. Then, the access location for the target anomaly interval is re-determined, and the need to switch access locations or adjust the intervention strategy is reassessed. Assuming that the latency of another backup link E in the network decreases at this time, the system recalculates using the A* algorithm and finds that link E has a better overall evaluation index. Therefore, link E is selected as the new access location, and a new target traffic path is determined, continuously providing dynamic intervention for the traffic anomaly interval.

[0103] Throughout the intervention process, the status of the traffic control module and changes in network traffic are monitored in real time. For example, when traffic in the abnormal range returns to normal, the system controls the transmission path of the restored traffic. Simultaneously, the system records the time, access location, adjusted parameters, and output metrics for each intervention operation, creating a detailed intervention log for subsequent analysis of intervention effectiveness and optimization of control strategies. Through this iterative intervention approach, dynamic tracking and precise control of abnormal traffic are achieved, ensuring stable network operation even under abnormal conditions.

[0104] Based on the same inventive concept, another embodiment of this disclosure provides a traffic anomaly handling system, the system comprising: a traffic acquisition module, a traffic control module, and an intelligent analysis platform, wherein the traffic acquisition module and the traffic control module are respectively communicatively connected to the intelligent analysis platform, and the intelligent analysis platform includes a feature extraction unit, a pattern modeling unit, and an anomaly intervention unit.

[0105] like Figure 2 As shown, Figure 2 A schematic diagram of the workflow of the traffic anomaly handling system is shown, which specifically includes:

[0106] The traffic acquisition module is used to collect network link traffic data and protocol parameters in real time. The traffic acquisition module includes a module housing and, housed within the housing, multi-source sensors, a feature analysis device, a status assessment module, and a transmission module. The module housing is made of metal, providing excellent protection against external electromagnetic interference and mechanical protection for the internal devices. The housing has multiple interfaces for connecting the network link and the wiring of the internal devices.

[0107] Multi-source sensing devices are deployed at critical nodes in the network link and consist of multiple sensors of different types, including traffic sensors and port status sensors. Traffic sensors are used to synchronously acquire packet traffic data. Specifically, they connect to the network link through mirrored ports or optical splitters, capturing flowing network packets in real time, parsing information such as source IP address, destination IP address, port number, protocol type, and packet length, and storing this information in a time-series format. Port status sensors are used to acquire port status monitoring data, monitoring the working status of network device ports in real time, such as port open / close status, link negotiation rate, duplex mode, number of error frames, packet loss rate, and other parameters. These sensors are directly connected to the ports through hardware interfaces to ensure the real-time nature and accuracy of data acquisition.

[0108] The feature analysis device is electrically connected to the multi-source sensing device to receive the traffic flow data it collects. The device integrates a signal processing unit, employing digital signal processing technology to preprocess the traffic flow data, removing noise and interference signals. Then, a Fourier transform algorithm is used to perform frequency domain transformation on the preprocessed traffic flow data, converting the time-domain traffic flow sequence into a frequency-domain spectral distribution. By analyzing the amplitude and phase changes of each frequency component in the spectrum, the frequency domain fluctuation characteristics of the traffic flow data are extracted, such as the energy distribution of different frequency components, the changing trend of the dominant frequency component, and the periodicity of frequency domain fluctuations. These characteristic parameters reflect the dynamic changes in traffic flow in the frequency domain, providing crucial information for subsequent anomaly detection.

[0109] The state assessment module is built upon a Transformer network, which is pre-trained on a large amount of historical normal traffic data. After the feature parsing device extracts the current frequency domain fluctuation features, the state assessment module inputs them into the Transformer network. The encoder layer inside the network encodes the features, capturing long-distance dependencies between features through a self-attention mechanism, and then compares them with historical standard patterns stored in the model. These historical standard patterns are typical patterns obtained through statistical analysis of a large amount of traffic frequency domain features under normal operating conditions, encompassing the feature distribution range and variation patterns of normal traffic in the frequency domain.

[0110] The status assessment module determines the network anomaly index by calculating the correlation coefficient between current features and historical standard patterns. The correlation calculation uses methods such as cosine similarity to measure the angle between the current feature vector and the standard pattern vector; the smaller the angle, the higher the correlation and the lower the anomaly index; conversely, the larger the angle, the higher the anomaly index. When the calculated anomaly index exceeds a preset threshold, the status assessment module triggers an alarm signal. This alarm signal is output through a hardware interface and can be connected to an alarm indicator light or alarm system to alert administrators to potential network anomalies.

[0111] The transmission module uploads monitoring data to the intelligent analysis platform, utilizing the SD-WAN protocol for data transmission. The SD-WAN protocol features flexible routing strategies and an efficient transmission mechanism. The transmission module first encapsulates the collected monitoring data, including traffic data, port status data, frequency domain characteristic data, and anomaly indices, adding protocol header information such as source address, destination address, and data type. Then, according to the SD-WAN protocol's routing rules, it selects the optimal transmission path, considering factors such as link bandwidth, latency, and packet loss rate to ensure stable and fast data upload. During transmission, the module encrypts the data to ensure its security and integrity, preventing theft or tampering. Upon arrival at the intelligent analysis platform, the transmission module verifies the data to ensure consistency between the received and transmitted data. If data loss or errors occur, the module retransmits the corresponding data to guarantee that the intelligent analysis platform receives complete and accurate monitoring data, providing reliable data support for subsequent feature extraction, pattern modeling, and anomaly intervention.

[0112] The traffic control module is used to receive control commands from the intelligent analysis platform to adjust the network traffic status.

[0113] The protocol conversion module consists of a protocol processing chip and a protocol conversion engine, supporting the conversion of multiple network protocols. When network traffic from different protocols needs to interact, the module first receives the input data packets. The protocol processing chip parses the protocol type of the data packets, such as TCP / IP, UDP, ARP, etc. Then, the protocol conversion engine re-encapsulates the header and content of the data packets according to the format requirements of the target protocol. For example, when converting a TCP / IP data packet to another protocol, the engine extracts the payload from the original data packet, adds new header information according to the target protocol's header format, and forms a new data packet. During the protocol conversion process, the module maintains a protocol mapping table, recording the field mapping relationships between different protocols to ensure that data is not lost or corrupted during conversion. Furthermore, the module supports protocol adaptation and conversion parameter configuration. Users can adjust the protocol conversion parameters by sending configuration commands through the command response module to adapt to different network environments and application scenarios. By implementing the conversion between different protocols, the module ensures that the traffic control module can communicate and interact with different types of network devices, improving the system's compatibility and adaptability.

[0114] The feature extraction unit is used to determine the abnormal interval by recording the traffic mutation period and parameter recovery period during the operation of the traffic control module, control the traffic control module to maintain the operation of the abnormal traffic at a preset constraint threshold and record the changed parameters, generate a traffic feature map based on the changed parameters and perform traffic distribution mapping on the network topology map.

[0115] The pattern modeling unit optimizes traffic paths on the network topology map after traffic distribution mapping and generates control strategies. The anomaly intervention unit includes a steady-state management unit and an emergency management unit. The steady-state management unit controls the traffic control module to execute the baseline traffic pattern when it is in a normal state. The emergency management unit controls the traffic control module to perform intervention operations within the abnormal range according to the control strategy when the traffic control module detects an abnormal state.

[0116] In the traffic anomaly handling system described in this embodiment, during the traffic acquisition stage, the traffic acquisition module can simultaneously acquire packet traffic data and port status monitoring data with the help of multi-source sensing devices. The feature analysis device can extract the frequency domain fluctuation characteristics of the traffic data. Combined with the status assessment module based on the Transformer network, it can accurately determine the network operation anomaly index and trigger alarm signals. At the same time, data is uploaded through the SD-WAN protocol, ensuring the comprehensiveness, accuracy and efficiency of data acquisition and transmission.

[0117] The feature extraction unit identifies abnormal intervals by recording the periods of traffic spikes and parameter recovery during the operation of the traffic control module. It then controls the traffic control module to operate within preset constraint thresholds and records changing parameters, thereby generating a traffic feature map and mapping the network topology to traffic distribution. This series of operations enables precise location and feature analysis of abnormal traffic, laying a solid foundation for subsequent traffic management and control.

[0118] The pattern modeling unit optimizes the traffic paths of the network topology map after completing the traffic distribution mapping, generates control strategies, and effectively optimizes the network traffic paths by logically isolating the preset traffic paths that overlap with high-traffic segments in the network topology map, thereby improving the network transmission efficiency and stability.

[0119] The anomaly intervention unit comprises a steady-state management unit and an emergency management unit. Under normal conditions, the steady-state management unit controls the traffic regulation module to execute the baseline traffic mode to ensure the normal operation of the network. When an anomaly is detected, the emergency management unit performs intervention operations within the abnormal range through a series of steps according to the regulation strategy. For example, it uses the A* algorithm to select the optimal access location and uses the RMSprop optimization algorithm to dynamically correct the output indicators. This achieves precise intervention and dynamic adjustment of abnormal traffic, improving the system's anomaly handling capability and response speed.

[0120] Through the collaborative work of its various modules, the entire system achieves real-time collection, precise analysis, optimized control, and effective intervention of network traffic, significantly improving the accuracy and real-time performance of network traffic anomaly detection. This enables it to better cope with complex and ever-changing network environments and ensure the secure and stable operation of the network. Furthermore, the system exhibits high processing efficiency and real-time performance when handling large-scale network traffic, meeting the needs of networks of varying sizes. In addition, the close communication connections between the system's modules and efficient data transmission guarantee the coordinated operation and stable functioning of the entire system.

[0121] It should be noted that the method of this disclosure embodiment can be executed by a single device, such as a computer or server. The method of this embodiment can also be applied to a distributed scenario, where multiple devices cooperate to complete the task. In such a distributed scenario, one of these devices may execute only one or more steps of the method of this disclosure embodiment, and the multiple devices will interact with each other to complete the method described.

[0122] It should be noted that the above description describes some embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in a different order than that shown in the above embodiments and still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0123] Based on the same inventive concept, corresponding to any of the above-described embodiments, this disclosure also provides a flow anomaly processing device.

[0124] refer to Figure 3 , Figure 3 The traffic anomaly handling apparatus of the embodiment includes:

[0125] Monitoring module 201 is configured to determine the abnormal traffic range in response to a sudden change in the traffic data of the monitored network;

[0126] The adjustment module 202 is configured to obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value.

[0127] The mapping module 203 is configured to acquire the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology;

[0128] The path determination module 204 is configured to determine a target traffic path based on the traffic mapping network topology and control traffic transmission based on the target traffic path, wherein the target traffic path is a path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval.

[0129] In some embodiments, the monitoring module 201 is specifically configured as follows:

[0130] In response to a detected abrupt change in traffic data of the monitored network, the time of the abrupt change is determined;

[0131] Determine the time required for the flow data to recover from the sudden change to the normal flow parameter range;

[0132] The abnormal flow range is determined based on the time of the mutation and the recovery time of the parameters.

[0133] In some embodiments, the mapping module 203 is specifically configured as follows:

[0134] Based on the bandwidth change adjustment value, a variational autoencoder is used to generate a dynamic traffic feature map;

[0135] According to a preset time interval, multiple key feature points are extracted from the dynamic feature map of the traffic flow.

[0136] The network topology is mapped based on the multiple key feature points to obtain a traffic-mapped network topology.

[0137] In some embodiments, the path determination module 204 is specifically configured as follows:

[0138] Obtain the start and end positions corresponding to the abnormal traffic interval, and determine the access position of the target abnormal interval based on the traffic mapping network topology, the start position, and the end position;

[0139] The starting position, the ending position, and the target abnormal interval access position are subjected to parameter synchronization processing;

[0140] In response to the completion of parameter synchronization, the target traffic path is determined to be from the starting position, through the target abnormal interval access position, to the ending position.

[0141] In some embodiments, the path determination module 204 is specifically configured as follows:

[0142] Based on the traffic mapping network topology, multiple initial network paths from the starting position to the ending position are found;

[0143] Determine the number of network hops and the latency parameter corresponding to each initial network path, and determine the comprehensive index value corresponding to each initial network path based on the number of network hops and the latency parameter;

[0144] The initial network path with the largest comprehensive index value is selected as the target network path, and the node positions in the target network path other than the starting position and the ending position are selected as the target abnormal interval access positions.

[0145] In some embodiments, the path determination module 204 is specifically configured as follows:

[0146] For each initial network path:

[0147] Based on the network hop count and delay parameters corresponding to the initial network path, determine the initial two-dimensional evaluation matrix;

[0148] The initial two-dimensional evaluation matrix is ​​normalized to obtain a two-dimensional evaluation matrix, wherein the two-dimensional evaluation matrix includes the normalized network hop count and the normalized delay parameter.

[0149] Obtain a preset weight value, and perform weighted processing on the normalized network hop count and normalized delay parameter according to the preset weight value to obtain the comprehensive index value corresponding to the initial network path.

[0150] In some embodiments, the path determination module 204 is specifically configured as follows:

[0151] Obtain the first routing information corresponding to the starting position, the second routing information corresponding to the ending position, and the third routing information corresponding to the access position of the target abnormal interval;

[0152] The first routing information, the second routing information, and the third routing information are compared and the comparison result is determined to be consistent with the routing table. The network parameters corresponding to the access location of the target abnormal interval are then obtained.

[0153] The network parameters are compared with preset parameter thresholds, and in response to the network parameters being within the preset parameter threshold range, parameter synchronization is completed.

[0154] For ease of description, the above apparatus is described in terms of its functions, divided into various modules. Of course, in implementing this disclosure, the functions of each module can be implemented in one or more software and / or hardware.

[0155] The apparatus described above is used to implement the corresponding traffic anomaly handling method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0156] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the traffic anomaly handling method described in any of the above embodiments.

[0157] Figure 4 This embodiment illustrates a more specific hardware structure of an electronic device, which may include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, memory 1020, input / output interface 1030, and communication interface 1040 are interconnected internally via the bus 1050.

[0158] The processor 1010 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0159] The memory 1020 can be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 can store the operating system and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program code is stored in the memory 1020 and is called and executed by the processor 1010.

[0160] The input / output interface 1030 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0161] The communication interface 1040 is used to connect a communication module (not shown in the figure) to enable communication between this device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0162] Bus 1050 includes a pathway for transmitting information between various components of the device, such as processor 1010, memory 1020, input / output interface 1030, and communication interface 1040.

[0163] It should be noted that although the above-described device only shows the processor 1010, memory 1020, input / output interface 1030, communication interface 1040, and bus 1050, in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the embodiments of this specification, and not necessarily all the components shown in the figures.

[0164] The electronic devices described above are used to implement the corresponding traffic anomaly handling methods in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0165] Based on the same inventive concept, corresponding to the methods of any of the above embodiments, this disclosure also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the traffic anomaly handling method as described in any of the above embodiments.

[0166] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information accessible by a computing device.

[0167] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to execute the traffic anomaly handling method as described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.

[0168] It is understood that before using the technical solutions of the various embodiments in this disclosure, users will be informed of the type, scope of use, and usage scenarios of the personal information involved in an appropriate manner, and user authorization will be obtained.

[0169] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose, based on the prompt message, whether to provide personal information to the software or hardware such as electronic devices, applications, servers, or storage media performing the operations of this disclosed technical solution.

[0170] As an optional but not limited implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0171] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0172] Those skilled in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of this disclosure (including the claims) is limited to these examples; within the framework of this disclosure, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of the embodiments of this disclosure as described above, which are not provided in detail for the sake of brevity.

[0173] Additionally, to simplify the description and discussion, and to avoid obscuring the embodiments of this disclosure, the provided drawings may or may not show well-known power / ground connections to integrated circuit (IC) chips and other components. Furthermore, the apparatus may be shown in block diagram form to avoid obscuring the embodiments of this disclosure, and this also takes into account the fact that the details of implementation of these block diagram apparatuses are highly dependent on the platform on which the embodiments of this disclosure will be implemented (i.e., these details should be fully understood by those skilled in the art). While specific details (e.g., circuitry) have been set forth to describe exemplary embodiments of this disclosure, it will be apparent to those skilled in the art that the embodiments of this disclosure may be implemented without these specific details or with variations thereof. Therefore, these descriptions should be considered illustrative rather than restrictive.

[0174] Although this disclosure has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0175] This disclosure is intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for handling traffic anomalies, characterized in that, include: In response to a sudden change in traffic data detected in the monitored network, the abnormal traffic range is determined; Obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value; Obtain the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology; The target traffic path is determined based on the traffic mapping network topology, and traffic transmission is controlled based on the target traffic path, wherein the target traffic path is the path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval. Determining the target traffic path based on the traffic mapping network topology includes: Obtain the start and end positions corresponding to the abnormal traffic interval, and determine the access position of the target abnormal interval based on the traffic mapping network topology, the start position, and the end position; The starting position, the ending position, and the target abnormal interval access position are subjected to parameter synchronization processing; In response to the completion of parameter synchronization, the target traffic path is determined to be from the starting position, through the target abnormal interval access position, to the ending position; Determining the access location of the target abnormal interval based on the traffic mapping network topology, the starting position, and the ending position includes: Based on the traffic mapping network topology, multiple initial network paths from the starting position to the ending position are found; Determine the number of network hops and the latency parameter corresponding to each initial network path, and determine the comprehensive index value corresponding to each initial network path based on the number of network hops and the latency parameter; The initial network path with the largest comprehensive index value is selected as the target network path, and the node positions in the target network path other than the starting position and the ending position are selected as the target abnormal interval access positions. The step of determining the comprehensive index value corresponding to each initial network path based on the network hop count and the latency parameter includes: For each initial network path: Based on the network hop count and delay parameters corresponding to the initial network path, determine the initial two-dimensional evaluation matrix; The initial two-dimensional evaluation matrix is ​​normalized to obtain a two-dimensional evaluation matrix, wherein the two-dimensional evaluation matrix includes the normalized network hop count and the normalized delay parameter. Obtain a preset weight value, and perform weighted processing on the normalized network hop count and normalized delay parameter according to the preset weight value to obtain the comprehensive index value corresponding to the initial network path.

2. The method according to claim 1, characterized in that, The response to a detected abrupt change in traffic data of the monitored network, determining the abnormal traffic range, includes: In response to a detected abrupt change in traffic data of the monitored network, the time of the abrupt change is determined; Determine the time required for the flow data to recover from the sudden change to the normal flow parameter range; The abnormal flow range is determined based on the time of the mutation and the recovery time of the parameters.

3. The method according to claim 1, characterized in that, The step of mapping the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology includes: Based on the bandwidth change adjustment value, a variational autoencoder is used to generate a dynamic traffic feature map; According to a preset time interval, multiple key feature points are extracted from the dynamic feature map of the traffic flow. The network topology is mapped based on the multiple key feature points to obtain a traffic-mapped network topology.

4. The method according to claim 1, characterized in that, The parameter synchronization processing for the starting position, the ending position, and the target abnormal interval access position includes: Obtain the first routing information corresponding to the starting position, the second routing information corresponding to the ending position, and the third routing information corresponding to the access position of the target abnormal interval; The first routing information, the second routing information, and the third routing information are compared and the comparison result is determined to be consistent with the routing table. The network parameters corresponding to the access location of the target abnormal interval are then obtained. The network parameters are compared with preset parameter thresholds, and in response to the network parameters being within the preset parameter threshold range, parameter synchronization is completed.

5. A flow anomaly processing device, characterized in that, include: The monitoring module is configured to determine the abnormal traffic range in response to a sudden change in the traffic data of the monitored network; The adjustment module is configured to obtain a preset bandwidth threshold, adjust the network link bandwidth within the abnormal traffic range according to the bandwidth threshold, and record the bandwidth adjustment change value. The mapping module is configured to acquire the network topology map corresponding to the monitored network, and perform mapping processing on the network topology map according to the bandwidth adjustment change value to obtain the traffic-mapped network topology. The path determination module is configured to determine a target traffic path based on the traffic mapping network topology and control traffic transmission based on the target traffic path, wherein the target traffic path is a path from the start position of the traffic anomaly interval to the end position of the traffic anomaly interval. Determining the target traffic path based on the traffic mapping network topology includes: Obtain the start and end positions corresponding to the abnormal traffic interval, and determine the access position of the target abnormal interval based on the traffic mapping network topology, the start position, and the end position; The starting position, the ending position, and the target abnormal interval access position are subjected to parameter synchronization processing; In response to the completion of parameter synchronization, the target traffic path is determined to be from the starting position, through the target abnormal interval access position, to the ending position; Determining the access location of the target abnormal interval based on the traffic mapping network topology, the starting position, and the ending position includes: Based on the traffic mapping network topology, multiple initial network paths from the starting position to the ending position are found; Determine the number of network hops and the latency parameter corresponding to each initial network path, and determine the comprehensive index value corresponding to each initial network path based on the number of network hops and the latency parameter; The initial network path with the largest comprehensive index value is selected as the target network path, and the node positions in the target network path other than the starting position and the ending position are selected as the target abnormal interval access positions. The step of determining the comprehensive index value corresponding to each initial network path based on the network hop count and the latency parameter includes: For each initial network path: Based on the network hop count and delay parameters corresponding to the initial network path, determine the initial two-dimensional evaluation matrix; The initial two-dimensional evaluation matrix is ​​normalized to obtain a two-dimensional evaluation matrix, wherein the two-dimensional evaluation matrix includes the normalized network hop count and the normalized delay parameter. Obtain a preset weight value, and perform weighted processing on the normalized network hop count and normalized delay parameter according to the preset weight value to obtain the comprehensive index value corresponding to the initial network path.

6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as claimed in any one of claims 1 to 4.

7. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing a computer to perform the method described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • SDN (Software Defined Network) overlay network fault positioning system and method

    CN106230650A

  • Abnormal traffic management and control method and device, electronic equipment and storage medium

    CN119854165A