Mirror image traffic processing method and device, equipment and storage medium

By introducing a mirroring scheme generation model trained with reinforcement learning algorithms into the SDN network, the mirroring traffic configuration is dynamically adjusted, which solves the shortcomings of the static configuration scheme, achieves multi-dimensional optimization, improves network performance and stability, and avoids mirroring node overload.

CN121750587APending Publication Date: 2026-03-27CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-03
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

The static mirroring traffic configuration scheme in existing SDN networks lacks dynamic adaptability and multi-dimensional optimization capabilities, which leads to mirror nodes becoming overloaded and crashing during sudden DDoS attacks, and RTT fluctuations affecting traffic scheduling efficiency in cross-border transmission scenarios.

Method used

A reinforcement learning algorithm is introduced to train the mirroring scheme generation model. The mirroring traffic configuration scheme is dynamically generated and adjusted according to the real-time network status. Multi-dimensional optimization is achieved through the collaborative work of the SDN controller and network switch.

Benefits of technology

Improve network performance and resource utilization, ensure data integrity and transmission efficiency, enhance network adaptability and stability, avoid mirror node overload, and ensure normal network operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121750587A_ABST
    Figure CN121750587A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a mirror image traffic processing method and device, equipment and a storage medium. The method comprises the following steps: acquiring network state information; inputting the network state information into a pre-trained mirror image scheme generation model to obtain a target mirror image traffic configuration scheme output by the mirror image scheme generation model, the target mirror image traffic configuration scheme being a configuration scheme for controlling acquisition, transmission and processing processes of mirror image traffic; and according to the target mirror image traffic configuration scheme, controlling a network switch to collect preset original service traffic to obtain mirror image traffic, and controlling the network switch to transmit the mirror image traffic to a mirror image node, so that the mirror image node processes the mirror image traffic. According to the embodiment of the invention, the mirror image configuration scheme is dynamically generated and adjusted according to the real-time network state, and the mirror image flow is comprehensively optimized in multiple dimensions, so that the network performance and the resource utilization rate can be effectively improved, and the data integrity and the transmission efficiency are ensured, thereby enhancing the self-adaptive capability and stability of the network and ensuring the normal operation of the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network technology, and in particular to a method and apparatus for processing mirrored traffic, an electronic device, and a storage medium. Background Technology

[0002] Currently, SDN (Software-Defined Networking) networks generally adopt static mirroring traffic configuration schemes. These schemes have the following main drawbacks: First, they lack dynamic adaptability. In scenarios involving sudden DDoS (Distributed Denial of Service) attacks, when the attack traffic far exceeds the processing capacity of the mirror node, existing mechanisms cannot automatically adjust the mirroring ratio of the original service traffic, leading to mirror node overload and downtime. Second, multi-dimensional optimization metrics are unbalanced. Existing methods use linear weighted algorithms for mirroring traffic configuration, which, in cross-border transmission scenarios, can cause excessively long algorithm convergence times due to RTT (Round-Trip Time) fluctuations, affecting traffic scheduling efficiency. Summary of the Invention

[0003] This application provides a method for processing mirrored traffic to solve the technical problems that the static mirrored traffic configuration scheme of the current SDN network cannot be dynamically adjusted and cannot achieve multi-dimensional comprehensive optimization.

[0004] Accordingly, embodiments of this application also provide a mirror traffic processing device, an electronic device, and a storage medium to ensure the implementation and application of the above method.

[0005] To address the aforementioned issues, this application discloses a method for processing mirrored traffic, applied to a software-defined network controller (SDB). The SDB is communicatively connected to a network switch, and the network switch is communicatively connected to a mirror node. The method includes: Obtain network status information; The network state information is input into a pre-trained mirroring scheme generation model to obtain the target mirroring traffic configuration scheme output by the mirroring scheme generation model. The target mirroring traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirroring traffic. According to the target mirrored traffic configuration scheme, the network switch is controlled to collect the preset original service traffic to obtain the mirrored traffic, and the network switch is controlled to transmit the mirrored traffic to the mirror node so that the mirror node can process the mirrored traffic.

[0006] This application also discloses a mirrored traffic processing device applied to a software-defined network controller, wherein the software-defined network controller is communicatively connected to a network switch, and the network switch is communicatively connected to a mirror node. The device includes: The status determination module is used to obtain network status information; The scheme generation module is used to input the network status information into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model. The target mirror traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirror traffic. The scheme execution module is used to control the network switch to collect preset original service traffic to obtain the mirrored traffic according to the target mirrored traffic configuration scheme, and to control the network switch to transmit the mirrored traffic to the mirror node so that the mirror node can process the mirrored traffic.

[0007] This application also discloses an electronic device, including: a processor; and a memory storing executable code thereon, which, when executed, causes the processor to perform one or more of the mirrored traffic processing methods described in this application.

[0008] This application also discloses a machine-readable medium storing executable code thereon, which, when executed, causes a processor to perform one or more of the mirror traffic processing methods described in this application.

[0009] Compared with the prior art, the embodiments of this application have the following advantages: In this embodiment, network status information is acquired; the network status information is input into a pre-trained mirroring scheme generation model to obtain a target mirroring traffic configuration scheme output by the mirroring scheme generation model. The target mirroring traffic configuration scheme is a configuration scheme that controls the collection, transmission, and processing of mirroring traffic. According to the target mirroring traffic configuration scheme, the network switch is controlled to collect preset original service traffic to obtain mirroring traffic, and the network switch is controlled to transmit the mirroring traffic to the mirroring node so that the mirroring node can process the mirroring traffic. This embodiment, by introducing a mirroring scheme generation model, comprehensively considers multi-dimensional network status information when generating the target mirroring traffic configuration scheme, realizing the dynamic generation and adjustment of the mirroring configuration scheme based on the real-time network status, and performing multi-dimensional comprehensive optimization of the mirroring traffic. This can effectively improve network performance and resource utilization, ensure data integrity and transmission efficiency, and solve the technical problems of static configuration, inability to dynamically adapt and adjust, and lack of multi-dimensional comprehensive optimization capabilities in the prior art. This enhances the network's adaptability and stability, avoids mirroring node overload, and ensures normal network operation. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating the relevant technical process of an embodiment of a method for processing mirrored traffic according to this application. Figure 2 This is a flowchart illustrating the open-loop control of a method for processing mirrored traffic according to this application. Figure 3 This is a flowchart illustrating the steps of an embodiment of a method for processing mirrored traffic according to this application; Figure 4 This is a dynamic optimization flowchart of an embodiment of the mirror traffic processing method of this application; Figure 5 This is a flowchart illustrating the dynamic optimization process supporting multi-protocol label switching, according to an embodiment of the mirror traffic processing method of this application. Figure 6 This is a structural block diagram of an embodiment of a mirror traffic processing device according to this application; Figure 7 This is a schematic diagram of the structure of a device provided in an embodiment of this application. Detailed Implementation

[0011] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0012] Reference Figure 1 This is a flowchart illustrating the technical process of one embodiment of a mirror traffic processing method according to this application.

[0013] Figure 1 The static mirroring traffic configuration scheme, which is commonly used in current SDN networks, follows the following process: (1) Based on historical traffic patterns, network administrators predefine mirroring rules (i.e., static mirrored traffic configuration schemes) on Open vSwitch switches (an open-source virtual switch). Mirroring rules refer to configuration instructions that define traffic mirroring policies in SDN networks, including source port, destination port, traffic filtering conditions, etc.

[0014] (2) The sFlow sampler collects network traffic characteristics of the target port of the switch at a fixed frequency (usually 500 times per second) and stores them in the traffic characteristic database; the Prometheus monitoring system (an open source monitoring system) periodically collects the resource indicators of the network devices (default 5-second interval) and stores them in the resource indicator database.

[0015] (3) Mirroring rules are updated only in the following two scenarios: ① Manual adjustment (new rules are issued through the OVSDB interface (OpenvSwitch Database Management Protocol)); ② Sudden changes in traffic patterns or exceeding resource thresholds (e.g., shutting down some mirrored ports when CPU (Central Processing Unit) utilization is >70%). The updated mirroring rules are fed back to the Open vSwitch switch.

[0016] For example, a certain operator's data center uses a static mirroring traffic configuration scheme, which continuously mirrors 80% of the original business traffic to the security audit node (i.e., the mirror node), causing the security audit node to experience continuous overload alarms during peak business periods.

[0017] Existing technical solutions face three main challenges when dealing with complex network environments: First, static mirroring traffic configuration schemes lack dynamic adaptability. In the event of a sudden DDoS attack, if the attack traffic reaches 300% of the mirror node's processing capacity, the existing system cannot automatically reduce the mirroring traffic ratio, ultimately causing the mirror node to crash due to overload. Second, multi-dimensional optimization metrics are unbalanced. The currently used linear weighted algorithm has excessively long convergence times, sometimes exceeding 15 minutes, in scenarios with drastic RTT fluctuations, such as cross-border transmissions. Furthermore, anomaly handling mechanisms are lacking. When a mirror node fails, the system relies on manual intervention to switch to a backup node, a process that results in a 12% to 15% loss of service traffic, severely impacting service continuity.

[0018] The fundamental reason for the aforementioned defects in existing technologies lies in their use of an open-loop control architecture, such as... Figure 2 The diagram shown is an open-loop control flowchart related to an embodiment of the mirror traffic processing method of this application. This open-loop control architecture follows the process of "rule presetting, traffic sampling, threshold judgment, and mirror execution", and has two key defects: (1) the decision loop lacks a feedback mechanism and cannot dynamically adjust the static mirror traffic configuration scheme according to the execution effect; (2) the rule generation algorithm is decoupled from the network state and no correlation model between traffic characteristics and resource load is established.

[0019] To address the aforementioned problems in the existing technology, some embodiments of this application introduce reinforcement learning algorithms to train a mirror scheme generation model, thereby enabling dynamic generation and adjustment of the target mirror traffic configuration scheme based on real-time network conditions, thus improving network performance and resource utilization.

[0020] Reference Figure 3 This is a flowchart illustrating the steps of an embodiment of a mirrored traffic processing method according to this application, including the following steps: Step 301: Obtain network status information.

[0021] This application's embodiments can be applied to SDN-based network environments, involving network devices including SDN controllers, mirror nodes, and network switches. The mirror traffic processing method shown in this application embodiment is specifically applied to a software-defined network controller (SDN controller). The SDN controller communicates with network switches and mirror nodes through network interfaces, and the network switches and mirror nodes communicate through the mirror ports of the network switches. In one embodiment, the SDN controller manages network devices and mirror traffic configuration schemes, mirror nodes receive and process mirror traffic, and network switches generate and forward mirror traffic. The network switch can be an Open vSwitch switch.

[0022] In one embodiment of this application, the software architecture may specifically include an operating system (such as Ubuntu), network virtualization software (such as Open vSwitch), a monitoring system (such as Prometheus, Grafana), and a reinforcement learning framework (such as Python, TensorFlow, stablebaselines3). In this embodiment, a hardware environment with at least three servers needs to be built, one as an SDN controller and two as image nodes. An Ubuntu 22.04 LTS operating system is installed on these hardware devices, and a software stack including Open vSwitch 3.2.0, Python 3.8 + TensorFlow 2.12, etc., is configured. Kubernetes 1.29 is optionally installed for containerized management.

[0023] In one embodiment of this application, port monitoring can be enabled on an Open vSwitch switch, and an initial mirroring scheme can be configured using the following command, where eth1 is specified as the mirror port of the network switch: # Configure OVS (Open vSwitch) image (limited image source) ovs-vsctl --add-br br0 \ -- add-port br0 eth0 \ -- add-port br0 eth1 \ -- --id=@m create Mirror name=mirror0 select_all=true output_port=eth1 \ -- set Bridge br0 mirrors=@m In step 301, network status information is obtained. This network status information may include data such as network device load data, network traffic mirroring requirements, and traffic characteristic data of the target ports of network switches.

[0024] Step 302: Input the network status information into the pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model. The target mirror traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirror traffic.

[0025] In step 302, the mirroring scheme generation model can be a Q-learning model trained using reinforcement learning. This model can be deployed on mirror nodes or on a standalone server. The mirroring scheme generation model generates a target mirror traffic configuration scheme based on the current network state information. This target mirror traffic configuration scheme controls the collection, transmission, and processing of mirror traffic. Specifically, it defines the traffic matching conditions and forwarding actions to dynamically adjust the mirroring paths and load distribution of network traffic.

[0026] The target mirroring traffic configuration scheme generated by the mirroring scheme generation model is sent to the SDN controller, which then controls the execution of the target mirroring traffic configuration scheme. Furthermore, the SDN controller can send the target mirroring traffic configuration scheme to network switches or routers.

[0027] Step 303: According to the target mirror traffic configuration scheme, control the network switch to collect the preset original service traffic to obtain the mirror traffic, and control the network switch to transmit the mirror traffic to the mirror node so that the mirror node can process the mirror traffic.

[0028] In step 303, the SDN controller, based on the target mirroring traffic configuration scheme, controls the network switch to collect preset raw service traffic to obtain mirrored traffic, and controls the network switch to transmit the mirrored traffic to the mirroring node through the mirroring port, so that the mirroring node can process the mirrored traffic. In one embodiment, when executing the target mirroring traffic configuration scheme, network status information can be continuously collected, and the target mirroring traffic configuration scheme can be dynamically adjusted based on the network status information through the mirroring scheme generation model.

[0029] This application's embodiments introduce a mirroring scheme generation model. When generating a target mirroring traffic configuration scheme, it comprehensively considers multi-dimensional network status information, enabling dynamic generation and adjustment of the mirroring configuration scheme based on real-time network status. It also performs multi-dimensional comprehensive optimization of mirroring traffic, effectively improving network performance and resource utilization, ensuring data integrity and transmission efficiency. This solves the technical problems of static configuration, inability to dynamically adapt and adjust, and lack of multi-dimensional comprehensive optimization capabilities in existing mirroring traffic configuration schemes, thereby enhancing the network's adaptability and stability, avoiding mirror node overload, and ensuring normal network operation.

[0030] Optionally, a sampling tool is deployed on the network switch, and the network switch has a target port. Step 301 includes: The sampling tool is controlled to sample the port traffic of the target port of the network switch to obtain traffic characteristic data; The bandwidth utilization of the target port of the network switch is determined based on the traffic characteristic data. Obtain device load data; The traffic characteristic data, the bandwidth utilization rate, and the device load data are used as the network status information.

[0031] In this embodiment of the application, sampling tools (such as sFlow tools) can be deployed on network switches to obtain traffic characteristic data, thereby obtaining network status information.

[0032] Specifically, the sampling tool is controlled to sample the port traffic of the target port of the network switch to obtain traffic feature data. In one embodiment, the sFlow tool can be configured to perform sampling operations based on the port traffic of the target port eth0 of the network switch, sampling at a frequency of 1000 times per second. The collected traffic feature data is sent to the target address 10.0.0.1:6343 for further processing, and then output to the traffic log file. The obtained traffic feature data is real-time network traffic sampling data on the network switch, including traffic characteristics (such as traffic size, traffic direction, etc.), which will be used for subsequent network performance analysis and decision-making. The corresponding sFlow tool configuration commands are as follows: # Configure OVS sFlow proxy ovs-vsctl -- --id=@sflow create sflow agent=eth0 target=\"10.0.0.1:6343\" \ sampling=1000 header=128 polling=10 -- set bridge br0 sflow=@sflow # Start sflowtool with log management nohup sflowtool -p 6343 -L size=100M -t maxage=7d> / var / log / sflow / traffic.log 2>&1& Based on traffic characteristic data, the bandwidth utilization of the target port of the network switch can be determined, and the device load data of the target device can also be obtained. Thus, traffic characteristic data, bandwidth utilization, and device load data can be used as network status information.

[0033] This application embodiment acquires network status information such as traffic characteristic data, bandwidth utilization, and device load data, which is then input into the mirror scheme generation model to generate the target mirror traffic configuration scheme, thereby realizing the dynamic generation and adjustment of the mirror configuration scheme based on the real-time network status.

[0034] Optionally, determining the bandwidth utilization of the target port of the network switch based on the traffic characteristic data includes: The current traffic and maximum bandwidth of the target port are determined from the traffic characteristic data. The bandwidth utilization of the target port of the network switch is obtained by calculating the ratio of the current traffic to the maximum bandwidth of the port.

[0035] This application embodiment can calculate the bandwidth utilization of the target port based on the traffic log file corresponding to the traffic characteristic data. According to the traffic log file, by reading the byte count data in the traffic log file, the total number of bytes is calculated and the bandwidth utilization per unit time is obtained. The bandwidth utilization is used to determine the network bandwidth usage and to provide input for the mirroring scheme generation model to optimize the transmission efficiency of traffic mirroring.

[0036] Specifically, the traffic log file is parsed to determine the current traffic and maximum bandwidth (in Gbps) of the target port from the traffic characteristic data. A Python script is then used to calculate the ratio of the current traffic to the maximum bandwidth to obtain the bandwidth utilization of the target port on the network switch. The implementation code is as follows: with open('traffic.log') as f: bytes_list = [int(line.split()[0]) for line in f] # Need to confirm log column index total_bytes = sum(bytes_list) # Calculate average bandwidth utilization (per unit time) avg_bytes_per_sec = total_bytes / time_window bandwidth_util = (avg_bytes_per_sec * 8) / (max_bandwidth * 1e9) *100 # Percentage This application's embodiments calculate the ratio of current traffic to the maximum bandwidth of the port to obtain the bandwidth utilization rate of the target port of the network switch. This is then used to input the target mirror traffic configuration scheme into the mirror scheme generation model, thereby realizing the dynamic generation and adjustment of the mirror configuration scheme based on the real-time network status.

[0037] Optionally, obtaining device load data includes: The system controls a pre-defined monitoring system to collect processor and memory data from the software-defined network controller and the mirror node. The processor data and the memory data are used as the device load data.

[0038] In this embodiment of the application, the Prometheus system can be deployed on a standalone server as a pre-set monitoring system to collect processor data and memory data of the software-defined network controller and mirror nodes, and use the processor data and memory data as device load data.

[0039] Specifically, resource collection is performed based on the IP (Internet Protocol) addresses of the mirror nodes and the SDN controller. Prometheus periodically (e.g., every 15 seconds) captures CPU (processor data) and memory data from the mirror nodes and the SDN controller. This CPU and memory data reflects the device's CPU and memory usage, and is used to determine device load, helping the image configuration model generate and adjust the target image configuration. The content of the prometheus.yml configuration file can be as follows: scrape_configs: - job_name: "node_exporter" scrape_interval: 15s static_configs: - targets: ["10.0.0.2:9100", "10.0.0.3:9100"] This application embodiment collects processor and memory data of the software-defined network controller and mirror nodes through a preset monitoring system. This data is then input into the mirror scheme generation model to generate the target mirror traffic configuration scheme, thereby enabling the dynamic generation and adjustment of the mirror configuration scheme based on the real-time network status.

[0040] Optionally, the method includes: A load heatmap is generated based on the processor and memory data of the software-defined network controller and the mirror node; The load heat map is shown.

[0041] In this embodiment, Grafana (an open-source visualization tool) can be deployed on a separate server or in an environment compatible with the Prometheus system. Grafana then generates and displays a load heatmap based on the processor and memory data of the software-defined network controller and mirror nodes. In one example, the accuracy of the load heatmap can be set to ±2%. In one example, the code for generating a load heatmap using Grafana can be represented as follows: (1 - sum(rate(node_cpu_seconds_total{mode="idle"}[5m])) by (instance) / sum(rate(node_cpu_seconds_total[5m])) by (instance)) * 100 This application embodiment can generate and display a load heatmap based on the processor and memory data of the software-defined network controller and mirror nodes. Users can understand the current processor and memory load usage of the network controller and mirror nodes based on the load heatmap.

[0042] Optionally, the training process of the mirror scheme generation model includes: Configure the model parameters to obtain the mirror scheme generation model to be trained; Obtain training network state information; Based on the training network state information, the mirror scheme generation model to be trained is trained using reinforcement learning methods to obtain the trained mirror scheme generation model.

[0043] This application embodiment can train a mirror scheme generation model to be trained using reinforcement learning methods based on the training network state information, thereby obtaining a trained mirror scheme generation model. In one embodiment, the training network state information can be real-time network state information, thus enabling real-time updating and optimization of the mirror scheme generation model while using it.

[0044] Specifically, training network state information can include current network state information, which is used to represent the network load and network traffic mirroring requirements. In one example, training network state information may include: current_bandwidth_util (current bandwidth utilization), packets (mirrored network packet information, including the CRC check result of each packet, etc.), current_delay (current delay, measuring the data transmission delay in the network), and baseline_delay (set baseline delay, usually the ideal delay value in the network).

[0045] Configure the model parameters to obtain the mirror image scheme model to be trained. Specifically, in one example, you can first install the dependent libraries using the following command, where gym is used to create a simulation environment for reinforcement learning training; stable-baselines3 provides implementations of reinforcement learning algorithms to help train and optimize the model: pip install gym==0.21.0 stable-baselines3==1.8.0 In one example, configuring the model parameters of the Q-learning model as a mirror image scheme to be trained to generate the model can be represented by the following code: # Add necessary parameters when creating the model model = DQN( policy="MlpPolicy", env=env, learning_rate=0.001, buffer_size=10000, exploration_initial_eps=1.0, exploration_final_eps=0.05, exploration_fraction=0.1, verbose=1 ) model.learn(total_timesteps=100000, callback=ProgressBarCallback()) Based on the training network state information, a reinforcement learning method is used to train the mirror scheme generation model to be trained, resulting in a trained mirror scheme generation model. In one example, the reinforcement learning method can be the DQN (Deep Q-Network, a Q-learning algorithm combined with deep learning), which trains the model to learn how to optimize the routing and mirror configuration schemes of mirror traffic based on network load and bandwidth utilization.

[0046] Specifically, the mirroring scheme generation model under training selects appropriate actions based on the network state information. These actions may involve adjusting mirrored traffic, changing traffic forwarding rules, etc. The model learns how to optimize mirroring configuration schemes by interacting with the environment. The model's output is a decision based on the current network state (e.g., choosing to adjust certain traffic mirroring rules, changing the bandwidth usage of mirrored traffic, etc.). This output is transformed into specific OpenFlow rules and applied as the target mirroring configuration scheme in the SDN network. The trained mirroring scheme generation model can output the optimal target mirroring configuration scheme based on real-time network state information to optimize network performance and resource utilization.

[0047] This application embodiment trains a mirror scheme generation model using reinforcement learning to obtain a trained mirror scheme generation model. This model is used to dynamically generate and adjust mirror configuration schemes based on real-time network conditions and to perform multi-dimensional comprehensive optimization of mirror traffic. This effectively improves network performance and resource utilization, ensures data integrity and transmission efficiency, thereby enhancing the network's adaptability and stability, avoiding mirror node overload, and ensuring normal network operation.

[0048] Optionally, training the mirror scheme generation model to be trained using reinforcement learning methods based on the training network state information includes: The training network state information is input into the mirror scheme generation model to be trained to obtain the training mirror traffic configuration scheme output by the mirror scheme generation model to be trained. Determine the current network status information after executing the training mirror traffic configuration scheme; Based on the training mirror traffic configuration scheme and the current network status information, the training reward is calculated using a preset reward function; The mirror scheme generation model to be trained is updated based on the training reward.

[0049] This application embodiment allows setting a reward function during model training. In each interaction during training, the model calculates the reward value for the current action based on the reward function, and then updates the model's policy according to this reward value, enabling the model to make more advantageous decisions in the future. The purpose of this reward function is to provide the model with an evaluation criterion, helping the model make optimal decisions based on current network conditions when dynamically adjusting mirroring configuration schemes. The effectiveness of each action is evaluated by comprehensively considering three dimensions: bandwidth utilization, data integrity, and latency.

[0050] Specifically, the training network state information is input into the mirroring scheme generation model to be trained, resulting in the training mirroring traffic configuration scheme output by the model. The current network state information after implementing the training mirroring traffic configuration scheme is determined. Based on the training mirroring traffic configuration scheme and the current network state information, a pre-defined reward function is used to calculate the training reward. During each model training iteration, the reward function calculates the training reward based on the model's output training mirroring traffic configuration scheme and the current network state information fed back by the environment. The model updates its mirroring configuration scheme based on this training reward, enabling future decisions to improve network performance and optimize bandwidth usage, latency, and data integrity. For example, during training, the model may select the most suitable mirroring configuration scheme based on network state information and the feedback from the reward function, such as choosing different target ports or adjusting the source IP address according to traffic patterns.

[0051] In one example, the reward function can be implemented using the following code: def calculate_reward(self, current_bandwidth_util, packets, current_delay, baseline_delay): # Normalized bandwidth utilization score bw_score = 0.5 * (1 - current_bandwidth_util / 100) # If util is 0~100% # Data Integrity Check if len(packets) == 0: integrity = 0.0 else: integrity = sum(pkt.get('crc_valid', 0) for pkt in packets) / len(packets) # Delayed penalty (normalized) delay_diff = max(0, current_delay - baseline_delay) max_delay = baseline_delay * 2 delay_penalty = 0.2 * (delay_diff / max_delay) # Normalize to 0~0.2 # Total Rewards total_reward = bw_score + 0.3 * integrity - delay_penalty return np.clip(total_reward, -1.0, 1.0) In this embodiment, a reward function is introduced during the training process of the mirror scheme generation model. The strategy of the mirror scheme generation model is continuously adjusted based on the training reward output by the reward function, so that the mirror scheme generation model learns how to dynamically generate and adjust mirror traffic configuration schemes under different network state information, thereby achieving the goal of optimizing network performance and resource utilization.

[0052] Optionally, the step of inputting the network state information into a pre-trained mirroring scheme generation model to obtain the target mirroring traffic configuration scheme output by the mirroring scheme generation model includes: The network state information is input into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model based on a preset configuration scheme template.

[0053] The target mirror traffic configuration scheme of this application embodiment can be output based on a preset configuration scheme template.

[0054] Real-time data, such as bandwidth utilization and latency, is obtained from network status information. Based on this information, the mirroring scheme generation model dynamically determines the mirroring traffic configuration scheme. Then, based on the configuration scheme template and the output of the mirroring scheme generation model, it executes the target mirroring traffic configuration scheme generation operation, thereby obtaining the target mirroring traffic configuration scheme to define traffic matching conditions and forwarding actions. The generated target mirroring traffic configuration scheme is then distributed to the SDN controller, which in turn applies it to other network devices via the OpenFlow protocol.

[0055] In one example, a configuration template can be generated based on the following code: rule_template = { "priority": 4000, "match": { "dl_type": "0x0800",# IPv4 "nw_proto": 6,# TCP "nw_src": "10.0.0.0 / 24",# Source URL "tp_dst": 80# Target port }, "actions": [ {"type": "OUTPUT", "port":target_node}, {"type": "OUTPUT", "port": "NORMAL"} ], "hard_timeout": 30 } Here, `priority` represents the rule's priority; a larger number indicates a higher priority, meaning the rule will match traffic that meets the criteria first. `match` specifies the matching conditions, defining the conditions that traffic must meet to apply the rule. In this template, traffic type, protocol type, source IP address, and destination port are key fields for matching traffic. `actions` specifies the actions to be performed after the rule is applied, typically forwarding traffic to a specified port. Two actions are defined here: `OUTPUT` forwards traffic to a destination port (the port to which mirrored traffic will be forwarded) and `NORMAL` forwards traffic normally, maintaining the original path. `hard_timeout` is the rule's maximum lifespan; once this time is reached, the rule will be automatically deleted to prevent it from continuously consuming resources.

[0056] In this embodiment, the mirroring scheme generation model is based on the configuration scheme template. The target mirroring traffic configuration scheme is generated according to the output of the mirroring scheme generation model. The target mirroring traffic configuration scheme is obtained to improve network performance and resource utilization, ensure data integrity and transmission efficiency, thereby enhancing the network's adaptability and stability, avoiding mirroring node overload, and ensuring normal network operation.

[0057] Optionally, the method includes: In response to a preset scheme viewing command, the target mirror traffic configuration scheme is displayed.

[0058] This application embodiment can respond to a preset scheme viewing command to display the target mirror traffic configuration scheme, thereby checking whether the target mirror traffic configuration scheme has been correctly issued and is effective. In one example, the scheme viewing command can be the ovs-ofctl command.

[0059] This application embodiment can display the target mirror traffic configuration scheme in response to a preset scheme viewing command. This helps the administrator confirm whether the forwarding rules of mirror traffic have been correctly applied, and check whether the configuration of the target mirror traffic configuration scheme meets expectations.

[0060] Optionally, the network switch has a mirroring port, and the method includes: In response to a preset traffic capture command, the port traffic of the mirrored port is captured; Verify the accuracy of the mirroring traffic replication and transmission process based on the port traffic of the mirrored port.

[0061] This application embodiment can also respond to a preset traffic capture command to capture port traffic of the mirrored port, and analyze the port traffic of the mirrored port to verify the accuracy of the mirroring traffic replication and transmission process, that is, whether the mirrored traffic is accurately replicated and sent to the monitoring or analysis device, ensuring that the traffic is correctly mirrored to the specified port. In one example, the tcpdump tool can be used to capture the port traffic of the mirrored port.

[0062] In one example, the following code can be used to view the distributed target mirror traffic configuration scheme and verify mirror traffic capture: # View all rules matching the target port ovs-ofctl dump-flows br0 | grep "output:${target_node}" # Verify mirror traffic tcpdump -i eth1 -c 100 'tcp port 80' -w mirrored_traffic.pcap The embodiments of this application can respond to a preset traffic capture command, capture port traffic of the mirror port, and verify the accuracy of the mirror traffic copying and transmission process, which helps to confirm whether the system is running according to the target mirror traffic configuration scheme.

[0063] Optionally, the method includes: The target device is determined from the software-defined network controller and the mirror node; Within a preset collection period, determine whether the device load data of the target device is greater than a preset load threshold; If the device load data of the target device is greater than the load threshold within a consecutive preset number of collection cycles, then a circuit breaker operation is performed on the target device.

[0064] In this embodiment, the system continuously monitors the resource usage of network devices such as software-defined network controllers and mirror nodes (e.g., using mirror nodes as target devices), particularly CPU load data in the processor data. Within a preset collection period, it determines whether the device load data of the target device exceeds a preset load threshold. If the device load data of the target device exceeds the preset load threshold within a preset number of consecutive collection periods (e.g., 3 times), a circuit breaker operation is performed on the target device.

[0065] Specifically, the Prometheus system records continuous device CPU load data through the `cpu_load_history` queue. To avoid short-term load fluctuations affecting judgment, the circuit breaker mechanism typically considers multiple historical data points for assessment. When the CPU load data exceeds a set load threshold (e.g., 80%) for three consecutive collection periods, the system determines that the device is overloaded. Once an overload is detected, the circuit breaker mechanism automatically removes the device from the traffic forwarding link, stopping traffic forwarding to it and preventing further overload. The circuit breaker operation is usually logged to notify the administrator that the device has been circuit-broken. When the device load returns to normal, the system can automatically resume traffic forwarding, no longer execute the circuit breaker operation, and restore normal network operation.

[0066] In one example, the device's circuit breaker logic can be implemented using the following code: from collections import deque # Define a state queue in a class or global scope cpu_load_history = deque(maxlen=3) # Update every time a new load is collected cpu_load_history.append(current_cpu_load) # Determine if the threshold is exceeded 3 times consecutively if len(cpu_load_history) == 3 and all(load>0.8 for load in cpu_load_history): if overload_node in target_list: target_list.remove(overload_node) logging.warning(f"Node {node_id} (IP: {overload_node}) has been circuit broken") The core purpose of the circuit breaker operation in this application embodiment is to automatically stop traffic forwarding when a device is overloaded, thereby protecting the device from the effects of continuous high load and preventing the spread of faults. By continuously monitoring the device load and determining whether the circuit breaker condition is triggered, the system can effectively ensure the stability of the overall network and the rational allocation of resources.

[0067] Optionally, the method includes: Detect attack events; If the attack event is detected, the network switch is controlled to transmit the attack traffic corresponding to the attack event to a preset security node.

[0068] This application embodiment can also detect attack events. If an attack event is detected, the system controls the network switch to transmit the attack traffic corresponding to the attack event to a preset security node. Specifically, when a DDoS attack is detected, the system will immediately switch the traffic path automatically through a security event preemption mechanism, forwarding the attack traffic to a security node for processing to avoid affecting normal services. This process achieves automatic traffic redirection and protection through emergency commands issued by the SDN controller.

[0069] In one example, the security event preemption mechanism can be implemented using the following code: curl -X POST -H "Content-Type: application / json" \ -u admin:securepassword \ http: / / sdn-controller / emergency\ -d '{"event": "ddos", "action": "redirect", "target": "security_node_ip:port"}' In this embodiment of the application, when an attack event is detected, the network switch is controlled to transmit the attack traffic corresponding to the attack event to a preset security node for processing, so as to avoid affecting normal services.

[0070] To enable those skilled in the art to more clearly understand the mirrored traffic processing method shown in the embodiments of this application, the following describes... Figure 4 This application provides an explanation of a method for processing mirrored traffic as illustrated in an embodiment.

[0071] Reference Figure 4 This is a dynamic optimization flowchart of an embodiment of a mirror traffic processing method of this application.

[0072] In this embodiment of the application, statistical analysis and status construction are performed on data related to network status information. Specifically, network traffic data is collected as traffic characteristic data, and device load data is statistically analyzed to construct network status information.

[0073] Based on network state information (such as training network state information or real-time network state information), a reinforcement learning method is used to train the mirror scheme generation model. Specifically, a training environment is set up, a Q-learning model is configured, and then the model is trained based on the network state information to learn the optimal policy.

[0074] The trained mirroring scheme generation model can dynamically distribute and verify rules. Specifically, the mirroring scheme generation model generates OpenFlow rules based on real-time network status information, which serve as the target mirroring traffic configuration scheme. These rules are then distributed to the SDN controller, and port traffic on the mirroring ports can be captured using preset traffic capture commands to verify the effectiveness of the rules.

[0075] This can include handling exceptions related to device circuit breaker logic and security event preemption mechanisms. Once the exception is resolved, the target device's functionality can be restored.

[0076] In one embodiment, support for Multi-Protocol Label Switching (MPLS) can be added to the above embodiments to expand the applicability of network traffic mirroring. MPLS label forwarding rules are configured on the OpenvSwitch switch to enable mirrored traffic to be transmitted through the MPLS network. Simultaneously, the reward function of the mirroring scheme generation model is modified to increase the weight of MPLS label forwarding efficiency, further optimizing the transmission path and performance of mirrored traffic.

[0077] Reference Figure 5 This is a flowchart illustrating the dynamic optimization process supporting multi-protocol label switching, representing an embodiment of a mirror traffic processing method of this application.

[0078] The sFlow detector detects high-bandwidth traffic and triggers the traffic mirroring process. The Open vSwitch switch (OVS) performs the push_label(1001) operation to add MPLS labels to the traffic to identify and distinguish different traffic paths, and then forwards it to the MPLS network.

[0079] Traffic undergoes label switching in the MPLS network, mapping the labels of mirrored traffic to MPLS routes. The LER (Label Edge Router) switches label 1001 to 2001, and the LSR (Label Switch Router) then switches label 2001 to 3001.

[0080] The mirror analysis node strips MPLS labels and decodes the raw traffic for analysis. The resulting analysis data is used as feedback for the reinforcement learning of the mirror scheme generation model. The input to the mirror scheme generation model is performance data such as MPLS efficiency, bandwidth, and latency. Based on these inputs, the model calculates and outputs a path weight update strategy.

[0081] Based on the adjustment strategy output by the mirroring scheme, the SDN controller generates and distributes new rules. Using the OpenFlow protocol, the SDN controller distributes MPLS label forwarding rules to the Open vSwitch. The rules specify how to handle traffic carrying MPLS labels and define the traffic forwarding path.

[0082] The modified reward function aims to improve the transmission efficiency of mirrored traffic by optimizing MPLS path selection. Specifically, this includes: increasing the weight of MPLS label forwarding efficiency, which will be evaluated based on path forwarding latency and bandwidth usage; simultaneously, the model needs to dynamically select the optimal path in the MPLS network based on network conditions such as bandwidth utilization and latency. Therefore, the modified reward function includes the following optimization objectives: first, bandwidth utilization optimization, rationally allocating mirrored traffic to avoid path congestion; and second, latency optimization, prioritizing low-latency paths to ensure real-time data transmission.

[0083] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of this application.

[0084] Based on the above embodiments, this embodiment also provides a mirror traffic processing device, which can be applied to terminal devices, servers and other electronic devices.

[0085] Reference Figure 6This diagram illustrates a structural block diagram of an embodiment of a mirrored traffic processing device according to this application. The device is applied to a software-defined network controller (SDB), which is communicatively connected to a network switch. The network switch is communicatively connected to a mirroring node. Specifically, it may include the following modules: The status determination module 601 is used to obtain network status information; The scheme generation module 602 is used to input the network status information into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model. The target mirror traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirror traffic. The scheme execution module 603 is used to control the network switch to collect preset original service traffic to obtain the mirrored traffic according to the target mirrored traffic configuration scheme, and to control the network switch to transmit the mirrored traffic to the mirror node so that the mirror node can process the mirrored traffic.

[0086] Optionally, a sampling tool is deployed on the network switch, the network switch has a target port, and the state determination module 601 includes: The traffic sampling submodule is used to control the sampling tool to sample the port traffic of the target port of the network switch to obtain traffic feature data; The bandwidth utilization determination submodule is used to determine the bandwidth utilization of the target port of the network switch based on the traffic characteristic data. The load data acquisition submodule is used to acquire device load data; The status information determination submodule is used to use the traffic characteristic data, the bandwidth utilization rate, and the device load data as the network status information.

[0087] Optionally, the bandwidth utilization determination submodule is specifically used for: The current traffic and maximum bandwidth of the target port are determined from the traffic characteristic data. The bandwidth utilization of the target port of the network switch is obtained by calculating the ratio of the current traffic to the maximum bandwidth of the port.

[0088] Optionally, the load data acquisition submodule includes: The load data acquisition unit is used to control the preset monitoring system to acquire processor data and memory data of the software-defined network controller and the mirror node; A load data determination unit is used to use the processor data and the memory data as the device load data.

[0089] Optionally, the device includes: A heatmap generation module is used to generate a load heatmap based on the processor data and memory data of the software-defined network controller and the mirror node; The heat map display module is used to display the load heat map.

[0090] Optionally, the device includes: The model parameter configuration module is used to configure model parameters and obtain the model generated from the mirror scheme to be trained. The training data acquisition module is used to acquire training network state information; The reinforcement learning module is used to train the mirror scheme generation model to be trained using reinforcement learning methods based on the state information of the training network, so as to obtain the trained mirror scheme generation model.

[0091] Optionally, the reinforcement learning module includes: The training data input submodule is used to input the training network state information into the mirror scheme generation model to be trained, and obtain the training mirror traffic configuration scheme output by the mirror scheme generation model to be trained. The current state determination submodule is used to determine the current network state information after executing the training image traffic configuration scheme; The reward calculation submodule is used to calculate the training reward using a preset reward function based on the training mirror traffic configuration scheme and the current network status information. The model update submodule is used to update the model generated by the mirror scheme to be trained based on the training reward.

[0092] Optionally, the scheme generation module 602 is specifically used for: The network state information is input into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model based on a preset configuration scheme template.

[0093] Optionally, the device includes: The scheme viewing module is used to display the target mirror traffic configuration scheme in response to a preset scheme viewing command.

[0094] Optionally, the network switch has a mirroring port, and the device includes: A traffic capture module is used to capture port traffic of the mirrored port in response to a preset traffic capture command; The traffic verification module is used to verify the accuracy of the mirroring traffic replication and transmission process based on the port traffic of the mirrored port.

[0095] Optionally, the device includes: A target device determination module is used to determine the target device from the software-defined network controller and the mirror node; The load judgment module is used to determine whether the device load data of the target device is greater than a preset load threshold within a preset collection period. The device circuit breaker module is used to perform a circuit breaker operation on the target device if the device load data of the target device is greater than the load threshold within a consecutive preset number of acquisition cycles.

[0096] Optionally, the device includes: The attack detection module is used to detect attack events; An automatic switching module is used to control the network switch to transmit the attack traffic corresponding to the attack event to a preset security node if the attack event is detected.

[0097] This application also provides a non-volatile readable storage medium storing one or more modules (programs). When these modules are applied to a device, they enable the device to execute the instructions for the method steps in this application.

[0098] This application provides one or more machine-readable media storing instructions that, when executed by one or more processors, cause an electronic device to perform one or more of the methods described in the above embodiments. In this application, the electronic device includes various types of devices such as terminal devices and servers (clusters).

[0099] The embodiments of this disclosure can be implemented as an apparatus configured as desired using any suitable hardware, firmware, software, or any combination thereof, including electronic devices such as terminal devices, servers (clusters), etc. Figure 7 An exemplary apparatus 700 is schematically shown that can be used to implement the various embodiments described in this application.

[0100] In one embodiment, Figure 7 An exemplary device 700 is shown, which includes one or more processors 702, a control module (chipset) 704 coupled to at least one of the processors 702, a memory 706 coupled to the control module 704, a non-volatile memory (NVM) / storage device 708 coupled to the control module 704, one or more input / output devices 710 coupled to the control module 704, and a network interface 712 coupled to the control module 704.

[0101] Processor 702 may include one or more single-core or multi-core processors, and processor 702 may include any combination of general-purpose processors or special-purpose processors (e.g., graphics processors, application processors, baseband processors, etc.). In some embodiments, device 700 can serve as a terminal device, server (cluster), or other device as described in the embodiments of this application.

[0102] In some embodiments, apparatus 700 may include one or more computer-readable media (e.g., memory 706 or NVM / storage device 708) having instructions 714 and one or more processors 702 that are combined with the one or more computer-readable media and configured to execute the instructions 714 to implement the module and thus perform the actions described in this disclosure.

[0103] In one embodiment, the control module 704 may include any suitable interface controller to provide any suitable interface to at least one of the processors 702 and / or any suitable device or component communicating with the control module 704.

[0104] The control module 704 may include a memory controller module to provide an interface to the memory 706. The memory controller module may be a hardware module, a software module, and / or a firmware module.

[0105] Memory 706 may be used, for example, to load and store data and / or instructions 714 for device 700. In one embodiment, memory 706 may include any suitable volatile memory, such as suitable DRAM. In some embodiments, memory 706 may include double data rate type quad synchronous dynamic random access memory (DDR4 SDRAM).

[0106] In one embodiment, the control module 704 may include one or more input / output controllers to provide an interface to the NVM / storage device 708 and (one or more) input / output devices 710.

[0107] For example, NVM / storage device 708 may be used to store data and / or instructions 714. NVM / storage device 708 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable (one or more) non-volatile storage devices (e.g., one or more hard disk drive (HDD), one or more optical disc (CD) drives, and / or one or more digital universal optical disc (DVD) drives).

[0108] NVM / storage device 708 may include storage resources that are physically part of a device on which device 700 is mounted, or that are accessible to the device but do not necessarily have to be part of the device. For example, NVM / storage device 708 may be accessed via a network via one or more input / output devices 710.

[0109] One or more input / output devices 710 may provide an interface for device 700 to communicate with any other suitable device. Input / output devices 710 may include communication components, audio components, sensor components, etc. A network interface 712 may provide an interface for device 700 to communicate via one or more networks. Device 700 may wirelessly communicate with one or more components of a wireless network according to any of one or more wireless network standards and / or protocols, such as accessing a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G, 5G, etc., or a combination thereof.

[0110] In one embodiment, at least one of the processors 702 may be logically packaged with one or more controllers (e.g., memory controller modules) of the control module 704. In one embodiment, at least one of the processors 702 may be logically packaged with one or more controllers of the control module 704 to form a system-in-package (SiP). In one embodiment, at least one of the processors 702 may be integrated with the logic of one or more controllers of the control module 704 on the same die. In one embodiment, at least one of the processors 702 may be integrated with the logic of one or more controllers of the control module 704 on the same die to form a system-on-a-chip (SoC).

[0111] In various embodiments, device 700 may be, but is not limited to, a server, desktop computing device, or mobile computing device (e.g., laptop computing device, handheld computing device, tablet computer, netbook, etc.). In various embodiments, device 700 may have more or fewer components and / or different architectures. For example, in some embodiments, device 700 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touchscreen display), a non-volatile memory port, multiple antennas, a graphics chip, an application-specific integrated circuit (ASIC), and a speaker.

[0112] The detection device can use a main control chip as a processor or control module, and sensor data, position information, etc. can be stored in a memory or NVM / storage device. The sensor group can be used as an input / output device, and the communication interface can include a network interface.

[0113] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0114] The foregoing has provided a detailed description of a method and apparatus for processing mirrored traffic, an electronic device, and a storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for processing mirrored traffic, characterized in that, Applied to a software-defined network controller, wherein the software-defined network controller is communicatively connected to a network switch, and the network switch is communicatively connected to a mirror node, the method includes: Obtain network status information; The network state information is input into a pre-trained mirroring scheme generation model to obtain the target mirroring traffic configuration scheme output by the mirroring scheme generation model. The target mirroring traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirroring traffic. According to the target mirrored traffic configuration scheme, the network switch is controlled to collect the preset original service traffic to obtain the mirrored traffic, and the network switch is controlled to transmit the mirrored traffic to the mirror node so that the mirror node can process the mirrored traffic.

2. The method according to claim 1, characterized in that, The network switch is equipped with a sampling tool and has a target port. The acquisition of network status information includes: The sampling tool is controlled to sample the port traffic of the target port of the network switch to obtain traffic characteristic data; The bandwidth utilization of the target port of the network switch is determined based on the traffic characteristic data. Obtain device load data; The traffic characteristic data, the bandwidth utilization rate, and the device load data are used as the network status information.

3. The method according to claim 2, characterized in that, Determining the bandwidth utilization of the target port of the network switch based on the traffic characteristic data includes: The current traffic and maximum bandwidth of the target port are determined from the traffic characteristic data. The bandwidth utilization of the target port of the network switch is obtained by calculating the ratio of the current traffic to the maximum bandwidth of the port.

4. The method according to claim 2, characterized in that, The acquisition of device load data includes: The system controls a pre-defined monitoring system to collect processor and memory data from the software-defined network controller and the mirror node. The processor data and the memory data are used as the device load data.

5. The method according to claim 4, characterized in that, The method includes: A load heatmap is generated based on the processor and memory data of the software-defined network controller and the mirror node; The load heat map is shown.

6. The method according to claim 1, characterized in that, The training process of the mirroring scheme generation model includes: Configure the model parameters to obtain the mirror scheme generation model to be trained; Obtain training network state information; Based on the training network state information, the mirror scheme generation model to be trained is trained using reinforcement learning methods to obtain the trained mirror scheme generation model.

7. The method according to claim 6, characterized in that, The step of training the mirror image generation model to be trained using reinforcement learning methods based on the training network state information includes: The training network state information is input into the mirror scheme generation model to be trained to obtain the training mirror traffic configuration scheme output by the mirror scheme generation model to be trained. Determine the current network status information after executing the training mirror traffic configuration scheme; Based on the training mirror traffic configuration scheme and the current network status information, the training reward is calculated using a preset reward function; The mirror scheme generation model to be trained is updated based on the training reward.

8. The method according to claim 1, characterized in that, The step of inputting the network state information into a pre-trained mirroring scheme generation model to obtain the target mirroring traffic configuration scheme output by the mirroring scheme generation model includes: The network state information is input into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model based on a preset configuration scheme template.

9. The method according to claim 1, characterized in that, The method includes: In response to a preset scheme viewing command, the target mirror traffic configuration scheme is displayed.

10. The method according to claim 1, characterized in that, The network switch has a mirroring port, and the method includes: In response to a preset traffic capture command, the port traffic of the mirrored port is captured; Verify the accuracy of the mirroring traffic replication and transmission process based on the port traffic of the mirrored port.

11. The method according to claim 4, characterized in that, The method includes: The target device is determined from the software-defined network controller and the mirror node; Within a preset collection period, determine whether the device load data of the target device is greater than a preset load threshold; If the device load data of the target device is greater than the load threshold within a consecutive preset number of collection cycles, then a circuit breaker operation is performed on the target device.

12. The method according to claim 4, characterized in that, The method includes: Detect attack events; If the attack event is detected, the network switch is controlled to transmit the attack traffic corresponding to the attack event to a preset security node.

13. A device for processing mirrored traffic, characterized in that, An apparatus applied to a software-defined network controller, wherein the software-defined network controller is communicatively connected to a network switch, and the network switch is communicatively connected to a mirror node, the apparatus comprising: The status determination module is used to obtain network status information; The scheme generation module is used to input the network status information into a pre-trained mirror scheme generation model to obtain the target mirror traffic configuration scheme output by the mirror scheme generation model. The target mirror traffic configuration scheme is a configuration scheme that controls the collection, transmission and processing of the mirror traffic. The scheme execution module is used to control the network switch to collect preset original service traffic to obtain the mirrored traffic according to the target mirrored traffic configuration scheme, and to control the network switch to transmit the mirrored traffic to the mirror node so that the mirror node can process the mirrored traffic.

14. An electronic device, characterized in that, include: processor; and A memory having executable code stored thereon, which, when executed, causes the processor to perform the method for processing mirrored traffic as described in any one of claims 1-12.

15. A machine-readable medium having executable code stored thereon, which, when executed, causes a processor to perform a method for processing mirrored traffic as described in any one of claims 1-12.