Business traffic auditing method, system, device and storage medium

By combining multi-dimensional data collection and intelligent verification with protocol-level interactive verification through proactive detection and traffic mirroring, the problems of blind spots and high false judgment rates in existing technologies for business IP auditing have been solved, enabling accurate auditing and rapid fault location of the entire lifecycle of business IP.

CN121561691BActive Publication Date: 2026-08-04SINO TELECOM TECHNOLOGY CO INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SINO TELECOM TECHNOLOGY CO INC
Filing Date
2025-10-29
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Existing technologies for managing business IP addresses suffer from numerous audit blind spots, high rates of missed detections and false positives, and low efficiency in anomaly detection, making it difficult to meet the demands of modern multi-datacenter, large-scale, and real-time operating environments.

Method used

By collecting multi-dimensional data sources, performing correlation comparison and collision analysis, and combining proactive detection and traffic mirroring with protocol-level interactive verification, a two-layer verification mechanism combining initial screening and fine judgment is adopted. Based on the lineage relationship between data table items and the business strategy matrix, root cause analysis is performed to achieve accurate auditing of the entire lifecycle of business IP.

Benefits of technology

It achieves full coverage of various hidden anomaly scenarios, effectively distinguishes between real anomalies and misjudgments, enhances the depth and breadth of audit work, and meets the needs of real-time fault location and rapid recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121561691B_ABST
    Figure CN121561691B_ABST
Patent Text Reader

Abstract

The application relates to a business traffic auditing method, comprising the following steps: collecting and dynamically updating data from mutually independent basic data sources, record information sources, network traffic sources and device configuration sources in a business system to form a multidimensional data set; performing correlation comparison and collision analysis on the multidimensional data set to identify potential abnormalities of a business IP in the whole-link life cycle from data entry, record registration to traffic traction and entry loading; adopting a double-layer verification mechanism combining preliminary screening and accurate judgment to confirm the identified potential abnormalities, wherein the accurate judgment adopts a protocol-level interactive verification mode based on active detection and traffic mirroring cooperation; and performing root cause analysis on the confirmed abnormalities based on the blood relationship between data entries and a preset business strategy matrix to automatically locate the specific link and type of the abnormalities. Through linkage and collision analysis on multi-source heterogeneous data such as basic data, record information, real-time traffic and device entries, the auditing dimension is expanded from traditional static data to dynamic business whole-link, and full coverage of various implicit abnormal scenarios is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, specifically to a business traffic auditing method, system, computer equipment, and storage medium. Background Technology

[0002] With the booming development of the digital economy, the business scale of Internet Data Centers (IDCs) and Internet Service Providers (ISPs) continues to expand, and the number of business IP addresses they manage and operate is growing exponentially. At the same time, industry regulators are imposing increasingly stringent compliance requirements on IDC / ISP businesses, demanding that operators ensure the accurate controllability and traceability of business IP addresses throughout the entire process, from entry and registration to traffic routing and device entry loading. Against this backdrop, building an efficient and accurate business traffic auditing system has become a core requirement for IDC / ISP operators to ensure business compliance, mitigate regulatory risks, and improve operational efficiency.

[0003] Currently, the traditional auditing model for IDC / ISP businesses in the industry mainly relies on static, single data table comparisons. A typical approach is to simply compare a data table recording basic IP information with the Ministry of Industry and Information Technology's (MIIT) filing information table to verify whether the IP address has been filed. However, this traditional auditing method has significant limitations and is no longer suitable for modern multi-data center, large-scale, and real-time demanding operating environments. Its shortcomings are specifically reflected in the following aspects: First, the limited data dimensions lead to numerous blind spots in auditing and a high rate of missed detections. Traditional methods focus only on the static consistency between "basic data" and "registration information," failing to cover the entire lifecycle of a business IP. For example, for IPs where "registration information is outdated but business traffic has already been generated," and IPs where "device entries have been loaded but registration information has not yet been entered," traditional single-table comparison mechanisms, lacking support from real-time traffic data and device configuration data, cannot effectively capture these "hidden" anomalies, resulting in a large number of unregistered active IPs being missed.

[0004] Secondly, the logic for judging traffic redirection anomalies is simplistic and prone to misjudgment. Traditional methods typically rely solely on the presence of traffic at an IP address as the sole criterion for determining traffic redirection anomalies. This simplistic logic of "traffic is normal, no traffic is abnormal" easily misjudges legitimate IPs (such as backup systems or periodic business IPs) that have completed traffic redirection configuration but are in a long-term dormant state as violating regulations. Furthermore, traditional methods lack effective identification capabilities for "traffic redirection failures" caused by IP addresses being incorrectly assigned to non-target data centers. Thirdly, anomaly troubleshooting is inefficient and relies heavily on manual tracing. When anomalies are discovered during audits, traditional troubleshooting methods require operations personnel to manually trace and investigate multiple stages step by step. For example, first verifying whether the central control unit successfully distributed basic data, and then verifying whether the edge device units correctly loaded table entries. This process is not only time-consuming and labor-intensive, but also prone to overlooking deeper issues such as "missing table entries" due to human error, failing to meet the demands of modern businesses for real-time fault location and rapid recovery. Summary of the Invention

[0005] The purpose of this invention is to provide a business traffic auditing method to solve the problem of business traffic auditing.

[0006] A first aspect of the present invention provides a business traffic auditing method, comprising: Data collection steps: Collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources, and device configuration sources in the business system to form a multi-dimensional data set; Joint audit steps: Perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of business IPs throughout the entire lifecycle from data entry and filing to traffic traction and table entry loading; Intelligent verification steps: For identified potential anomalies, a two-layer verification mechanism combining initial screening and fine judgment is used for confirmation. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. Precise location steps: Based on the lineage relationship between data table items and the preset business strategy matrix, root cause analysis is performed on confirmed anomalies to automatically locate the specific link and type of the anomaly.

[0007] In one possible implementation, the step of performing correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies in the entire lifecycle of the business IP, from data entry and filing to traffic generation and table entry loading, includes: The data from the basic data source, the filing information source, the network traffic source, and the device configuration source are compared and contrasted to cover various abnormal scenarios in the entire business chain. Specifically, by comparing data from basic data sources and network traffic sources, business IPs that have generated traffic but have not been entered are identified; by comparing data from basic data sources and filing information sources, business IPs that have been entered but not filed are identified; by comparing data from network traffic sources and filing information sources, business IPs that have generated traffic but have not filed are identified; and by comparing data from device configuration sources and filing information sources, business IPs that have loaded table entries but have not filed are identified.

[0008] In one possible implementation, the identified potential anomalies are confirmed using a two-layer verification mechanism combining initial screening and fine-grained judgment. The fine-grained judgment employs a protocol-level interactive verification method based on proactive detection and traffic mirroring, including: According to the business rules, the set of business IPs that are expected to complete the traffic redirection configuration and the set of business IPs that have actually completed the traffic redirection behavior are respectively aggregated from the multi-dimensional data set; By calculating the differences between two sets, a list of IPs with a high probability of being involved in abnormal traffic redirection can be quickly generated.

[0009] In one possible implementation, the protocol-level interactive verification method includes: Initiate liveness detection requests following standard network protocols to the IP addresses in the list of highly suspected abnormal traffic sources; The instruction is deployed to synchronously monitor mirrored traffic directed to the IP address; If no response traffic is detected for the activation request, it is determined to be a genuine traffic redirection anomaly; if response traffic is detected but the service type of the IP does not match the preset service policy of the data center, it is determined to be an IP address misrecording anomaly.

[0010] In one possible implementation, the root cause analysis of confirmed anomalies based on the lineage relationships between data entries includes: Establish a mapping of generation dependencies between basic data table entries and derived device configuration table entries; When a missing or incorrect entry in the configuration table of a derived device is identified, the generation dependency mapping can be traced to directly determine whether the problem is an abnormality in the distribution of basic data or an abnormality in the loading of derived entries, without the need to check upstream and downstream links step by step.

[0011] In one possible implementation, the root cause analysis of confirmed anomalies based on the business strategy matrix includes: The business strategy matrix defines the legal mapping relationship between IPs of different business types and data center attributes; In the intelligent verification step, when a service IP does not respond to the probe in a specific data center, its service type is matched with the service policy matrix. If the match fails, it is automatically determined to be an IP address misrecording anomaly.

[0012] In one possible implementation, logically isolated audit strategy instances and data analysis views are created for different business tenants; Based on the aforementioned business strategy matrix, a legal mapping relationship between the business IP and data center resources is defined for each tenant. During the joint audit and precise location steps, the system distinguishes data ownership and compliance policies based on tenant identifiers and generates independent audit reports at the tenant level.

[0013] A second aspect of the present invention provides a business traffic auditing system, comprising: The data acquisition module is used to collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources, and device configuration sources in the business system, forming a multi-dimensional data set; The linkage audit module is used to perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of business IPs throughout the entire lifecycle from data entry and filing to traffic traction and table entry loading. The intelligent verification module is used to confirm the identified potential anomalies using a two-layer verification mechanism that combines initial screening and fine judgment. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. The precise location module is used to perform root cause analysis on confirmed anomalies based on the lineage relationships between data table items and a preset business strategy matrix, automatically locating the specific link and type of the anomaly.

[0014] A third aspect of the present invention provides a computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the business traffic auditing method as described in the first aspect of the present invention.

[0015] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the business traffic auditing method as described in the first aspect of the present invention.

[0016] Compared with the prior art, the beneficial effects of the present invention are: 1. By linking and analyzing heterogeneous data from multiple sources, such as basic data, filing information, real-time traffic, and device entries, the audit dimensions are expanded from traditional static data to the entire dynamic business chain. This achieves full coverage of various hidden abnormal scenarios such as "active without being entered", "entered but not filed", and "traffic redirected but not filed". It effectively solves the blind spots and data fragmentation problems of traditional single-table verification and avoids compliance risks caused by missed judgments.

[0017] 2. Through protocol-level interactive verification via proactive testing and traffic mirroring, the system effectively distinguishes between "genuine traffic redirection anomalies" and "silent business IPs," effectively resolving the issue of misjudgment of silent IPs caused by traditional methods that rely solely on traffic existence checks. "Incorrect IP entries" can be identified simultaneously in a single process, significantly enhancing the depth and breadth of auditing work. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the business traffic auditing method of the present invention; Figure 2 This is a schematic diagram of the business traffic auditing system of the present invention; Figure 3 This is a schematic diagram of a computer device according to an embodiment of the present invention. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. Based on the embodiments of this invention, those skilled in the art will understand... All other embodiments obtained through creative labor are within the scope of protection of this invention.

[0020] It should be noted that the serial numbers assigned to the components in the embodiments of the present invention, such as "first" and "second", are only used to distinguish the described objects and have no sequential or technical meaning.

[0021] The following is combined Figure 1 This invention describes a business traffic auditing method.

[0022] A business traffic auditing method includes: S1. Data collection steps: Collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources and device configuration sources in the business system to form a multi-dimensional data set; The basic data sources typically refer to fundamental information such as IP addresses, associated users, business types (e.g., IDC, ISP), and allocated data centers collected from the business configuration management database or central control unit. The registration information sources refer to IP address registration status, registration number, and update time collected from the Ministry of Industry and Information Technology's registration system or internal registration database. Network traffic sources refer to real-time network traffic logs collected through network probes or traffic analysis systems, including source IP, destination IP, traffic volume, and timestamps, used to determine IP activity. Device configuration sources refer to actual effective configuration entries collected from network devices (e.g., routers, switches) or network controllers, such as access control lists or routing policies (i.e., INOUT tables), used to confirm whether traffic redirection configurations have been loaded. These data sources are physically and logically independent, collected and integrated through data interfaces to form a unified, analytically correlated data view.

[0023] S2. Linked audit steps: Perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of the business IP in the entire lifecycle from data entry, filing and registration to traffic traction and table entry loading; This step is crucial for discovering potential anomalies. This invention is not a simple equality comparison, but rather a multi-faceted and multi-dimensional data collision based on business logic. For example, by using left outer joins or set difference operations, it can quickly find records that "exist in set A but not in set B," thereby pinpointing the anomaly target.

[0024] Specifically, the data from the basic data source, the filing information source, the network traffic source, and the device configuration source are compared and contrasted to cover various abnormal scenarios in the entire business chain. Specifically, by comparing data from basic data sources and network traffic sources, business IPs that have generated traffic but have not been entered are identified; by comparing data from basic data sources and filing information sources, business IPs that have been entered but not filed are identified; by comparing data from network traffic sources and filing information sources, business IPs that have generated traffic but have not filed are identified; and by comparing data from device configuration sources and filing information sources, business IPs that have loaded table entries but have not filed are identified.

[0025] S3. Intelligent verification steps: For the identified potential anomalies, a two-layer verification mechanism combining initial screening and fine judgment is used for confirmation. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. Active probing refers to the auditing system proactively sending network probe packets to the target IP, such as ICMP Ping packets, TCP SYN packets (e.g., initiating a connection to port 80), or HTTP / HTTPS-based GET requests. Traffic mirroring collaboration refers to the system instructing traffic acquisition devices on the target data center side to mirror traffic destined for that IP in order to verify whether the probe packets have actually been redirected to the target data center, and monitoring whether the mirrored port returns response packets. This effectively distinguishes between an IP that is physically unreachable and one that simply lacks service traffic.

[0026] Specifically, based on business rules, the set of business IPs that are expected to complete traffic redirection configuration and the set of business IPs that have actually completed traffic redirection behavior are respectively aggregated from the multi-dimensional data set; By calculating the differences between two sets, a list of IPs with a high probability of being involved in abnormal traffic redirection can be quickly generated.

[0027] According to IDC / ISP business management standards, a business IP must meet two basic conditions to be "expectedly" configured for traffic redirection: (1) The IP has been recorded in the basic data table, indicating that it has been allocated and is planned to be put into use.

[0028] (2) The IP address has been recorded in the filing information table and its status is "filed", indicating that it has met the compliance requirements.

[0029] Therefore, the result of the inner join between the basic data table and the filing information table is considered. Only IPs that simultaneously meet both of the above conditions are considered legitimate, compliant, and should be providing services normally. They belong to the set of business IPs that have completed the traffic redirection configuration.

[0030] To determine whether an IP address has "completed redirection behavior," two actual conditions must be met simultaneously: (1) That is, the traffic redirection policy (such as routing, ACL policy) of the IP has been successfully issued and loaded onto the network device, and there is a corresponding entry in the INOUT table.

[0031] (2) That is, the network traffic collection system has indeed captured the traffic of the IP. This is the most direct evidence of successful traffic redirection.

[0032] Therefore, an IP that meets both of these conditions indicates that its traffic redirection channel is open and is carrying business, and it belongs to the set of business IPs that have completed traffic redirection.

[0033] By identifying the IPs that are in the "set of business IPs configured for traffic redirection" but not in the "set of business IPs that have actually completed traffic redirection behavior", we can obtain the abnormal traffic redirection IPs.

[0034] Among them, protocol-level interactive verification methods include: Initiate liveness detection requests following standard network protocols to the IP addresses in the list of highly suspected abnormal traffic sources; The instruction is deployed to synchronously monitor mirrored traffic directed to the IP address; If no response traffic is detected for the activation request, it is determined to be a genuine traffic redirection anomaly; if response traffic is detected but the service type of the IP does not match the preset service policy of the data center, it is determined to be an IP address misrecording anomaly.

[0035] For example: Take an IP address 192.168.1.100 from the high-suspect list and send a TCP SYN packet (target port 443) to it via the public network. The system also notifies the EU (data collection unit) in the data center where 192.168.1.100 is located: "Please monitor the mirrored traffic sent to TCP port 443 of 192.168.1.100, especially whether there are SYN-ACK response packets."

[0036] Result determination: Scenario 1 (Genuine Traffic Redirection Anomaly): The EU report did not detect any SYN-ACK response packets from 192.168.1.100 within the specified time. This indicates that the probe packets failed to reach the target server or the server did not respond, confirming an abnormal traffic redirection configuration.

[0037] Scenario 2 (IP Incorrect Entry Anomaly): The EU detects a SYN-ACK response packet, but according to the business policy matrix, this IP is registered for IDC services but has been assigned to an ISP data center. Since ISP data centers are not allowed to handle IDC traffic, theoretically there should be no response. In this case, the system determines it as an "IP incorrect entry anomaly," meaning the IP has been entered into the wrong data center.

[0038] S4. Precise Positioning Steps: Based on the lineage relationships between data table items and the preset business strategy matrix, root cause analysis is performed on confirmed anomalies to automatically locate the specific link and type of the anomaly.

[0039] This includes establishing a lineage relationship between data table entries and performing root cause analysis on confirmed anomalies, which includes: Mapping of generation dependencies between basic data table entries and derived device configuration table entries; When a missing or incorrect entry in the configuration table of a derived device is identified, the generation dependency mapping can be traced to directly determine whether the problem is an abnormality in the distribution of basic data or an abnormality in the loading of derived entries, without the need to check upstream and downstream links step by step.

[0040] The lineage relationship between data table entries refers to the generation dependency between basic data table entries and device configuration table entries. For example, the "basic data table" issued by the central control unit is the source, and the edge device unit will generate the "INOUT table" that is finally loaded on the device based on this table. If this conversion logic is known, when a missing IP is found in the INOUT table, it can be directly inferred that the problem lies in "issue failure" or "loading failure" without having to log into the two systems to check separately.

[0041] Root cause analysis based on the business strategy matrix includes: The business strategy matrix defines the legal mapping relationship between IPs of different business types and data center attributes; In the intelligent verification step, when a service IP does not respond to the probe in a specific data center, its service type is matched with the service policy matrix. If the match fails, it is automatically determined to be an IP address misrecording anomaly.

[0042] The business strategy matrix is ​​a predefined rule base that defines business constraints in matrix form. For example, one dimension of the matrix is ​​"business type" (IDC business, ISP leased line business), and the other dimension is "data center attribute" (IDC data center, ISP data center). A rule could be: IDC business IPs can only be routed to IDC data centers; ISP leased line business IPs can only be routed to ISP data centers. Any IP-data center allocation that does not conform to this matrix is ​​considered an "incorrect allocation".

[0043] To adapt to multi-tenant scenarios, the present invention also includes: Create logically isolated audit strategy instances and data analysis views for different business tenants; Based on the aforementioned business strategy matrix, a legal mapping relationship between the business IP and data center resources is defined for each tenant. During the joint audit and precise location steps, the system distinguishes data ownership and compliance policies based on tenant identifiers and generates independent audit reports at the tenant level.

[0044] like Figure 2 As shown, the present invention also provides a business traffic auditing system, comprising: Data acquisition module 10 is used to collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources and device configuration sources in the business system to form a multi-dimensional data set; The linkage audit module 20 is used to perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of the business IP in the entire lifecycle from data entry, filing and registration to traffic traction and table entry loading; The intelligent verification module 30 is used to confirm the identified potential anomalies using a two-layer verification mechanism that combines initial screening and fine judgment. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. The precise positioning module 40 is used to perform root cause analysis on confirmed anomalies based on the lineage relationship between data table items and the preset business strategy matrix, and automatically locate the specific link and type of the anomaly.

[0045] In one embodiment, such as Figure 3 As shown, a computer device 50 is provided, including a memory 52, a processor 51, and a computer program 53 stored in the memory 52 and executable on the processor 51. When the processor 51 executes the computer program 53, it implements the steps in the data processing method of the above embodiments. To avoid repetition, these steps will not be repeated here. Alternatively, when the processor 51 executes the computer program 53, it implements the functions of each module in the above-described business traffic audit system embodiments. To avoid repetition, these steps will not be repeated here.

[0046] In one embodiment, a readable storage medium is provided, which stores a computer program 53. When the computer program 53 is executed by the processor 51, it implements the steps in the data processing method of the above embodiments. To avoid repetition, these steps will not be repeated here. Alternatively, when the processor 51 executes the computer program 53, it implements the functions of each module in the above data processing device embodiments. To avoid repetition, these functions will not be repeated here.

[0047] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAM bus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0048] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional modules, sub-modules, and units as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method of traffic flow auditing, the method comprising: include: Data collection steps: Collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources, and device configuration sources in the business system to form a multi-dimensional data set; Joint audit steps: Perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of business IPs throughout the entire lifecycle from data entry and filing to traffic traction and table entry loading; Intelligent verification steps: For identified potential anomalies, a two-layer verification mechanism combining initial screening and fine judgment is used for confirmation. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. Precise location steps: Based on the lineage relationship between data table items and the preset business strategy matrix, root cause analysis is performed on confirmed anomalies to automatically locate the specific link and type of the anomaly. The intelligent verification step specifically includes: According to the business rules, the set of business IPs that are expected to complete the traffic redirection configuration and the set of business IPs that have actually completed the traffic redirection behavior are respectively aggregated from the multi-dimensional data set; By calculating the difference between the two sets, a list of IPs with high suspicion of abnormal traffic redirection can be quickly generated; Initiate liveness detection requests following standard network protocols to the IP addresses in the list of highly suspected abnormal traffic sources; The instruction is deployed to synchronously monitor mirrored traffic directed to the IP address; If no response traffic is detected for the activation request, it is determined to be a genuine traffic redirection anomaly; if response traffic is detected but the service type of the IP does not match the preset service policy of the data center, it is determined to be an IP address misrecording anomaly.

2. The traffic flow auditing method of claim 1, wherein, The process of performing correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies in the entire lifecycle of the business IP, from data entry and filing to traffic generation and table entry loading, includes: The data from the basic data source, the filing information source, the network traffic source, and the device configuration source are compared and contrasted to cover various abnormal scenarios in the entire business chain. Specifically, by comparing data from basic data sources and network traffic sources, business IPs that have generated traffic but have not been entered are identified; by comparing data from basic data sources and filing information sources, business IPs that have been entered but not filed are identified; by comparing data from network traffic sources and filing information sources, business IPs that have generated traffic but have not filed are identified; and by comparing data from device configuration sources and filing information sources, business IPs that have loaded table entries but have not filed are identified.

3. The method of claim 1, wherein, The root cause analysis of confirmed anomalies based on the lineage relationships between data table entries includes: Establish a mapping of generation dependencies between basic data table entries and derived device configuration table entries; When a missing or incorrect entry in the configuration table of a derived device is identified, the generation dependency mapping can be traced to directly determine whether the problem is an abnormality in the distribution of basic data or an abnormality in the loading of derived entries, without the need to check upstream and downstream links step by step.

4. The traffic flow auditing method of claim 1, wherein, The root cause analysis of confirmed anomalies based on the business strategy matrix includes: The business strategy matrix defines the legal mapping relationship between IPs of different business types and data center attributes; In the intelligent verification step, when a service IP does not respond to the probe in a specific data center, its service type is matched with the service policy matrix. If the match fails, it is automatically determined to be an IP address misrecording anomaly.

5. The method of business traffic auditing of claim 1, wherein, The method further includes: Create logically isolated audit strategy instances and data analysis views for different business tenants; Based on the aforementioned business strategy matrix, a legal mapping relationship between each tenant's business IP and data center resources is defined. During the joint audit and precise location steps, the system distinguishes data ownership and compliance policies based on tenant identifiers and generates independent audit reports at the tenant level.

6. A business traffic auditing system, comprising: The data acquisition module is used to collect and dynamically update data from independent basic data sources, filing information sources, network traffic sources, and device configuration sources in the business system, forming a multi-dimensional data set; The linkage audit module is used to perform correlation comparison and collision analysis on the multi-dimensional data set to identify potential anomalies of business IPs throughout the entire lifecycle from data entry and filing to traffic traction and table entry loading. The intelligent verification module is used to confirm the identified potential anomalies using a two-layer verification mechanism that combines initial screening and fine judgment. The fine judgment adopts a protocol-level interactive verification method based on active detection and traffic mirroring collaboration. Specifically, this includes: according to business rules, aggregating the set of business IPs that are expected to complete traffic redirection configuration from the multi-dimensional data set, and the set of business IPs that have actually completed traffic redirection behavior; By calculating the difference between the two sets, a list of IPs with high suspicion of abnormal traffic redirection can be quickly generated; Initiate liveness detection requests following standard network protocols to the IP addresses in the list of highly suspected abnormal traffic sources; The instruction is deployed to synchronously monitor mirrored traffic directed to the IP address; If no response traffic is detected for the activity probe request, it is determined to be a genuine traffic redirection anomaly; if response traffic is detected but the service type of the IP does not match the preset service policy of the data center, it is determined to be an IP address misrecording anomaly. The precise location module is used to perform root cause analysis on confirmed anomalies based on the lineage relationships between data table items and a preset business strategy matrix, automatically locating the specific link and type of the anomaly.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the business traffic auditing method as described in any one of claims 1-5.

8. A computer-readable storage medium storing a computer program, the computer-readable storage medium comprising: When the computer program is executed by the processor, it implements the business traffic auditing method as described in any one of claims 1-5.