Network traffic monitoring analysis method, system and device, and storage medium
By constructing network topology diagrams and managing records to generate differentiated traffic collection strategies, and combining them with a multi-dimensional evaluation index system for traffic analysis, the problem of low efficiency in network traffic monitoring in existing technologies has been solved, achieving more accurate and efficient network operation and maintenance.
Patent Information
- Application Number
- CN202511326686.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-12-12
AI Technical Summary
Existing network traffic monitoring technologies struggle to accurately and effectively collect and analyze data from complex network structures, resulting in low traffic monitoring efficiency and failing to meet the needs of network management, performance optimization, and security protection.
By constructing a network topology map and combining it with management records, differentiated traffic collection strategies are generated. A multi-dimensional traffic evaluation index system is used to extract traffic data features and perform interactive analysis to generate network operation and maintenance strategies.
This improves the targeting and accuracy of traffic data collection and analysis, reduces redundant monitoring, and enhances the reliability and efficiency of network operation and maintenance strategies.
Smart Images

Figure CN121125507A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network operation and maintenance technology, and in particular to a network traffic monitoring and analysis method, system, device, and storage medium. Background Technology
[0002] With the development of communication technology, network applications are gradually permeating all aspects of our lives. From daily office work and high-definition video streaming to data exchange of industrial IoT devices and high-frequency transactions in the financial industry, the timeliness requirements for network traffic are constantly increasing across all sectors.
[0003] Against this backdrop, traffic monitoring technology, through the collection and analysis of network traffic data, can provide accurate data support for network management, performance optimization, and security protection, and has become a key technology for the stable and efficient operation of modern networks.
[0004] However, due to the continuous expansion of network scale and the increasingly complex composition of traffic, existing traffic monitoring technologies are unable to accurately and effectively collect network traffic. Summary of the Invention
[0005] This application provides a network traffic monitoring and analysis method, system, device, and storage medium. It determines the traffic collection strategy by using network topology diagrams and management records, thereby improving the targeting of network traffic collection. Furthermore, it enhances the accuracy of traffic analysis through a multi-dimensional traffic evaluation index system.
[0006] To address the above problems, the embodiments of this application provide the following technical solutions:
[0007] Firstly, this application provides a network traffic monitoring and analysis method, which includes: acquiring network topology data of a target area and constructing a network topology map based on the network topology data; determining a traffic collection strategy based on the network topology map and management records of the target area; the traffic collection strategy including traffic collection strategies for different monitoring sub-areas within the target area; collecting traffic from different monitoring sub-areas within the target area based on the traffic collection strategy to obtain traffic data for the target area; evaluating and processing the traffic data based on a traffic evaluation index system to obtain traffic evaluation and processing data corresponding to the traffic data; the traffic evaluation index system being used to process traffic data from different dimensions; determining traffic interaction analysis results based on the traffic evaluation and processing data; the traffic interaction analysis results including traffic interaction analysis results within a single monitoring sub-area within the target area and / or traffic interaction analysis results between different monitoring sub-areas; performing visualization processing based on the traffic interaction analysis results to obtain visualized data and displaying the visualized data on a visualization interface; and generating a network operation and maintenance strategy for the target area based on the traffic interaction analysis results.
[0008] The network traffic monitoring method provided in this application firstly integrates network topology data and management records within a target area to generate differentiated traffic monitoring strategies. This allows for the analysis of operational needs in different monitoring sub-regions from a global perspective, improving the targeting of traffic data collection. Simultaneously, by introducing a traffic evaluation index system, a comprehensive feature assessment of traffic data can be performed from multiple dimensions, yielding traffic characteristic data. Then, using this traffic characteristic data, traffic interaction analysis is conducted on different monitoring sub-regions within the target area, providing results reflecting traffic interaction across time and space dimensions. Finally, a network operation and maintenance strategy is generated based on the traffic interaction analysis results. Compared to existing technologies, this method reduces redundant traffic monitoring by developing differentiated traffic collection strategies. Furthermore, the multi-dimensional traffic evaluation index system and multi-regional traffic interaction analysis overcome the limitations of single-dimensional traffic analysis, providing a global traffic flow perspective for traffic analysis, thereby improving the accuracy of traffic analysis and the reliability of network operation and maintenance strategies.
[0009] One possible implementation method is to include the following traffic evaluation index system: traffic status, number of active connections and basic resource parameters, network element support for IPv6 protocol, functional availability of business applications in IPv6 environment, proportion of IPv6 routing protocol error packets and IPv6 and cloud service interface adaptation rate.
[0010] One possible implementation involves a traffic collection strategy that includes a traffic collection frequency. Based on the network topology and management records of the target area, the traffic collection strategy is determined, including: generating network node entities based on the network topology; generating management event entities based on management records, whereby management event entities include at least the following categories: operation and maintenance event entities, traffic anomaly event entities, traffic configuration event entities, performance monitoring event entities, and security operation and maintenance event entities; dividing the target area into multiple sub-regions based on preset sub-region division rules, and generating corresponding region entities for each sub-region; determining the relationships between the region entities, network node entities, and management event entities to obtain a management knowledge graph; and determining the monitoring sub-regions and their corresponding traffic collection frequencies from the multiple sub-regions to define the traffic collection strategy.
[0011] One possible implementation involves determining monitoring sub-regions and their corresponding traffic collection frequencies from multiple sub-regions based on a management knowledge graph, thereby determining a traffic collection strategy. This includes: determining the number of times each region entity manages its corresponding sub-region based on the number of management event entities corresponding to each region entity in the management knowledge graph; identifying sub-regions with a management count greater than a management count threshold as monitoring sub-regions; determining the traffic monitoring frequency corresponding to each monitoring sub-region based on the management count and a preset management count-collection frequency mapping rule; and finally, determining a traffic collection strategy based on the monitoring sub-regions and their corresponding traffic monitoring frequencies.
[0012] One possible implementation involves determining monitoring sub-regions and their corresponding traffic collection frequencies from multiple sub-regions based on a management knowledge graph, thereby determining a traffic collection strategy. This includes: determining the number of traffic anomalies in the sub-regions corresponding to each regional entity based on the number of traffic anomaly event entities in the management event entity corresponding to each regional entity in the management knowledge graph; identifying sub-regions with a traffic anomaly count exceeding a traffic anomaly count threshold as monitoring sub-regions; determining the traffic monitoring frequency for each monitoring sub-region based on the number of traffic anomalies and a preset traffic anomaly count-collection frequency mapping rule; and finally, determining a traffic collection strategy based on the monitoring sub-regions and their corresponding traffic monitoring frequencies.
[0013] One possible implementation involves collecting traffic data from different monitoring sub-regions within a target area, based on a traffic acquisition strategy. This includes: acquiring performance information for multiple network nodes within each monitoring sub-region; quantifying the performance information for each network node to obtain a performance quantification score; identifying network nodes with performance quantification scores greater than a performance score threshold as traffic acquisition nodes; determining the traffic acquisition priority of traffic acquisition nodes within each monitoring sub-region based on their performance quantification scores and a pre-defined score-priority mapping rule; and collecting traffic data from traffic acquisition nodes in different monitoring sub-regions within the target area based on their traffic acquisition priorities and the traffic acquisition strategy.
[0014] One possible implementation involves determining the traffic interaction analysis results for a target area based on traffic assessment and processing data. This includes: if the traffic interaction analysis results include the traffic interaction analysis results for a single monitoring sub-area within the target area, obtaining the target traffic assessment and processing data corresponding to the target monitoring sub-area from the traffic assessment and processing data. The target monitoring sub-area can be any one of the different monitoring sub-areas. The target traffic assessment and processing data is then input into a pre-trained traffic interaction analysis model to determine the traffic interaction analysis results for the target monitoring sub-area. The traffic interaction analysis result analysis model is used to perform spatiotemporal correlation analysis based on the traffic assessment and processing data of the monitoring sub-area to determine the traffic interaction analysis results between different traffic acquisition nodes within the monitoring sub-area.
[0015] One possible implementation involves determining the traffic interaction analysis results for a target area based on traffic assessment processing data. This includes: when the traffic interaction analysis results are between different monitoring sub-regions, obtaining the traffic interaction analysis results corresponding to each of the different monitoring sub-regions; inputting the traffic interaction analysis results corresponding to each of the different monitoring sub-regions into a pre-trained joint traffic interaction analysis model to determine the traffic interaction analysis results between the different monitoring sub-regions; and using the joint traffic interaction analysis model to determine the traffic interaction analysis results between the different monitoring sub-regions based on the traffic interaction analysis results corresponding to each of the different monitoring sub-regions.
[0016] One possible implementation involves generating a network operation and maintenance strategy for a target area based on traffic interaction analysis results. This includes: inputting the traffic interaction analysis results into a traffic prediction model; performing time-series characteristic analysis on the traffic interaction analysis results using the traffic prediction model to determine the predicted traffic data; and generating a network operation and maintenance strategy for the target area based on the predicted traffic data.
[0017] Secondly, this application provides a network traffic monitoring and analysis system, which includes: a policy management module, a pre-collection evaluation module, a traffic data acquisition module, a traffic data processing module, a traffic data storage module, a traffic analysis module, a traffic prediction module, and a traffic operation module.
[0018] The policy management module is used to acquire network topology data for the target area and construct a network topology map based on this data. Based on the network topology map and management records for the target area, a traffic collection policy is determined. This traffic collection policy includes traffic collection policies for different monitoring sub-areas within the target area.
[0019] The pre-collection evaluation module is used to acquire performance information for multiple network nodes within the monitoring sub-region. This performance information is then quantified to obtain performance quantification scores for each network node. Network nodes with performance quantification scores greater than a performance score threshold are identified as traffic collection nodes. Based on the performance quantification scores of the traffic collection nodes and a preset score-priority mapping rule, the traffic collection priority of the traffic collection nodes within the monitoring sub-region is determined.
[0020] The traffic acquisition module is used to acquire traffic data of the target area by acquiring traffic from traffic acquisition nodes in different monitoring sub-regions based on the traffic acquisition priority and traffic acquisition strategy of the traffic acquisition nodes.
[0021] The traffic data processing module is used to preprocess traffic data.
[0022] The traffic analysis module is used to evaluate and process traffic data based on a traffic assessment index system, obtaining corresponding traffic assessment and processing data. The traffic assessment index system is used to process traffic data from different dimensions. Based on the traffic assessment and processing data, the traffic interaction analysis results are determined. These results include traffic interaction analysis results within a single monitoring sub-region of the target area and / or traffic interaction analysis results between different monitoring sub-regions.
[0023] The traffic operations module is used to visualize the results of traffic interaction analysis, obtain visualized data, and display the visualized data on the visualization interface. In response to received traffic operation and maintenance decision commands, it sends traffic prediction commands to the traffic prediction module.
[0024] The traffic prediction module is used to respond to traffic prediction commands by inputting the traffic interaction analysis results into the traffic prediction model. The traffic prediction model then performs time-series feature analysis on the traffic interaction analysis results to determine the predicted traffic data.
[0025] The traffic operations module is also used to generate network operation and maintenance strategies for target areas based on predicted traffic data, and to visualize these strategies.
[0026] The traffic data storage module is used to convert traffic data, traffic assessment and processing data, traffic interaction analysis results, and network operation and maintenance strategies into structured data. It stores this structured data.
[0027] The various functional modules used in the method described in the first aspect above.
[0028] Thirdly, this application provides an electronic device comprising a processor and a memory. The memory stores processor-executable instructions, which, when configured to execute the instructions, cause the electronic device to perform the method described in the first aspect above.
[0029] Fourthly, this application provides a readable storage medium comprising software instructions. When the software instructions are executed in an electronic device, they cause the electronic device to perform the method described in the first aspect above.
[0030] Fifthly, this application provides a computer program product comprising computer instructions. When the computer instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method described in the first aspect.
[0031] The beneficial effects of the second to fifth aspects mentioned above can be referred to the first aspect, and will not be repeated here. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 A schematic diagram of the composition of a network traffic monitoring and analysis system provided in this application embodiment;
[0034] Figure 2 A flowchart illustrating a network traffic monitoring and analysis method provided in this application embodiment;
[0035] Figure 3 A flowchart illustrating a method for determining a traffic collection strategy provided in an embodiment of this application;
[0036] Figure 4 A flowchart illustrating a method for determining a traffic collection strategy based on the number of maintenance operations provided in this application embodiment;
[0037] Figure 5 A flowchart illustrating a method for determining a traffic acquisition strategy based on the number of failures, provided in an embodiment of this application;
[0038] Figure 6 A flowchart illustrating a method for determining traffic acquisition nodes provided in an embodiment of this application;
[0039] Figure 7 A flowchart illustrating a method for determining traffic interaction analysis results in a single monitoring sub-region, provided in an embodiment of this application;
[0040] Figure 8 A flowchart illustrating a method for determining the results of traffic interaction analysis involving multiple monitoring sub-regions, provided in an embodiment of this application;
[0041] Figure 9 A flowchart illustrating a method for generating network operation and maintenance strategies provided in this application embodiment;
[0042] Figure 10 This is a schematic diagram of the composition of an electronic device provided in an embodiment of this application. Detailed Implementation
[0043] Hereinafter, the terms "first," "second," and "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined as "first," "second," or "third," etc., may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.
[0044] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0045] As described in the background section, network traffic monitoring technology is crucial for ensuring stable network operation, and its importance is self-evident. By collecting and analyzing network traffic data, network traffic monitoring provides detailed and accurate data for network management, performance optimization, and security protection. Through precise monitoring and analysis of network traffic, network administrators can promptly identify potential problems in the network, such as bandwidth bottlenecks and abnormal traffic fluctuations, and take targeted optimization measures to improve the overall performance and stability of the network.
[0046] However, as networks grow in scale and their structures become increasingly complex, existing network traffic monitoring technologies, due to their single traffic monitoring mode, may be unable to meet the traffic monitoring needs of the current network structure.
[0047] Therefore, improving the efficiency of network traffic data monitoring and analysis is an urgent problem to be solved.
[0048] Based on this, this application provides a network traffic monitoring and analysis method. By constructing a network topology map and integrating management records, it generates differentiated traffic collection strategies for different sub-regions, reducing redundant traffic monitoring. Furthermore, by evaluating traffic data from multiple dimensions, it extracts specific features from the traffic data, obtaining accurate characteristic data and improving the efficiency of traffic analysis. Further, by analyzing the characteristic data, it obtains traffic interaction analysis results for different monitoring sub-regions within the target area, improving the comprehensiveness and accuracy of traffic analysis. Ultimately, this enhances the accuracy of network operation and maintenance strategies.
[0049] First, a brief introduction to the application scenarios of the embodiments of this application will be given.
[0050] The network traffic monitoring and analysis method provided in this application embodiment can be applied to a network traffic monitoring and analysis system. Specifically, the network traffic monitoring and analysis system can be deployed as pure software on a computing device or cloud platform, or it can be deployed as an embedded system on a network detection and analysis device or a smart network card.
[0051] Specifically, such as Figure 1 The diagram shown is a schematic of the composition of a network traffic monitoring and analysis system. The network traffic monitoring and analysis system includes the following modules: policy management module 110, pre-collection evaluation module 120, traffic acquisition module 130, traffic data processing module 140, traffic analysis module 150, traffic operation module 160, traffic prediction module 170, and traffic data storage module 180.
[0052] The policy management module 110 is used to acquire network topology data of the target area and construct a network topology map based on the network topology data. Based on the network topology map and the management records of the target area, a traffic collection policy is determined. The traffic collection policy includes traffic collection policies for different monitoring sub-areas within the target area.
[0053] The pre-collection evaluation module 120 is used to acquire performance information corresponding to multiple network nodes in the monitoring sub-region. The performance information of each network node is quantified to obtain a performance quantification score for each node. Network nodes with performance quantification scores greater than a performance score threshold are identified as traffic collection nodes. Based on the performance quantification scores of the traffic collection nodes and a preset score-priority mapping rule, the traffic collection priority of the traffic collection nodes in the monitoring sub-region is determined.
[0054] The traffic acquisition module 130 is used to acquire traffic data of the target area by acquiring traffic from traffic acquisition nodes in different monitoring sub-areas based on the traffic acquisition priority and traffic acquisition strategy of the traffic acquisition nodes.
[0055] The traffic data processing module 140 is used to preprocess traffic data.
[0056] The traffic analysis module 150 is used to evaluate and process traffic data based on a traffic assessment index system, obtaining corresponding traffic assessment and processing data. The traffic assessment index system is used to process traffic data from different dimensions. Based on the traffic assessment and processing data, the traffic interaction analysis results are determined. These results include traffic interaction analysis results within a single monitoring sub-region of the target area and / or traffic interaction analysis results between different monitoring sub-regions.
[0057] The traffic operation module 160 is used to perform visualization processing based on traffic interaction analysis results, obtain visualized data, and display the visualized data on the visualization interface. In response to the received traffic operation and maintenance decision command, it sends a traffic prediction command to the traffic prediction module 170.
[0058] The traffic prediction module 170 is used to respond to traffic prediction commands by inputting the traffic interaction analysis results into the traffic prediction model, and then performing time-series characteristic analysis on the traffic interaction analysis results through the traffic prediction model to determine the predicted traffic data.
[0059] The traffic operations module 160 is also used to generate network operation and maintenance strategies for target areas based on predicted traffic data, and to visualize these strategies.
[0060] The traffic data storage module 180 is used to convert traffic data, traffic assessment and processing data, traffic interaction analysis results, and network operation and maintenance strategies into structured data.
[0061] One possible implementation method is to include the following traffic evaluation index system: traffic status, number of active connections and basic resource parameters, network element support for IPv6 protocol, functional availability of business applications in IPv6 environment, proportion of IPv6 routing protocol error packets and IPv6 and cloud service interface adaptation rate.
[0062] One possible implementation involves a policy management module 110, specifically used to generate network node entities based on the network topology diagram. Based on management records, it generates management event entities, which include at least the following categories: operation and maintenance event entities, traffic anomaly event entities, traffic configuration event entities, performance monitoring event entities, and security operation and maintenance event entities. Based on preset sub-region division rules, the target area is divided into multiple sub-regions, and corresponding region entities are generated for each sub-region. Based on the region entities, network node entities, and management event entities, the relationships between these entities are determined, resulting in a management knowledge graph. Based on the management knowledge graph, monitoring sub-regions and their corresponding traffic collection frequencies are determined from the multiple sub-regions to establish a traffic collection strategy.
[0063] One possible implementation involves a policy management module 110, specifically used to determine the number of management events for each sub-region corresponding to each regional entity based on the number of management event entities corresponding to each regional entity in the management knowledge graph. Sub-regions with a management count exceeding a management count threshold are identified as monitoring sub-regions. Based on the management count corresponding to the monitoring sub-regions and a preset management count-collection frequency mapping rule, the traffic monitoring frequency corresponding to the monitoring sub-regions is determined. Finally, based on the monitoring sub-regions and their corresponding traffic monitoring frequencies, a traffic collection strategy is determined.
[0064] One possible implementation involves a traffic analysis module 150, specifically used to obtain target traffic assessment and processing data corresponding to the target monitoring sub-region from the traffic assessment and processing data, when the traffic interaction analysis results include the traffic interaction analysis results of a single monitoring sub-region within the target area. The target monitoring sub-region can be any one of the different monitoring sub-regions. The target traffic assessment and processing data is input into a pre-trained traffic interaction analysis model to determine the traffic interaction analysis results of the target monitoring sub-region. The traffic interaction analysis result analysis model is used to perform spatiotemporal correlation analysis based on the traffic assessment and processing data of the monitoring sub-region to determine the traffic interaction analysis results between different traffic acquisition nodes within the monitoring sub-region.
[0065] One possible implementation involves a traffic analysis module 150, specifically used to obtain the traffic interaction analysis results for each of the different monitoring sub-regions when the traffic interaction analysis results are for different monitoring sub-regions. The traffic interaction analysis results for each of the different monitoring sub-regions are then input into a pre-trained joint traffic interaction analysis model to determine the traffic interaction analysis results between the different monitoring sub-regions. The joint traffic interaction analysis model is used to determine the traffic interaction analysis results between the different monitoring sub-regions based on the traffic interaction analysis results for each of the different monitoring sub-regions.
[0066] For a detailed description of the specific functions of this network traffic monitoring and analysis system, please refer to the specific implementation of the network monitoring and analysis method below, which will not be elaborated here.
[0067] The network traffic monitoring and analysis method provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0068] like Figure 2 As shown, this network traffic monitoring and analysis method includes the following steps:
[0069] S101. Obtain network topology data for the target area and construct a network topology map based on the network topology data.
[0070] It should be noted that the target area can be a prefecture-level city, district / county, or township. This application does not limit the specific scope of the target area in its embodiments.
[0071] It should also be noted that the network topology data within the target area can be an IPv4 network and / or an IPv6 network. This application does not limit the network type of the network topology data.
[0072] In some embodiments, the network traffic monitoring and analysis system can obtain the network topology data of the target area by fusing network topology data from network planning systems in different areas of the target area.
[0073] In this context, the strategy management module of the traffic monitoring and analysis system is also used to interface with network planning systems in different areas within the target region.
[0074] In some embodiments, the network traffic monitoring and analysis system may execute step S101 after receiving a monitoring instruction from the operations and maintenance personnel. Alternatively, the network traffic monitoring and analysis system may also perform traffic monitoring periodically according to a preset time interval.
[0075] For example, the preset timeout could be 12:00 or 18:00 every day. Alternatively, it could be understood as an execution interval, such as executing once every 30 minutes or 2 hours.
[0076] S102. Determine the traffic collection strategy based on the network topology map and the management records of the target area.
[0077] Among them, the traffic acquisition strategy is used to indicate the traffic acquisition strategy for different monitoring sub-regions within the target area.
[0078] It should be noted that management records refer to the management operation records of network nodes within the target area by the traffic monitoring and analysis system. Each record includes information such as: time of occurrence, location of occurrence, type of occurrence, source of occurrence, solution, and feedback plan.
[0079] In some embodiments, management records may include the following: operation and maintenance event records, traffic anomaly event records, traffic configuration event records, performance monitoring event records, and security operation and maintenance event records.
[0080] It should also be noted that a monitoring sub-region refers to a sub-region of the target area for traffic monitoring. This sub-region can be divided according to preset sub-region division rules. The process for determining the monitoring sub-region and the traffic collection strategy can be found below. Figure 3This will not be elaborated upon here. For example, the preset regional division rules can be based on administrative divisions. Assuming the target area is set as a prefecture-level city, the streets and towns within that area can be used as the basis for dividing sub-regions, resulting in multiple sub-regions.
[0081] For example, preset area division rules can also be based on preset distances. Assuming the preset distance is 5 kilometers, the target area can be divided into grids with sides of 5 kilometers, with each grid serving as a sub-region.
[0082] In some embodiments, the traffic acquisition strategy may include: traffic acquisition nodes, traffic acquisition frequency, traffic acquisition method, traffic acquisition indicator set, traffic acquisition transmission parameters, traffic acquisition priority, etc.
[0083] In some embodiments, the traffic monitoring and analysis system can also obtain the quality status of the collected traffic data (such as the continuity of traffic data) through the traffic acquisition module, and adjust the traffic acquisition strategy (such as adjusting the acquisition frequency, traffic acquisition transmission parameters, etc.) based on the quality status of the traffic data.
[0084] S103. Based on the traffic acquisition strategy, traffic is acquired from different monitoring sub-areas within the target area to obtain traffic data for the target area.
[0085] It should be noted that traffic collection within different monitoring sub-regions of the target area actually involves collecting traffic data from network nodes within those sub-regions. Furthermore, since the types of network nodes within the target area are diverse, the traffic collection methods for different types of network nodes may differ.
[0086] For example, core router nodes, needing to collect both configuration data and traffic statistics simultaneously, are well-suited for traffic collection using the Netconf protocol. Security devices such as firewalls typically employ port mirroring to obtain complete data packets. Cloud server clusters can utilize telemetry to push metrics in real time. Network storage devices are well-suited for transferring log files via the Secure File Transfer Protocol (SFTP). This application does not limit the traffic collection methods used in the traffic collection process.
[0087] S104. Based on the traffic evaluation index system, evaluate and process the traffic data to obtain the traffic evaluation and processing data corresponding to the traffic data.
[0088] The traffic evaluation index system is used to evaluate and process the traffic data from different dimensions.
[0089] It should be noted that the traffic assessment indicator system can include assessment indicators for multiple network types.
[0090] In some embodiments, the network traffic monitoring and analysis system may perform data preprocessing on the traffic data during the execution of step S104 in order to verify, clean, and supplement the traffic data.
[0091] For example, a network traffic monitoring and analysis system can be based on, for example, Figure 1 The traffic data processing module 140 shown preprocesses the traffic data.
[0092] In some embodiments, the traffic evaluation index system includes the following: traffic status, number of active connections and basic resource parameters, network element support for IPv6 protocol, functional availability of business applications in IPv6 environment, proportion of IPv6 routing protocol error packets and IPv6 and cloud service interface adaptation rate.
[0093] Traffic status-related indicators include bandwidth utilization, peak / valley traffic, traffic trend (rising / falling), and traffic type (reflecting the data flow characteristics of network nodes), which are used to evaluate traffic data from the perspective of "traffic transmission efficiency and rationality" (such as determining whether traffic exceeds the link's carrying capacity or whether there are abnormal fluctuations).
[0094] Active connection metrics include the number of new connections per second (TCP / UDP) and the number of current concurrent connections (reflecting the connection activity of network nodes), which are used to assess traffic data from the perspective of "connection health" (such as identifying potential malicious traffic or connection overload risks through abnormal connection counts).
[0095] Basic resource parameters include CPU utilization, memory usage, cache hit rate, and interface error rate (reflecting the usage of network node hardware resources), which are used to evaluate traffic data from the perspective of "traffic matching with hardware resources" (such as determining whether traffic is experiencing transmission delays, packet loss, or other issues due to insufficient hardware resources).
[0096] The indicators related to the network element's support for the IPv6 protocol include the support for functions such as IPv6 address resolution, IPv6 routing protocols, and IPv6 security policies (the node's own IPv6 compatibility). These indicators are used to evaluate traffic data from the perspective of "IPv6 traffic data integrity." If a node does not support IPv6 address resolution, IPv6 traffic will be dropped. In this case, "IPv6 traffic is 0" may be data distortion (not a true traffic state). This indicator can help verify whether the data completely reflects the actual transmission situation.
[0097] The functional availability metrics of business applications in the IPv6 environment include business interface response time, data transmission integrity, and service access success rate (the operating status of the business in the IPv6 environment). These metrics are used to evaluate traffic data from the dimension of "IPv6 business traffic validity" (such as determining whether IPv6 traffic truly supports business operation, rather than invalid data such as "successful transmission but unavailable service").
[0098] The IPv6 routing protocol error packet percentage refers to the proportion of error packets generated by the IPv6 routing protocol during network node operation to the total number of protocol packets (such as routing update errors and neighbor establishment failure packets). It is used to evaluate traffic data from the perspective of "IPv6 traffic data reliability". An excessively high error packet percentage may lead to traffic transmission interruption. At this time, "traffic data fluctuation" may be an anomaly caused by routing failure (not a real business change). This indicator can help distinguish the root cause of data anomalies.
[0099] Indicators related to IPv6 and cloud service interface compatibility include cloud service interface call success rate, data format compatibility, and service access performance (the degree of compatibility between cloud services and the IPv6 protocol). These indicators are used to evaluate traffic data from the dimension of "IPv6 cloud service traffic synergy" (such as determining whether the IPv6 interaction data between the node and the cloud is lost or formatted incorrectly due to interface incompatibility, and ensuring that the collected cloud service traffic data is true and valid).
[0100] In some embodiments, when using a traffic evaluation index system to evaluate and process traffic data, the traffic evaluation index system may include one or more of the above-mentioned dimensions of indicators. This application embodiment does not limit the specific number of traffic evaluation indicators in the traffic evaluation index system.
[0101] It should be understood that by using different traffic assessment indicator systems, different dimensions of traffic data can be evaluated, thereby extracting characteristic data that can intuitively reflect the traffic data. In other words, this step is equivalent to secondary data processing of traffic data, reducing the complexity of subsequent traffic data analysis.
[0102] S105. Based on the traffic assessment and processing data, determine the traffic interaction analysis results.
[0103] The traffic interaction analysis results include the traffic interaction analysis results within a single monitoring sub-region within the target area and / or the traffic interaction analysis results between different monitoring sub-regions.
[0104] It should be noted that the traffic interaction analysis results within a single monitoring sub-region of the target area can be understood as the basic area traffic analysis, while the traffic interaction analysis results between different monitoring sub-regions can be understood as the joint area traffic analysis of multiple monitoring sub-regions based on the basic area traffic analysis.
[0105] It should also be noted that the traffic interaction analysis results refer to the flow relationship of traffic between multiple network nodes within a specific area. These traffic interaction analysis results can include interaction relationships in both time and spatial dimensions.
[0106] For example, within a single monitoring sub-region, traffic interaction analysis results may include: the TCP request traffic from "Terminal Node A to Server Node B" within that sub-region peaks at 10:00 on weekdays (accounting for 40% of the total traffic within the sub-region) and drops to a trough at 12:00 (accounting for 15%).
[0107] For example, among multiple monitoring sub-regions (such as office sub-region and data center sub-region), the traffic interaction analysis results can be expressed as follows: the UDP synchronization traffic from the office sub-region to the data center sub-region accounts for 60% of the total cross-region traffic from 15:00 to 16:00 every day, and the return traffic from the data center sub-region during this period is only 20% of the traffic sent by the office sub-region.
[0108] For details on the implementation of step S105, please refer to the following text. Figure 7 as well as Figure 8 This will not be elaborated upon here.
[0109] S106. Based on the traffic interaction analysis results, perform visualization processing to obtain visualized data and display the visualized data on the visualization interface.
[0110] In some embodiments, such as Figure 1 As shown, the network traffic monitoring and analysis system has a traffic operation module, which includes a visualization page that can display the analysis results of the traffic data to the operation and maintenance staff, namely the traffic interaction analysis results.
[0111] In some embodiments, traffic interaction data is visualized and displayed on a webpage or mobile device.
[0112] S107. Based on the traffic interaction analysis results, generate network operation and maintenance strategies for the target area.
[0113] It should be noted that step S106 is to visualize the analysis results, while step S107 can generate corresponding network operation and maintenance strategies based on the operation and maintenance needs of the operation and maintenance staff for the traffic interaction data.
[0114] In some embodiments, the network operation and maintenance strategy can be implemented based on an artificial intelligence model. That is, the artificial intelligence model can predict future traffic data based on traffic interaction analysis results, and then generate a targeted network operation and maintenance strategy based on the predicted traffic data. Specifically, this step can be referred to below. Figure 9 This will not be elaborated upon here.
[0115] The network traffic monitoring and analysis method provided in this application first acquires network topology data within a target area to construct a network topology map, integrating network nodes and links within the target area to obtain relatively complete network structure information (i.e., a network topology map). Then, by utilizing management records, it captures the operational needs of different sub-regions within the target area, determining the differentiated traffic monitoring frequencies between sub-regions, thereby obtaining targeted and effective traffic data. Ultimately, this improves the efficiency of network operation and maintenance analysis within the target area. Compared with existing technologies, this method, through data-driven (management record) traffic collection strategy design, can improve the targeting of traffic collection, reduce redundant traffic monitoring, and optimize the efficiency of traffic monitoring.
[0116] The network traffic monitoring method provided in this application firstly integrates network topology data and management records within a target area to generate differentiated traffic monitoring strategies. This allows for the analysis of traffic monitoring and analysis needs in different monitoring sub-regions from a global perspective, improving the targeting of traffic data collection. Simultaneously, by introducing a traffic evaluation index system, a comprehensive feature evaluation of traffic data can be performed from multiple dimensions to obtain traffic characteristic data. Then, using the traffic characteristic data, traffic interaction analysis is conducted on different monitoring sub-regions within the target area to obtain traffic interaction analysis results reflecting traffic in both temporal and spatial dimensions. Finally, a network operation and maintenance strategy is generated based on the traffic interaction analysis results. Compared with existing technologies, this method reduces redundant traffic monitoring by formulating differentiated traffic collection strategies. Furthermore, the multi-dimensional traffic evaluation index system and multi-regional traffic interaction analysis overcome the limitations of single-dimensional traffic analysis, enabling traffic analysis from a global traffic flow perspective, improving the accuracy of traffic analysis and the reliability of network operation and maintenance strategies.
[0117] In some embodiments, step S104, the process of evaluating traffic data based on the traffic evaluation index system, involves: first, extracting the corresponding raw data from the traffic data according to the index type; then cleaning, verifying, and supplementing the raw data to ensure that the data meets the evaluation criteria. Subsequently, evaluating each index dimension according to preset rules. Finally, summarizing the evaluation results of each dimension to form structured traffic evaluation processing data.
[0118] One possible implementation method, taking the traffic status assessment rule as an example, is to define the assessment rule as judging the traffic transmission status by comparing the real-time bandwidth utilization rate with the maximum link capacity threshold (e.g., 80%) and the historical average value for the same period, combined with the short-term fluctuation range (e.g., fluctuation > 20% within 1 hour).
[0119] When using it, after inputting real-time bandwidth data, if the utilization rate is less than 60% and the fluctuation is small, it is judged as "stable". If it is in the range of 60%-80% and the fluctuation is large, it is judged as "potential saturation risk". If it is ≥80%, "link congestion warning" is triggered directly.
[0120] Another possible implementation method, taking the evaluation rule of active connection count as an example, is to use 80% of the maximum number of connections that a node can carry as the warning line, combined with the threshold of new connections per second (such as 200 / second), to judge the connection load and abnormal risks. When in use, when the number of concurrent connections is less than 80% of the maximum capacity and the number of new connections is normal, it is marked as "no overload risk". If the number of concurrent connections is close to the maximum value or the number of new connections exceeds the limit, it is marked as "suspected connection storm" and associated with potential attack investigation.
[0121] The traffic collection strategy is described below with reference to the attached diagram.
[0122] In some embodiments, the traffic collection strategy may include the traffic collection frequency. The network traffic monitoring and analysis system can determine the traffic collection strategy by constructing a management knowledge graph to associate sub-regions within the target area with fault events and by analyzing the fault risks within the sub-regions.
[0123] The process is as follows Figure 3 As shown, step S102 specifically includes the following steps:
[0124] S201. Generate network node entities based on the network topology diagram.
[0125] One possible implementation is that the network traffic monitoring and analysis system can extract basic information about network nodes (such as node identifiers and IP addresses) from the aforementioned network topology diagram, create network node entities based on this basic information, and obtain the network node type, interface configuration, communication protocol, and topology level information as attributes of the network node entities. Furthermore, the network traffic monitoring and analysis system can also construct the neighboring nodes and link parameter attributes of each network node entity based on its link information, used to identify the connection relationships between network node entities.
[0126] S202. Generate management event entities based on management records.
[0127] Among them, the management event entities include at least the following categories: operation and maintenance event entities, traffic anomaly event entities, traffic configuration event entities, performance monitoring event entities, and security operation and maintenance event entities.
[0128] It should be noted that,
[0129] An operation and maintenance event entity refers to an entity that performs planned maintenance operations on a node. This operation and maintenance event entity includes attributes such as: maintenance type (e.g., inspection, upgrade, etc.), maintenance steps, maintenance time window, operation and maintenance personnel, maintenance impact, and maintenance effect.
[0130] A traffic anomaly event entity refers to an entity that experiences a traffic anomaly event on a node. This traffic anomaly event entity includes attributes such as: traffic anomaly type, traffic anomaly event, scope of impact of traffic anomaly, root cause of traffic anomaly, and solution.
[0131] Security operation and maintenance event entities refer to intrusion prevention events related to node security. These security operation and maintenance event entities include attributes such as intrusion event type, security threat level, and solution.
[0132] A performance monitoring event entity refers to an entity that performs performance monitoring and analysis on a node. This performance monitoring event entity includes: node type, node performance metrics, performance data collection method, performance monitoring results, and performance improvement strategies.
[0133] Traffic configuration event entities refer to configuration operation events that manually or automatically adjust node traffic policies. These entities include: configuration type, configuration content, triggering method, scope of impact, rollback strategy, etc.
[0134] One possible implementation is that the network traffic monitoring and analysis system can extract the basic attributes of each management record (event) from the management logs, such as the occurrence node, occurrence time, and duration of the operation and maintenance event, and create a management event entity based on these basic attributes. Then, the type attribute of each management event entity is set to the corresponding operation and maintenance event type. Based on the operation and maintenance event type of each management event entity, the attribute fields specific to that type are then populated, thereby completely constructing a fault event entity, a routine maintenance event entity, a performance monitoring event entity, or a security management event entity.
[0135] In some embodiments, management records may include expert experience, system operation logs, user feedback, etc., and the specific content of management records is not limited in this application embodiment.
[0136] S203. Based on the preset sub-region division rules, the target region is divided into multiple sub-regions, and the corresponding region entities of each sub-region are generated.
[0137] One possible implementation is that the network traffic monitoring and analysis system can divide sub-regions according to preset sub-region division rules (refer to the introduction of sub-region division in step S102 above, which will not be repeated here), and create regional entities based on the geographical location and coverage of the sub-regions. Furthermore, the network traffic monitoring and analysis system can also construct a list of nodes belonging to the regional entity and node distribution density attributes based on the inclusion relationship between the sub-regions and network nodes.
[0138] S204. Based on regional entities, network node entities, and management event entities, determine the relationships between these entities to obtain a management knowledge graph.
[0139] One possible implementation approach is to construct a triplet model to associate three types of entities: regions, network nodes, and operational events, forming a management knowledge graph. Regions and nodes are linked by an "inclusion" relationship, nodes and events by an "occurrence" relationship, and different types of events by "trigger" or "cause" relationships. Then, a graph database is used to store these entities and relationships, constructing the management knowledge graph.
[0140] S205. Based on the management knowledge graph, determine the monitoring sub-regions and the corresponding traffic collection frequencies from multiple sub-regions to determine the traffic collection strategy.
[0141] For a detailed description of this step, please refer to [link / reference]. Figure 4 or Figure 5 This will not be elaborated upon here.
[0142] As can be seen from steps S201-S205, this method, by constructing a management knowledge graph, transforms sub-regions, network nodes, and management events into structural entities, which can intuitively present the management density of different sub-regions within the target area. Through this management knowledge graph, sub-regions with high management needs and high-frequency traffic anomalies can be accurately located, thereby improving the targeting of traffic collection strategies and realizing a shift from passive response to proactive prevention in operation and maintenance strategies.
[0143] In some embodiments, the network traffic monitoring and analysis system can determine the monitoring sub-regions and their corresponding traffic monitoring frequencies based on the number of maintenance operations in sub-regions within a target area, thereby determining the traffic collection strategy. In this case, such as Figure 4 As shown, step S205 specifically includes the following steps:
[0144] S301. Based on the number of management event entities corresponding to each regional entity in the management knowledge graph, determine the number of times each regional entity manages the corresponding sub-region.
[0145] It should be noted that, as mentioned above, in the management knowledge graph, regional entities are associated with (including) network node entities, and network node entities are associated with (occurring with) management event entities. Therefore, the network traffic monitoring and analysis system can determine the number of maintenance operations for a sub-region by calculating the number of management event entities associated with regional entities, including network node entities.
[0146] It should also be noted that the number of times a sub-region is managed refers to the total number of times network nodes within that region are operated and managed.
[0147] In some embodiments, when determining the number of times a sub-region corresponding to a regional entity is managed, the network traffic monitoring and analysis system can also set time conditions to limit the occurrence time of the management event entity to a preset time period. This allows the network traffic monitoring and analysis system to acquire fault events within a specified time range, reducing interference from historical data.
[0148] In some embodiments, when determining the number of times a sub-region corresponding to a regional entity is managed, the network traffic monitoring and analysis system can also set time conditions to limit the occurrence time of management events to a preset time period. This allows the network traffic monitoring and analysis system to acquire management events within a specified time range, enabling more accurate analysis of the trends and periodic characteristics of traffic data.
[0149] For example, the preset time can be a time period, such as 12 hours, 24 hours, or 36 hours. Alternatively, the preset time can be a fixed time period within a time range each day, such as 7 PM, 10 PM, and 12 PM every day within a month. This application embodiment does not limit the specific value of the preset time.
[0150] S302. Sub-regions with more than the management frequency threshold are identified as monitoring sub-regions.
[0151] In some embodiments, the network traffic monitoring and analysis system may also identify sub-regions with a number of management attempts greater than or equal to a management attempt threshold as monitoring sub-regions.
[0152] For example, the management frequency threshold can be set to 30, 40, or 50. This application embodiment does not limit the specific value of the fault quantity threshold.
[0153] For example, if the threshold for the number of false management attempts is set to 60, and the number of regional entities in the management knowledge graph is 5 (i.e., there are 5 sub-regions within the target region), the corresponding number of management attempts are 40, 60, 70, 30, and 100, respectively. Based on the relationship between the number of management attempts for each regional entity and the fault number threshold, the sub-regions corresponding to the regional entities with 60, 70, and 100 faults are determined as monitoring sub-regions.
[0154] S303. Based on the number of management sessions corresponding to the monitoring sub-region and the preset management session-collection frequency mapping rule, determine the traffic monitoring frequency corresponding to the monitoring sub-region.
[0155] One possible implementation involves a pre-defined mapping rule for the number of management sessions and the acquisition frequency: dividing the number of management sessions into multiple gradient intervals, with each interval corresponding to a different acquisition frequency.
[0156] For example, when the number of times a monitored sub-area is managed is between 60 and 75, traffic data is collected once per hour according to the mapping rules; if the number of times is managed is between 75 and 100, traffic data is collected twice per hour; and if the number of times is managed exceeds 100, traffic data is collected four times per hour.
[0157] Another possible implementation method is to use a preset management frequency-collection frequency mapping rule: adopt a dynamic ratio mapping rule, and determine the collection frequency based on the ratio of the management frequency to the historical average management frequency.
[0158] The historical average number of management sessions refers to the average number of management sessions conducted in the monitored sub-area over the same period in the past.
[0159] For example, if the ratio of the current number of managements in a monitored sub-area to the historical average number of managements in the same period is between 1.2 and 1.5, then according to the mapping rules, traffic data is collected once per hour; if the ratio is between 1.5 and 2, then traffic data is collected twice per hour; when the ratio exceeds 2, then traffic data is collected four times per hour. This allows for dynamic adjustment of the monitoring frequency based on changes in the number of managements, accurately capturing traffic anomalies.
[0160] S304. Determine the traffic collection strategy based on the monitoring sub-region and the corresponding traffic monitoring frequency of the monitoring sub-region.
[0161] In other embodiments, the network traffic monitoring and analysis system may also determine the monitoring sub-regions and their corresponding traffic monitoring frequencies based on the number of traffic anomaly events (i.e., the number of traffic anomalies) occurring in sub-regions within the target area, thereby determining the traffic collection strategy. In this case, such as Figure 5 As shown, step S205 specifically includes the following steps:
[0162] S401. Based on the number of traffic anomaly event entities in the management event entities corresponding to each regional entity in the management knowledge graph, determine the number of traffic anomalies in the sub-regions corresponding to each regional entity.
[0163] One possible implementation is that the network traffic monitoring and analysis system can retrieve the number of traffic anomaly event entities among the management event entities associated with each regional entity in the management knowledge graph, and determine the number of traffic anomalies in the sub-regions corresponding to each regional entity.
[0164] S402. Sub-regions with a number of abnormal traffic occurrences exceeding the threshold for abnormal traffic occurrences are identified as monitoring sub-regions.
[0165] For example, the threshold for the number of traffic anomalies can be 10, 15, or 20. This application does not limit the specific value of the threshold for the number of traffic anomalies.
[0166] S403. Based on the number of traffic anomalies corresponding to the monitored sub-region and the preset traffic anomaly number-collection frequency mapping rule, determine the traffic monitoring frequency corresponding to the monitored sub-region.
[0167] One possible implementation is that the traffic anomaly count-collection frequency mapping rule can be as follows: normalize the number of traffic anomalies corresponding to the monitored sub-regions to determine the severity score of traffic anomalies for each monitored sub-region. Then, based on the severity score of traffic anomalies, determine the traffic monitoring frequency for each monitored sub-region.
[0168] For example, suppose that in a network, the number of traffic anomalies in three monitoring sub-regions within 30 days are 15 for sub-region A, 8 for sub-region B, and 20 for sub-region C. After normalizing the number of traffic anomalies (traffic anomaly severity score = actual number of traffic anomalies / maximum number of traffic anomalies in the entire network, 20), we get a traffic anomaly severity score of 0.75 for sub-region A, 0.4 for sub-region B, and 1.0 for sub-region C. The mapping rule is set as follows: high-frequency monitoring every 5 minutes when the score is ≥0.8, medium-frequency monitoring every 15 minutes when the score is 0.4 ≤ score <0.8, and low-frequency monitoring every 30 minutes when the score <0.4. Therefore, it is determined that sub-region C, with a score of 1.0, needs to collect traffic data every 5 minutes; sub-region A, with a score of 0.75, needs to collect data every 15 minutes; and sub-region B, with a score of 0.4, needs to collect data every 15 minutes. Furthermore, when the number of traffic anomalies in sub-region A increases to 18, the score is updated to 0.9, and the monitoring frequency is increased to once every 5 minutes.
[0169] S404. Determine the traffic collection strategy based on the monitoring sub-region and the corresponding traffic monitoring frequency of the monitoring sub-region.
[0170] As can be seen from steps S301-S304 and S401-S404, the network traffic monitoring and analysis system, by managing a knowledge graph, can determine traffic collection strategies based on the relationships between various entities and the frequency of maintenance, enabling rapid identification of sub-regions with intensive management needs. Determining the traffic collection strategy based on the frequency of traffic anomalies allows for the identification of sub-regions where traffic anomalies occur frequently. Through these two different analysis dimensions, differentiated traffic collection strategies can be implemented, effectively saving on traffic monitoring costs.
[0171] In some embodiments, when collecting traffic, the network traffic monitoring and analysis system can first evaluate the performance of network nodes in the monitored sub-region, identifying the network nodes with better performance as traffic collection nodes to ensure the stability of the traffic collection process. In this case, such as... Figure 6 As shown, step S104 specifically includes the following steps:
[0172] S501. Obtain the performance information of each of the multiple network nodes in the monitoring sub-region.
[0173] Among them, performance information can be understood as a quantitative indicator of the operating status of network nodes, which is used to reflect the comprehensive capabilities of nodes in data processing, network transmission, resource consumption, etc.
[0174] Specifically, network node performance information can include the following metrics: CPU utilization, remaining memory, network bandwidth utilization, disk I / O read / write speed, process response time, and number of error logs.
[0175] In some embodiments, the network traffic monitoring and analysis system can acquire the performance information of multiple network nodes in a monitoring sub-region according to a preset time range.
[0176] S502. Quantify the performance information of each of the multiple network nodes to obtain the performance quantification score of each of the multiple network nodes.
[0177] One possible implementation is that the network traffic monitoring and analysis system can use a weighted scoring method, assigning weights to each indicator in the performance information. Then, the indicator values in the performance information of each network node are normalized to fall within the 0-1 range, and then multiplied by the corresponding weights of each indicator before summing to obtain a quantitative performance score.
[0178] For example, suppose the weights for CPU utilization, remaining memory, network bandwidth utilization, disk I / O read / write speed, process response time, and number of error logs are set to: 0.2, 0.15, 0.15, 0.15, 0.2, and 0.15. The performance information of a certain network node shows CPU utilization, remaining memory, network bandwidth utilization, disk I / O read / write speed, process response time, and number of error logs as: 70%, 2GB, 60%, 120MB / s, 200ms, and 8 logs, respectively. After normalizing each metric using the max-min normalization formula, the values are: 0.86, 0.33, 0.71, 0.47, 0.6, and 0.4. Finally, the performance quantification score of the network node is obtained by multiplying the normalized values of each indicator by their corresponding weights and then summing them up, i.e., 0.86×0.2+0.33×0.15+0.71×0.15+0.47×0.15+0.6×0.2+0.4×0.15=0.6115.
[0179] The maximum and minimum values of each indicator are obtained by statistically monitoring the historical data of the corresponding indicators of all network nodes within the sub-region.
[0180] S503. Network nodes whose performance quantification scores are greater than the performance score threshold are identified as traffic collection nodes.
[0181] It should be noted that network node performance may be unstable in the monitoring sub-region, affecting the traffic collection process. Therefore, the network traffic monitoring and analysis system can evaluate the performance of network nodes in the monitoring sub-region and select stable network nodes as traffic collection nodes.
[0182] In some embodiments, the network traffic monitoring and analysis system may also identify network nodes whose performance quantification score is greater than or equal to the performance score threshold as traffic collection nodes.
[0183] For example, the performance scoring threshold can be set to 0.6, 0.8, or 0.9. The specific value of the performance scoring threshold can be determined according to the method for determining performance quantification scores, and the embodiments of this application do not limit the specific value of the performance scoring threshold.
[0184] For example, if there are 100 network nodes in a certain monitoring sub-region, the performance quantification score of these 100 network nodes is determined in step S502. Network nodes with a performance quantification score greater than the performance score threshold of 0.8 are identified as traffic monitoring nodes. Assuming that 30 network nodes out of the 100 network nodes have a performance score greater than 0.8, these 30 network nodes are identified as traffic monitoring nodes.
[0185] S504. Based on the performance quantification score of the traffic acquisition node and the preset score-priority mapping rule, determine the traffic acquisition priority of the traffic acquisition node in the monitoring sub-region.
[0186] It should be noted that traffic acquisition priority is used to indicate the traffic monitoring task resources allocated by the network traffic monitoring and analysis system to the traffic acquisition node during the traffic acquisition process, such as the traffic acquisition bandwidth channel, traffic data cache priority, acquisition task scheduling weight, and monitoring anomaly response level.
[0187] It should also be noted that the scoring-priority mapping rule can refer to the management number-collection frequency mapping rule in step S303 above, or the relevant description of the traffic anomaly number-collection frequency mapping rule in step S403, which will not be elaborated here.
[0188] In some embodiments, the traffic collection method of a corresponding traffic collection node can also be determined based on the traffic collection priority. Collection nodes with higher traffic collection priority have more real-time and comprehensive traffic collection methods, which can prioritize the capture and processing of critical traffic data.
[0189] For example, traffic collection methods include: full collection, sampling collection, triggered collection, real-time streaming collection, and periodic collection. This application does not limit the methods of traffic collection.
[0190] For example, traffic collection methods include: telemetry, port mirroring / traffic mirroring, netconf, Secure File Transfer Protocol (SFTP), etc. (sorted from high to low according to traffic collection priority).
[0191] S505. Based on the traffic acquisition priority and traffic acquisition strategy of the traffic acquisition nodes, traffic acquisition nodes in different monitoring sub-regions within the target area are used to acquire traffic data of the target area.
[0192] As shown in steps S501-S505, this method, within the monitoring sub-region, filters traffic collection nodes from the network nodes based on their performance information and determines the traffic collection priority of these nodes. This makes the traffic collection process more targeted and efficient, ensuring that monitoring resources are concentrated on nodes with better performance, and guaranteeing the stability and reliability of traffic collection.
[0193] The following section, in conjunction with the accompanying diagram, describes the process for determining the results of traffic interaction analysis.
[0194] In some embodiments, when the network traffic monitoring and analysis system performs analysis based on traffic characteristic data, it can use a pre-trained traffic interaction analysis model to analyze the traffic interaction analysis results.
[0195] One possible implementation, when the traffic interaction analysis results include the traffic interaction analysis results of a single monitored sub-region, is as follows: Figure 7 As shown, the specific steps include the following:
[0196] S601. If the traffic interaction analysis results include the traffic interaction analysis results of a single monitoring sub-region within the target area, obtain the target traffic assessment and processing data corresponding to the target monitoring sub-region from the traffic assessment and processing data.
[0197] The target monitoring sub-region is any one of the different monitoring sub-regions.
[0198] S602. Input the target traffic assessment and processing data into the pre-trained traffic interaction analysis model to determine the traffic interaction analysis results of the target monitoring sub-region.
[0199] Among them, the traffic interaction analysis model is used to perform spatiotemporal correlation analysis based on the traffic assessment and processing data of the monitoring sub-region, and to determine the traffic interaction analysis results between different traffic acquisition nodes in the monitoring sub-region.
[0200] One possible implementation, where the traffic interaction analysis model analyzes traffic assessment characteristics, can be represented as follows:
[0201] The traffic interaction analysis model analyzes traffic assessment features as follows: First, it preprocesses the input traffic assessment data for the target monitoring sub-region. This data covers multi-dimensional indicators such as traffic status, active connection count, basic resource parameters, IPv6 adaptation, and operational status. The model then extracts spatial and temporal features. The spatial dimension includes the location, type, and traffic attributes of each traffic collection node based on these multi-dimensional indicators. The temporal dimension represents the dynamic changes of these indicators within a continuous time window, while outlier removal and data standardization are performed. Next, the feature extraction module conducts spatiotemporal correlation analysis. Spatially, it combines the physical distance between nodes and the matching degree of node types presented by multi-dimensional indicators to determine potential correlations. Temporally, it calculates the temporal synchronicity of traffic changes between nodes based on multi-dimensional indicators, statistically analyzes the frequency and duration of interactions to generate temporal correlation strength values, and then extracts node correlation features. Finally, it combines preset thresholds and business rules to determine the type and strength of interaction relationships between nodes, and outputs structured data and correlation labels to provide a foundation for subsequent visualization.
[0202] In some embodiments, when the traffic interaction analysis results include traffic interaction analysis results for multiple monitoring sub-regions, the process can determine the traffic interaction analysis results corresponding to each of the different monitoring sub-regions through the above steps S601-S602, and then perform correlation analysis on the traffic interaction analysis results corresponding to each of the different monitoring sub-regions to obtain the traffic interaction analysis results for different monitoring sub-regions. This process is as follows: Figure 8 As shown, the specific steps include the following:
[0203] S701. When the traffic interaction analysis result is the traffic interaction analysis result between different monitoring sub-regions, obtain the traffic interaction analysis result corresponding to each of the different monitoring sub-regions.
[0204] S702. Input the traffic interaction analysis results corresponding to different monitoring sub-regions into the pre-trained joint traffic interaction analysis model to determine the traffic interaction analysis results between different monitoring sub-regions.
[0205] Among them, the joint traffic interaction analysis model is used to determine the traffic interaction analysis results between different monitoring sub-regions based on the traffic interaction analysis results corresponding to each of the different monitoring sub-regions.
[0206] It should be noted that the joint traffic interaction analysis model differs from the traffic interaction analysis model in that their analysis granularity differs. The traffic interaction analysis model analyzes traffic characteristic data of network nodes within the same monitoring sub-region, while the joint traffic interaction analysis model analyzes traffic interaction results corresponding to different monitoring regions. However, in the embodiments of this application, the traffic interaction analysis results of different monitoring sub-regions are also obtained based on their respective traffic characteristic data. That is, the traffic interaction analysis results can be regarded as aggregated traffic characteristic data. Therefore, in some embodiments, the joint traffic interaction analysis model and the traffic interaction analysis model can be the same model. In this case, the specific analysis process of step S702 can be referred to the analysis process of step S602, and will not be elaborated here.
[0207] In some embodiments, the initial model and the joint traffic interaction analysis model can be graph neural network models.
[0208] The following section, in conjunction with the accompanying diagram, introduces the method for generating network operation and maintenance strategies.
[0209] In some embodiments, such as Figure 9 As shown, step S107 can be specifically implemented as follows:
[0210] S801. Input the traffic interaction analysis results into the traffic prediction model, and use the traffic prediction model to perform time series feature analysis on the traffic interaction analysis results to determine the predicted traffic data.
[0211] In some embodiments, the initial model for the traffic prediction model may be a long short-term memory network model or a spatiotemporal fusion model.
[0212] Long Short-Term Memory (LSTM) network models are recurrent neural network models that process time-series data through gating mechanisms (input gate, forget gate, output gate). Traffic prediction models pre-trained with LTM network models can selectively retain important long-term dependency information (such as the daily peak traffic patterns of a node) while forgetting noise or short-term irrelevant fluctuations (such as sudden bursts of small traffic flows) when analyzing the historical time-series characteristics of traffic interaction analysis results. This allows for accurate capture of traffic data trends over time (e.g., predicting traffic changes in the next 24 hours based on the node interaction traffic time-series of the past week), making them particularly suitable for single-dimensional or single-node traffic time-series prediction scenarios.
[0213] A spatiotemporal fusion model refers to a model that simultaneously integrates spatial correlation features and time series features for analysis. A traffic prediction model pre-trained using a spatiotemporal fusion model captures the spatial correlations between different nodes / sub-regions (such as the traffic interaction dependency between node A and node B due to their close physical distance) through a spatial feature extraction module (as shown in the convolutional layer). Simultaneously, it captures the dynamic changes in traffic over time through a time feature extraction module (such as a time attention mechanism) (such as the lag pattern where traffic in region B increases synchronously 10 minutes after traffic in region A increases). Finally, it combines these spatiotemporal features to achieve prediction. This model can adapt to complex traffic scenarios involving multiple nodes and regions (such as predicting the interconnected traffic changes of all nodes within a certain area, or the interactive traffic trends between different sub-regions), avoiding prediction biases caused by neglecting spatial correlations.
[0214] In some embodiments, the network traffic monitoring and analysis system can also use a training dataset to train the initial model of the traffic prediction model to obtain a pre-trained traffic prediction model.
[0215] Specifically, the training dataset includes multiple training samples, each of which includes the traffic interaction analysis results within the training area in the first time period and the predicted traffic data labels for the training area in the second time period.
[0216] S802. Based on the predicted traffic data, generate network operation and maintenance strategies for the target area.
[0217] One possible implementation, step S802 can be specifically implemented as follows:
[0218] Based on the predicted traffic data, relevant historical operation and maintenance cases, risk assessment rules and resource configuration templates can be retrieved from the management knowledge graph mentioned above (such as S204). For example, "cases of handling when the predicted traffic peak exceeds the link carrying threshold", "routing protocol anomaly warning rules corresponding to IPv6 traffic surge", and "resource allocation template for regional traffic expansion" can be retrieved.
[0219] Then, the predicted traffic data is matched and analyzed with the retrieved related information (such as determining whether the current predicted traffic triggers the threshold conditions in the risk rules and the similarity of traffic characteristics with historical cases), and targeted strategies are generated by combining the real-time network status data of the target area (such as the current link bandwidth utilization, server CPU load, IPv6 interface adaptation rate, etc.).
[0220] For example, if it is predicted that the traffic in a certain sub-region will reach the link capacity limit in the next 3 hours, and similar historical cases are found where "expanding capacity 1 hour in advance can avoid congestion", then based on the current bandwidth availability in the region, an operation and maintenance strategy of "initiating temporary bandwidth expansion to 1.2 times the current capacity within 30 minutes" is generated.
[0221] As shown in steps S801-S802, the predicted traffic data obtained based on the traffic interaction analysis results and the traffic prediction model can reflect the future traffic interaction trends between network nodes and monitoring sub-regions within the target area. This prediction result combines the spatiotemporal correlation characteristics of the traffic interaction analysis results with a comprehensive judgment of multi-dimensional evaluation indicators, ensuring the accuracy of traffic prediction. Finally, based on this prediction result, a network operation and maintenance strategy is generated, realizing a closed-loop strategy for traffic monitoring and analysis, and constructing a "monitoring-analysis-prediction-optimization" network operation and maintenance mechanism.
[0222] The above primarily describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the network traffic monitoring device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Experts may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0223] In exemplary embodiments, as described above, the traffic acquisition system may specifically be an electronic device with computing processing capabilities, such as a computer or service. In this case, embodiments of this application also provide an electronic device. Figure 10This is a schematic diagram illustrating the composition of an electronic device provided in an embodiment of this application. For example... Figure 10 As shown, the electronic device includes: a processor 10, a memory 20, a communication line 30, a communication interface 40, and an input / output interface 50.
[0224] The processor 10, memory 20, communication interface 40, and input / output interface 50 can be connected via communication line 30.
[0225] The processor 10 is used to execute instructions stored in the memory 20 to implement the network traffic monitoring and analysis method provided in the above embodiments of this application. The processor 10 can be a CPU, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller (MCU) / single-chip microcomputer / microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 10 can also be any other device with processing capabilities, such as a circuit, device, or software module; this application embodiment does not limit this. In one example, the processor 10 may include one or more CPUs, for example... Figure 10 CPU0 and CPU1 in the example. As an optional implementation, the electronic device may include multiple processors; for example, in addition to processor 10, it may also include processor 60. Figure 10 (The example shown is a dashed line).
[0226] The memory 20 is used to store instructions. For example, the instructions may be computer programs. Optionally, the memory 20 may be a read-only memory (ROM) or other types of static storage devices that can store static information and / or instructions; it may also be a random access memory (RAM) or other types of dynamic storage devices that can store information and / or instructions; it may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, etc. The embodiments of this application do not limit this.
[0227] It should be noted that the memory 20 can exist independently of the processor 10 or it can be integrated with the processor 10. The memory 20 can be located inside or outside the electronic device, and this application embodiment does not impose any restrictions on this.
[0228] Communication line 30 is used to transmit information between the components included in the electronic device.
[0229] Communication interface 40 is used to communicate with other devices or other communication networks. These other communication networks can be Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc. Communication interface 40 can be a module, circuit, transceiver, or any device capable of enabling communication.
[0230] Input / output interface 50 is used to enable human-computer interaction between users and electronic devices. For example, it enables action interaction or information exchange between users and electronic devices.
[0231] For example, the input / output interface 50 can be a mouse, keyboard, display screen, or touch screen. Action or information interaction between the user and the electronic device can be achieved through a mouse, keyboard, display screen, or touch screen.
[0232] It should be noted that, Figure 10 The structures shown do not constitute a limitation on electronic devices, except... Figure 10 In addition to the components shown, electronic devices may include more or fewer components than illustrated, or combinations of certain components, or different component arrangements.
[0233] In an exemplary embodiment, this application also provides a readable storage medium including software instructions that, when run on an electronic device, cause the electronic device to perform any of the methods provided in the above embodiments.
[0234] In an exemplary embodiment, this application also provides a computer program product containing computer execution instructions, which, when run on an electronic device, causes the electronic device to perform any of the methods provided in the above embodiments.
[0235] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer-executable instructions. When these computer-executable instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer-executable instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer-executable instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).
[0236] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, disclosure, and appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0237] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
[0238] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network traffic monitoring and analysis method, characterized in that, include: Obtain network topology data for the target area, and construct a network topology map based on the network topology data; Based on the network topology map and the management records of the target area, a traffic collection strategy is determined; The traffic acquisition strategy includes traffic acquisition strategies for different monitoring sub-regions within the target area; Based on the traffic acquisition strategy, traffic is collected from different monitoring sub-regions within the target area to obtain traffic data for the target area. The traffic data is evaluated and processed based on the traffic evaluation index system to obtain the traffic evaluation and processing data corresponding to the traffic data. The traffic evaluation index system is used to evaluate and process the traffic data from different dimensions; Based on the traffic assessment and processing data, the traffic interaction analysis results are determined; The traffic interaction analysis results include the traffic interaction analysis results within a single monitoring sub-region within the target area and / or the traffic interaction analysis results between different monitoring sub-regions; Based on the traffic interaction analysis results, visualization processing is performed to obtain visualized data and display the visualized data on a visualization interface; Based on the traffic interaction analysis results, a network operation and maintenance strategy for the target area is generated.
2. The method according to claim 1, characterized in that, The traffic assessment index system includes the following: Traffic status, number of active connections and basic resource parameters, network element support for IPv6 protocol, functional availability of business applications in IPv6 environment, proportion of IPv6 routing protocol error packets and IPv6 and cloud service interface adaptation rate.
3. The method according to claim 1, characterized in that, The traffic collection strategy includes the traffic collection frequency; determining the traffic collection strategy based on the network topology map and the management records of the target area includes: Based on the network topology diagram, generate network node entities; Based on the management records, management event entities are generated; the management event entities include the following categories: operation and maintenance event entities, traffic anomaly event entities, traffic configuration event entities, performance monitoring event entities, and security operation and maintenance event entities; Based on preset sub-region division rules, the target region is divided into multiple sub-regions, and region entities corresponding to each sub-region are generated. Based on the regional entities, the network node entities, and the management event entities, the relationships between the entities are determined to obtain a management knowledge graph; Based on the management knowledge graph, the monitoring sub-region and the corresponding traffic collection frequency of the monitoring sub-region are determined from the multiple sub-regions to determine the traffic collection strategy.
4. The method according to claim 3, characterized in that, The step of determining the monitoring sub-region and the corresponding traffic collection frequency from the multiple sub-regions based on the management knowledge graph, in order to determine the traffic collection strategy, includes: Based on the number of management event entities corresponding to each regional entity in the management knowledge graph, the number of times each regional entity manages a sub-region is determined. The sub-regions whose number of management attempts exceeds the management attempt threshold are defined as the monitoring sub-regions; Based on the number of management sessions corresponding to the monitoring sub-region and the preset management session-collection frequency mapping rule, the traffic monitoring frequency corresponding to the monitoring sub-region is determined; The traffic acquisition strategy is determined based on the monitoring sub-region and the corresponding traffic monitoring frequency of the monitoring sub-region.
5. The method according to claim 3, characterized in that, The step of determining the monitoring sub-region and the corresponding traffic collection frequency from the multiple sub-regions based on the management knowledge graph, in order to determine the traffic collection strategy, includes: Based on the number of traffic anomaly event entities in the management event entity corresponding to each regional entity in the management knowledge graph, the number of traffic anomalies in the sub-region corresponding to each regional entity is determined. The sub-regions where the number of abnormal traffic occurrences exceeds the threshold for abnormal traffic occurrences are defined as the monitoring sub-regions; Based on the number of traffic anomalies corresponding to the monitoring sub-region and the preset traffic anomaly number-collection frequency mapping rule, the traffic monitoring frequency corresponding to the monitoring sub-region is determined. The traffic acquisition strategy is determined based on the monitoring sub-region and the corresponding traffic monitoring frequency of the monitoring sub-region.
6. The method according to claim 1, characterized in that, The step of collecting traffic data for different monitoring sub-regions within the target area based on the traffic collection strategy, to obtain traffic data for the target area, includes: Obtain the performance information of each of the multiple network nodes in the monitoring sub-region; The performance information corresponding to each of the multiple network nodes is quantified to obtain the performance quantification score corresponding to each of the multiple network nodes. Network nodes whose performance quantification score is greater than the performance score threshold are identified as traffic collection nodes; Based on the performance quantification score of the traffic acquisition node and the preset score-priority mapping rule, the traffic acquisition priority of the traffic acquisition node in the monitoring sub-region is determined. Based on the traffic acquisition priority of the traffic acquisition nodes and the traffic acquisition strategy, traffic acquisition nodes in different monitoring sub-regions within the target area are used to acquire traffic data for the target area.
7. The method according to claim 1, characterized in that, The step of determining the traffic interaction analysis results for the target area based on the traffic assessment and processing data includes: If the traffic interaction analysis result includes the traffic interaction analysis result of a single monitoring sub-region within the target area, the target traffic assessment and processing data corresponding to the target monitoring sub-region is obtained from the traffic assessment and processing data; the target monitoring sub-region is any one of the different monitoring sub-regions. The target traffic assessment and processing data is input into a pre-trained traffic interaction analysis model to determine the traffic interaction analysis results of the target monitoring sub-region. The traffic interaction analysis model is used to perform spatiotemporal correlation analysis based on the traffic assessment and processing data of the monitoring sub-region to determine the traffic interaction analysis results between different traffic acquisition nodes within the monitoring sub-region.
8. The method according to claim 7, characterized in that, The step of determining the traffic interaction analysis results for the target area based on the traffic assessment and processing data includes: If the traffic interaction analysis result is the traffic interaction analysis result between the different monitoring sub-regions, then obtain the traffic interaction analysis result corresponding to each of the different monitoring sub-regions. The traffic interaction analysis results corresponding to each of the different monitoring sub-regions are input into a pre-trained joint traffic interaction analysis model to determine the traffic interaction analysis results between the different monitoring sub-regions; the joint traffic interaction analysis model is used to determine the traffic interaction analysis results between the different monitoring sub-regions based on the traffic interaction analysis results corresponding to each of the different monitoring sub-regions.
9. The method according to claim 1, characterized in that, The process of generating a network operation and maintenance strategy for the target area based on the traffic interaction analysis results includes: The traffic interaction analysis results are input into the traffic prediction model, and the traffic prediction model performs time-series feature analysis on the traffic interaction analysis results to determine the predicted traffic data. Based on the predicted traffic data, a network operation and maintenance strategy for the target area is generated.
10. A network traffic monitoring and analysis system, characterized in that, The network traffic monitoring and analysis system includes: a policy management module, a pre-collection evaluation module, a traffic data acquisition module, a traffic data processing module, a traffic data storage module, a traffic analysis module, a traffic prediction module, and a traffic operation module. The policy management module is used to acquire network topology data of the target area and construct a network topology map based on the network topology data; and determine a traffic collection policy based on the network topology map and the management records of the target area; the traffic collection policy includes traffic collection policies for different monitoring sub-areas within the target area. The pre-collection evaluation module is used to acquire the performance information corresponding to each of the multiple network nodes in the monitoring sub-region; quantify the performance information corresponding to each of the multiple network nodes to obtain the performance quantification score corresponding to each of the multiple network nodes; identify the network nodes whose performance quantification score is greater than the performance score threshold as traffic collection nodes; and determine the traffic collection priority of the traffic collection nodes in the monitoring sub-region based on the performance quantification score of the traffic collection nodes and the preset score-priority mapping rule. The traffic acquisition module is used to acquire traffic data of the target area by acquiring traffic data from traffic acquisition nodes in different monitoring sub-areas within the target area based on the traffic acquisition priority of the traffic acquisition nodes and the traffic acquisition strategy. The traffic data processing module is used to preprocess the traffic data; The traffic analysis module is used to evaluate and process the traffic data based on the traffic evaluation index system to obtain the traffic evaluation and processing data corresponding to the traffic data; the traffic evaluation index system is used to process the traffic data from different dimensions; based on the traffic evaluation and processing data, the traffic interaction analysis results are determined; the traffic interaction analysis results include the traffic interaction analysis results within a single monitoring sub-region within the target area and / or the traffic interaction analysis results between different monitoring sub-regions; The traffic operation module is used to perform visualization processing based on the traffic interaction analysis results, obtain visualized data, and display the visualized data on the visualization interface; in response to the received traffic operation and maintenance decision instruction, it sends a traffic prediction instruction to the traffic prediction module. The traffic prediction module is used to respond to the traffic prediction command by inputting the traffic interaction analysis results into the traffic prediction model, and performing time-series feature analysis on the traffic interaction analysis results through the traffic prediction model to determine the predicted traffic data. The traffic operation module is also used to generate a network operation and maintenance strategy for the target area based on the predicted traffic data; and to visualize the network operation and maintenance strategy. The traffic data storage module is used to convert the traffic data, the traffic assessment and processing data, the traffic interaction analysis results, and the network operation and maintenance strategy into structured data; and to store the structured data.
11. An electronic device, characterized in that, include: Processor and memory; The memory stores instructions that the processor can execute; When the processor is configured to execute the instructions, the electronic device performs the method as described in any one of claims 1-9.
12. A readable storage medium, characterized in that, include: Software instructions; When the software instructions are executed in the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-9.
13. A computer program product, characterized in that, include: Computer instructions; When the computer instructions are executed in the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-9.