Network optimization balancing system and network controller

By optimizing the network balance system and controller, and dynamically balancing security and efficiency, the problem of rigid traditional design in large-scale time-varying network transmission is solved, and high reliability and efficiency of end-to-end communication are achieved.

CN121771013APending Publication Date: 2026-03-31SHANGHAI FEIQI NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-25
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional network transmission methods for large-scale time-varying networks are rigid and inefficient, making it difficult to meet the high reliability requirements of end-to-end communication. They are also susceptible to natural and malicious interference. Existing technologies that focus on reliable communication designs at the link or device level are insufficient to meet the high reliability requirements of end-to-end communication.

Method used

A network optimization and balancing system and network controller are provided, including a data analysis module, an estimation module, an optimization module and a deployment module. By dynamically balancing security and efficiency, a target security policy is selected from a combination of security policies using a multi-objective optimization algorithm and deployed to the network server.

Benefits of technology

It achieves a dynamic balance between network transmission security and efficiency based on business scenario requirements, meets the high reliability requirements of end-to-end communication, and improves the security and efficiency of network transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121771013A_ABST
    Figure CN121771013A_ABST
Patent Text Reader

Abstract

The invention provides a network optimization balance system and a network controller, and relates to the technical field of network optimization, the network optimization balance system comprises a data analysis module, an estimation module, an optimization module and a deployment module; the data analysis module is used for acquiring the workload intensity in the current state; the estimation module is used for estimating the security level and the delay level of each security policy in the security policy combination under the current workload intensity; the optimization module is used for selecting a target security policy from the security policy combination based on the security level and the time delay level according to a pre-configured optimization algorithm; and the deployment module is used for deploying the target security policy to the network server. According to the network optimization balancing system and the network controller provided by the invention, the security and the efficiency can be fully considered, and the relationship between the security and the efficiency of network transmission is dynamically balanced, so that the requirement of high reliability of end-to-end communication is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of network optimization, and in particular to a network optimization balancing system and a network controller. Background Technology

[0002] With the trend of space-ground integration, large-scale time-varying networks, characterized by sparse network connections and complex spatiotemporal evolution, have become a key research focus in the industry. However, due to the changeable, complex, ambiguous, and uncertain nature of the boundaries of large-scale time-varying networks, traditional boundary protection models are facing severe challenges, and their vulnerability and security have become major problems.

[0003] Furthermore, large-scale time-varying networks are massive in scale and complex in structure, with their topology constantly changing. However, traditional network transmission methods are rigid and inefficient, making it difficult to meet the diverse service requirements carried on them. In addition, large-scale time-varying networks have a large spatial scale, making communication links easily exposed and susceptible to natural and malicious interference. However, research and applications of reliable communication technologies, such as those related to interference resistance, are concentrated at the link or device level, focusing only on point-to-point reliable communication, which is insufficient to meet the high reliability requirements of end-to-end communication. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a network optimization and balancing system and a network controller that can dynamically balance the relationship between security and efficiency of network transmission according to different business scenario requirements, thereby alleviating the above-mentioned technical problems and meeting the high reliability requirements of end-to-end communication.

[0005] In a first aspect, embodiments of the present invention provide a network optimization and balancing system, the system being applied to a network controller, the system comprising: a data analysis module, an estimation module, an optimization module, and a deployment module; wherein, the data analysis module is used to obtain the workload intensity under the current state and input the workload intensity to the estimation module, wherein the workload intensity is used to characterize the request rate of each user; the estimation module is used to obtain the workload intensity and a pre-configured combination of security policies including multiple security policies, and to estimate the security level and latency level of each security policy in the combination of security policies under the current workload intensity, and input the security level and latency level of each security policy to the optimization module; the optimization module is used to select a target security policy from the combination of security policies based on the security level and latency level of each security policy according to a pre-configured optimization algorithm, and send the target security policy to the deployment module; the deployment module is used to deploy the target security policy to a network server.

[0006] In conjunction with the first aspect, the present invention provides a first possible implementation of the first aspect, wherein the estimation module includes a security estimation unit and an efficiency estimation unit; the security estimation unit is used to calculate the security level of each security policy; and the efficiency estimation unit is used to calculate the latency level of each security policy.

[0007] In conjunction with the first possible implementation of the first aspect, this embodiment of the invention provides a second possible implementation of the first aspect, wherein the security estimation unit is configured with a security level calculation model; the security level calculation model is used to calculate the security strength of each role in each of the network servers; the security strength is weighted and calculated to obtain the total security strength; and the security level of each of the security policies is calculated based on the total security strength.

[0008] In conjunction with the first possible implementation of the first aspect, this embodiment of the invention provides a third possible implementation of the first aspect, wherein the calculation formula for the above-mentioned security level is expressed as follows:

[0009] in, Indicates the security level. and The sharpness parameter is pre-configured; S represents the total security strength of all roles in the network server; wherein, the security strength of each role is expressed as:

[0010] in, A represents the security strength of role r; A represents the total number of security protection dimensions that role r needs to evaluate. This represents the importance weight coefficient of role r in the j-th security protection dimension; N represents the total number of specific evaluation indicators under the j-th security protection dimension. This represents the quantitative value of the importance of the i-th specific indicator under the j-th security protection dimension; This indicates the actual degree to which role r meets the requirements for the i-th safety indicator; The total security strength is expressed as: ,in, The safety strength weight for role r.

[0011] In conjunction with the first possible implementation of the first aspect, this embodiment of the invention provides a fourth possible implementation of the first aspect, wherein the efficiency estimation unit is configured with a latency level calculation model; the latency level calculation model is used to calculate the latency level of the security policy based on the average response time of the network server; wherein the average response time is calculated by weighting and summing the response times of each role, and the average response time is expressed as:

[0012] Where Tr is the response time of character r. r represents the weight of role r at response time t; The latency level is represented as follows: ;in, and This is the sharpness parameter in the latency level.

[0013] In conjunction with the first aspect, this embodiment of the invention provides a fifth possible implementation of the first aspect, wherein the above-mentioned optimization algorithm is a multi-objective optimization algorithm; the optimization module sorts the security policies based on the security level and latency level of each security policy using the multi-objective optimization algorithm to obtain a security policy sequence; obtains the demand preference information of the network server; and selects a target security policy from the security policy sequence based on the demand preference information.

[0014] In conjunction with the first aspect, this embodiment of the invention provides a sixth possible implementation of the first aspect, wherein the optimization module is further configured to select at least one of the security policies from the security policy combination based on the optimization algorithm, wherein the security level is greater than a preset security threshold and the latency level is less than a preset latency threshold; and to select one of the at least one security policy as the target security policy.

[0015] In conjunction with the first aspect, this embodiment of the invention provides a seventh possible implementation of the first aspect, wherein the deployment module includes an IDPS queue; the target security policy is deployed to the network server through the IDPS queue.

[0016] In conjunction with the first aspect, this embodiment of the invention provides an eighth possible implementation of the first aspect, wherein the data analysis module is further configured to acquire user requests, acquire the request rate from the user requests, and use the request rate as the workload intensity in the current state.

[0017] Secondly, embodiments of the present invention also provide a network controller, the network controller being configured with the network optimization balancing system described in the first aspect; the network controller is used to deploy security policies on network servers.

[0018] The embodiments of the present invention bring the following beneficial effects: This invention provides a network optimization and balancing system and network controller, comprising: a data analysis module, an estimation module, an optimization module, and a deployment module. The data analysis module acquires the workload intensity under the current state and inputs it into the estimation module, whereby the workload intensity characterizes the request rate of each user. The estimation module acquires the workload intensity and a pre-configured combination of multiple security policies, estimating the security level and latency level of each security policy in the combination under the current workload intensity, and inputs these levels into the optimization module. The optimization module selects a target security policy from the combination based on the security level and latency level of each security policy according to a pre-configured optimization algorithm, and sends the target security policy to the deployment module. The deployment module deploys the target security policy to the network server. Because the optimization module determines the security level and latency level based on each security policy, it can fully consider security and efficiency, dynamically balancing the relationship between security and efficiency in network transmission, thereby meeting the high reliability requirements of end-to-end communication.

[0019] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained in accordance with the structures particularly pointed out in the description, claims and drawings.

[0020] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0021] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0022] Figure 1 This is a schematic diagram of the structure of a network optimization balancing system provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of another network optimization balancing system provided in an embodiment of the present invention. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0024] Currently, existing research and applications of reliable communication, including interference resistance, focus on the link level or device level, designing only from the perspective of point-to-point reliable communication, which is insufficient to meet the high reliability requirements of end-to-end communication. To address these issues, this invention proposes a scenario-driven "security-efficiency" dynamic balancing system, capable of dynamically balancing the relationship between security and efficiency in network transmission according to different business scenario requirements.

[0025] To facilitate understanding of this embodiment, a network optimization balancing system disclosed in this embodiment of the invention will first be described in detail.

[0026] In one possible implementation, embodiments of the present invention provide a network optimization balancing system, which is applied to a network controller and a network server for deploying security policies on the network system's network servers.

[0027] Specifically, such as Figure 1 The diagram shows the structure of a network optimization balancing system, which includes: a data analysis module 10, an estimation module 20, an optimization module 30, and a deployment module 40.

[0028] The data analysis module 10 is used to obtain the workload intensity under the current state and input the workload intensity into the estimation module 20. In this embodiment of the invention, the workload intensity is used to characterize the request rate of each user. The estimation module 20 is used to obtain the workload intensity and a pre-configured combination of security policies including multiple security policies, and to estimate the security level and latency level of each security policy in the combination under the current workload intensity. The security level and latency level of each security policy are then input into the optimization module 30. The optimization module 30 is used to select a target security policy from the combination of security policies based on the security level and latency level of each security policy according to a pre-configured optimization algorithm, and to send the target security policy to the deployment module 40. The deployment module 40 is then used to deploy the target security policy to the network server.

[0029] In practical use, since the embodiments of the present invention are based on a dynamic balance between security and efficiency, the optimization algorithm configured in the above-mentioned optimization module of the present invention is actually a dual-objective optimization algorithm, that is, dynamically optimizing the two objectives of security and efficiency in order to find a set of optimal or near-optimal security strategy combinations.

[0030] In practical use, security policies can include physical security policies, access control policies, firewall policies, information encryption policies, network security management policies, etc. Or, according to the nature of authorization, security policies can also be divided into the following aspects: identity-based security policies, rule-based security policies, role-based security policies, etc. Network administrators can formulate corresponding principles to select and use security policies to meet the needs of network transmission.

[0031] In this invention, "security" actually refers to security strength. In real-world environments, the relationship between security strength, efficiency, and user needs is not necessarily a simple linear one. For example, in most cases, as security strength increases, the urgency for users to further increase security gradually decreases. When security strength is far from meeting user security needs, users urgently desire improved security; then, when security strength approaches or exceeds user security needs, user demand for improved security gradually decreases. On the other hand, as response time increases, user tolerance for further reductions in network efficiency gradually decreases; when response time approaches or exceeds the deadline required for user network efficiency, user tolerance for further reductions in efficiency rapidly decreases. Therefore, to obtain a more realistic optimization solution, in this invention, the optimization module selects a target security policy from a combination of security policies based on the security level and latency level of each security policy for deployment, aiming to achieve a security strength approaching or exceeding user security needs while ensuring efficiency remains within user tolerance.

[0032] Furthermore, in this embodiment of the invention, security level and latency level are used to characterize the specific quantitative values ​​of security and efficiency. That is, in this embodiment of the invention, the security level is used to measure the security strength; therefore, the security level represents the user's actual expectation of system security, and the higher the security level, the more satisfied the user is with the security. Furthermore, in this embodiment of the invention, the latency level is used to measure efficiency; the latency level represents the user's actual tolerance for system response time, and the lower the latency level, the more satisfied the user is with the efficiency.

[0033] In practical use, based on the above security and latency levels, when deploying security policies, the network controller can select the optimal approximate solution that meets the system's security and efficiency requirements from the security policy combination. That is, it selects the optimal set from multiple security policies in the security policy combination. At the same time, it dynamically changes the security policy combination according to changes in user requests to meet the user's security and efficiency requirements, that is, to meet higher security levels and lower latency levels.

[0034] Specifically, in order to facilitate the calculation of security level and latency level, in this embodiment of the invention, the estimation module includes a security estimation unit and an efficiency estimation unit; wherein, the security estimation unit is used to calculate the security level of each security policy; and the efficiency estimation unit is used to calculate the latency level of each security policy.

[0035] For ease of understanding, Figure 1 On this basis, Figure 2 A schematic diagram of another network optimization balancing system is shown, specifically, as follows: Figure 2 As shown, the safety estimation unit 201 and efficiency estimation unit 202 included in the estimation module 20 are illustrated.

[0036] In practice, the network controller runs the optimization process according to a preset control interval. That is, the aforementioned estimation unit typically calculates the security level and latency level once every preset control interval. Furthermore, the aforementioned data analysis module also obtains the workload intensity of the system under the current state every preset control interval. Specifically, the data analysis module is also used to obtain user requests, extract the request rate from the user requests, and use the request rate as the workload intensity under the current state.

[0037] Furthermore, the aforementioned security policy combination refers to a combination of multiple security policies that the current network controller can deploy or run. Typically, this can be pre-configured; for example, currently feasible security policies can be combined to obtain multiple feasible security policy groups, which can be stored in the aforementioned security policy combination. The workload intensity and security policy combination obtained by the data analysis module are then input into the estimation module as input parameters.

[0038] Furthermore, the security estimation unit in the estimation module is equipped with a security level calculation model; the security level calculation model is used to calculate the security strength of each role in each network server; the security strength is weighted and calculated to obtain the total security strength; and then the security level of each security policy is calculated based on the total security strength.

[0039] The formula for calculating the security level is as follows:

[0040] in, Indicates the security level. and The pre-configured sharpness parameter; S represents the total security strength of all roles in the web server; In this embodiment of the invention, the "role" refers to a role in the network system, such as various access points, routing devices, relay devices, network nodes, etc., depending on the actual usage. This embodiment of the invention does not impose any limitations on this. Furthermore, in this embodiment of the invention, the security strength of each role is expressed as follows:

[0041] in, A represents the security strength of role r; A represents the total number of security protection dimensions that role r needs to evaluate. This represents the importance weight coefficient of role r in the j-th security protection dimension; N represents the total number of specific evaluation indicators under the j-th security protection dimension. This represents the quantitative value of the importance of the i-th specific indicator under the j-th security protection dimension; This represents the actual degree of compliance of role r with the i-th security indicator; in specific implementation, it includes the specific security protection dimensions and the total number of security protection dimensions, as well as the quantification parameter d in the quantification value of the importance of the specific indicator. ij The actual level of compliance and other parameters can be set according to the actual usage situation, and the embodiments of the present invention do not impose any restrictions on this.

[0042] The above total safety strength is expressed as ,in, The safety strength weight for role r.

[0043] Furthermore, the efficiency estimation unit in the aforementioned estimation module is configured with a latency level calculation model; the latency level calculation model is used to calculate the latency level of the security policy based on the average response time of the network server; wherein, the average response time is calculated by weighting the response times of each role, and the average response time is expressed as:

[0044] Where Tr is the response time of character r. r represents the weight of role r at response time t; Latency levels are represented as follows:

[0045] in, and This is the sharpness parameter in the latency level.

[0046] Furthermore, the aforementioned optimization algorithm is a multi-objective optimization algorithm, such as the bi-objective optimization algorithm described above. Specifically, the optimization module sorts the security policies based on their security level and latency level using a multi-objective optimization algorithm to obtain a security policy sequence; then, it obtains the network server's demand preference information; and based on this demand preference information, it selects a target security policy from the security policy sequence. In specific implementation, the aforementioned demand preference information refers to the relative importance or priority preference of the network server or system for security and efficiency in a specific business scenario.

[0047] Furthermore, in this embodiment of the invention, considering the large amount of possible combinations of security strategies, it is impractical to use an exhaustive search method to find all possible configurations. Therefore, this embodiment uses a multi-objective optimization algorithm to find a combination of security strategies that can better balance the system's security and efficiency requirements, and obtains a set of superior strategy combinations. Then, based on system requirements, a security strategy is selected from the set of superior solutions for deployment. For example, if the security strength or level of security strategy A is higher than that of security strategy B, and the response time or latency level of security strategy A is not greater than that of security strategy B, then security strategy A is superior to security strategy B.

[0048] Furthermore, to facilitate the optimization module in selecting a target security policy from the security policy combination, a security threshold and a latency threshold can be pre-configured. This allows the optimization module to select at least one security policy from the security policy combination whose security level is greater than the preset security threshold and whose latency level is less than the preset latency threshold, and then select one of the at least one security policy as the target security policy.

[0049] In other words, by configuring security thresholds and latency thresholds, at least one security policy with a high security level and a low latency level can be selected. These security policies can meet the system's requirements to a certain extent, that is, they have high security strength and low latency. Therefore, one of them can be selected as the target security policy for deployment.

[0050] Furthermore, such as Figure 2 As shown, the deployment module in this embodiment of the invention includes an IDPS (Intrusion Detection and Prevention Systems) queue. The IDPS queue refers to the event queue in the intrusion detection and prevention system, which can perform tasks such as network traffic monitoring and malicious behavior detection. Therefore, the target security policy can be put into the IDPS queue and deployed to the network server through the IDPS queue.

[0051] In summary, the network optimization and balancing system provided by this invention includes: a data analysis module, an estimation module, an optimization module, and a deployment module. The data analysis module obtains the workload intensity under the current state and inputs it into the estimation module, whereby the workload intensity characterizes the request rate of each user. The estimation module obtains the workload intensity and a pre-configured combination of multiple security policies, estimates the security level and latency level of each security policy in the combination under the current workload intensity, and inputs these levels into the optimization module. The optimization module selects a target security policy from the combination based on the security level and latency level of each security policy according to a pre-configured optimization algorithm and sends the target security policy to the deployment module. The deployment module deploys the target security policy to the network server. Because the optimization module determines the security level and latency level based on each security policy, it can fully consider security and efficiency, dynamically balancing the relationship between security and efficiency in network transmission, thereby meeting the high reliability requirements of end-to-end communication.

[0052] Furthermore, based on the above embodiments, this embodiment of the invention also provides a network controller configured with the above-mentioned network optimization and balancing system; the network controller is used to deploy security policies on network servers.

[0053] The network controller provided in this embodiment of the invention has the same technical features as the network optimization and balancing system provided in the above embodiments, so it can also solve the same technical problems and achieve the same technical effects.

[0054] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the network controller described above can be referred to the corresponding process in the foregoing embodiments, and will not be repeated here.

[0055] The computer program product of the network optimization balancing system and network controller provided in the embodiments of the present invention includes a computer-readable storage medium storing program code. The instructions included in the program code can be used to execute the methods described in the preceding method embodiments. For specific implementation, please refer to the foregoing embodiments, which will not be repeated here.

[0056] Furthermore, in the description of the embodiments of the present invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in the present invention based on the specific circumstances.

[0057] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0058] In the description of this invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0059] Finally, it should be noted that the above embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit it. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the technical scope disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A network optimization balancing system, characterized by, The system is applied to a network controller, and comprises a data analysis module, an estimation module, an optimization module and a deployment module; The data analysis module is configured to obtain a workload intensity under a current state and input the workload intensity to the estimation module, wherein the workload intensity is used to represent a request rate of each user; The estimation module is configured to obtain the workload intensity and a security policy combination comprising a plurality of security policies, estimate a security level and a time delay level of each security policy in the security policy combination under the current workload intensity, and input the security level and the time delay level of each security policy to the optimization module; The optimization module is configured to select a target security policy from the security policy combination according to a preconfigured optimization algorithm based on the security level and the time delay level of each security policy, and send the target security policy to the deployment module; The deployment module is configured to deploy the target security policy to a network server.

2. The system of claim 1, wherein, The estimation module comprises a security estimation unit and an efficiency estimation unit; The security estimation unit is configured to calculate the security level of each security policy; The efficiency estimation unit is configured to calculate the time delay level of each security policy.

3. The system of claim 2, wherein, The security estimation unit is configured with a security level calculation model; The security level calculation model is used to calculate a security intensity of each role in each network server; The security intensity is weighted and calculated to obtain a total security intensity; The security level of each security policy is calculated according to the total security intensity.

4. The system of claim 2, wherein, The calculation formula of the security level is as follows: wherein, represents a security level, and is a preconfigured sharpness parameter; S represents the total security strength of all roles in the network server. The security intensity of each role is represented as: wherein, represents the security strength of the role r; A represents the total number of security protection dimensions that the role r needs to evaluate; represents the importance weight coefficient of the role r on the jth security protection dimension; N represents the total number of specific evaluation indexes under the jth security protection dimension; represents the importance quantization value of the ith specific index under the jth security protection dimension; represents the actual compliance degree of the role r on the ith security index; The total security strength is expressed as wherein, is the security strength weight for the role r.

5. The system of claim 3, wherein, The efficiency estimation unit is configured with a time delay level calculation model; The time delay level calculation model is used to calculate the time delay level of the security policy based on an average response time of the network server; The average response time is calculated by weighting and calculating the response time of each role, and is represented as: wherein Tr is the response time of the character r, r denotes the weight of the character r at the response time t; The delay level is expressed as: wherein and is a sharpness parameter in the delay level.

6. The system of claim 1, wherein, The optimization algorithm is a multi-objective optimization algorithm; The optimization module sorts the security policies based on the security level and the time delay level of each security policy by using the multi-objective optimization algorithm to obtain a security policy sequence; Demand preference information of the network server is obtained; The target security policy is selected from the security policy sequence based on the demand preference information.

7. The system of claim 1, wherein, The optimization module is further configured to select at least one security policy with a security level greater than a preset security threshold and a time delay level less than a preset time delay threshold from the security policy combination based on the optimization algorithm, and select one of the at least one security policy as the target security policy. The deployment module comprises an IDPS queue; 8. The system of claim 1, wherein, The target security policy is deployed to the network server through the IDPS queue. The data analysis module is further configured to obtain a user request, obtain the request rate from the user request, and use the request rate as the workload intensity under the current state.

9. The system of claim 1, wherein, ​ 10. A network controller, characterized by The network controller is configured with the network optimization balancing system of any one of claims 1-9. The network controller is configured to deploy security policies to network servers.