Video conference network detection method and system

By acquiring network traffic and meeting room entry/exit data of participants, utilizing network mirroring port technology and grayscale analysis, and combining similar anomaly factors and meeting room switching times, the problem of inaccurate video conferencing network detection in existing technologies has been solved, enabling accurate identification and security assurance of video conferencing network anomalies.

CN121888041APending Publication Date: 2026-04-17闻志伟
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
闻志伟
Filing Date
2023-11-30
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing video conferencing network detection technologies do not take into account all scenarios, resulting in inaccurate network anomaly detection and a tendency to make false judgments.

Method used

By acquiring network traffic data of attendees and data on entry and exit from the venue, network mirroring technology is used to obtain network traffic in real time, which is then converted into grayscale images for anomaly detection. The comprehensive risk coefficient is calculated by combining the abnormal attendee behavior formula, including the analysis of similar anomaly factors and the number of venue switching times.

Benefits of technology

It enables accurate detection of network anomalies in video conferencing, improves network security, reduces false alarms, and can promptly identify potential network threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121888041A_ABST
    Figure CN121888041A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of video conference network detection, in particular to a video conference network detection method and system, and the method comprises the steps: obtaining network flow data and meeting place entering and exiting data of participants participating in a video conference; converting the network traffic data of the participants into a two-dimensional grey-scale map, and detecting the grey-scale map through a video conference traffic detection model to obtain a network traffic anomaly probability; wherein weighting is carried out through similar abnormal factors of the grey-scale maps of the participants and the grey-scale maps of the remaining participants; measuring and calculating the abnormal probability of the participating behaviors of the participants according to the meeting place entering and exiting data of the participants; and the comprehensive danger coefficient of the video conference is judged according to the network flow abnormal probability of the participants and the participant behavior abnormal probability. According to the method, the comprehensive danger coefficient of the video conference is measured and calculated from the two aspects of network flow abnormity and conference participation behavior abnormity, and the abnormity degree of the video conference is accurately measured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of video conferencing network detection technology, specifically to a video conferencing network detection method and system. Background Technology

[0002] The rapid development of online video technology has helped people break free from the limitations of space and distance, making communication faster and more convenient, and enriching people's work and life.

[0003] When meeting organizers lack cybersecurity awareness, it is easy for them to obtain relevant information about the video conference through online means and then join the meeting to eavesdrop on the content or share inappropriate documents. They may also post malicious links in the chat room to lure other participants into clicking, creating cybersecurity risks. This can disrupt the normal conduct of the meeting, and in severe cases, even lead to meeting interruption, alteration of meeting content, and other situations, causing significant losses to the meeting organizers and participants.

[0004] By obtaining online meeting information and passwords through various channels, and then systematically disrupting online classes, maliciously interfering with the teaching order, the negative impact on normal online education is greatly diminished. Therefore, secure and effective network detection technologies are needed to identify abnormal risks in video conferences and ensure their safe operation.

[0005] Most existing video conferencing network detection technologies focus on detecting overall video conferencing traffic, without adequately considering the scenario and analyzing the behavior of participants. This results in inaccurate detection of network anomalies in video conferencing and a tendency to make misjudgments.

[0006] To address this, a method and system for detecting video conferencing networks are proposed. Summary of the Invention

[0007] The purpose of this invention is to provide a video conferencing network detection method and system, comprising: acquiring network traffic data of participants in the video conference and entry and exit data of each meeting room; calculating the probability of abnormal network traffic based on the participants' network traffic data; calculating the probability of abnormal participation behavior based on the participants' meeting room entry and exit data; and then determining the comprehensive risk coefficient of the video conference based on the abnormal network traffic data and abnormal participation behavior data of the participants; thereby achieving accurate detection of the degree of risk during the online video conference.

[0008] To achieve the above objectives, the present invention provides a video conferencing network detection method and system, comprising:

[0009] Obtain the participation information of participants in multiple video conference sessions; the participation information includes participants' network traffic data and session entry and exit data;

[0010] The network traffic data of the attendees was analyzed to obtain the probability of network traffic anomalies. The specific steps are as follows:

[0011] Real-time network traffic data of participating IP addresses during online video conferences can be obtained through network mirroring port technology.

[0012] Based on the set time threshold, obtain the phased network traffic data and cumulative network traffic data of the participating IP addresses;

[0013] After cleaning the phased network traffic data and the cumulative network traffic data, they are converted into two-dimensional grayscale images to obtain phased traffic grayscale images and cumulative traffic grayscale images.

[0014] Anomaly detection is performed on the stage traffic grayscale map and the cumulative traffic grayscale map using a video conferencing traffic detection model to obtain the probability of network traffic anomalies for the corresponding participants. The similarity anomaly factor between the stage traffic grayscale map and the cumulative traffic grayscale map and the grayscale map corresponding to the remaining participants' IP addresses is used as an influencing factor and applied to the detection of the video conferencing traffic detection model.

[0015] The probability of abnormal meeting behavior is obtained by detecting the meeting attendees' entry and exit data.

[0016] Based on the set time threshold, obtain the cumulative number of times participants switched between meeting rooms and the number of times they switched between meeting rooms during the meeting.

[0017] The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula;

[0018] The overall risk coefficient of the video conference is obtained by combining the abnormal probability of network traffic and the abnormal probability of participant behavior.

[0019] The calculation process for the similarity anomaly factor is as follows:

[0020] Obtain the phased network traffic data and the cumulative network traffic data of the participating IP address i;

[0021] The stage network traffic data and the cumulative network traffic data are converted into two-dimensional grayscale images to obtain the stage traffic grayscale image and the cumulative traffic grayscale image;

[0022] The mean values ​​of the grayscale images of the phase traffic and the cumulative traffic for the participating IP address i are calculated.

[0023] The grayscale image of the stage flow and the grayscale image of the cumulative flow are compared with the mean value of the corresponding image to obtain the corresponding binary image of the stage flow and the binary image of the cumulative flow.

[0024] Calculate the hash values ​​of the stage traffic binary graph and the cumulative traffic binary graph to obtain the stage traffic hash value and the cumulative traffic hash value;

[0025] The first type of similarity is calculated based on the phase traffic hash value of the participating IP address i and the phase traffic hash value of the participating IP address of the same category. The first type of similarity is used to measure the similarity of the grayscale images of the corresponding phase traffic.

[0026] The second type of similarity is calculated based on the cumulative traffic hash value of the participating IP address i and the cumulative traffic hash value of the participating IP addresses of the same category. The second type of similarity is used to measure the similarity of the corresponding cumulative traffic grayscale images.

[0027] The similarity anomaly factor of the network traffic data of participant i is calculated based on the first type of similarity and the second type of similarity:

[0028]

[0029] Where, r t i For participant i at stage t, r is a similarity anomaly factor. t i The smaller the value of r, the smaller the abnormal trend; when r t i A larger value indicates a stronger abnormal trend; ss t ih The first-class similarity between participant i and participant h in network traffic data at stage t; ls t ik Let be the second type of similarity between participant i and participant k in network traffic at stage t; ∈ is the similarity control coefficient.

[0030] The video conferencing traffic detection model includes a data input layer, a feature training layer, and a result output layer;

[0031] The data output layer is used to input the network traffic grayscale image into the model for training.

[0032] The feature training layer is used to train the input network traffic grayscale image and output the training result; wherein the feature training layer includes a first convolutional training block, a second convolutional training block, a third convolutional training block and a fourth convolutional training block;

[0033] The output layer is used to fuse and transform the training results to obtain the anomaly probability of the network traffic grayscale image; wherein the output layer contains the similarity anomaly factor used to weight the training results.

[0034] The detection process of the video conferencing traffic detection model is as follows:

[0035] The grayscale image of network traffic is input into the model through the data input layer to obtain dataset U1;

[0036] The dataset U1 is trained using the first convolutional training block to obtain dataset U2;

[0037] The dataset U2 is trained using the second convolutional training block to obtain dataset U3;

[0038] The dataset U3 is trained by the third convolutional training block to obtain dataset U4;

[0039] The dataset U4 is trained by the fourth convolutional training block to obtain dataset U5;

[0040] The dataset U5 is processed by the result output layer to output the probability of network traffic anomalies.

[0041] The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula;

[0042] The formula for the abnormal meeting participation behavior is:

[0043]

[0044] Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

[0045] The overall risk coefficient of the online video conference is calculated based on the probability of abnormal network traffic and the probability of abnormal participation behavior of the participants.

[0046]

[0047] Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1 tcσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the abnormal probability of participant behavior in stage t; e is a mathematical constant.

[0048] The video conferencing network detection system includes a data acquisition module, a data cleaning module, a network traffic anomaly detection module, a participant behavior anomaly detection module, a comprehensive risk factor calculation module, and a response processing module.

[0049] The data acquisition module is used to acquire the participation information of participants during the video conference in real time; the participation information includes network traffic data of the participants' IP addresses and the participants' entry and exit from the venue;

[0050] The data cleaning module is used to clean and process the obtained network traffic data.

[0051] The network traffic anomaly detection module is used to calculate the probability of anomalies in the network traffic data of the attendees, and to obtain the probability of network traffic anomalies.

[0052] The abnormal behavior detection module is used to detect the probability of abnormal behavior of attendees and obtain the probability of abnormal behavior.

[0053] The comprehensive risk factor calculation module calculates the comprehensive risk factor of the meeting based on the probability of abnormal network traffic and the probability of abnormal meeting behavior.

[0054] The reaction processing module determines the response strategy based on the comprehensive risk factor.

[0055] The network traffic anomaly detection module includes a video conferencing traffic detection model.

[0056] The video conferencing traffic detection model includes a data input layer, a feature training layer, and a result output layer;

[0057] The data output layer is used to input the grayscale image of network traffic into the model for training.

[0058] The feature training layer is used to train the input network traffic grayscale image and output the training result; wherein the feature training layer includes a first convolutional training block, a second convolutional training block, a third convolutional training block and a fourth convolutional training block;

[0059] The output layer is used to fuse and transform the training results to obtain the anomaly probability of the network traffic grayscale image; wherein the output layer contains a similarity anomaly factor for weighting the training results.

[0060] The data stream characteristics of the video conferencing traffic detection model are as follows:

[0061] The grayscale image of network traffic is input into the model through the data input layer to obtain dataset U1;

[0062] The dataset U1 is trained using the first convolutional training block to obtain dataset U2;

[0063] The dataset U2 is trained using the second convolutional training block to obtain dataset U3;

[0064] The dataset U3 is trained by the third convolutional training block to obtain dataset U4;

[0065] The dataset U4 is trained by the fourth convolutional training block to obtain dataset U5;

[0066] The dataset U5 is processed by the result output layer to output the probability of network traffic anomalies.

[0067] The abnormal participation behavior detection module calculates the probability of abnormal participation behavior of the participants using an abnormal participation behavior formula;

[0068] The formula for the abnormal meeting participation behavior is:

[0069]

[0070] Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

[0071] The comprehensive risk coefficient calculation module calculates the comprehensive risk coefficient of the online video conference based on the abnormal probability of network traffic and the abnormal probability of participation behavior of the participants.

[0072]

[0073] Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1t cσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the probability of abnormal behavior in the meeting during stage t; e is a mathematical constant.

[0074] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0075] 1. This invention acquires network traffic from video conference IP addresses in real time using mirroring port technology. After cleaning the network traffic data, it converts it into a grayscale image. The similarity between phased and cumulative network traffic data from participating IP addresses is calculated to obtain a first-type similarity and a second-type similarity. A similarity anomaly factor is then derived from this similarity. This similarity anomaly factor is used as an influencing factor in the video conference traffic detection model to detect the probability of network traffic anomalies, thus obtaining the probability of abnormal network traffic for each participant. This invention obtains a similarity anomaly factor by comparing the network traffic data of each participant with that of the remaining participants. Then, the video conference traffic detection model uses this similarity anomaly factor to weight the network traffic data, which helps to accurately identify abnormal network traffic.

[0076] 2. This invention performs anomaly analysis on the behavior of participants in online video conferences, proposes an anomaly formula for participant behavior, and calculates the probability of abnormal behavior. The formula sets a threshold for the cumulative number of meeting room transitions to measure anomalies; it also sets a threshold for the number of meeting room transitions at different stages to measure anomalies; and it considers the changes in the number of meeting room transitions at different stages, calculating the probability of abnormal behavior through multiple factors. This invention monitors the cumulative and stage-based number of meeting room transitions for participants, and accurately measures abnormal behavior by setting appropriate thresholds.

[0077] 3. This invention calculates the probability of abnormal network traffic and abnormal participation behavior for all participants, and then uses these probabilities to measure the overall risk coefficient of the video conference. This overall risk coefficient considers the combined impact of abnormal network traffic and abnormal participation behavior probabilities, and incorporates a non-linear factor. It also includes the variances of the probability of abnormal network traffic and abnormal participation behavior for all participants. This invention calculates the combined impact and variance fluctuations of the probability of abnormal network traffic and abnormal participation behavior for participants to obtain the overall risk coefficient of the video conference, which can accurately measure any abnormal situations that may occur during the entire video conference. Attached Figure Description

[0078] Figure 1This is a schematic diagram of the video conferencing network detection method of the present invention;

[0079] Figure 2 This is a schematic diagram of the similarity anomaly factor calculation process for network traffic of meeting participants according to the present invention;

[0080] Figure 3 This is a schematic diagram of the video conferencing traffic detection model structure of the present invention;

[0081] Figure 4 This is a schematic diagram of the convolution training block structure of the present invention;

[0082] Figure 5 This is a schematic diagram of the convolutional attention module structure of the present invention;

[0083] Figure 6 This is a schematic diagram of the system structure of the present invention. Detailed Implementation

[0084] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0085] Most existing video conferencing network detection technologies focus on detecting overall video conferencing traffic, without adequately considering the specific scenarios. This results in inaccurate network detection for video conferencing and a tendency to make misjudgments.

[0086] To address this, a video conferencing network detection method and system are proposed, including:

[0087] Obtain the participation information of participants in multiple video conference sessions; the participation information includes participants' network traffic data and session entry and exit data;

[0088] The network traffic data of the attendees was analyzed to obtain the probability of network traffic anomalies.

[0089] Real-time network traffic data of participating IP addresses during online video conferences can be obtained through network mirroring port technology.

[0090] Based on the set time threshold, obtain the phased network traffic data and cumulative network traffic data of the participating IP addresses;

[0091] After cleaning the phased network traffic data and the cumulative network traffic data, they are converted into two-dimensional grayscale images to obtain phased traffic grayscale images and cumulative traffic grayscale images.

[0092] Anomaly detection is performed on the stage traffic grayscale map and the cumulative traffic grayscale map using a video conferencing traffic detection model to obtain the probability of network traffic anomalies for the corresponding participants. The similarity anomaly factor between the stage traffic grayscale map and the cumulative traffic grayscale map and the grayscale map corresponding to the remaining participants' IP addresses is used as an influencing factor and applied to the detection of the video conferencing traffic detection model.

[0093] The data on attendees entering and exiting the meeting venue during the meeting was analyzed to obtain the probability of abnormal attendee behavior.

[0094] Based on the set time threshold, obtain the cumulative number of times participants switched between meeting rooms and the number of times they switched between meeting rooms during the meeting.

[0095] The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula;

[0096] The overall risk coefficient of the video conference is obtained by combining the abnormal probability of network traffic and the abnormal probability of participant behavior.

[0097] Example 1;

[0098] In recent years, the rapid development of online video courses has enriched teaching methods, and many people have benefited from it. However, some individuals have obtained online meeting information and passwords through various channels and then systematically interfered with online classes, maliciously disrupting the teaching order and causing significant negative impacts on normal online education. Therefore, this invention will be described in detail, using online video courses as an example.

[0099] A well-known educational organization is conducting a public welfare education activity, inviting outstanding lecturers to conduct live courses. The live courses include five courses in different fields, namely Course A, Course B, Course C, Course D and Course E. Multiple courses are conducted simultaneously through multiple online video conferences, and all live courses are offered free of charge to people from all walks of life.

[0100] Obtain the participation information of participants in multiple online video courses; the participation information includes participants' network traffic data and entry and exit data of the venues;

[0101] The network traffic data of the attendees was analyzed to obtain the probability of network traffic anomalies.

[0102] Real-time network traffic data of participating IP addresses during online video conferences can be obtained through network mirroring port technology.

[0103] Regarding data acquisition, in order to reflect the security status of video conferencing in real time, this invention uses port mirroring technology to obtain real-time network traffic data of video conferencing. The specific data acquisition and processing steps are as follows:

[0104] Real-time network traffic data acquisition:

[0105] Port mirroring technology is used to capture network traffic from the IP addresses of participants in a video conference. Port mirroring is a network management technique designed to copy the traffic of a specific port on a network device to another port for monitoring and analysis. Through port mirroring, network traffic can be observed and recorded non-intrusively without interrupting normal network operations.

[0106] DPDK is used to collect network mirror traffic data. DPDK is a high-speed data processing tool that uses polling to send and receive data packets, which can effectively deal with problems such as multiple copies and time consumption of user kernel mode switching in the process of network traffic data processing.

[0107] The collected network mirror traffic data is processed using Spark Streaming technology. Spark Streaming is a stream processing framework that performs real-time processing of data streams and features high scalability, high throughput, and high fault tolerance.

[0108] To reflect the changing trend of network traffic of participating IP addresses during video conferences, this invention sets a time threshold and divides network data traffic into phase network traffic data according to the time threshold. The network traffic data from the start of the video conference to the most recent phase is called cumulative network traffic data. The phase network traffic data and the cumulative network traffic data are continuously updated as the time phase progresses.

[0109] Based on the set time threshold, obtain the phased network traffic data and cumulative network traffic data of the participating IP addresses;

[0110] After cleaning the phased network traffic data and the cumulative network traffic data, they are converted into two-dimensional grayscale images to obtain phased traffic grayscale images and cumulative traffic grayscale images.

[0111] Anomaly detection is performed on the stage traffic grayscale map and the cumulative traffic grayscale map using a video conferencing traffic detection model to obtain the probability of network traffic anomalies for the corresponding participants. The similarity anomaly factor between the stage traffic grayscale map and the cumulative traffic grayscale map and the grayscale map corresponding to the remaining participants' IP addresses is used as an influencing factor and applied to the detection of the video conferencing traffic detection model.

[0112] The data on attendees entering and exiting the meeting venue during the meeting was analyzed to obtain the probability of abnormal attendance behavior.

[0113] The calculation process for the similarity anomaly factor is as follows: Figure 2 As shown:

[0114] Obtain the phased network traffic data and the cumulative network traffic data of the participating IP address i;

[0115] The stage network traffic data and the cumulative network traffic data are converted into two-dimensional grayscale images to obtain the stage traffic grayscale image and the cumulative traffic grayscale image;

[0116] The mean values ​​of the grayscale images of the phase traffic and the cumulative traffic for the participating IP address i are calculated.

[0117] The grayscale image of the stage flow and the grayscale image of the cumulative flow are compared with the mean value of the corresponding image to obtain the corresponding binary image of the stage flow and the binary image of the cumulative flow.

[0118] Calculate the hash values ​​of the stage traffic binary graph and the cumulative traffic binary graph to obtain the stage traffic hash value and the cumulative traffic hash value;

[0119] The first type of similarity is calculated based on the phase traffic hash value of the participating IP address i and the phase traffic hash value of the participating IP address of the same category. The first type of similarity is used to measure the similarity of the grayscale images of the corresponding phase traffic.

[0120] The second type of similarity is calculated based on the cumulative traffic hash value of the participating IP address i and the cumulative traffic hash value of the participating IP addresses of the same category. The second type of similarity is used to measure the similarity of the corresponding cumulative traffic grayscale images.

[0121] The similarity anomaly factor of the network traffic data of participant i is calculated based on the first type of similarity and the second type of similarity:

[0122]

[0123] Where, r t i For participant i at stage t, r is a similarity anomaly factor. t i The smaller the value of r, the smaller the abnormal trend; when r t i A larger value indicates a stronger abnormal trend; ss t ih The first-class similarity between participant i and participant h in network traffic data at stage t; ls t ik Let be the second type of similarity between participant i and participant k in network traffic at stage t; ∈ is the similarity control coefficient.

[0124] The present invention will now demonstrate the detailed calculation process using specific data, where the similarity control coefficient ∈ takes the value 0.5.

[0125] Table 1. Similarity data of network traffic of participants during Phase i, Stage 5

[0126] i z x c v b n Type I similarity 0.78 0.64 0.84 0.72 0.63 0.81 Second type of similarity 0.85 0.76 0.72 0.88 0.76 0.59

[0127] Based on the data in Table 1, the formula for calculating the similarity anomaly factor of participant i in stage 5 is as follows:

[0128] r 5 i =exp(1-0.74*0.76)*0.5=0.78;

[0129] This invention acquires the network traffic of video conference IP addresses in real time using mirror port technology. After cleaning the network traffic data, it is converted into a grayscale image. The similarity between the phased network traffic data and the cumulative network traffic data of the participating IP addresses is calculated to obtain a first type of similarity and a second type of similarity. A similarity anomaly factor is obtained through the similarity. The similarity anomaly factor is used as an influencing factor to apply to the video conference traffic detection model to detect the probability of network traffic anomalies, thereby obtaining the probability of network traffic anomalies of the participants.

[0130] The video conferencing traffic detection model is an improvement upon the CNN convolutional neural network model; its specific structure is as follows: Figure 3 As shown.

[0131] The video conferencing traffic detection model includes a data input layer, a feature training layer, and a result output layer;

[0132] The data output layer is used to input the network traffic grayscale image into the model for training.

[0133] The feature training layer is used to train the input network traffic grayscale image and output the training result; wherein the feature training layer includes a first convolutional training block, a second convolutional training block, a third convolutional training block and a fourth convolutional training block;

[0134] The output layer is used to fuse and transform the training results to obtain the anomaly probability of the network traffic grayscale image; wherein the output layer contains the similarity anomaly factor used to weight the training results.

[0135] The detection process of the video conferencing traffic detection model is as follows: the grayscale image of network traffic is input into the model through the data input layer to obtain dataset U1; dataset U1 is trained through the first convolutional training block to obtain dataset U2; dataset U2 is trained through the second convolutional training block to obtain dataset U3; dataset U3 is trained through the third convolutional training block to obtain dataset U4; dataset U4 is trained through the fourth convolutional training block to obtain dataset U5; dataset U5 is processed through the result output layer to output the probability of abnormal network traffic.

[0136] The convolutional training block sequentially comprises a 1x1 convolutional layer, a 3x3 convolutional layer, a 3x3 convolutional layer, a 1x1 convolutional layer, and a convolutional attention module; the specific structure of the convolutional training block is as follows: Figure 4 As shown.

[0137] The convolutional attention module uses the CBAM attention mechanism, consisting of a channel attention module and a spatial attention module, implementing a sequential attention structure from channel to spatial. The detailed structure of the convolutional attention module is as follows: Figure 5 As shown.

[0138] Among them, channel attention is used to handle the allocation relationship of feature map channels, and the attention allocation on two dimensions enhances the effect of the attention mechanism on improving model performance.

[0139] The channel attention mechanism module works as follows: First, the input feature maps are subjected to global max pooling and global average pooling respectively; the feature mapping is based on two-dimensional compression to obtain two different dimensional feature descriptions, and the pooled feature maps share a multilayer perceptron network; the number of channels is first reduced through a fully connected layer, and then restored through another fully connected layer; the two feature maps are stacked in the channel dimension, and the weights of each channel of the feature map are normalized by the sigmoid activation function; the normalized weights are multiplied by the input feature map.

[0140] Spatial attention allows neural networks to focus more on pixel regions in an image that play a decisive role in classification, while ignoring irrelevant regions.

[0141] The spatial attention mechanism module is as follows: First, max pooling and average pooling are performed on the input feature map in the channel dimension, and the two pooled feature maps are stacked in the channel dimension; then, convolutional kernels are used to fuse channel information; finally, the spatial weights of the feature map are normalized by the sigmoid function after the convolution result, and then the input feature map and weights are multiplied.

[0142] The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula.

[0143] The formula for the abnormal meeting participation behavior is:

[0144]

[0145] Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

[0146] The following uses the data in Table 2 as an example to calculate the actual probability of abnormal meeting participation behavior.

[0147] Table 2. Meeting Behavior Data of Participant i

[0148] stage 1 2 3 4 5 6 7 Number of times the venue was switched between stages 1 0 2 3 5 3 4 Total number of venue switching times 1 1 3 6 11 14 18

[0149] in, The threshold for the cumulative number of venue conversions is set to 15. The threshold for the number of times a session can be switched is set to 4.

[0150] The formula and result for calculating the probability of abnormal behavior of participant i in phase 5 are as follows:

[0151]

[0152] The formula and result for calculating the probability of abnormal behavior of participant i in phase 6 are as follows:

[0153]

[0154] The formula and result for calculating the probability of abnormal behavior of participant i in phase 7 are as follows:

[0155]

[0156] This invention performs anomaly analysis on the behavior of participants in online video conferences, proposing an anomaly formula to calculate the probability of abnormal behavior. The formula sets a threshold for the cumulative number of meeting room transitions to measure anomalies; it also sets a threshold for the number of meeting room transitions at different stages to measure anomalies; and it considers the changes in the number of meeting room transitions at different stages. By considering multiple factors, the probability of abnormal behavior is calculated. This invention monitors the cumulative and stage-based number of meeting room transitions and accurately measures abnormal behavior by setting appropriate thresholds.

[0157] The overall risk coefficient of the online video conference is calculated based on the probability of abnormal network traffic and the probability of abnormal participation behavior of the participants.

[0158]

[0159] Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1 t cσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the abnormal probability of participant behavior in stage t; e is a mathematical constant.

[0160] The following is a calculation of the overall risk factor based on the data in Table 3.

[0161] Table 3. Participants and Risk Probability Table

[0162] Participants Network traffic anomaly probability Probability of Abnormal Participation Behavior 1 0.44 0.94 2 0.74 0.36 3 0.65 0.82 4 0.23 0.35 5 0.67 0.59 6 0.45 0.67

[0163] The following can be calculated using the above formula and data:

[0164]

[0165] This invention calculates the probability of abnormal network traffic and abnormal participation behavior for all participants, and then uses these probabilities to measure the overall risk coefficient of the video conference. This overall risk coefficient considers the combined impact of abnormal network traffic and abnormal participation behavior probabilities, and incorporates a non-linear factor. Furthermore, it includes the variances of the probability of abnormal network traffic and abnormal participation behavior for all participants. This invention calculates the combined impact and variance fluctuations of the probability of abnormal network traffic and abnormal participation behavior for participants to obtain the overall risk coefficient of the video conference, which can accurately measure any abnormal situations that may occur during the entire video conference.

[0166] Example 2;

[0167] Furthermore, this invention uses an online academic discussion and sharing session to illustrate the specific details of this method. The academic discussion and sharing session is organized by university P, which is responsible for opening and closing remarks, chairing the meeting, and controlling the progress. It also needs to answer questions from the participants. The academic discussion and sharing session covers multiple different academic fields. In addition, the meeting is open to scholars and students from universities across the country. Anyone who is interested in participating in the meeting can join the meeting through the meeting ID and can communicate and interact at appropriate times.

[0168] First, the similarity anomaly factor of the participants is calculated; then, the video conferencing anomaly detection model is used to detect anomalies using the similarity anomaly factor to obtain the probability of abnormal network traffic; the formula for calculating the similarity anomaly factor is as follows:

[0169]

[0170] Where, r t i For participant i at stage t, r is a similarity anomaly factor. t i The smaller the value of r, the smaller the abnormal trend; when r t i A larger value indicates a stronger abnormal trend; ss t ih The first-class similarity between participant i and participant h in network traffic data at stage t; ls t ik Let be the second type of similarity between participant i and participant k in network traffic at stage t; ∈ is the similarity control coefficient.

[0171] Table 4 shows the network traffic data of the participants in this online academic sharing and discussion meeting, where the similarity control coefficient ∈ takes a value of 0.5.

[0172] Table 4. Similarity Table of Network Traffic Data for Participant j in Phase 4

[0173] j q w e r t y Type I similarity 0.59 0.38 0.54 0.46 0.45 0.35 Second type of similarity 0.48 0.51 0.71 0.28 0.60 0.46

[0174] Based on the data in Table 4, the formula for calculating the similarity anomaly factor of participant i in stage 4 is as follows:

[0175] r 4 j =exp(1-0.46*0.51)*0.5=0.23;

[0176] Next, the probability of abnormal meeting behavior of the participants is calculated using the abnormal meeting behavior formula;

[0177] The formula for the abnormal meeting participation behavior is:

[0178]

[0179] Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

[0180] The following uses the data in Table 5 as an example to calculate the actual probability of abnormal meeting behavior.

[0181] Table 5. Meeting Behavior Data of Participant j

[0182] i 1 2 3 4 5 Number of times the venue was switched between stages 2 3 2 5 4 Total number of venue switching times 2 5 7 12 16

[0183] in, The threshold for the cumulative number of venue conversions is set to 15. The threshold for the number of times a session can be switched is set to 4.

[0184] The formula and result for calculating the probability of abnormal behavior of participant j in phase 4 are as follows:

[0185]

[0186] Finally, the overall risk coefficient of the online video conference can be calculated by using the abnormal probability of network traffic and the abnormal probability of participation behavior of the participants.

[0187]

[0188] Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1 t cσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the abnormal probability of participant behavior in stage t; e is a mathematical constant.

[0189] The above are specific embodiments based on the technical solution of the present invention. Various changes made to the embodiments without departing from the basic principles and ideas of the present invention are all within the protection scope of the present invention.

Claims

1. A method for detecting video conferencing networks, characterized in that: Obtain the participation information of participants in multiple video conference sessions; the participation information includes participants' network traffic data and session entry and exit data; The network traffic data of the attendees was analyzed to obtain the probability of network traffic anomalies. The specific steps are as follows: Real-time network traffic data of participating IP addresses during online video conferences can be obtained through network mirroring port technology. Based on the set time threshold, obtain the phased network traffic data and cumulative network traffic data of the participating IP addresses; After cleaning the phased network traffic data and the cumulative network traffic data, they are converted into two-dimensional grayscale images to obtain phased traffic grayscale images and cumulative traffic grayscale images. Anomaly detection is performed on the stage traffic grayscale map and the cumulative traffic grayscale map using a video conferencing traffic detection model to obtain the probability of network traffic anomalies for the corresponding participants. The similarity anomaly factor between the stage traffic grayscale map and the cumulative traffic grayscale map and the grayscale map corresponding to the remaining participants' IP addresses is used as an influencing factor and applied to the detection of the video conferencing traffic detection model. The probability of abnormal meeting behavior is obtained by detecting the meeting attendees' entry and exit data. Based on the set time threshold, obtain the cumulative number of times participants switched between meeting rooms and the number of times they switched between meeting rooms during the meeting. The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula; The overall risk coefficient of the video conference is obtained by combining the abnormal probability of network traffic and the abnormal probability of participant behavior.

2. The video conferencing network detection method according to claim 1, characterized in that: The calculation process for the similarity anomaly factor is as follows: Obtain the phased network traffic data and the cumulative network traffic data of the participating IP address i; The stage network traffic data and the cumulative network traffic data are converted into two-dimensional grayscale images to obtain the stage traffic grayscale image and the cumulative traffic grayscale image; The mean values ​​of the grayscale images of the phase traffic and the cumulative traffic for the participating IP address i are calculated. The grayscale image of the stage flow and the grayscale image of the cumulative flow are compared with the mean value of the corresponding image to obtain the corresponding binary image of the stage flow and the binary image of the cumulative flow. Calculate the hash values ​​of the stage traffic binary graph and the cumulative traffic binary graph to obtain the stage traffic hash value and the cumulative traffic hash value; The first type of similarity is calculated based on the phase traffic hash value of the participating IP address i and the phase traffic hash value of the participating IP address of the same category. The first type of similarity is used to measure the similarity of the grayscale images of the corresponding phase traffic. The second type of similarity is calculated based on the cumulative traffic hash value of the participating IP address i and the cumulative traffic hash value of the participating IP addresses of the same category. The second type of similarity is used to measure the similarity of the corresponding cumulative traffic grayscale images.

3. The video conferencing network detection method according to claim 2, characterized in that: The similarity anomaly factor of the network traffic data of participant i is calculated based on the first type of similarity and the second type of similarity: Where, r t i For participant i at stage t, r is a similarity anomaly factor. t i The smaller the value of r, the smaller the abnormal trend; when r t i A larger value indicates a stronger abnormal trend; ss t ih The first-class similarity between participant i and participant h in network traffic data at stage t; ls t ik Let be the second type of similarity between participant i and participant k in network traffic at stage t; ∈ is the similarity control coefficient.

4. The video conferencing network detection method according to claim 1, characterized in that: The video conferencing traffic detection model includes a data input layer, a feature training layer, and a result output layer; The data output layer is used to input the network traffic grayscale image into the model for training. The feature training layer is used to train the input network traffic grayscale image and output the training result; The feature training layer includes a first convolutional training block, a second convolutional training block, a third convolutional training block, and a fourth convolutional training block. The output layer is used to fuse and transform the training results to obtain the anomaly probability of the network traffic grayscale image; wherein the output layer contains the similarity anomaly factor used to weight the training results. The detection process of the video conferencing traffic detection model is as follows: The grayscale image of network traffic is input into the model through the data input layer to obtain dataset U1; The dataset U1 is trained using the first convolutional training block to obtain dataset U2; The dataset U2 is trained using the second convolutional training block to obtain dataset U3; The dataset U3 is trained by the third convolutional training block to obtain dataset U4; The dataset U4 is trained by the fourth convolutional training block to obtain dataset U5; The dataset U5 is processed by the result output layer to output the probability of network traffic anomalies.

5. The video conferencing network detection method according to claim 1, characterized in that: The probability of abnormal meeting behavior of the participants is calculated using an abnormal meeting behavior formula; The formula for the abnormal meeting participation behavior is: Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

6. The video conferencing network detection method according to claim 1, characterized in that: The overall risk coefficient of the online video conference is calculated based on the probability of abnormal network traffic and the probability of abnormal participation behavior of the participants. Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1 t cσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the abnormal probability of participant behavior in stage t; e is a mathematical constant.

7. A video conferencing network detection system, characterized in that: The video conferencing network detection system includes a data acquisition module, a data cleaning module, a network traffic anomaly detection module, a participant behavior anomaly detection module, a comprehensive risk factor calculation module, and a response processing module. The data acquisition module is used to acquire the participation information of participants during the video conference in real time; the participation information includes network traffic data of the participants' IP addresses and the participants' entry and exit from the venue; The data cleaning module is used to clean and process the obtained network traffic data. The network traffic anomaly detection module is used to calculate the probability of anomalies in the network traffic data of the attendees, and to obtain the probability of network traffic anomalies. The abnormal behavior detection module is used to detect the probability of abnormal behavior of attendees and obtain the probability of abnormal behavior. The comprehensive risk factor calculation module calculates the comprehensive risk factor of the meeting based on the probability of abnormal network traffic and the probability of abnormal meeting behavior. The reaction processing module determines the response strategy based on the comprehensive risk factor.

8. A video conferencing network detection system according to claim 7, characterized in that: The network traffic anomaly detection module includes a video conferencing traffic detection model. The video conferencing traffic detection model includes a data input layer, a feature training layer, and a result output layer; The data output layer is used to input the grayscale image of network traffic into the model for training. The feature training layer is used to train the input network traffic grayscale image and output the training result; The feature training layer includes a first convolutional training block, a second convolutional training block, a third convolutional training block, and a fourth convolutional training block. The output layer is used to fuse and transform the training results to obtain the anomaly probability of the network traffic grayscale image; wherein the output layer contains a similarity anomaly factor for weighting the training results. The data stream characteristics of the video conferencing traffic detection model are as follows: The grayscale image of network traffic is input into the model through the data input layer to obtain dataset U1; The dataset U1 is trained using the first convolutional training block to obtain dataset U2; The dataset U2 is trained using the second convolutional training block to obtain dataset U3; The dataset U3 is trained by the third convolutional training block to obtain dataset U4; The dataset U4 is trained by the fourth convolutional training block to obtain dataset U5; The dataset U5 is processed by the result output layer to output the probability of network traffic anomalies.

9. A video conferencing network detection system according to claim 7, characterized in that: The abnormal participation behavior detection module calculates the probability of abnormal participation behavior of the participants using an abnormal participation behavior formula; The formula for the abnormal meeting participation behavior is: Among them, dg t i Let lg be the probability of abnormal behavior of participant i in stage t; t i The cumulative number of times participant i switched between meeting rooms during phase t; sg t i The number of times participant i switches between stage venues in stage t; The threshold for the cumulative number of venue conversions is set. The threshold for the number of times a session can be switched is set; e is a mathematical constant.

10. A video conferencing network detection system according to claim 7, characterized in that: The comprehensive risk coefficient calculation module calculates the comprehensive risk coefficient of the online video conference based on the abnormal probability of network traffic and the abnormal probability of participation behavior of the participants. Among them, cp t The overall risk factor for video conferencing at stage t; dg t i The probability of abnormal behavior of participant i in stage t; kg t i The probability of abnormal network traffic for participant i during stage t; cσ 1 t cσ is the variance of the probability of network traffic anomalies in stage t. 2 t Let be the variance of the abnormal probability of participant behavior in stage t; e is a mathematical constant.