Hot event traffic scheduling and network quality correlation analysis method and device

By constructing a multi-dimensional baseline and combining DNS request counts, flow rate, and congestion circuit analysis, the problem of inaccurate traffic scheduling under hot events was solved, achieving accurate identification of hot events and effective guarantee of network quality.

CN121887671APending Publication Date: 2026-04-17CHINA UNITECHS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNITECHS
Filing Date
2025-12-26
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing traffic analysis technologies lack multi-dimensional feature fusion in hot event scenarios, making it impossible to accurately identify traffic scheduling behavior. This leads to inaccurate network resource scheduling, affecting network quality and billing policy formulation.

Method used

We construct a multi-dimensional baseline, analyze hot events by combining DNS request counts and flow rate, obtain congested circuits by combining backbone mirror probes, analyze cross-provincial traffic scheduling behavior, and evaluate the scheduling impact through network quality indicators.

Benefits of technology

It enables accurate identification of hot events and location of cross-provincial traffic scheduling behavior, improves the accuracy of network resource scheduling and the efficiency of network quality assurance, and reduces data processing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887671A_ABST
    Figure CN121887671A_ABST
Patent Text Reader

Abstract

The invention discloses a hotspot event traffic scheduling and network quality correlation analysis method and device. The method comprises the following steps: S01, constructing a multi-dimensional baseline of an application; s02, analyzing whether a hotspot event occurs or not according to the Flow velocity and DNS request times of the application; s03, acquiring a congestion circuit based on the bandwidth utilization rate of the backbone mirror probe and the equipment; s04, analyzing whether a trans-provincial flow scheduling behavior exists in combination with the hotspot event and the congestion circuit; and S05, based on the circuit traffic before and after scheduling, analyzing the influence of traffic scheduling on the network quality under the hot event. According to the hotspot event traffic scheduling and network quality correlation analysis method and device, the hotspot event and the congestion circuit are combined, so that the traffic scheduling behavior of the application when the hotspot event occurs can be quickly found, and more comprehensive and more accurate traffic insight is provided for an operator.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of traffic billing, and in particular to a method and apparatus for traffic scheduling and network quality correlation analysis of hot events. Background Technology

[0002] With the increasing complexity of network services, traffic scheduling triggered by local sporting events, popular cultural and tourism activities, and sudden social hotspots has become a core pain point for operators' network management. Sudden hotspot events can lead to large data center customers flexibly scheduling traffic, causing sudden surges in traffic in certain directions on the backbone network, resulting in relay congestion and network performance degradation. Operators lack effective monitoring methods and cannot accurately control customer traffic scheduling behavior. Operators need to quickly identify such events, analyze their scheduling paths and scale, and assess their impact on network quality (such as latency and packet loss) in order to provide timely and prioritized protection.

[0003] Existing traffic analysis technologies have significant shortcomings in hotspot event scenarios. They fail to integrate multi-dimensional features for comprehensive judgment, either solely monitoring traffic anomalies to identify hotspot events or analyzing only billing characteristics to detect evasion behavior, lacking consideration of auxiliary features such as user access behavior, bandwidth utilization, and circuit latency. This prevents operators from fully and accurately understanding the true drivers of network traffic changes, making it difficult to distinguish between normal business growth and customer traffic scheduling operations. Consequently, it impacts the precise allocation of network resources, the effective guarantee of service quality, and the rational formulation of billing policies. Summary of the Invention

[0004] To address the problems existing in the prior art, this invention provides a method and apparatus for hotspot event traffic scheduling and network quality correlation analysis. By combining hotspot events and congestion circuits, it can quickly discover the traffic scheduling behavior of applications when hotspot events occur, providing operators with more comprehensive and accurate traffic insights.

[0005] To achieve the above objectives, the present invention adopts the following technical solution:

[0006] In one embodiment of the present invention, a method for hotspot event traffic scheduling and network quality correlation analysis is proposed, the method comprising:

[0007] S01. Construct a multi-dimensional baseline for the application;

[0008] Further, S01 includes:

[0009] S011. Statistical application of the flow velocity baseline in each province over the past 30 days;

[0010] S012. Statistical application of the national flow velocity baseline over the past 30 days;

[0011] S013. Statistical application baseline of DNS request count in each province over the past 30 days;

[0012] S014. Generate the flow rate baseline for the application in the province and the whole country according to the 5-minute time granularity, and at the same time generate the DNS request count baseline for the province.

[0013] S02. Analyze whether hotspot events occur based on the application's flow rate and DNS request count;

[0014] Further, S02 includes:

[0015] S021. Based on DNS logs and flow traffic statistics, determine flow rate and DNS request characteristics;

[0016] Furthermore, the statistical flow rate includes: the uplink and downlink flow rates of the application traffic;

[0017] The DNS request characteristics include: the number of DNS requests, the average access time of users, etc.

[0018] S022. Observe the number of DNS requests and the application's flow rate, and identify the occurrence of hot events based on the hot event identification rules;

[0019] Furthermore, the hotspot event identification rules include: if one-third of the provinces experience a rapid increase in the number of DNS requests and the application's flow rate, and both the number of DNS requests and the application's flow rate exceed the baseline threshold of 30% for 15 consecutive minutes, then a hotspot event is identified.

[0020] S023. Observe the number of DNS requests and the application's flow rate, and determine the end of the hot event based on the hot event end rule.

[0021] Furthermore, the hotspot event termination rules include the following: if the number of DNS requests and the application's flow rate deviate from the baseline by less than 30% for two consecutive times, then the hotspot event is considered to have ended.

[0022] Hotspot event scheduling behavior is generally not repeatable and has a limited duration, so comparing based on a monthly baseline can better identify hotspot events;

[0023] Maintain a "customer-application association database" where applications and customers have a "many-to-one" relationship: a customer can operate multiple applications, and an application belongs to only one core operating customer; the association database contains the following fields: customer ID, customer name, application domain name, application name, and CDN node identifier; customer contract filing data and application information are synchronized monthly and updated, and the database is directly called for quick association during subsequent matching to improve matching efficiency.

[0024] S03. Based on the bandwidth utilization of the backbone mirror probe and the device, obtain the congested circuit;

[0025] Furthermore, the backbone mirror probe is a network data acquisition device deployed at key nodes of the operator's backbone network. Its core function is to copy and analyze the network traffic of the inter-provincial link without interfering with the original traffic transmission, and to obtain key quality indicators such as latency, jitter, and packet loss rate.

[0026] The bandwidth utilization resolution standard is: the data is processed and entered into the database within 5 minutes after the IP network management system collects the data.

[0027] Further, S03 includes:

[0028] S031. Use backbone network mirror probes to collect data on jitter, latency, and packet loss between provinces;

[0029] Furthermore, the data collected by the probe in S031 includes: collection time, source province, destination province, latency (ms), packet loss rate, and jitter;

[0030] S032. If the inter-provincial latency exceeds 15ms, the packet loss rate exceeds 0, and the jitter exceeds 30%, then the network quality between the two provinces is considered to be problematic.

[0031] S033. When there are problems with the quality of the inter-provincial network and there is circuit congestion on the backbone network side equipment, the congestion circuit information shall be recorded.

[0032] Furthermore, the congested circuit in S033 is one where the average bandwidth utilization of the devices at both ends of the circuit exceeds 85%;

[0033] The circuit information for recording congestion includes: local device name, local device address, local interface address, local interface description, peer device name, peer device address, peer interface address, peer interface description, peak bandwidth utilization, bandwidth, inbound bandwidth utilization, outbound bandwidth utilization, congestion start time and end time.

[0034] S04. Analyze whether cross-provincial traffic scheduling behavior exists by combining hot events and congested circuits;

[0035] Further, S04 includes:

[0036] S041. If a hotspot event occurs and the intra-provincial traffic deviates from the baseline by less than ±15%, while the out-of-province traffic is more than 3 times the baseline threshold, then it is considered that there is cross-provincial traffic scheduling behavior.

[0037] Taking application A as an example, if the number of DNS requests and the flow traffic of application A in a certain province increase rapidly, but the flow traffic within the province of application A does not change much, and the flow traffic flowing out to other provinces is more than 3 times the baseline threshold, then it is considered that application A has engaged in cross-provincial traffic scheduling behavior.

[0038] S042. Based on the time of occurrence of hot events, query whether there are congested circuits in the same time period.

[0039] Further, S042 includes:

[0040] S0421. No congested circuits occurred during the same period, indicating that the cross-provincial traffic scheduling behavior under this hotspot event had no significant impact on network quality.

[0041] S0422. If a congested circuit exists in the same time period, it is determined whether any of the contracted customers of the IDC data center in the congested circuit belong to the application to which the hot event occurred. If such customers exist, the cross-provincial traffic scheduling under the hot event has affected the network quality.

[0042] S05. Based on the circuit traffic before and after scheduling, analyze the impact of traffic scheduling on network quality under hot events.

[0043] Further, S05 includes:

[0044] S051. Network quality index comparison: Extract mirror probe data between provinces and statistically analyze latency, jitter and packet loss rate before, during and after scheduling.

[0045] S052. Calculate the change range of each indicator at different stages, assess the impact of scheduling behavior on network transmission stability, and determine whether the indicators have deteriorated.

[0046] Further, S052 includes:

[0047] If the latency increases by 50% or more compared to the baseline before scheduling, or the absolute latency exceeds 25ms, dynamic routing based on network probe data is required, prioritizing the allocation of low-latency links.

[0048] If the jitter increases by 40% or more compared to the baseline before scheduling, or the absolute jitter exceeds 45%, then traffic shaping will be used to smooth the fluctuations and limit the proportion of traffic scheduled on a single link.

[0049] If the packet loss rate increases by 100% or more compared to the baseline before scheduling, or the absolute packet loss rate exceeds 0.8%, the system will issue a warning for links that exceed the threshold and temporarily expand capacity or divert traffic to backup links.

[0050] S053, Link bandwidth utilization analysis;

[0051] Further, S053 includes:

[0052] The bandwidth utilization of source IDC uplink lines and cross-provincial backbone links is statistically analyzed using a 5-minute time granularity: before scheduling, the average utilization rate is taken 1 hour before the occurrence of the hot event; during scheduling, the average utilization rate is taken during the duration of the event; and after scheduling, the average utilization rate is taken 1 hour after the end of the event.

[0053] Set the security threshold to 85% and determine whether the link utilization exceeds the threshold.

[0054] If the scheduling scale exceeds the baseline by 2 times or more, and the utilization rate increases by 30% or more compared to the baseline before scheduling, and the utilization rate exceeds 85% and lasts for more than 15 minutes, it is determined to be link congestion caused by scheduling.

[0055] The system synchronously records the start and end times of congestion and assesses the affected provincial scope and the scale of affected users.

[0056] S054. Continuously monitor network hotspot events at a frequency of 5 minutes / time. When customer traffic increases by more than 50% above the baseline within 15 minutes and is predicted to reach 70% of the safety threshold within 30 minutes, trigger a high-traffic scheduling behavior warning.

[0057] It works in real time with the backbone network scheduling system to establish a rapid response mechanism within 15 minutes after a congestion warning, accurately optimize network resource allocation, improve network quality and stability, and reduce operation and maintenance pressure.

[0058] In one embodiment of the present invention, a device for hotspot event traffic scheduling and network quality correlation analysis is also proposed, the device comprising:

[0059] The baseline building module constructs multi-dimensional baselines for applications.

[0060] The hotspot event analysis module analyzes whether hotspot events have occurred based on the application's flow rate and the number of DNS requests.

[0061] The congestion circuit acquisition module acquires congestion circuits based on the backbone mirror probe and the bandwidth utilization of the device.

[0062] The cross-provincial analysis module, combining hot events and congested circuits, analyzes whether cross-provincial traffic scheduling behavior exists;

[0063] The network quality analysis module analyzes the impact of traffic scheduling on network quality under hot events based on circuit traffic before and after scheduling.

[0064] In one embodiment of the present invention, a computer device is also proposed, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned hotspot event traffic scheduling and network quality correlation analysis method.

[0065] In one embodiment of the present invention, a computer-readable storage medium is also proposed, which stores a computer program that performs a method for hotspot event traffic scheduling and network quality correlation analysis.

[0066] This invention provides a method and apparatus for hotspot event traffic scheduling and network quality correlation analysis, with the following advantages:

[0067] 1. Construct a multi-dimensional baseline that combines provincial and national data, as well as flow rate and DNS request count, to provide a comprehensive benchmark for identifying hot events and improve identification accuracy;

[0068] 2. By linking DNS and Flow multi-source data and combining hot events and congested circuits in dual scenarios, we can accurately locate cross-provincial traffic scheduling behavior and solve the limitations of single data dimension analysis.

[0069] 3. Establish a quantitative evaluation system for network quality throughout the entire lifecycle of scheduling (before, during, and after), and simultaneously match targeted optimization solutions to form a closed loop of "identification-evaluation-optimization" to improve network assurance efficiency;

[0070] 4. The time granularity and baseline period are designed according to the characteristics of hot events, and key data is screened layer by layer to reduce the scale of data processing and analysis costs, making it highly practical. Attached Figure Description

[0071] Figure 1 This is a schematic diagram illustrating the specific process of the hotspot event traffic scheduling and network quality correlation analysis method of the present invention;

[0072] Figure 2 This is a schematic diagram of the structure of the hotspot event traffic scheduling and network quality correlation analysis device of the present invention;

[0073] Figure 3 This is a schematic diagram of a computer device structure according to an embodiment of the present invention. Detailed Implementation

[0074] The principles and spirit of the present invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.

[0075] Those skilled in the art will recognize that embodiments of the present invention can be implemented as a system, apparatus, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0076] According to an embodiment of the present invention, a method and apparatus for hotspot event traffic scheduling and network quality correlation analysis are proposed. By combining hotspot events and congestion circuits, the traffic scheduling behavior of applications when hotspot events occur can be quickly discovered, providing operators with more comprehensive and accurate traffic insights.

[0077] The principles and spirit of the present invention will be explained in detail below with reference to several representative embodiments.

[0078] like Figure 1 As shown, the present invention relates to a method for hotspot event traffic scheduling and network quality correlation analysis, the method comprising:

[0079] S01. Construct a multi-dimensional baseline for the application, including:

[0080] S011. Statistical application of the flow velocity baseline in each province over the past 30 days;

[0081] S012. Statistical application of the national flow velocity baseline over the past 30 days;

[0082] S013. Statistical application baseline of DNS request count in each province over the past 30 days;

[0083] S014. Generate the flow rate baseline for the application in the province and the whole country according to the 5-minute time granularity, and at the same time generate the DNS request count baseline for the province.

[0084] S02. Based on the application's flow rate and DNS request count, analyze whether hotspot events have occurred, including:

[0085] S021. Based on DNS logs and flow traffic statistics, determine flow rate and DNS request characteristics;

[0086] Statistical flow rate includes: the upstream and downstream flow rates of application traffic;

[0087] The DNS request characteristics include: the number of DNS requests, the average access time of users, etc.

[0088] S022. Observe the number of DNS requests and the application's flow rate, and identify the occurrence of hot events based on the hot event identification rules;

[0089] The criteria for identifying hot events include: if one-third of the provinces experience a rapid increase in the number of DNS requests and the application's flow rate, and both the number of DNS requests and the application's flow rate exceed the baseline threshold of 30% for 15 consecutive minutes, then a hot event is identified.

[0090] S023. Observe the number of DNS requests and the application's flow rate, and determine the end of the hot event based on the hot event end rule.

[0091] The rules for ending a hotspot event include: if the number of DNS requests and the application's flow rate deviate from the baseline by less than 30% for two consecutive times, the hotspot event is considered to have ended.

[0092] Hotspot event scheduling behavior is generally not repeatable and has a limited duration, so comparing based on a monthly baseline can better identify hotspot events;

[0093] Maintain a "customer-application association database" where applications and customers have a "many-to-one" relationship: a customer can operate multiple applications, and an application belongs to only one core operating customer; the association database contains the following fields: customer ID, customer name, application domain name, application name, and CDN node identifier; customer contract filing data and application information are synchronized monthly and updated, and the database is directly called for quick association during subsequent matching to improve matching efficiency.

[0094] S03. Based on the bandwidth utilization of the backbone mirror probe and the device, obtain the congested circuit;

[0095] Backbone mirror probes are network data acquisition devices deployed at key nodes of the operator's backbone network. Their core function is to replicate and analyze the network traffic of inter-provincial links without interfering with the original traffic transmission, and to obtain key quality indicators such as latency, jitter, and packet loss rate.

[0096] The bandwidth utilization resolution standard is: the data is processed and entered into the database within 5 minutes after the IP network management system collects the data.

[0097] S03 includes:

[0098] S031. Use backbone network mirror probes to collect data on jitter, latency, and packet loss between provinces;

[0099] The data collected by the probe in S031 includes: collection time, source province, destination province, latency (ms), packet loss rate, and jitter;

[0100] S032. If the inter-provincial latency exceeds 15ms, the packet loss rate exceeds 0, and the jitter exceeds 30%, then the network quality between the two provinces is considered to be problematic.

[0101] S033. When there are problems with the quality of the inter-provincial network and there is circuit congestion on the backbone network side equipment, the congestion circuit information shall be recorded.

[0102] In S033, the congested circuit is one where the average bandwidth utilization of the devices at both ends of the circuit exceeds 85%.

[0103] The circuit information recorded for congestion includes: local device name, local device address, local interface address, local interface description, peer device name, peer device address, peer interface address, peer interface description, peak bandwidth utilization, bandwidth, inbound bandwidth utilization, outbound bandwidth utilization, congestion start time and end time.

[0104] S04. Combining hot events and congested circuits, analyze whether cross-provincial traffic scheduling behavior exists, including:

[0105] S041. If a hotspot event occurs and the intra-provincial traffic deviates from the baseline by less than ±15%, while the out-of-province traffic is more than 3 times the baseline threshold, then it is considered that there is cross-provincial traffic scheduling behavior.

[0106] Taking application A as an example, if the number of DNS requests and the flow traffic of application A in a certain province increase rapidly, but the flow traffic within the province of application A does not change much, and the flow traffic flowing out to other provinces is more than 3 times the baseline threshold, then it is considered that application A has engaged in cross-provincial traffic scheduling behavior.

[0107] S042. Based on the time of occurrence of hot events, query whether there are congested circuits in the same time period.

[0108] S042 includes:

[0109] S0421. No congested circuits occurred during the same period, indicating that the cross-provincial traffic scheduling behavior under this hotspot event had no significant impact on network quality.

[0110] S0422. If a congested circuit exists in the same time period, it is determined whether any of the contracted customers of the IDC data center in the congested circuit belong to the application to which the hot event occurred. If such customers exist, the cross-provincial traffic scheduling under the hot event has affected the network quality.

[0111] S05. Based on the circuit traffic before and after scheduling, analyze the impact of traffic scheduling on network quality under hotspot events, including:

[0112] S051. Network quality index comparison: Extract mirror probe data between provinces and statistically analyze latency, jitter and packet loss rate before, during and after scheduling.

[0113] S052. Calculate the change range of each indicator at different stages, assess the impact of scheduling behavior on network transmission stability, and determine whether the indicators have deteriorated.

[0114] S052 includes:

[0115] If the latency increases by 50% or more compared to the baseline before scheduling, or the absolute latency exceeds 25ms, dynamic routing based on network probe data is required, prioritizing the allocation of low-latency links.

[0116] If the jitter increases by 40% or more compared to the baseline before scheduling, or the absolute jitter exceeds 45%, then traffic shaping will be used to smooth the fluctuations and limit the proportion of traffic scheduled on a single link.

[0117] If the packet loss rate increases by 100% or more compared to the baseline before scheduling, or the absolute packet loss rate exceeds 0.8%, the system will issue a warning for links that exceed the threshold and temporarily expand capacity or divert traffic to backup links.

[0118] S053, Link bandwidth utilization analysis, including:

[0119] The bandwidth utilization of source IDC uplink lines and cross-provincial backbone links is statistically analyzed using a 5-minute time granularity: before scheduling, the average utilization rate is taken 1 hour before the occurrence of the hot event; during scheduling, the average utilization rate is taken during the duration of the event; and after scheduling, the average utilization rate is taken 1 hour after the end of the event.

[0120] Set the security threshold to 85% and determine whether the link utilization exceeds the threshold.

[0121] If the scheduling scale exceeds the baseline by 2 times or more, and the utilization rate increases by 30% or more compared to the baseline before scheduling, and the utilization rate exceeds 85% and lasts for more than 15 minutes, it is determined to be link congestion caused by scheduling.

[0122] The system synchronously records the start and end times of congestion and assesses the affected provincial scope and the scale of affected users.

[0123] S054. Continuously monitor network hotspot events at a frequency of 5 minutes / time. When customer traffic increases by more than 50% above the baseline within 15 minutes and is predicted to reach 70% of the safety threshold within 30 minutes, trigger a high-traffic scheduling behavior warning.

[0124] It works in real time with the backbone network scheduling system to establish a rapid response mechanism within 15 minutes after a congestion warning, accurately optimize network resource allocation, improve network quality and stability, and reduce operation and maintenance pressure.

[0125] It should be noted that although the operation of the method of the present invention has been described in a specific order in the above embodiments and figures, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0126] To provide a clearer explanation of the above-mentioned methods for traffic scheduling and network quality correlation analysis of hot events, specific embodiments are described below. However, it is worth noting that these embodiments are only for better illustrating the present invention and do not constitute an improper limitation of the present invention.

[0127] In a specific implementation, taking a social app (hereinafter referred to as "App Z") that covers multiple provinces across the country as an example, and a sudden social hot topic triggers a surge in user access, prompting a major IDC customer to initiate cross-provincial traffic scheduling to cope with the traffic surge, this embodiment analyzes the process and its impact on network quality based on the method of the present invention:

[0128] S01. Constructing a multi-dimensional baseline for application Z:

[0129] The statistical application Z recently generated multi-dimensional baselines, including the flow rate baselines of each province, the national flow rate baseline, and the DNS request count baselines of each province, all with a 5-minute time granularity.

[0130] Get the flow traffic data of application Z for the past 30 days (inbound / outbound flow rate statistics for each province in 5-minute granularity) and DNS log data (request count statistics for each province in 5-minute granularity);

[0131] Taking the baseline of flow velocity in Province A over the past 30 days as an example, the average flow inflow velocity and outflow velocity for each 5-minute period of each day over the past 30 days are used as the baseline of flow velocity in Province A for that period.

[0132] After calculating the baseline of application Z, generate the provincial flow rate baseline table, the national flow rate baseline table, and the provincial DNS request count baseline table for application Z.

[0133] S02. Analyze whether hotspot events occur based on the flow rate and DNS request count of application Z:

[0134] Collect real-time DNS logs and flow traffic data from application Z to analyze characteristics such as flow rate and number of DNS requests;

[0135] The number of DNS requests and flow rate in multiple provinces were observed to increase rapidly, and the conditions of "more than 1 / 3 of the provinces + both indicators continuously reaching the baseline ratio for the set duration" were met, indicating that a hotspot event had occurred.

[0136] Subsequent monitoring revealed that the proportion of two indicators fell below the baseline multiple times, indicating the end of the hotspot event, and the start and end times of the event were recorded.

[0137] The application Z provides real-time statistics on flow rate and DNS request count across 31 provinces in China.

[0138] Assume that starting at 18:30 on the same day, the flow rate of application Z in 12 provinces, including Province A, Province B, and Province C (more than 1 / 3 of the 31 provinces) exceeds the corresponding provincial baseline by 30% for 15 consecutive minutes (for example, the baseline flow rate of Province A in the past 30 days was 20Gbps at 18:30 on the same day, and the flow rate reached 26Gbps, exceeding the baseline by 30%).

[0139] Meanwhile, the number of DNS requests in these 12 provinces also exceeded the corresponding provincial baseline by 30% for 15 consecutive minutes (for example, the baseline for the number of DNS requests in the past 30 days in Province A at 18:30 was 500,000, and the number of DNS requests at 18:30 on that day reached 650,000, exceeding the baseline by 30%).

[0140] Application Z's flow rate and DNS request count meet the conditions of "1 / 3 of the provinces + both indicators exceeding the baseline by 30% + lasting for 15 minutes", so it is determined that application Z has a hot event, and the start time of the hot event is recorded as 18:30 on the same day;

[0141] Starting at 22:00 on the same day, if the flow rate and number of DNS requests in the above-mentioned provinces are lower than 30% of the baseline for two consecutive times (each time for 5 minutes), the hotspot event is determined to have ended, and the end time of the hotspot event is recorded as 22:00.

[0142] Record trending events, including the following information: application name, start time of the trending event (18:30), end time of the trending event (22:00), and the 12 provinces involved in the trending event.

[0143] S03. Based on the bandwidth utilization of the backbone mirror probe and the device, obtain the congested circuit:

[0144] Inter-provincial network quality data, including latency, packet loss rate, and jitter, are collected through backbone network mirror probes.

[0145] When network quality issues were found in some provinces, the bandwidth utilization of backbone network equipment was queried simultaneously for the corresponding time period. It was confirmed that there were circuits where the average utilization of equipment at both ends exceeded the set threshold, and the relevant information of the congested circuits was recorded.

[0146] Inter-provincial network quality data and device port bandwidth utilization data (5-minute granularity) collected using backbone network mirror probes.

[0147] Assuming the mirror probe collects data in real time, it finds that between 19:30 and 21:00 on the same day, the network quality between province A and provinces D and E is abnormal: latency reaches 22ms (exceeding the 15ms threshold), jitter reaches 38% (exceeding the 30% threshold), and packet loss rate is 0.5% (exceeding the 0 threshold).

[0148] Synchronously querying the bandwidth utilization of backbone network equipment ports during this period, it was found that the average bandwidth utilization of the circuit between backbone equipment in province A (equipment name: A-BACKBONE-01) and backbone equipment in province D (equipment name: D-BACKBONE-02) both exceeded 92% (exceeding the 85% threshold), and was determined to be a congested circuit.

[0149] Record congestion circuit information: Local device name A-BACKBONE-01, Local device address 10.0.0.1, Local interface address 10.0.1.1, Local interface description "AD Inter-provincial Backbone Link", Remote device name D-BACKBONE-02, Remote device address 10.1.1.2, Remote interface address 10.1.2.2, Remote interface description "DA Inter-provincial Backbone Link", Peak bandwidth utilization 95%, Bandwidth 100G, Inbound bandwidth utilization 93%, Outbound bandwidth utilization 92%, Congestion start time 19:30, Congestion end time 21:00.

[0150] S04. Combining hot events and congested circuits, analyze whether cross-provincial traffic scheduling behavior exists:

[0151] Based on the records of hot events, it was found that during the hot events, the intra-provincial traffic of application Z did not change much, but the inter-provincial traffic far exceeded the baseline setting multiple, indicating that there was cross-provincial traffic scheduling behavior.

[0152] By correlating the timeframes of hot events and congested circuits, an overlap was found between the two. Further investigation confirmed that the IDC devices in the congested circuit belonged to the operating customer of application Z, and it was determined that the scheduling behavior affected network quality.

[0153] During the hot event, the flow rate of application Z in province A was observed to be around 22Gbps (not much different from the baseline of 20Gbps). However, the flow rate of application Z flowing out of province A to province D reached 65Gbps, which is 3.25 times the baseline outflow rate (20Gbps). It was determined that application Z was engaging in cross-provincial flow scheduling behavior.

[0154] By correlating the hotspot event time (18:30-22:00) with the congested circuit time (19:30-21:00), an overlap was found between the two.

[0155] The customer associated with the IDC equipment in the congested circuit was queried to confirm that the IDC equipment carried by the circuit belonged to the operating entity of application Z, and it was determined that the cross-provincial traffic scheduling under this hot event had an impact on network quality.

[0156] S05. Based on the circuit traffic before and after scheduling, analyze the impact of traffic scheduling on network quality under hotspot events:

[0157] Extract inter-provincial mirror probe data before, during, and after scheduling, compare changes in latency, jitter, and packet loss rate, and evaluate network transmission stability.

[0158] By analyzing the bandwidth utilization of source IDC uplink lines and cross-provincial backbone links at different stages, we can determine whether congestion has occurred and the extent of its impact.

[0159] In response to deteriorating indicators, corresponding optimization measures are taken: if latency increases, dynamic routing is selected; if jitter worsens, traffic shaping is implemented; and if packet loss rate increases, warnings are issued and traffic is diverted.

[0160] To address the increased latency: Based on probe data, dynamic routing is used to switch part of the scheduled traffic from province A to province D to the AFD backup link (latency 10ms).

[0161] To address increased jitter: limit the proportion of single-link scheduling traffic on AD links to within 85% of the link bandwidth through traffic shaping;

[0162] To address congestion risks: temporarily expand the bandwidth of the AD inter-provincial backbone circuit to 150G to divert excess traffic.

[0163] Through the above specific embodiments, the present invention successfully identifies hot events caused by sudden social hotspots in application Z, accurately locates cross-provincial traffic scheduling behavior and associated congestion circuits, quantifies the impact of scheduling on network quality, and provides effective support for operators and large customers to coordinate scheduling and ensure the stability of the large network.

[0164] Based on the same inventive concept, this invention also proposes a device for hotspot event traffic scheduling and network quality correlation analysis. The implementation of this device can refer to the implementation of the above-described method, and repeated details will not be elaborated further. The term "module" used below can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0165] Figure 2 This is a schematic diagram of the structure of the hotspot event traffic scheduling and network quality correlation analysis device of the present invention. Figure 2 As shown, the device includes:

[0166] Baseline building module 110 builds multi-dimensional baselines for the application;

[0167] The hotspot event analysis module 120 analyzes whether hotspot events occur based on the application's flow rate and the number of DNS requests.

[0168] The congestion circuit acquisition module 130 acquires congestion circuits based on the bandwidth utilization of the backbone mirror probe and the device.

[0169] The cross-provincial analysis module 140 combines hot events and congested circuits to analyze whether cross-provincial traffic scheduling behavior exists;

[0170] The network quality analysis module 150 analyzes the impact of traffic scheduling on network quality under hot events based on circuit traffic before and after scheduling.

[0171] It should be noted that although several modules of the hotspot event traffic scheduling and network quality correlation analysis device are mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.

[0172] Based on the aforementioned inventive concept, such as Figure 3 As shown, the present invention also proposes a computer device 200, including a memory 210, a processor 220, and a computer program 230 stored in the memory 210 and executable on the processor 220. When the processor 220 executes the computer program 230, it implements the aforementioned hotspot event traffic scheduling and network quality correlation analysis method.

[0173] Based on the aforementioned inventive concept, the present invention also proposes a computer-readable storage medium storing a computer program that executes the aforementioned hotspot event traffic scheduling and network quality correlation analysis method.

[0174] This invention provides a method and apparatus for hotspot event traffic scheduling and network quality correlation analysis, with the following advantages:

[0175] 1. Construct a multi-dimensional baseline that combines provincial and national data, as well as flow rate and DNS request count, to provide a comprehensive benchmark for identifying hot events and improve identification accuracy;

[0176] 2. By linking DNS and Flow multi-source data and combining hot events and congested circuits in dual scenarios, we can accurately locate cross-provincial traffic scheduling behavior and solve the limitations of single data dimension analysis.

[0177] 3. Establish a quantitative evaluation system for network quality throughout the entire lifecycle of scheduling (before, during, and after), and simultaneously match targeted optimization solutions to form a closed loop of "identification-evaluation-optimization" to improve network assurance efficiency;

[0178] 4. The time granularity and baseline period are designed according to the characteristics of hot events, and key data is screened layer by layer to reduce the scale of data processing and analysis costs, making it highly practical.

[0179] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.

[0180] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0181] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0182] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0183] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0184] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0185] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.

[0186] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0187] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

[0188] Regarding the limitation of the scope of protection of this invention, those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solution of this invention are still within the scope of protection of this invention.

Claims

1. A method for hotspot event traffic scheduling and network quality correlation analysis, characterized in that, The method includes: S01. Construct a multi-dimensional baseline for the application; S02. Analyze whether hotspot events occur based on the application's flow rate and DNS request count; S03. Based on the bandwidth utilization of the backbone mirror probe and the device, obtain the congested circuit; S04. Analyze whether cross-provincial traffic scheduling behavior exists by combining hot events and congested circuits; S05. Based on the circuit traffic before and after scheduling, analyze the impact of traffic scheduling on network quality under hot events.

2. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, S01 includes: S011. Statistical application of the flow velocity baseline in each province over the past 30 days; S012. Statistical application of the national flow velocity baseline over the past 30 days; S013. Statistical application baseline of DNS request count in each province over the past 30 days; S014. Generate the flow rate baseline for the application in the province and the whole country according to the 5-minute time granularity, and at the same time generate the DNS request count baseline for the province.

3. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, S02 includes: S021. Based on DNS logs and flow traffic statistics, determine flow rate and DNS request characteristics; S022. Observe the number of DNS requests and the application's flow rate, and identify the occurrence of hot events based on the hot event identification rules; S023. Observe the number of DNS requests and the application's flow rate, and determine the end of the hot event based on the hot event end rule.

4. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 3, characterized in that, The statistical flow rate in S021 includes: the uplink and downlink flow rates of the application traffic; The DNS request characteristics include: the number of DNS requests, the average access time of users, etc.

5. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 3, characterized in that, The hotspot event identification rules in S022 include: if one-third of the provinces experience a rapid increase in the number of DNS requests and the application's flow rate, and both the number of DNS requests and the application's flow rate exceed the baseline threshold of 30% for 15 consecutive minutes, then a hotspot event is identified.

6. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 3, characterized in that, The hotspot event termination rules in S023 include the following: if the number of DNS requests and the application's flow rate deviate from the baseline by less than 30% for two consecutive times, then the hotspot event is considered to have ended.

7. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, The backbone mirror probe is a network data acquisition device deployed at key nodes of the operator's backbone network. Its core function is to copy and analyze the network traffic of inter-provincial links without interfering with the original traffic transmission, and to obtain indicators such as latency, jitter, and packet loss rate. The bandwidth utilization resolution standard is: the data is processed and entered into the database within 5 minutes after the IP network management system collects the data.

8. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, S03 includes: S031. Use backbone network mirror probes to collect data on jitter, latency, and packet loss between provinces; S032. If the inter-provincial latency exceeds 15ms, the packet loss rate exceeds 0, or the jitter exceeds 30%, then the inter-provincial network quality is considered to be problematic. S033. When there are problems with the quality of the inter-provincial network and there is circuit congestion on the backbone network side equipment, the congestion circuit information shall be recorded.

9. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 8, characterized in that, The data collected by the probe in S031 includes: collection time, source province, destination province, latency, packet loss rate, and jitter.

10. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 8, characterized in that, The congested circuit in S033 is one where the average bandwidth utilization of the devices at both ends of the circuit exceeds 85%. The circuit information for recording congestion includes: local device name, local device address, local interface address, local interface description, peer device name, peer device address, peer interface address, peer interface description, peak bandwidth utilization, bandwidth, inbound bandwidth utilization, outbound bandwidth utilization, congestion start time and end time.

11. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, S04 includes: S041. If a hotspot event occurs and the intra-provincial traffic deviates from the baseline by less than ±15%, while the out-of-province traffic is more than 3 times the baseline threshold, then it is considered that there is cross-provincial traffic scheduling behavior. S042. Based on the time of occurrence of hot events, query whether there are congested circuits in the same time period.

12. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 11, characterized in that, S042 includes: S0421. No congested circuits occurred during the same period, indicating that the cross-provincial traffic scheduling behavior under this hotspot event had no significant impact on network quality. S0422. If a congested circuit exists in the same time period, it is determined whether any of the contracted customers of the IDC data center in the congested circuit belong to the application to which the hot event occurred. If such customers exist, the cross-provincial traffic scheduling under the hot event has affected the network quality.

13. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 1, characterized in that, S05 includes: S051. Network quality index comparison: Extract mirror probe data between provinces and statistically analyze latency, jitter and packet loss rate before, during and after scheduling. S052. Calculate the change range of each indicator at different stages, assess the impact of scheduling behavior on network transmission stability, and determine whether the indicators have deteriorated. S053, Link bandwidth utilization analysis; S054. Continuously monitor network hotspot events at a frequency of 5 minutes / time. When customer traffic increases by more than 50% above the baseline within 15 minutes and is predicted to reach 70% of the safety threshold within 30 minutes, trigger a high-traffic scheduling behavior warning. It is linked in real time with the backbone network scheduling system to establish a mechanism for responding within 15 minutes after a congestion warning.

14. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 13, characterized in that, S052 includes: If the latency increases by 50% or more compared to the baseline before scheduling, or the absolute latency exceeds 25ms, dynamic routing based on network probe data is required, prioritizing the allocation of low-latency links. If the jitter increases by 40% or more compared to the baseline before scheduling, or the absolute jitter exceeds 45%, then traffic shaping will be used to smooth the fluctuations and limit the proportion of traffic scheduled on a single link. If the packet loss rate increases by 100% or more compared to the baseline before scheduling, or the absolute packet loss rate exceeds 0.8%, the system will issue a warning for links that exceed the threshold and temporarily expand capacity or divert traffic to backup links.

15. The method for hotspot event traffic scheduling and network quality correlation analysis according to claim 13, characterized in that, S053 includes: The bandwidth utilization of source IDC uplink lines and cross-provincial backbone links is statistically analyzed using a 5-minute time granularity: before scheduling, the average utilization rate is taken 1 hour before the occurrence of the hot event; during scheduling, the average utilization rate is taken during the duration of the event; and after scheduling, the average utilization rate is taken 1 hour after the end of the event. Set the security threshold to 85% and determine whether the link utilization exceeds the threshold. If the scheduling scale exceeds the baseline by 2 times or more, and the utilization rate increases by 30% or more compared to the baseline before scheduling, and the utilization rate exceeds 85% and lasts for more than 15 minutes, it is determined to be link congestion caused by scheduling. The system synchronously records the start and end times of congestion and assesses the affected provincial scope and the scale of affected users.

16. A device for hotspot event traffic scheduling and network quality correlation analysis, characterized in that, The device includes: The baseline building module constructs multi-dimensional baselines for applications. The hotspot event analysis module analyzes whether hotspot events have occurred based on the application's flow rate and the number of DNS requests. The congestion circuit acquisition module acquires congestion circuits based on the backbone mirror probe and the bandwidth utilization of the device. The cross-provincial analysis module, combining hot events and congested circuits, analyzes whether cross-provincial traffic scheduling behavior exists; The network quality analysis module analyzes the impact of traffic scheduling on network quality under hot events based on circuit traffic before and after scheduling.

17. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1-15.

18. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that performs the method according to any one of claims 1-15.