Performance self-adaption method based on flow analysis and control system

By dynamically adjusting the processing threshold of the network traffic analysis system, the problems of lag and resource waste in existing technologies are solved, and the system can achieve stable operation and efficient traffic control near its performance limits.

CN121239633AActive Publication Date: 2025-12-30科来网络技术股份有限公司
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511786906.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2025-12-30
Estimated Expiration
2045-12-01

AI Technical Summary

Technical Problem

Existing network traffic analysis systems, when faced with performance bottlenecks, employ passive threshold control mechanisms, resulting in delayed responses. The systems become unstable for extended periods under high loads, and inappropriate recovery strategies lead to frequent oscillations and resource waste.

Method used

By continuously monitoring traffic volume and the upper and lower limits set by the system's caching capacity, the system can intelligently determine the system status and dynamically adjust the processing thresholds to control the traffic rate, thereby achieving proactive and refined adaptive performance control.

Benefits of technology

The system can maintain stable operation near its performance limits, reduce traffic trend fluctuations, improve resource utilization efficiency, and enhance traffic control efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121239633A_ABST
    Figure CN121239633A_ABST
Patent Text Reader

Abstract

The invention provides a performance self-adaption method based on flow analysis and a control system, and relates to the technical field of flow regulation and control. The method comprises the following steps: S1, monitoring flow data of a working system to obtain flow measurement which is not analyzed and processed; s2, determining a maximum threshold value of the buffer flow seconds of the working system and a system processing threshold value; s3, whether the working system is in an overload state or not is determined, and a system processing threshold value is controlled to be reduced; s4, whether the working system is in a normal load state or not is determined, and a normal state timer is controlled to be started to record the normal state duration of the working system; s5, controlling to increase the system processing threshold value, resetting the normal state duration time, and adjusting the increase amplitude of the system processing threshold value; and S6, repeatedly executing the steps S3 to S5 so as to maintain the flow measurement within the target range. According to the method, the effectiveness of flow regulation and control can be improved, and the resource utilization efficiency of a working system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of flow regulation technology, specifically to a performance adaptive method and control system based on flow analysis. Background Technology

[0002] Existing technologies typically employ a relatively passive threshold control mechanism when addressing performance bottlenecks in network traffic analysis systems. The core problem lies in the rigidity and lag of the control strategy. The system often sets a fixed high-water mark as a trigger condition, passively initiating extreme measures, such as completely discarding newly collected traffic, only when the cache accumulates to near a dangerous threshold of memory exhaustion. This "all-or-nothing" control approach is essentially an emergency braking mechanism, lacking early detection of increasing load trends and the ability to gradually adjust. Because intervention only occurs when the system is already deeply overloaded, its response lags significantly behind actual load changes, meaning the system may have been in an unhealthy state of high load and high latency for an extended period before triggering flow control, resulting in low overall flow control efficiency.

[0003] Furthermore, once the system reduces the load below a safe threshold using a drop-down strategy, it typically reverts directly to the initial maximum processing rate. This recovery strategy is overly aggressive, failing to consider the actual recovery of system processing capacity and the smooth handling of subsequent traffic. Due to a lack of careful control and effect evaluation of the recovery process, the system is highly susceptible to rapid overload again due to a sudden surge in processing rate, subsequently triggering traffic drop-down again. This frequent oscillation between the two extreme states of full-speed processing and complete drop-down not only wastes computing resources but also results in a short and unstable effective traffic processing window, further reducing overall traffic control and processing efficiency. Summary of the Invention

[0004] Based on this, this application provides a performance adaptive method and control system based on traffic analysis. By continuously monitoring traffic metrics reflecting system load and comparing them with upper and lower thresholds set based on system caching capacity, the system intelligently determines whether it is overloaded, normal, or in another state. Based on this state determination, the system does not simply enable or disable processing functions, but rather precisely and dynamically adjusts the system processing threshold, which directly controls the rate at which the system analyzes traffic. When the system is overloaded, the threshold is proactively lowered to quickly reduce the load; when the system load is normal, the threshold is tentatively raised to improve performance. By repeatedly executing this cycle of monitoring, judging, and adjusting, the system can automatically find and maintain stable operation near its performance limits, thereby keeping the backlog of unprocessed traffic within a reasonable range.

[0005] In a first aspect, embodiments of this application provide a performance adaptive method based on traffic analysis, including: S1. Monitor the traffic data of the working system, and obtain an unanalyzed traffic metric based on the traffic data; the traffic metric represents the current load status of the working system; S2. Determine the maximum threshold for the number of seconds the working system caches traffic and the system processing threshold; the system processing threshold is used to control the rate at which the working system analyzes traffic; S3. Determine whether the working system is in an overload state based on the traffic volume measurement and the first preset threshold. If the working system is in an overload state, control the reduction of the system processing threshold. The first preset threshold is determined based on the maximum threshold of the number of seconds of cached traffic. S4. Determine whether the working system is in a normal load state based on the traffic volume measurement and the second preset threshold. If the working system is in a normal load state, control the start of a normal state timer to record the duration of the normal state of the working system; wherein, the second preset threshold is determined based on the maximum threshold of the number of seconds of cached traffic. S5. When the duration of the normal state reaches a preset duration threshold, control the increase of the system processing threshold and reset the duration of the normal state. When the system processing threshold is increased, monitor the processing traffic of the working system to adjust the increase of the system processing threshold according to the processing traffic and the system processing threshold. S6. Repeat steps S3 to S5 to maintain the traffic volume within the target range based on dynamically adjusting the system processing threshold.

[0006] In some embodiments, S3 may include: Record the peak traffic volume processed by the working system during operation, and determine whether the working system is in an overload state based on the traffic volume measurement and a first preset threshold. When the operating system is overloaded, the system processing threshold is reduced based on the peak flow rate.

[0007] In some embodiments, S3 may further include: When the operating system is overloaded, the system stops analyzing traffic exceeding the system's processing threshold to reduce the traffic volume of the operating system.

[0008] In some embodiments, the first preset threshold is determined based on the maximum threshold of the number of seconds of cached traffic and a first proportional coefficient.

[0009] In some embodiments, S4 may include: If the flow rate is lower than the second preset threshold, the count of the normal state duration is increased; if the flow rate is not lower than the second preset threshold, the count is decreased.

[0010] In some embodiments, S5 may include: The increase in the system processing threshold is determined based on the base growth rate and the ratio of the actual processing traffic of the working system to the system processing threshold.

[0011] In some embodiments, the formula for adjusting the system processing threshold based on the increase in the system processing threshold includes: L' = L * (1 + A + (1 – T / L)) Where L' is the increased system processing threshold, L is the original system processing threshold, A is the base growth rate, and T is the actual processing flow monitored after increasing the system processing threshold.

[0012] In some embodiments, the method may further include: If the flow rate remains below a high-performance threshold for one or more complete cycles, the system processing threshold is adjusted in a stepwise multiplication manner; wherein, for each continuous cycle, the increase factor increases with the number of cycles.

[0013] In some embodiments, the traffic metric is the number of data packets or sessions cached by the working system for analysis; the system processing threshold is the threshold for the number of data packets or sessions processed by the working system per second.

[0014] Secondly, embodiments of this application provide a performance adaptive control system based on flow analysis, which may include: The monitoring module is used to monitor the traffic data of the working system and obtain an unanalyzed traffic metric based on the traffic data; the traffic metric represents the current load status of the working system. An initialization module is used to determine the maximum threshold for the number of seconds the working system caches traffic and the system processing threshold; the system processing threshold is used to control the rate at which the working system analyzes traffic. A control module is configured to: determine whether the operating system is in an overload state based on the traffic volume and a first preset threshold; if the operating system is in an overload state, control to decrease the system processing threshold; determine whether the operating system is in a normal load state based on the traffic volume and a second preset threshold; if the operating system is in a normal load state, control to start a normal state timer to record the duration of the normal state of the operating system; and if the duration of the normal state reaches a preset duration threshold, control to increase the system processing threshold and reset the normal state duration, and if the system processing threshold is increased, monitor the processing traffic of the operating system to adjust the increase of the system processing threshold according to the processing traffic and the system processing threshold; repeatedly execute the operations of determining whether the operating system is in an overload state, determining whether the operating system is in a normal load state, and monitoring the processing traffic of the operating system to adjust the increase of the system processing threshold according to the processing traffic and the system processing threshold, so as to maintain the traffic volume within a target range based on dynamically adjusting the system processing threshold; wherein the first preset threshold and the second preset threshold are determined based on the maximum threshold of the number of seconds of buffered traffic.

[0015] Compared with existing technologies, the beneficial effects of this application are as follows: By continuously monitoring traffic metrics reflecting system load and comparing them with upper and lower thresholds set based on system caching capacity, the system intelligently determines whether it is overloaded, normal, or in another state. Based on this state determination, the system does not simply enable or stop processing functions, but precisely and dynamically adjusts the system processing threshold, which directly controls the rate at which the system analyzes traffic. When the system is overloaded, the threshold is proactively lowered to quickly reduce the load; when the system load is normal, the threshold is tentatively raised to improve performance. By repeatedly executing this cycle of monitoring, judging, and adjusting, the system can automatically find and maintain stable operation near its performance limits, thereby keeping the backlog of unprocessed traffic within a reasonable range. This enables the network traffic analysis system to transform from passive and rigid overload protection to proactive and refined performance adaptation, allowing the system to maintain stable operation even when approaching its performance limits. It effectively eliminates the sawtooth fluctuations in traffic trend graphs caused by traditional crude drop strategies, improving the effectiveness of traffic control and increasing the resource utilization efficiency of the system. Attached Figure Description

[0016] Figure 1 A schematic diagram illustrating the steps of the performance adaptive method based on traffic analysis provided in this application embodiment.

[0017] Figure 2 This is a schematic diagram illustrating the trend of the adjustment process of the working system provided in the embodiments of this application. Detailed Implementation

[0018] The present application will now be described in further detail with reference to experimental examples and specific embodiments. However, this should not be construed as limiting the scope of the subject matter of the present application to the following embodiments. All technologies implemented based on the content of the present application fall within the scope of protection of the present application.

[0019] Unless otherwise specified, the terms "upper," "lower," "left," "right," "center," "inner," "outer," and "side" used in the description of specific embodiments of this application to indicate orientation or positional relationships are based on the orientation or positional relationships shown in the accompanying drawings, or the orientation or positional relationship in which the product / equipment / device is usually placed during use. These terms are merely for the purpose of facilitating the description of the solution in this application or simplifying the description in specific embodiments, so as to enable those skilled in the art to quickly understand the solution, and do not indicate or imply that a particular device / component / element must have a specific orientation, or be constructed and operated in a specific positional relationship. Therefore, they should not be construed as limitations on this application.

[0020] In the description of the embodiments of this application, technical terms such as "first" and "second" only distinguish one entity or operation from another, and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary or secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.

[0021] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0022] Please refer to Figure 1 , Figure 1 A schematic diagram illustrating the steps of the performance adaptive method based on traffic analysis provided in this application embodiment. The method may include the following steps: S1. Monitor the flow data of the working system and obtain the unanalyzed flow metric based on the flow data; the flow metric characterizes the current load status of the working system; S2. Determine the maximum threshold for the number of seconds the working system caches traffic and the system processing threshold; the system processing threshold is used to control the rate at which the working system analyzes traffic. S3. Determine whether the working system is in an overload state based on the traffic volume and a first preset threshold. If the working system is in an overload state, control the reduction of the system processing threshold. The first preset threshold is determined based on the maximum threshold of the number of seconds of buffered traffic. S4. Determine whether the working system is in a normal load state based on the traffic volume and the second preset threshold. If the working system is in a normal load state, control the start of the normal state timer to record the duration of the normal state of the working system. The second preset threshold is determined based on the maximum threshold of the number of seconds of buffered traffic. S5. When the duration of normal state reaches the preset duration threshold, control the increase of system processing threshold and reset the duration of normal state. When the system processing threshold is increased, monitor the processing flow of the working system to adjust the increase of system processing threshold according to the processing flow and system processing threshold. S6. Repeat steps S3 to S5 to maintain the flow rate within the target range based on dynamically adjusting the system processing threshold.

[0023] The method provided in this application can be applied to a performance adaptive control system based on traffic analysis (hereinafter referred to as the control system). The control system maintains the stable operation of the working system by dynamically adjusting the processing rate. The working system refers to a system that needs to process continuous data streams, but whose processing capacity may have bottlenecks, thus requiring dynamic adjustment of the processing rate to maintain stability. Specifically, the working system can be a network traffic analysis system, a network security monitoring system, a log analysis and auditing system, a big data stream processing platform, a video stream intelligent analysis system, a telecommunications signaling analysis system, etc. Traffic data is relevant data reflecting the working status of the network traffic analysis system, mainly including information related to traffic that the system has collected but has not yet completed analysis and processing, such as its data volume, buffer time, and number of data packets. The traffic metric M specifically refers to a measure of the amount of unanalyzed traffic data, such as the number of seconds, bytes, data packets, or sessions of traffic waiting to be analyzed in the system buffer. The larger the value of the traffic metric M, the heavier the processing load of the system. The maximum threshold N for buffered traffic seconds refers to the maximum time limit for buffering unprocessed traffic, preset by the system to ensure stable operation. It's used to determine if the system load is nearing its limit. When the traffic metric M approaches or exceeds N, it indicates that the system needs to implement load control measures. The system processing threshold L is a dynamic limit set by the system to actively control its own traffic analysis rate. When processing newly collected traffic, the system does not unconditionally process all traffic, but rather uses L as the upper limit. When the input traffic rate exceeds L, the system only processes the portion of traffic with a rate not exceeding L, discarding the excess traffic, thereby controlling the system load.

[0024] Overload state refers to a working state where the system is overloaded due to insufficient processing capacity, while normal load state refers to a working state where the system has a moderate load and can operate stably. The normal state timer is a counter used to record the duration of continuous normal load state. In this application, the normal state timer can be a software counter, and its counting rule can be: when the system is continuously in normal load state, the counter S increments; once the system exits normal load state, the counter S decrements or resets. When the value of S reaches a preset duration threshold (e.g., 30 counting units), it triggers an increase in the system processing threshold L.

[0025] Maintaining the flow rate within a target range means expecting the flow rate M to fall within a certain numerical range. In the embodiments of this application, the lower limit of this range is typically related to a second preset threshold for determining a normal load state, and the upper limit is typically related to a first preset threshold for determining an overload state. For example, the target range could be M between 0.8N and 1.5N.

[0026] In some embodiments, this application uses historical performance indicators of peak traffic flow as a benchmark for the system to self-adjust under overload conditions. Step S3 may specifically include: Record the peak traffic volume processed by the working system during operation, and determine whether the working system is in an overload state based on the traffic volume measurement and a first preset threshold; if the working system is in an overload state, control the reduction of the system processing threshold based on the peak traffic volume.

[0027] The performance adaptive control system based on flow analysis continuously records the highest rate at which it successfully processes traffic during actual operation, i.e., the peak flow rate, which represents the maximum processing capacity the system has ever achieved under unconstrained conditions. When the system determines that it is overloaded by comparing the real-time monitored flow rate with a first preset threshold, it enters the second stage—the adjustment stage. At this point, the system does not arbitrarily or by a fixed value decrease its processing threshold, but rather adjusts it based on the peak flow rate. For example, the current processing threshold L is adjusted to a proportion (such as 50%) of the previously recorded peak flow rate P. The advantage of this approach is that the adjustment magnitude is closely related to the system's historical performance, enabling it to quickly pull the system load back from a dangerously high level to a known, relatively safe level, creating conditions for stable operation within the target range and avoiding the problems of insufficient or excessive adjustment that may result from blind adjustments.

[0028] The first preset threshold is determined based on the maximum threshold of the number of seconds of buffered traffic and the first proportional coefficient. That is, the control system does not directly use the maximum threshold N of the number of seconds of buffered traffic as the absolute limit for overload judgment, but multiplies it by a configurable first proportional coefficient to obtain a first preset threshold with more flexibility and fault tolerance.

[0029] Specifically, the first proportional coefficient can be 1.5. Therefore, the control system will set the first preset threshold to 1.5N. The control system does not immediately determine overload when the buffered flow rate M in the working system just exceeds the maximum threshold N. Instead, it allows for a reasonable excess in the buffered flow rate until M > 1.5N, at which point it confirms that the working system is indeed in a state of continuous insufficient processing capacity. This threshold setting method based on coefficient adjustment aims to establish a buffer zone, avoiding excessively frequent state switching and parameter adjustments by the control system between normal load fluctuations and actual performance bottlenecks caused by instantaneous flow rate fluctuations. This enhances the stability and robustness of the entire adaptive adjustment process.

[0030] Furthermore, when the working system is determined to be in an overload state, the specific intervention action executed by the control system is to directly and meticulously manage the data processing behavior of the working system through a precise instruction. S3 may also include: When the operating system is overloaded, the system stops analyzing traffic exceeding the system's processing threshold to reduce the traffic volume of the operating system.

[0031] Upon confirming an overload, the control system sends an instruction to the operating system, instructing it to limit its flow analysis to a dynamically adjusted system processing threshold L. This means that for newly acquired flow data, the operating system only performs in-depth analysis on the portion with a rate not exceeding L. For flow with an instantaneous rate exceeding L, it actively prevents it from entering the analysis queue, effectively discarding it. The direct purpose of this action is to immediately reduce the input load on the operating system's analysis engine, thereby controlling the backlog of unprocessed flow (i.e., flow metric M) to decrease, creating conditions for the system to recover from the overload state to a stable state.

[0032] In some embodiments, the control system carefully evaluates the state stability of the operating system through a counting mechanism with hysteresis characteristics. That is, when the flow rate is lower than the second preset threshold, the control system increases the count of the duration of the normal state; when the flow rate is not lower than the second preset threshold, the control system decreases the count.

[0033] The control system dynamically manages this count by comparing the real-time monitored flow rate metric M with a second preset threshold (e.g., 0.8N). When M is below the threshold, the control system increases the count, indicating a positive confirmation of the system's load reduction trend; conversely, when M is equal to or above the threshold, the control system decreases the count, essentially questioning or negating the previous positive confirmation. This design ensures that the counter's value accurately reflects the continuity and stability of the system's load state, rather than a snapshot at a specific moment. Only when the accumulated positive confirmations (i.e., the net increase in the count) reach a certain amount does the control system ultimately confirm that the system has truly escaped the risk of overload and entered a sustainable normal load state, thus triggering a subsequent tentative operation to increase the processing threshold L.

[0034] In some embodiments, the control system is configured with a dynamic adjustment strategy, the magnitude of which is determined by a preset base growth rate and a dynamic adjustment factor reflecting the actual processing capacity of the working system. Step S5 specifically includes: The increase in the system processing threshold is determined based on the base growth rate and the ratio of the actual processing traffic of the working system to the system processing threshold.

[0035] When the control system determines that the threshold L needs to be increased, it monitors the actual flow rate T that the system can handle at the current L value. The dynamic adjustment factor is the ratio (T / L) of the actual flow rate T to the system's processing threshold L. If T is much smaller than L, it indicates that the system's actual processing capacity has a large margin of error, and the current L value is set too conservatively. In this case, the control system will use the formula L' = L * (1 + A + (1 – T / L)) to significantly increase L, thereby quickly improving throughput and preventing the system from being unable to handle sudden high flow rates due to slow threshold growth. Conversely, if T is very close to or even equal to L, it indicates that the system is operating close to full capacity. In this case, the control system will mainly use the base growth rate A to make small, tentative increases to ensure stability.

[0036] In the formula for adjusting the system processing threshold by increasing the system processing threshold, L' is the increased system processing threshold, L is the original system processing threshold, A is the base growth rate, and T is the actual processing flow monitored after increasing the system processing threshold.

[0037] Furthermore, the method provided in this application also introduces an optimization mechanism to address the problem of slow convergence speed that may occur when adjusting the system processing threshold L based on conventional rules under extremely low system load. The method may further include: when the flow rate metric remains below a high-performance threshold for one or more complete cycles, performing a step-wise doubling adjustment on the system processing threshold; wherein, for each continuous cycle, the increase factor increases with the number of cycles.

[0038] When the control system detects that the load on the working system is extremely light, it will initiate a more aggressive adjustment strategy. The control system will set a high-performance threshold (e.g., buffer seconds M) that is much lower than the normal load threshold. When the flow rate M remains below this threshold for a configurable full cycle (e.g., 30 seconds), the control system determines that the system is in a high-performance processing state. In this state, the control system no longer uses a fixed growth rate to increase L, but instead initiates a step-by-step doubling adjustment strategy. Its core feature is that the increase factor used increases significantly with each cycle. For example, it increases by 10% in the first cycle, 50% in the second, and 100% (doubling) in the third, and so on. This design allows the system processing threshold L to increase exponentially and rapidly. The purpose is that when external input traffic (such as TAP access traffic) suddenly recovers from an extremely low level to normal or even peak levels, the system's processing capacity limit L can quickly increase to a level sufficient to handle it. This avoids the large amount of traffic that could be processed being discarded due to an excessively low threshold L, allowing the system to respond promptly to sudden traffic changes and maintain efficient operation.

[0039] In some optional embodiments, the method provided in this application can also be applied to various scenarios that require processing discrete data streams and face performance bottlenecks, such as network analysis, security auditing, and log processing. As long as the load index monitored by the control system and the processing rate index controlled by the working system are some countable data processing units, the performance adaptive method based on traffic analysis provided in this application can be used to adaptively control the traffic of the working system. The adaptive adjustment mechanism of the method provided in this application is not limited to environments using bandwidth (such as Gbps) as a metric, but is applicable to any streaming processing system with discrete data processing units as the load index.

[0040] For example, traffic metrics could be the number of data packets or sessions that the operating system is caching for analysis; system processing thresholds could be the threshold for the number of data packets or sessions that the operating system can process per second.

[0041] In network security detection systems, load status may not be directly manifested as bandwidth, but rather as the backlog of data packets or network sessions that need to be detected per second. Correspondingly, the system processing threshold is defined as the threshold for the number of data packets or sessions that the operating system can process per second. In this case, the adaptive adjustment logic of the control system is fully applicable: when the number of buffered data packets exceeds a certain threshold, the control system will lower the threshold L for the number of data packets processed per second to stabilize the system; when the load decreases, L will be gradually increased. As long as the load indicator monitored by the control system and the processing rate indicator controlled by the operating system are some kind of countable data processing unit, they should be included within the scope of protection of this application.

[0042] In the above implementation process, by continuously monitoring traffic metrics reflecting system load and comparing them with upper and lower thresholds set based on system caching capacity, the system intelligently determines whether it is overloaded, normal, or in another state. Based on this state determination, the system does not simply enable or stop processing functions, but precisely and dynamically adjusts the system processing threshold, which directly controls the rate at which the system analyzes traffic. When the system is overloaded, the threshold is proactively lowered to quickly reduce the load; when the system load is normal, the threshold is tentatively raised to improve performance. By repeatedly executing this cycle of monitoring, judging, and adjusting, the system can automatically find and maintain stable operation near its performance limits, thereby keeping the backlog of unprocessed traffic within a reasonable range. This enables the network traffic analysis system to transform from passive and rigid overload protection to proactive and refined performance adaptation, allowing the working system to maintain stable operation even when approaching its performance limits. It effectively eliminates the sawtooth fluctuations in traffic trend graphs caused by traditional crude drop strategies, improving the effectiveness of traffic control and increasing the resource utilization efficiency of the working system.

[0043] To more clearly demonstrate how this solution operates in practice, the above explanations of the claims are further elaborated below with reference to a preferred embodiment described in the detailed description of the technical solution of this application. This embodiment uses the buffer traffic seconds M and the traffic size threshold L as examples to demonstrate how the control system dynamically adjusts the processing performance of the working system through a complete closed-loop control logic that includes judgment, load reduction, tentative boosting, and rapid recovery, ultimately achieving the goal of stable operation near the performance limit. This specific embodiment serves as an instance supporting the scope of the foregoing claims, helping those skilled in the art to understand and apply the method provided by this application to a wider range of scenarios.

[0044] This embodiment includes: 1. The traffic of the working system is submitted for analysis on a second-by-second basis. The number of seconds that are not analyzed and processed after submission is recorded as M.

[0045] 2. Set a maximum threshold N for the number of seconds that the working system can cache traffic.

[0046] 3. Set a threshold L for the size of the traffic that the working system is currently analyzing and processing; when the working system initially runs, L can be set to a very large value, or no judgment is made on L, that is, no traffic processing limit is imposed.

[0047] 4. Record the peak traffic P processed after the working system runs.

[0048] 5. When the number of seconds M of the traffic to be analyzed and processed cached in the working system exceeds a coefficient, such as 1.5 times N, it is regarded that the current traffic size exceeds the processing capacity of the working system.

[0049] 6. Reduce L in proportion, such as becoming 0.5P, that is, half of the peak value. The excess traffic is no longer analyzed, the load of the working system is reduced, and the number of seconds M cached by the working system is reduced.

[0050] 7. After L is reduced, if M continues to increase, then L continues to be reduced, such as being halved to become 0.25P.

[0051] 8. After L is reduced to a certain value, if M is reduced to a certain coefficient. For example, when it is 0.8 times N, it is regarded that the working system enters the normal load state. If the normal state lasts for 1 second, the count S is incremented by 1, otherwise it is decremented by 1.

[0052] 9. When S exceeds a coefficient, such as 30 seconds, it means that the working system has entered the continuous working state. At this time, L is increased by 50%, and S is reset to 0.

[0053] 10. If after L is increased by 50% for the first time, the working system enters step 9 again, record the actual processed traffic size T under the current threshold L state, L = L * (1 + 0.1 + (1 – T / L)); if T = L, it means that the collected traffic exceeds the threshold L, and the system only analyzes and processes to obtain T according to the threshold L. At this time, L = L * (1 + 0.1), that is, it is increased by 10%; if T < L, it means that the collected traffic becomes smaller, and the actual processed traffic does not reach the threshold L. Assuming T = 0.2L, then L = L * (1 + 0.1 + 0.8), that is, it is increased by 90%; the lower the traffic, the smaller the value of T / L, and the faster L grows; making L grow rapidly is to avoid the situation of being unable to process peak traffic (traffic suddenly becomes large) in time.

[0054] 11. After L is increased, re-count S, and repeat steps 9 and 10.

[0055] 12. If after L is increased, the working system enters step 5 again, then reduce L by 20%, that is, L = L * 0.8.

[0056] 13. If the working system still enters step 5 after L is reduced, then repeat step 12 and continue to reduce it by 20%.

[0057] 14. If the working system enters step 8 after L decreases, then repeat steps 9 and 10.

[0058] 15. After multiple rounds of increasing and decreasing adjustments, a limit value L will be obtained, making M between 0.8N and 1.5N.

[0059] 16. If L can only increase by 10% each time, the growth is too slow. When the collected traffic connected to the network traffic splitter (Test Access Point, TAP) is adjusted below the bottleneck value of the working system, the actual traffic cannot be processed in a timely manner. For example, if the working system's processing limit is 40Gbps, the TAP access traffic is 50Gbps, and the current L is 30Gbps, after adjusting the TAP traffic to 38Gbps, if L increases too slowly, the excess 8Gbps cannot be processed in a timely manner. An additional algorithm allows L to increase rapidly: When M <= 3 (configurable), it is considered a high-performance processing state, with each 30-second (configurable) period considered a cycle; after one cycle, L increases by 10%, the same as in step 10, i.e., L1 = L * 1.1; after two cycles, L increases by 50% on top of the 10% increase in the previous cycle, i.e., L2 = L1 * 1.5; after three cycles, L3 = L2 * 2; after four cycles, L4 = L3 * 3; after five cycles, L5 = L4 * 4; after more than five cycles, the current access traffic is considered to be far below the maximum performance that the working system can handle, and traffic is no longer limited; when the subsequent TAP access traffic increases again, the previous steps are repeated, and automatic adjustment is performed again.

[0060] Please refer to Figure 2 , Figure 2 This is a schematic diagram illustrating the trend of the adjustment process of the working system provided in the embodiments of this application. Figure 2 In the diagram, the vertical axis represents the magnitude of the traffic flow, while the horizontal axis represents the adjustment results of the traffic threshold under different adjustment strategies or stages. Specifically, dark blue represents the current traffic volume collected by the system, while blue represents the current system's maximum processing capacity. When certain system functions are disabled, the system's processing capacity can be improved, hence the subsequent blue lines increase in height. Red, orange, purple, and green represent the adjustment process of L. Red indicates that L far exceeds the system's processing capacity and needs to be adjusted downwards immediately; orange indicates that L slightly exceeds the system's processing capacity and needs to be adjusted downwards based on the state of S; purple indicates that L is close to the system's maximum processing capacity and no adjustment is needed, maintaining maximum capacity operation in the long term; green indicates that L or the actual traffic flow is lower than the system's processing capacity and needs to be adjusted upwards based on the state of S.

[0061] Based on the same concept, embodiments of this application also provide a performance adaptive control system based on flow analysis, which may include: The monitoring module is used to monitor the traffic data of the working system and obtain an unanalyzed traffic metric based on the traffic data; the traffic metric represents the current load status of the working system. An initialization module is used to determine the maximum threshold for the number of seconds the working system caches traffic and the system processing threshold; the system processing threshold is used to control the rate at which the working system analyzes traffic. A control module is configured to: determine whether the operating system is in an overload state based on the traffic volume and a first preset threshold; if the operating system is in an overload state, control to decrease the system processing threshold; determine whether the operating system is in a normal load state based on the traffic volume and a second preset threshold; if the operating system is in a normal load state, control to start a normal state timer to record the duration of the normal state of the operating system; and if the duration of the normal state reaches a preset duration threshold, control to increase the system processing threshold and reset the normal state duration, and if the system processing threshold is increased, monitor the processing traffic of the operating system to adjust the increase of the system processing threshold according to the processing traffic and the system processing threshold; repeatedly execute the operations of determining whether the operating system is in an overload state, determining whether the operating system is in a normal load state, and monitoring the processing traffic of the operating system to adjust the increase of the system processing threshold according to the processing traffic and the system processing threshold, so as to maintain the traffic volume within a target range based on dynamically adjusting the system processing threshold; wherein the first preset threshold and the second preset threshold are determined based on the maximum threshold of the number of seconds of buffered traffic.

[0062] It should be understood that when the various modules of the system provided in the above embodiments are working, the division of each functional module in the above description is only used as an example. In actual applications, the above functions can be assigned to different functional modules as needed. That is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0063] The functional modules in the above embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of the embodiments of this application.

[0064] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for performance adaptation based on traffic analysis, characterized in that, The method comprises: S1, monitoring traffic data of a working system, and obtaining an unprocessed traffic metric based on the traffic data; the traffic metric represents a current load state of the working system; S2, determining a maximum threshold of cache traffic seconds of the working system and a system processing threshold; the system processing threshold is used to control a rate of traffic analysis of the working system; S3, determining whether the working system is in an overload state based on the traffic metric and a first preset threshold, and controlling to reduce the system processing threshold in a case where the working system is in the overload state; wherein the first preset threshold is determined based on the maximum threshold of cache traffic seconds; S4, determining whether the working system is in a normal load state based on the traffic metric and a second preset threshold, and controlling to start a normal state timer to record a normal state duration of the working system in a case where the working system is in the normal load state; wherein the second preset threshold is determined based on the maximum threshold of cache traffic seconds; S5, in a case where the normal state duration reaches a preset duration threshold, controlling to increase the system processing threshold and reset the normal state duration, and in a case where the system processing threshold is increased, monitoring processing traffic of the working system to adjust an increasing amplitude of the system processing threshold according to the processing traffic and the system processing threshold; S6, repeatedly performing steps S3 to S5 to maintain the traffic metric within a target range based on dynamic adjustment of the system processing threshold.

2. The method of claim 1, wherein, The S3 comprises: recording a traffic peak value processed by the working system in a running state, and determining whether the working system is in an overload state based on the traffic metric and a first preset threshold; in a case where the working system is in the overload state, controlling to reduce the system processing threshold based on the traffic peak value.

3. The method of claim 2, wherein, The S3 further comprises: in a case where the working system is in the overload state, controlling to stop analyzing traffic exceeding the system processing threshold to reduce the traffic metric of the working system.

4. The method of claim 2, wherein, The first preset threshold is determined based on the maximum threshold of cache traffic seconds and a first proportionality coefficient.

5. The method of claim 1, wherein, The S4 comprises: in a case where the traffic metric is lower than the second preset threshold, increasing a count of the normal state duration; and in a case where the traffic metric is not lower than the second preset threshold, decreasing the count.

6. The method of claim 1, wherein, The S5 comprises: determining the increasing amplitude of the system processing threshold based on a basic increasing rate and a proportion of actual processing traffic of the working system to the system processing threshold.

7. The method of claim 6, wherein, A formula for adjusting the system processing threshold based on the increasing amplitude of the system processing threshold comprises: L' = L * (1 + A + (1 – T / L)) wherein L' is the system processing threshold after the increase, L is the system processing threshold before the increase, A is the basic increasing rate, and T is actual processing traffic monitored after the system processing threshold is increased.

8. The method for performance adaptation based on traffic analysis according to claim 1, wherein, The method further comprises: In a case where the traffic metric continuously falls below a high performance threshold for one or more complete cycles, the system processing threshold is adjusted by a step-up factor; wherein the step-up factor increases with the number of cycles for each cycle.

9. The method of performance self-adaptation based on traffic analysis according to any of claims 1-8, characterized in that, The traffic metric is a number of packets or a number of sessions buffered by the working system for analysis; and the system processing threshold is a threshold of a number of packets or a number of sessions processed per second by the working system.

10. A flow analysis based performance adaptive control system, characterized by, The method comprises: monitoring a traffic data of a working system to obtain a traffic metric of unanalyzed traffic based on the traffic data; The traffic metric represents a current load state of the working system; initializing a maximum threshold of buffered traffic seconds and a system processing threshold of the working system; The system processing threshold is used to control a rate of analyzing traffic of the working system; controlling whether the working system is in an overload state based on the traffic metric and a first preset threshold, and controlling to decrease the system processing threshold in a case where the working system is in the overload state; controlling whether the working system is in a normal load state based on the traffic metric and a second preset threshold, and controlling to start a normal state timer to record a duration of the normal state of the working system in a case where the working system is in the normal load state; and in a case where the duration of the normal state reaches a preset duration threshold, controlling to increase the system processing threshold and reset the duration of the normal state, and in a case where the system processing threshold is increased, monitoring a processed traffic of the working system to adjust an increasing amplitude of the system processing threshold according to the processed traffic and the system processing threshold; repeating the operations of controlling whether the working system is in the overload state, controlling whether the working system is in the normal load state, and monitoring the processed traffic of the working system to adjust the increasing amplitude of the system processing threshold according to the processed traffic and the system processing threshold, to maintain the traffic metric within a target range based on dynamically adjusting the system processing threshold; wherein the first preset threshold and the second preset threshold are determined based on the maximum threshold of the buffered traffic seconds.

Citation Information

Patent Citations

  • Adaptive interrupt control method and device for mobile application processor

    CN102760079A

  • CPU load control method and system

    CN116225198A

  • Micro-service dynamic current limiting automatic control system based on system load

    CN117834542A

  • Access system control method based on power-down delay protection and controller

    CN118625911A

  • Computer network flow intelligent monitoring system

    CN120281685A