Transaction flow allocation method, device, equipment, medium and program product
By dynamically adjusting network traffic, the problem of traditional network traffic monitoring being unable to quickly respond to sudden traffic fluctuations has been solved, enabling precise allocation of transaction traffic and efficient utilization of network resources.
Patent Information
- Application Number
- CN202511360286.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-23
- Publication Date
- 2026-01-13
AI Technical Summary
Traditional network traffic monitoring methods cannot quickly and automatically respond to sudden large-scale data transmission or transaction requests in the link, resulting in link congestion and increased latency, which affects the normal processing of upper-layer services.
By acquiring transaction traffic information, the baseline maximum network traffic is dynamically adjusted, and capacity is expanded or reduced according to traffic category and historical baseline. Combined with abnormal transaction detection and related business traffic prediction, precise allocation of transaction category traffic can be achieved.
It improves the immediacy and stability of network traffic allocation, avoids link congestion, and enhances the utilization of network resources and transaction stability.
Smart Images

Figure CN121333941A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network communication, and can be used in the financial field, and more particularly to a transaction traffic deployment method and device, equipment, medium and program product. BACKGROUND
[0002] The conventional network traffic monitoring method usually relies on manual intervention and cannot quickly and automatically schedule burst traffic at the network device level. When large-scale data transmission or transaction requests occur in the link, due to the fixed configuration of the bandwidth parameters, queue weights or access control policies of the switch or router, link congestion and increased latency are easily caused, thereby affecting the normal processing of upper-layer services. The existing method often relies on manual identification of traffic burst through monitoring tools, and then manually modifies the bandwidth upper limit, shaping parameters or release rules of the device to expand the capacity. This kind of post-adjustment lacks immediacy and is difficult to respond to second-level or millisecond-level traffic fluctuations in a timely manner. SUMMARY
[0003] In view of the above problems, the present application provides a transaction traffic deployment method, device, equipment, medium and program product for improving the immediacy of deployment.
[0004] According to a first aspect of the present application, a transaction traffic deployment method is provided, comprising: obtaining traffic information of at least one transaction in a target network; determining a transaction category traffic of a first category of transactions to which the at least one transaction belongs according to the traffic information; in response to the transaction category traffic not falling within a first proportion range of a benchmark maximum network traffic of the first category, expanding or shrinking the benchmark maximum network traffic; after waiting for a predetermined time interval, obtaining the transaction category traffic of the first category again; if the transaction category traffic obtained again does not fall within the first proportion range of the benchmark maximum network traffic of the first category, continuing to expand or shrink the benchmark maximum network traffic until the transaction category traffic falls within the first proportion range.
[0005] According to an embodiment of the present application, expanding or shrinking the benchmark maximum network traffic comprises: in response to the transaction category traffic being lower than a first proportion of the benchmark maximum network traffic, adjusting the benchmark maximum network traffic to a second proportion of the current value; and in response to the transaction category traffic being higher than a third proportion of the benchmark maximum network traffic, adjusting the benchmark maximum network traffic to a fourth proportion of the current value, the third proportion being greater than or equal to the ratio of the first proportion to the second proportion, and the first proportion being less than or equal to the ratio of the third proportion to the fourth proportion.
[0006] According to an embodiment of the present application, the reference maximum network traffic is determined in advance according to at least one of a special scenario baseline of the first category, a daily peak baseline, and a yesterday transaction average traffic baseline, the special scenario baseline including a transaction traffic reference value of a specific date determined according to historical traffic statistics, the daily peak baseline including a transaction traffic reference value of at least one transaction period of each date determined according to historical traffic statistics, and the yesterday transaction average traffic baseline including an average reference value calculated according to network traffic data of the previous date transaction.
[0007] According to an embodiment of the present application, the method further comprises: obtaining continuous N transaction category traffics, wherein N is a positive integer; if the continuous N transaction category traffics are higher than a fifth proportion of the reference maximum network traffic, and the N transaction category traffics do not contain abnormal traffics, correcting at least one of the special scenario baseline, the daily peak baseline, and the yesterday transaction average traffic baseline according to the N transaction category traffics.
[0008] According to an embodiment of the present application, the method further comprises: in response to obtaining the traffic information of each transaction, decrypting and extracting transaction instructions and parameter information in the traffic information; in response to the traffic information of the transaction having unqualified items, determining that the transaction is an abnormal transaction; wherein the unqualified items include at least one of the following: the transaction instruction does not exist in a historical traffic statistics list and the transaction parameters are not in compliance, wherein the historical traffic statistics list is obtained according to historical normal transaction statistics; and the number of transactions from the same source Internet protocol address is greater than a preset number of times.
[0009] According to an embodiment of the present application, the method further comprises: obtaining at least one associated business traffic associated with the transaction category traffic; predicting a transaction category traffic prediction value of the transaction category traffic at a first time according to the at least one associated business traffic; and in response to the transaction category traffic prediction value not being within a first proportion range of the reference maximum network traffic at the first time, adjusting the reference maximum network traffic.
[0010] According to an embodiment of the present application, the method further comprises: in response to obtaining a first transaction category traffic and a second transaction category traffic on the same device; if the first transaction category traffic is higher than a third proportion of the reference maximum network traffic of the first category, adjusting the reference maximum network traffic of a second category to which the second transaction category traffic belongs to a second proportion of the current value and maintaining; wherein the first category priority is higher than the second category priority.
[0011] A second aspect of this application provides a transaction traffic allocation device, comprising: a traffic monitoring module for acquiring traffic information of at least one transaction in a target network; determining, based on the traffic information, the transaction category traffic of the at least one transaction to which a first category belongs; and a traffic allocation module for scaling up or down the baseline maximum network traffic in response to the transaction category traffic not falling within a first proportional range of the baseline maximum network traffic of the first category; acquiring the transaction category traffic of the first category again after waiting for a predetermined time interval; and continuing to scale up or down the baseline maximum network traffic if the acquired transaction category traffic does not fall within the first proportional range of the baseline maximum network traffic of the first category, until the transaction category traffic falls within the first proportional range.
[0012] A third aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.
[0013] A fourth aspect of this application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.
[0014] The fifth aspect of this application also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description
[0015] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0016] Figure 1 The illustration shows an application scenario diagram of the transaction traffic allocation method, apparatus, device, medium, and program product according to embodiments of this application;
[0017] Figure 2 A flowchart illustrating a first transaction flow allocation method according to an embodiment of this application is shown schematically;
[0018] Figure 3 A flowchart illustrating a second transaction flow allocation method according to an embodiment of this application is shown schematically;
[0019] Figure 4 A flowchart illustrating a third transaction flow allocation method according to an embodiment of this application is shown schematically;
[0020] Figure 5 A flowchart illustrating a fourth transaction flow allocation method according to an embodiment of this application is shown schematically;
[0021] Figure 6 A flowchart illustrating a fifth transaction flow allocation method according to an embodiment of this application is shown schematically;
[0022] Figure 7 This schematic diagram illustrates a structural block diagram of a first transaction flow allocation device according to an embodiment of this application;
[0023] Figure 8 This schematically illustrates a structural block diagram of a second transaction flow allocation device according to an embodiment of this application;
[0024] Figure 9 A flowchart illustrating a sixth transaction flow allocation method according to an embodiment of this application is shown schematically; and
[0025] Figure 10 A block diagram of an electronic device suitable for implementing a transaction flow allocation method according to an embodiment of this application is shown schematically. Detailed Implementation
[0026] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.
[0027] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0029] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).
[0030] In the technical solution of this application, the user information (including but not limited to user information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.
[0031] In scenarios involving automated decision-making using information, the methods, devices, and systems provided in this application all offer users corresponding entry points for choosing to agree to or reject the automated decision results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to activities that automatically analyze and evaluate behavioral habits, interests, or economic, health, and credit conditions through computer programs, and then make decisions accordingly. Here, "expert decision-making" refers to the activities of personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise in making decisions.
[0032] The transaction flow allocation method and apparatus of this application can be used in the financial field in terms of transaction flow, and can also be used in any field other than the financial field. The application field of the transaction flow allocation method and apparatus of this application is not limited.
[0033] This application provides a transaction traffic allocation method, comprising: acquiring traffic information of at least one transaction in a target network; determining the transaction category traffic of the at least one transaction to which a first category belongs based on the traffic information; scaling up or down the baseline maximum network traffic in response to the transaction category traffic not falling within a first proportional range of the baseline maximum network traffic of the first category; acquiring the transaction category traffic of the first category again after waiting for a predetermined time interval; if the acquired transaction category traffic does not fall within the first proportional range of the baseline maximum network traffic of the first category, continuing to scale up or down the baseline maximum network traffic until the transaction category traffic falls within the first proportional range of the baseline maximum network traffic of its category. This application overcomes the problem of existing technologies that rely on manual intervention to block or allow transaction traffic, and the drawback of difficulty in achieving rapid response when network traffic fluctuates significantly within a short period.
[0034] Figure 1 The illustration shows an application scenario diagram of the transaction traffic allocation method, apparatus, device, medium, and program product according to embodiments of this application.
[0035] like Figure 1As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0036] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0037] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0038] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0039] It should be noted that the transaction traffic allocation method provided in this application embodiment can generally be executed by server 105. Correspondingly, the transaction traffic allocation device provided in this application embodiment can generally be located in server 105. The transaction traffic allocation method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the transaction traffic allocation device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0040] It should be understood that Figure 1The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0041] The following will be based on Figure 1 The described scene, through Figure 2~Figure 6 The transaction flow allocation method according to the embodiments of this application will be described in detail.
[0042] Figure 2 A flowchart illustrating a first transaction flow allocation method according to an embodiment of this application is shown.
[0043] like Figure 2 As shown, the transaction flow allocation method in this embodiment includes operations S210 to S230.
[0044] In operation S210, traffic information for at least one transaction in the target network is obtained.
[0045] In embodiments of this application, user consent or authorization can be obtained before acquiring user information. For example, a request to acquire user information can be sent to the user before operation S210. If the user consents or authorizes the acquisition of user information, operation S210 is executed.
[0046] In the target network, transaction traffic flows through nodes such as clients, access layer networks, core switches, service servers, and databases. Targeted collection points allow for the acquisition of key traffic data. For example, at the access layer, raw traffic between the client and the access gateway can be collected via switch mirror ports or splitters to obtain transaction initiation information. Deploying traffic acquisition probes at core switches and load balancers can collect traffic characteristics of transactions flowing through core links. Preferably, deploying application performance monitoring tools on service servers can collect application layer data of transactions, allowing for specific association between transactions and traffic. Traditional technologies collect traffic at the network layer, lacking application layer transaction identifiers, making it impossible to bind a segment of traffic to a specific transaction. They can only count the total traffic of a certain type of Internet Protocol address, unable to pinpoint individual transactions.
[0047] This embodiment aggregates all traffic data for the same transaction by cross-matching application-layer transaction identifiers with network-layer session characteristics. For example, the application layer records the transaction initiation time and transaction end time, while the network layer records the session start time and session end time; these two are matched. The client's Internet Protocol address and server's Internet Protocol address of the application-layer transaction match the source Internet Protocol address and destination Internet Protocol address of the network-layer session, and the request port of the application-layer transaction matches the destination port of the network-layer session. The successfully matched network-layer traffic data is uniformly tagged with the application-layer transaction identifier, ultimately forming an association result where each transaction corresponds to a complete set of traffic information.
[0048] In operation S220, at least one transaction is determined to belong to a first category of transaction category traffic based on the traffic information.
[0049] In operation S220, the user information is processed / determined to "determine the transaction category traffic of at least one transaction belonging to the first category based on the traffic information" in order to allocate transaction traffic.
[0050] In the embodiments of this application, a corresponding operation entry can be provided to the user, allowing the user to choose to agree to or reject the automated decision result. That is, before processing / making a decision on user information in step S220, the user's instruction to agree to or reject the processing / decision can be obtained through the corresponding operation entry. If the user agrees to the processing / decision, the user information is processed to determine at least one transaction belonging to a first category, i.e., step S220 is executed. If the user refuses to process / make a decision, the expert decision-making process is initiated.
[0051] This embodiment can classify transactions into a first category based on transaction identifiers, such as transaction identifier 001 being a transfer; it can also classify transactions based on traffic information and business rules, extracting transaction type fields from application layer traffic information (such as "transaction category: payment" in the Hypertext Transfer Protocol request header, and "type: transfer" in the Lightweight Data Exchange Format parameters) to directly map the transaction category; it can also infer the category through the "transmission characteristics" of network layer traffic, building a classification model based on historical data for judgment, such as payment or transfer categories: single transaction traffic bytes greater than 10240 bytes, link latency requirement less than 100 milliseconds, session duration 50~200 milliseconds; it can also verify the transaction category based on the business context of the transaction, for example, if the target Internet Protocol address of a transaction is a bank payment gateway, and the amount field of the request parameter has a value greater than 100, then it is determined to be a large-amount payment. Specific transaction categories may include savings, wealth management, consumption, login, business operations, etc., and are not limited here.
[0052] In operation S230, in response to the transaction category traffic not falling within the first proportion range of the baseline maximum network traffic of the first category, the baseline maximum network traffic is scaled up or down; after waiting for a predetermined time interval, the transaction category traffic of the first category is acquired again; if the acquired transaction category traffic does not fall within the first proportion range of the baseline maximum network traffic of the first category, the baseline maximum network traffic is scaled up or down again until the transaction category traffic falls within the first proportion range.
[0053] For example, if the current traffic value of a certain transaction category A is 30 megabytes per second, which does not fall within the first proportion range (40%~70%, i.e., 40~70 megabytes per second) of the baseline maximum network traffic of category A of 100 megabytes per second, then the baseline maximum network traffic of this type of transaction will be adjusted. For example, the baseline maximum network traffic will be adjusted to 60 megabytes per second (reduced capacity). Finally, the traffic of transaction category A will fall into the first proportion range (approximately 50%) of the baseline maximum network traffic of its first category.
[0054] For example, if the baseline maximum network traffic is 100 megabytes per second at a certain moment, and the traffic for a certain transaction category is 38 megabytes per second, which is less than 40% of the baseline maximum network traffic, the baseline maximum network traffic is adjusted to 50% of the current value, i.e., 50 megabytes per second. Five minutes later, the transaction category traffic for that type of transaction is acquired again. At this time, the transaction category traffic is 38 megabytes per second, accounting for 76% of the baseline maximum network traffic, which is greater than 70% of the current baseline maximum network traffic of 50 megabytes per second. The baseline maximum network traffic is then adjusted to 120% of the current value, i.e., 60 megabytes per second. At this time, the transaction category traffic is 38 megabytes per second, accounting for 63% of the baseline maximum network traffic (meeting the first ratio range of 40%~70%). This embodiment, through two adjustments, gradually converges and stabilizes the traffic for a certain transaction category within a reasonable range of its baseline maximum network traffic. It should be noted that in reality, the traffic for a certain transaction category may change at every moment. For ease of comparison and description, the embodiments of this application assume that the traffic for a certain transaction category remains essentially unchanged after waiting for a predetermined time interval.
[0055] This embodiment acquires transaction category traffic, focusing on the traffic characteristics of similar transactions. This avoids the drawbacks of traditional solutions' coarse control of overall traffic, making traffic management more aligned with the actual needs of different transactions. By scaling up and down the baseline maximum network traffic and then waiting for a predetermined time interval to acquire transaction category traffic, if it does not fall within the first proportional range, the scaling up and down continues. Through cyclical adjustments and proportional constraints, the accuracy of adjustments is extracted while avoiding excessively large single adjustments that cause frequent traffic jumps across ranges. At the same time, it ensures that the scaling up and down direction accurately adapts to traffic fluctuations, ultimately achieving stable flow of transaction category traffic within the target range, improving the convergence of traffic management and the stability of network resource allocation.
[0056] In some embodiments of this application, scaling up or down the baseline maximum network traffic includes: adjusting the baseline maximum network traffic to a current value at a second ratio in response to a first ratio where the transaction category traffic is lower than the baseline maximum network traffic; and adjusting the baseline maximum network traffic to a current value at a fourth ratio in response to a third ratio where the transaction category traffic is higher than the baseline maximum network traffic. Wherein, the first ratio is less than the second ratio, the second ratio is less than the third ratio, the third ratio is less than 1, and the fourth ratio is greater than 1. The third ratio is greater than or equal to the ratio of the first ratio to the second ratio, and the first ratio is less than or equal to the ratio of the third ratio to the fourth ratio.
[0057] For example, if the baseline maximum network traffic for a certain type of transaction is 100 megabytes per second at a certain moment, in response to the transaction type traffic being lower than 40% of the baseline maximum network traffic (first proportion), the baseline maximum network traffic is adjusted to 50% of the current value (second proportion); and in response to the transaction type traffic being higher than 70% of the baseline maximum network traffic (third proportion), the baseline maximum network traffic is adjusted to 120% of the current value (fourth proportion).
[0058] Specifically, at a certain moment, the baseline maximum network traffic is 100 megabytes per second (MB / s), and the traffic for a certain transaction category is 88 MB / s, which is higher than 70% of the baseline maximum network traffic. The baseline maximum network traffic is then adjusted to 120% of its current value, i.e., 120 MB / s. Five minutes later, the transaction category traffic for that type of transaction is acquired again. This time, the traffic for that transaction category is 88 MB / s, accounting for 73% of the baseline maximum network traffic, still higher than 70% of the current baseline maximum network traffic of 120 MB / s. The baseline maximum network traffic is then adjusted to 120% of its current value, i.e., 144 MB / s. At this point, the traffic for that transaction category is 88 MB / s, accounting for 61% of the baseline maximum network traffic (meeting the first ratio range of 40%~70%). This embodiment, through two adjustments, ensures that the traffic for a certain transaction category gradually converges and stabilizes within a reasonable range of its baseline maximum network traffic.
[0059] In the example above, the value of the third ratio can be set to be greater than or equal to the ratio of the first ratio (40%) to the second ratio (50%), that is, greater than or equal to 80%, and the first ratio can be less than or equal to the ratio of the third ratio (80%) to the fourth ratio (120%), that is, less than or equal to 66.7%.
[0060] Specifically, at a certain moment, the baseline maximum network traffic for a certain transaction category is 100 megabytes per second. In response to a transaction category traffic of 38 megabytes per second, which is less than 40% of the baseline maximum network traffic, the baseline maximum network traffic is adjusted to 50% of the current value, i.e., 50 megabytes per second. Five minutes later, the transaction category traffic is acquired again. This time, the transaction category traffic of 38 megabytes per second accounts for 76% of the baseline maximum network traffic, which is less than 80% of the current baseline maximum network traffic of 50 megabytes per second (the third ratio). At this point, the transaction category traffic of 38 megabytes per second accounts for 63% of the baseline maximum network traffic (meeting the first ratio range of 40%~80%). This embodiment, through a single adjustment, ensures that the traffic for a certain transaction category gradually converges and stabilizes within a reasonable range of its baseline maximum network traffic.
[0061] For example, if the baseline maximum network traffic is 100 megabytes per second at a certain moment, and the traffic for a certain transaction category is 88 megabytes per second, exceeding 80% of the baseline maximum network traffic, the baseline maximum network traffic is adjusted to 120% of the current value, i.e., 120 megabytes per second. Five minutes later, the transaction category traffic for that transaction is retrieved again. This time, the traffic for that transaction category is 88 megabytes per second, accounting for 73% of the baseline maximum network traffic (meeting the first ratio range of 40%~80%). This embodiment, through a single adjustment, ensures that the traffic for a certain transaction category gradually converges and stabilizes within a reasonable range of its baseline maximum network traffic.
[0062] This embodiment further reduces the number of adjustments by setting a third ratio greater than or equal to the ratio of the first ratio to the second ratio, and a first ratio less than or equal to the ratio of the third ratio to the fourth ratio. This ensures that a single reduction falls within the range of the first ratio, guaranteeing that the traffic share ultimately remains stable within the target range. It also optimizes adjustment efficiency as needed, improving the accuracy and flexibility of traffic management.
[0063] In some embodiments of this application, the baseline maximum network traffic is predetermined based on at least one of the special scenario baseline for a first category, the daily peak baseline, and the previous day's average transaction traffic baseline. The special scenario baseline includes a transaction traffic baseline value for a specific date determined based on historical traffic statistics, which can record the special scenario traffic for each type of transaction (such as month-end settlement). The daily peak baseline is a transaction traffic baseline value for at least one transaction period on each date determined based on historical traffic statistics, which can record the maximum network traffic value during the daily peak trading period for each transaction, such as the trading peak from 9:00 to 11:00 and the trading peak from 13:00 to 15:00. The previous day's average transaction traffic baseline is an average baseline value calculated based on the transaction network traffic data of the previous day, which can calculate the average network traffic of each transaction of the previous day at 24:00 each day.
[0064] The baseline maximum network traffic for the first category of a transaction can be determined according to the principles of prioritizing special scenarios, adapting to peak periods, and using daily averages as a safety net. For example, first determine whether the current date falls within the date range of a special scenario (such as month-end settlement or quarterly financial report). If it does, and a baseline for a specific scenario exists for the first category, then the baseline maximum network traffic for that first category on that day is directly set to the baseline value for that specific scenario. If the current date does not involve a special scenario, or there is no baseline for a specific scenario corresponding to the transaction, then further determine whether the current day falls within the fixed peak period of the transaction. If it falls within the peak period and a daily peak baseline exists for the transaction, then the baseline maximum network traffic for the first category during that period on that day is set to the corresponding daily peak baseline value. If there is neither a baseline for a specific scenario available, nor does it fall within the daily peak period, or there is no daily peak baseline corresponding to the transaction, then the baseline maximum network traffic for the first category is the average transaction traffic baseline from the previous day.
[0065] This embodiment can also obtain the benchmark maximum network traffic by weighted summation based on the special scenario baseline, the daily peak baseline, and the average transaction traffic baseline of yesterday.
[0066] This embodiment determines the baseline maximum network traffic for the first category based on three baselines: specific scenarios, daily peak traffic, and yesterday's average transaction volume. This approach is more accurate than single-threshold allocation and reduces misjudgments. The dynamic adjustment mechanism can quickly respond to traffic fluctuations, avoiding the lag of traditional manual adjustments. It prevents resource shortages from affecting transactions when traffic is too high, and also avoids resource waste when traffic is too low, thereby improving network resource utilization and transaction stability.
[0067] Figure 3 A flowchart illustrating a second transaction flow allocation method according to an embodiment of this application is shown.
[0068] like Figure 3 As shown, in some embodiments of this application, the transaction flow allocation method includes operations S310 to S320.
[0069] In operation S310, acquire N consecutive transaction category flows, where N is a positive integer.
[0070] When operating S320, if the traffic of N consecutive transaction categories is higher than the fifth percentage of the maximum network traffic of the baseline, and there is no abnormal traffic among the N transaction categories, at least one of the special scenario baseline, the daily peak baseline, and the average transaction traffic baseline of yesterday is adjusted based on the traffic of the N transaction categories.
[0071] For example, by monitoring real-time traffic, if a transaction category experiences more than three consecutive non-attack traffic fluctuations, such as exceeding 130% of the baseline maximum network traffic (i.e., the traffic is 30% higher than the baseline maximum network traffic for three consecutive times), the baseline value for the corresponding period will be automatically corrected.
[0072] For example, suppose the baseline maximum network traffic for a certain product payment transaction category is 200 megabytes per second, the fifth proportion is set to 120% (i.e., 240 megabytes per second), N is set to 5, and the initial baseline for special scenarios is an average of 200 megabytes per second per day during the pre-sale period, a daily peak baseline of 220 megabytes per second during the 10:00-12:00 period, and a baseline of 1100 megabytes per second for the average transaction traffic of the previous day; the system continuously obtains the traffic of 5 product payment transaction categories as 250 megabytes per second, 255 megabytes per second, 248 megabytes per second, 252 megabytes per second, 249 megabytes per second, and 249 megabytes per second, respectively. The data volume is in megabytes per second. After anomaly detection (verification that all transaction instructions are in the historical normal list, transaction parameters are compliant, and the number of failed Internet Protocol address calls from the same origin does not exceed the threshold), it is confirmed that there is no abnormal traffic. Moreover, all five traffic flows are higher than 120% of the baseline maximum network traffic (240 megabytes per second). At this point, based on the average of these five traffic flows, 250.8 megabytes per second, the special scenario baseline is adjusted to 250 megabytes per second, and the daily peak baseline is adjusted to 250 megabytes per second. This ensures that the subsequent traffic control baseline can adapt to the traffic growth trend and avoids normal transactions being misjudged or resources being insufficient due to a low baseline.
[0073] This embodiment corrects at least one of three baselines—special scenarios, daily peaks, and yesterday's average transaction volume—when N consecutive transaction categories with traffic exceeding the fifth proportion of the baseline maximum network traffic and without any abnormalities are obtained. This allows the baseline to dynamically adapt to non-abnormal traffic change trends, avoiding misjudgments caused by long-term fixed baselines. Consequently, it improves the accuracy of subsequent traffic control and allocation, ensuring that network resource allocation is more in line with actual business needs.
[0074] Figure 4 A flowchart illustrating a third transaction flow allocation method according to an embodiment of this application is shown.
[0075] like Figure 4 As shown, in some embodiments of this application, the transaction flow allocation method further includes operations S410~S420.
[0076] When operating the S410, in response to acquiring the traffic information for each transaction, the transaction instructions and parameter information in the traffic information are decrypted and extracted.
[0077] Transaction traffic transmitted over the network is often encrypted to ensure data security, making direct reading impossible to obtain valid business information. By decrypting and extracting fields, network layer traffic data is transformed into identifiable business layer information, providing crucial evidence for subsequent judgments on transaction compliance. Specifically, a preset encryption key is used to decrypt encrypted traffic packets, restoring them to plaintext data. From the decrypted plaintext data, key transaction-related fields are located and extracted, including transaction instructions identifying the transaction type and parameter information supporting transaction execution.
[0078] For example, a user initiates an order payment on an e-commerce platform, and the traffic information is transmitted encrypted using the T protocol. The received encrypted data packet is decrypted using a pre-stored T protocol session key to obtain the plaintext data. The extracted transaction instruction is: Order Payment; the extracted parameter information includes: order number OD202509XXXXX, payment amount 999.00 yuan, payment method A, and client address XX.XX.XX.XX.
[0079] During operation S420, if the traffic information responding to a transaction contains non-compliant items, the transaction is determined to be an abnormal transaction. The non-compliant items include at least one of the following: the transaction instruction is not present in the historical traffic statistics list; the transaction parameters are non-compliant; the historical traffic statistics list is obtained based on historical normal transaction statistics; and the number of failed transactions originating from the same Internet Protocol address exceeds a preset number.
[0080] The historical traffic statistics list can be a compliant instruction library formed by analyzing all normal transaction instructions over the past few months. If the extracted transaction instruction is not in this list, it means that the instruction has no normal business support and may be a constructed non-compliant instruction.
[0081] For different trading instructions, the compliance range of parameters can be preset (such as format, value, required fields, etc.). If a parameter is missing a required field, has an incorrect format, or its value exceeds the reasonable range, it is considered non-compliant.
[0082] Same-origin Internet Protocol (IP) addresses refer to all transactions originating from the same IPC address. If a transaction of this type fails more than a preset number of times within one minute, it may indicate abnormal behavior.
[0083] For example, the baseline maximum network traffic for order payment transactions is 200 megabytes per second, and the maximum allowed number of failures is 10 per minute. Monitoring revealed that an Internet Protocol address 192.XX.XX.XX initiated 20 order payment transactions within one minute, and all of them failed due to non-existent order numbers. The number of failures (20 times) exceeded 10, thus the transaction was deemed to have this non-compliance.
[0084] In this embodiment, abnormal transactions are determined as follows: if a transaction's traffic information contains at least one of the aforementioned non-compliant items, it is considered an abnormal transaction. For example, transaction A is considered abnormal if it has both "transaction instruction not in the list" and "parameters non-compliant"; transaction B is considered abnormal if it only has "same-origin Internet Protocol address failures exceed a preset number"; and transaction C is considered normal if it has no non-compliant items.
[0085] This embodiment first decrypts and extracts the transaction instructions and parameter information after obtaining the traffic information of each transaction, and then judges abnormal transactions. It can identify anomalies from multiple dimensions such as the legality of transaction instructions, the compliance of parameters, and the abnormality of behavior of the same source address, avoiding the omissions of traditional single-dimensional detection, and thus more comprehensively blocking malicious attack traffic and ensuring network transaction security.
[0086] Figure 5 A flowchart illustrating a fourth transaction flow allocation method according to an embodiment of this application is shown.
[0087] like Figure 5 As shown, in some embodiments of this application, the transaction flow allocation method further includes: operations S510 to S530.
[0088] In operation S510, at least one associated business traffic is acquired that is related to the transaction category traffic.
[0089] Related business traffic refers to traffic generated by other businesses that have business logic dependencies or data associations with the target transaction category. For example, transfer transactions (the target transaction category) and account inquiry transactions are related. Users typically check their account balance first (inquiry transaction) and then initiate a transfer (transfer transaction), with a time difference of several minutes between the two. Account inquiry traffic can be considered related business traffic to transfer traffic. For example, monitoring can reveal that the query traffic data for account inquiries related to transfer transactions is 122 megabytes per minute.
[0090] In operation S520, based on at least one associated business traffic, the transaction category traffic prediction value is obtained in the first instant.
[0091] In the example above, based on the monitored query traffic data, the historical average query traffic for the same period was extracted as 80 megabytes per minute. The difference between the current query traffic and the historical average was calculated to be 42.5 megabytes per minute. Based on empirical values, the estimated increase in transfer traffic is approximately (42.5 megabytes per minute ÷ 30 megabytes per minute) × 25 megabytes per minute ≈ 35.4 megabytes per minute. The historical average transfer traffic for the same period (5 minutes later) was extracted, and the average transfer traffic was 65 megabytes per minute. The predicted transfer traffic for the first time (5 minutes later) was calculated as: 65 megabytes per minute + 35.4 megabytes per minute ≈ 100.4 megabytes per minute.
[0092] When operating S530, in response to a transaction category traffic prediction value not falling within the first proportional range of the baseline maximum network traffic at the moment, the baseline maximum network traffic is adjusted. If the predicted traffic will exceed the upper limit, the baseline value is increased in advance to avoid insufficient resources at that time; if the predicted traffic will fall below the lower limit, the capacity is reduced in advance to avoid wasting resources.
[0093] In the example above, the first proportional range (40~70 megabytes per minute) of the baseline maximum network traffic (100 megabytes per minute) for the first time (5 minutes later) of transfer transactions is calculated. Comparing the predicted value with the range, 100.4 megabytes per minute exceeds the normal range of 40~70 megabytes per minute. Therefore, the baseline maximum network traffic is increased from 100 megabytes per minute to 120 megabytes per minute.
[0094] This embodiment first obtains the associated business traffic related to the target transaction category traffic, then predicts the target transaction category traffic at the first time based on the associated traffic, and finally adjusts the benchmark value when the predicted value exceeds the first proportion range of the maximum network traffic at the corresponding time benchmark. This allows for early prediction of traffic change trends, thereby optimizing network resource allocation more promptly and ensuring the stable operation of transactions at the first time.
[0095] Figure 6 A flowchart illustrating a fifth transaction flow allocation method according to an embodiment of this application is shown.
[0096] like Figure 6 As shown, in some embodiments of this application, the transaction flow allocation method further includes: operations S610 to S620.
[0097] In operation S610, in response to acquiring first transaction category traffic and second transaction category traffic on the same device, the first category traffic, belonging to the first category, has a higher priority than the second category traffic, belonging to the second category.
[0098] Because network equipment carrying transaction transmissions has limited resources such as bandwidth and forwarding capacity. Furthermore, the same device may simultaneously transmit two different types of transaction traffic with a clear priority difference, such as the first transaction type having high priority and the second having low priority. For example, the first transaction type might be large-amount transfers, and the second might be account detail inquiries.
[0099] In operation S620, if the traffic of the first transaction category is higher than the third proportion of the baseline maximum network traffic of the first category, the baseline maximum network traffic of the second category to which the traffic of the second transaction category belongs is adjusted to the second proportion of the current value and maintained.
[0100] For example, in the above example, the traffic for large-amount transfers is 85 megabytes per minute, and the traffic for account detail queries is 70 megabytes per minute, both originating from the same device. For the first transaction category (large-amount transfers), the real-time traffic is 85 megabytes per minute, and the threshold corresponding to the third proportion (80%) of its baseline maximum traffic is 80 megabytes per minute. The traffic for high-priority large-amount transfers exceeds this threshold. The baseline maximum network traffic for the second transaction category (account queries) (assuming a current value of 80 megabytes per minute) is adjusted to the second proportion (60%) of the current value, i.e., 80 × 60% = 48 megabytes per minute, while maintaining this scaled-down baseline. The maximum available resources for low-priority account query services are limited to 48 megabytes per minute, and the released resources (80 - 48 = 32 megabytes per minute) can be prioritized for high-priority large-amount transfer services. Furthermore, if the traffic for the first transaction category decreases subsequently, the restriction on the second transaction category can be lifted, i.e., the second proportion maintained at the current value can be removed.
[0101] This embodiment obtains high-priority first-class transaction traffic and low-priority second-class transaction traffic on the same device. If the high-priority traffic exceeds the third ratio of its baseline maximum network traffic, the baseline maximum network traffic of the low-priority traffic is adjusted to the second ratio of the current value and maintained. This can prioritize the traffic resource needs of high-priority transactions by distinguishing priorities, avoid low-priority traffic occupying too many resources and affecting the operation of high-priority transactions, and thus improve the rationality of network resource allocation and the stability of core transactions.
[0102] In some embodiments of this application, the transaction traffic allocation method further includes: monitoring transaction category traffic at a first time interval in response to a first proportion in which transaction category traffic is lower than a baseline maximum network traffic; and monitoring transaction category traffic at a second time interval in response to a third proportion in which transaction category traffic is higher than a baseline maximum network traffic.
[0103] For example, monitor the relationship between the current network traffic of at least one category of transactions and the baseline maximum network traffic value of that category every minute. If the current network traffic of this category of transactions is less than 70% of its baseline maximum network traffic, adjust the monitoring interval to once every 5 minutes. If the current network traffic of this category of transactions is greater than 70% of its baseline maximum network traffic, adjust the baseline maximum network traffic of this category to 1.2 times the current value, and simultaneously adjust the dynamic monitoring interval to once per second. Continue until the current network traffic of this category of transactions falls below 70% of its baseline maximum network traffic, indicating that the network traffic of this category of transactions has stabilized. If the current network traffic of this category of transactions is less than 40% of its baseline maximum network traffic, adjust the baseline maximum network traffic of this category to 50% of the current value, and simultaneously adjust the dynamic monitoring interval to once every 5 minutes, until the current network traffic of this category of transactions stabilizes.
[0104] This embodiment reduces monitoring resource consumption when traffic is under low load and increases monitoring frequency when traffic is under high load. This avoids the resource waste or response delay caused by traditional fixed-interval monitoring, and achieves accurate allocation of monitoring resources and timely capture of traffic fluctuations, thus ensuring a balance between traffic control efficiency and resource utilization.
[0105] Based on the above-described transaction flow allocation method, this application also provides a transaction flow allocation device. The following will be combined with... Figure 7 The device is described in detail.
[0106] Figure 7 A schematic block diagram of a first transaction flow allocation device according to an embodiment of this application is shown.
[0107] like Figure 7 As shown, the transaction traffic allocation device 700 in this embodiment includes a traffic monitoring module 710 and a traffic allocation module 720.
[0108] The traffic monitoring module 710 is used to acquire traffic information of at least one transaction in the target network; and to determine the first category of transaction traffic to which at least one transaction belongs based on the traffic information.
[0109] The traffic allocation module 720 is used to scale up or down the baseline maximum network traffic in response to the fact that the transaction category traffic does not fall within the first proportional range of the baseline maximum network traffic of the first category; after waiting for a predetermined time interval, it acquires the transaction category traffic of the first category again; if the transaction category traffic acquired again does not fall within the first proportional range of the baseline maximum network traffic of the first category, it continues to scale up or down the baseline maximum network traffic until the transaction category traffic falls within the first proportional range of the baseline maximum network traffic of the category.
[0110] According to an embodiment of this application, the traffic allocation module 720 is configured to adjust the benchmark maximum network traffic to a second proportion of its current value in response to a first proportion where the transaction category traffic is lower than the benchmark maximum network traffic; and to adjust the benchmark maximum network traffic to a fourth proportion of its current value in response to a third proportion where the transaction category traffic is higher than the benchmark maximum network traffic; wherein the third proportion is greater than or equal to the ratio of the first proportion to the second proportion, and the first proportion is less than or equal to the ratio of the third proportion to the fourth proportion. The traffic monitoring module 710 is configured to acquire the transaction category traffic of its respective category again after waiting for a predetermined time interval.
[0111] According to an embodiment of this application, the benchmark maximum network traffic is predetermined based on at least one of the special scenario baseline of the first category, the daily peak baseline, and the average transaction traffic baseline of yesterday. The special scenario baseline includes the transaction traffic benchmark value for a specific date determined based on historical traffic statistics. The daily peak baseline includes the transaction traffic benchmark value for at least one transaction period on each date determined based on historical traffic statistics. The average transaction traffic baseline of yesterday includes the average benchmark value calculated based on the transaction network traffic data of the previous date.
[0112] According to an embodiment of this application, the transaction traffic allocation device further includes a historical traffic statistics module, which is used to: if the traffic of N consecutive transaction categories is higher than the fifth proportion of the baseline maximum network traffic, and there is no abnormal traffic among the N transaction categories, adjust at least one of the special scenario baseline, the daily peak baseline, and the yesterday's average transaction traffic baseline based on the N transaction categories traffic.
[0113] According to an embodiment of this application, the traffic monitoring module 710 is further configured to, in response to obtaining traffic information for each transaction, decrypt and extract transaction instructions and parameter information from the traffic information; and, in response to the traffic information of a transaction having non-compliant items, determine that the transaction is an abnormal transaction; wherein the non-compliant items include at least one of the following: the transaction instruction is not present in the historical traffic statistics list and the transaction parameters are non-compliant, wherein the historical traffic statistics list is obtained based on historical normal transaction statistics; and the number of transaction failures from the same origin Internet Protocol address is greater than a preset number.
[0114] According to an embodiment of this application, the traffic monitoring module 710 is further configured to acquire at least one associated service traffic related to the transaction category traffic; predict the transaction category traffic forecast value at a first time based on the at least one associated service traffic; and adjust the benchmark maximum network traffic in response to the transaction category traffic forecast value not being within a first proportional range of the benchmark maximum network traffic at the first time.
[0115] According to an embodiment of this application, the traffic allocation module 720 is further configured to respond to the acquisition of first transaction category traffic and second transaction category traffic on the same device; if the first transaction category traffic is higher than the third proportion of the baseline maximum network traffic of the first category to which it belongs, adjust the baseline maximum network traffic of the second transaction category traffic to which it belongs to the second proportion of the current value, and maintain it; wherein, the first category priority is higher than the second category priority.
[0116] According to embodiments of this application, any plurality of modules among the flow monitoring module 710, flow allocation module 720, and flow statistics module can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least some of the functions of one or more of these modules can be combined with at least some of the functions of other modules and implemented in one module. According to embodiments of this application, at least one of the flow monitoring module 710, flow allocation module 720, and flow statistics module can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the flow monitoring module 710, flow allocation module 720, and flow statistics module can be at least partially implemented as a computer program module, which can perform corresponding functions when the computer program module is run.
[0117] Figure 8 A schematic block diagram illustrating a second type of transaction flow allocation device according to an embodiment of this application is shown. Figure 8 As shown in this embodiment, the transaction traffic allocation device includes a real-time traffic monitoring module, a traffic allocation module, and a historical traffic statistics module.
[0118] Figure 9 A flowchart illustrating a sixth transaction flow allocation method according to an embodiment of this application is shown.
[0119] like Figure 9 As shown, the method for allocating transaction traffic using the second transaction traffic allocation device according to the embodiments of this application is described in detail below.
[0120] The real-time traffic monitoring module monitors the traffic information of each type of transaction every minute, sends the traffic information of the transaction to the historical traffic statistics module for statistics, and monitors the relationship between the current network traffic occupied by each type of transaction and the baseline maximum network traffic of that type of transaction. Based on the monitoring results, it adjusts the dynamic monitoring time interval of each type of transaction and notifies the traffic allocation module to adjust the baseline maximum network traffic value of each type of transaction.
[0121] The historical traffic statistics module calculates traffic data for each type of transaction under various scenarios, providing the real-time traffic monitoring module with information to compare the current and maximum network traffic for each type of transaction. The historical traffic statistics module calculates historical network traffic values for each dimension of each transaction and sends this information to the traffic allocation module for further analysis. Specific traffic information for each dimension is shown in Table 1. The special scenario baseline records the traffic for each transaction under special scenarios (e.g., end-of-month settlement), with a priority of 10; the daily peak baseline records the maximum network traffic for each transaction during daily peak periods, such as 9:00-11:00 and 13:00-15:00, with a priority of 9; the yesterday's average transaction traffic baseline calculates the average network traffic for each transaction from the previous day at 24:00 each day, with a priority of 8.
[0122] Table 1. Flow of each type of transaction across different dimensions
[0123] Device Type Function Priority (10 is the highest) Historical traffic statistics module Special scene baseline Record the special scene traffic of each transaction (such as the end of the month settlement) 10 Historical traffic statistics module Daily peak baseline Record the maximum network traffic of each transaction during the daily transaction peak period, such as 9:00~11:00 transaction peak, 13:00~15:00 transaction peak 9 Historical traffic statistics module Yesterday's transaction average traffic baseline Record the average network traffic of each transaction of the previous day within 24 hours 8
[0124] The functions of the traffic allocation module include: 1) Based on the information provided by the historical traffic module, firstly determine whether each type of transaction has a special scenario baseline. If so, and the current date of the transaction falls within the date range of that scenario, then adjust the baseline maximum network traffic of that type of transaction to the value of that special scenario baseline. If the type of transaction does not have a special scenario baseline, then determine whether the type of transaction has a daily peak baseline. If so, then adjust the baseline maximum network traffic of that type of transaction to that value. If there is no daily peak baseline, then check whether there is a baseline for yesterday's average transaction traffic. If so, then automatically set the baseline maximum network traffic to 1.2 times that value at 7:00 AM every day. 2) Decrypt the traffic information sent by the real-time traffic monitoring module and verify the decrypted transaction instructions and parameter information. If it is found that the decrypted transaction instructions do not exist in the historical list, or the decrypted parameter instructions do not meet the requirements, and the number of failed transactions from the same origin Internet Protocol address is greater than or equal to 10, then the transaction is determined to be an attack. At this time, push the access control list rules to the destination router or switch to set the traffic of that origin Internet Protocol address to 0, thus blocking the traffic attack. 3) Collect the geographical distribution of source Internet Protocol addresses to provide richer feature dimensions for subsequent attack detection.
[0125] The traffic allocation module schedules traffic scaling up and down based on the monitoring results from the real-time traffic monitoring module. Simultaneously, the traffic allocation module monitors traffic content; if it detects an abnormal transaction originating from the same source Internet Protocol address, it sets the inbound traffic to that source address to 0 and blocks the incoming traffic. Otherwise, no action is taken.
[0126] The real-time traffic monitoring module monitors the traffic of routers or switches and encrypts this information before sending it to the traffic allocation module for further judgment. The specific process is as follows.
[0127] The system determines whether the current network traffic for this type of transaction is below 70% of its baseline maximum network traffic. If so, it adjusts the monitoring interval to once every 5 minutes to check the relationship between the current network traffic and the baseline maximum network traffic. If not, it notifies the traffic allocation module to dynamically adjust the baseline maximum network traffic for this type of transaction to 120% of its current value, and simultaneously adjusts the dynamic monitoring interval for this type of transaction to once per second. It continues to determine whether the current network traffic for this type of transaction is above 70% of its baseline maximum network traffic until the current network traffic for this type of transaction falls below 70% of its baseline maximum network traffic, indicating that the network traffic for this type of transaction has stabilized.
[0128] Determine if the current network traffic for this type of transaction is less than 40% of its baseline maximum network traffic. If not, no action is taken; if so, notify the traffic allocation module to adjust the baseline maximum network traffic for this type of transaction to 50% of the current value, and simultaneously adjust the dynamic monitoring interval for this type of transaction to once every 5 minutes until the current network traffic for this type of transaction stabilizes. Meanwhile, if the real-time traffic monitoring module detects more than three consecutive non-attack-related traffic fluctuations for this type of transaction (e.g., a transaction's traffic is 30% higher than the baseline for three consecutive times), it will automatically correct the baseline value for the corresponding period.
[0129] In cases where network traffic fluctuates significantly within a short period, this embodiment can determine the maximum network traffic based on a baseline and perform traffic blocking and allowing operations in an adaptive manner. This approach avoids resource waste or shortage and enables a rapid response.
[0130] Figure 10 A block diagram of an electronic device suitable for implementing a transaction flow allocation method according to an embodiment of this application is shown schematically.
[0131] like Figure 10As shown, an electronic device 1000 according to an embodiment of this application includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage portion 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.
[0132] RAM 1003 stores various programs and data required for the operation of electronic device 1000. Processor 1001, ROM 1002, and RAM 1003 are interconnected via bus 1004. Processor 1001 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 1002 and / or RAM 1003. It should be noted that programs may also be stored in one or more memories other than ROM 1002 and RAM 1003. Processor 1001 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in one or more memories.
[0133] According to embodiments of this application, the electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to a bus 1004. The electronic device 1000 may also include one or more of the following components connected to the input / output (I / O) interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to the input / output (I / O) interface 1005 as needed. A removable medium 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1010 as needed so that computer programs read from it can be installed into the storage section 1008 as needed.
[0134] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.
[0135] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 1002 and / or RAM 1003 and / or one or more memories other than ROM 1002 and RAM 1003 described above.
[0136] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to enable the computer system to implement the transaction flow allocation method provided in the embodiments of this application.
[0137] When the computer program is executed by the processor 1001, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0138] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1009, and / or installed from a removable medium 1011. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0139] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1009, and / or installed from the removable medium 1011. When the computer program is executed by the processor 1001, it performs the functions defined in the system of this application embodiment. According to the embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0140] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0141] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0142] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.
Claims
1. A method for allocating transaction flow, characterized in that, include: Obtain traffic information for at least one transaction in the target network; Based on the traffic information, determine the transaction category traffic to which the at least one transaction belongs in the first category; In response to the fact that the traffic of the transaction category does not fall within a first proportional range of the baseline maximum network traffic of the first category, the baseline maximum network traffic is scaled up or down. After waiting for a predetermined time interval, the transaction category traffic of the first category is acquired again; if the acquired transaction category traffic does not fall within the first proportion range of the baseline maximum network traffic of the first category, the baseline maximum network traffic is scaled up or down until the transaction category traffic falls within the first proportion range.
2. The method according to claim 1, characterized in that, The scaling up or down of the baseline maximum network traffic includes: in response to a first proportion of the transaction category traffic being lower than the baseline maximum network traffic, adjusting the baseline maximum network traffic to a second proportion of the current value; And in response to a third proportion where the transaction category traffic is higher than the baseline maximum network traffic, a fourth proportion is adjusted to the current value of the baseline maximum network traffic, wherein the third proportion is greater than or equal to the ratio of the first proportion to the second proportion, and the first proportion is less than or equal to the ratio of the third proportion to the fourth proportion.
3. The method according to claim 1, characterized in that, The benchmark maximum network traffic is predetermined based on at least one of the special scenario baseline of the first category, the daily peak baseline, and the yesterday's average transaction traffic baseline. The special scenario baseline includes a transaction traffic benchmark value for a specific date determined based on historical traffic statistics. The daily peak baseline includes a transaction traffic benchmark value for at least one transaction period on each date determined based on historical traffic statistics. The yesterday's average transaction traffic baseline includes an average benchmark value calculated based on the transaction network traffic data of the previous date.
4. The method according to claim 1, characterized in that, Also includes: Obtain N consecutive traffic flows of the aforementioned transaction category, where N is a positive integer; If the traffic of the N consecutive transaction categories is higher than the fifth proportion of the maximum network traffic of the benchmark, and there is no abnormal traffic among the N transaction categories, at least one of the special scenario baseline, the daily peak baseline, and the average transaction traffic baseline of yesterday is adjusted based on the N transaction categories.
5. The method according to claim 1, characterized in that, Also includes: In response to obtaining the transaction flow information, the transaction instructions and parameter information in the flow information are decrypted and extracted; If the transaction's traffic information contains non-compliant items, the transaction is determined to be an abnormal transaction. The non-conforming items include at least one of the following: The transaction instruction is absent from the historical traffic statistics list and the transaction parameters are non-compliant, wherein the historical traffic statistics list is obtained based on historical normal transaction statistics; and The number of failed transactions originating from the same Internet Protocol address exceeds the preset limit.
6. The method according to claim 1, characterized in that, Also includes: Obtain at least one associated business traffic related to the traffic of the stated transaction category; Based on the at least one associated business traffic, predict the transaction category traffic forecast value at the first time. In response to the transaction category traffic prediction value not being within the first proportion range of the baseline maximum network traffic at the first time, the baseline maximum network traffic is adjusted.
7. The method according to claim 2, characterized in that, Also includes: In response to acquiring first and second transaction category traffic on the same device; If the traffic of the first transaction category is higher than the third proportion of the benchmark maximum network traffic of the first category, the benchmark maximum network traffic of the second category to which the traffic of the second transaction category belongs is adjusted to the second proportion of the current value and maintained; The first category has a higher priority than the second category.
8. A transaction flow allocation device, characterized in that, The device includes: A traffic monitoring module is used to acquire traffic information of at least one transaction in a target network; determine the transaction category traffic of a first category to which the at least one transaction belongs based on the traffic information; and The traffic allocation module is used to scale up or down the baseline maximum network traffic in response to the transaction category traffic not falling within the first proportion range of the baseline maximum network traffic for the first category; after waiting for a predetermined time interval, it acquires the transaction category traffic for the first category again; if the acquired transaction category traffic does not fall within the first proportion range of the baseline maximum network traffic for the first category, it continues to scale up or down the baseline maximum network traffic until the transaction category traffic falls within the first proportion range.
9. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 7.