Distributed monitoring and automatic response control system for network security devices
Patent Information
- Application Number
- CN202512030825.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-30
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2045-12-30
AI Technical Summary
[0002]在当代复杂网络安全架构中,现有的分布式安全设备监控与控制技术面临着严峻的系统性挑战
本发明提升了企业级网络安全防护体系的协同作战能力和运行稳定性,在面对复杂多变的网络攻击时,本发明能够精准识别防护链路中的潜在瓶颈,智能调整资源分配策略,防止安全事件引发的级联失效,确保防护体系的整体韧性。特别在高压力网络环境下,本发明能使安全设备能够根据威胁态势无缝协作,既保持全局防御策略的一致性,又能针对本地特殊威胁做出快速响应。这种协同运作模式减轻了安全团队的运维负担,将日常资源调配从人工决策转为智能化自动响应,使安全专家能够专注于更高层次的威胁分析和防御策略制定。本发明的预见性调控能力确保了关键业务的持续可用,即使在遭受大规模DDoS攻击或零日漏洞利用时,也能保持检测和防护能力的平稳输出,避免了传统架构中常见的防护质量断崖式下降。
Smart Images

Figure CN121966957B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of monitoring and automatic control technology, and more specifically, to a distributed monitoring and automatic response control system for network security devices. Background Technology
[0002] In contemporary complex network security architectures, existing distributed security device monitoring and control technologies face severe systemic challenges. Large enterprises and data centers typically deploy dozens of security devices to form multi-layered defenses, including firewalls, intrusion detection systems, and threat analysis platforms. However, these devices exhibit complex resource competition and traffic dependencies, forming a hidden coupled network. Existing technologies manage devices as independent units, ignoring how load changes on front-end devices can be transmitted to back-end analysis systems through coupling effects during traffic surges or DDoS attacks, leading to a chain reaction of collapse in the entire protection chain. During major security incidents, the non-linear coupling between devices means that adjustments to a single device often trigger abnormal fluctuations in other devices, and existing monitoring systems lack effective methods for coupling identification and quantitative analysis, making it impossible to predict such cascading effects. Furthermore, both perimeter protection devices and internal network analysis devices use the same resource allocation algorithm, ignoring the differences in coupling characteristics among different device groups, resulting in inefficient resource allocation. In real-time transaction security protection, it is frequently observed that perimeter devices are simultaneously affected by multiple groups of devices, leading to control conflicts. The system cannot effectively handle this particularity, resulting in unstable and fluctuating protection capabilities. Existing systems generally lack adaptive mechanisms. When faced with dynamic threats such as zero-day vulnerability outbreaks or ransomware attacks, they cannot automatically adjust detection depth and resource allocation strategies based on attack characteristics, resulting in delayed and rigid responses. A particularly pronounced problem in cloud security services is that centralized control architectures prevent distributed detection nodes from responding quickly to local threats, while completely decentralized control renders global collaborative defense ineffective. Furthermore, existing technologies lack a precise mathematical description of the dynamic characteristics of security device clusters, and control decisions are often based on empirical rules rather than system theory. This leads to instability and difficulty in optimization under high-pressure network environments, causing performance degradation in the protection system at the most critical moments when stability is most needed.
[0003] In view of this, the present invention proposes a distributed monitoring and automatic response control system for network security devices to solve the above problems. Summary of the Invention
[0004] To overcome the aforementioned deficiencies of the prior art and to achieve the above objectives, the present invention provides the following technical solution: a distributed monitoring and automatic response control system for network security devices, comprising: The data acquisition module is used to obtain real-time operational status data of multiple network security devices deployed in a distributed manner. The operational status data includes device processing load rate, response latency, and resource utilization. The deviation analysis module is used to compare the operating status variables with the preset system target operating status and calculate the state deviation vector of each network security device. The function modeling module is used to construct the control deviation transfer function of each network security device based on the state deviation vector. The control deviation transfer function describes the evolution of the device state deviation over time. The coupling analysis module is used to identify control coupling channels between devices and calculate the coupling transfer coefficient and coupling time constant of the coupling channels. The system modeling module is used to construct a multi-input multi-output control system model for distributed network security devices based on the control deviation transfer function, coupling transfer coefficient, and coupling time constant. The control system model includes the state space equations of each device and the coupling matrix between devices. The controllability analysis module is used to perform controllability analysis on the control system model and identify strongly coupled and weakly coupled device groups in the system. The controller design module is used to design decoupling controllers for strongly coupled device groups. It cancels the coupling effect between devices by constructing a decoupling compensation network and generates decoupling control laws for each device. For a group of loosely coupled devices, a distributed controller is designed, which independently configures a feedback controller for each device and generates an independent control law for each device. The strategy integration module is used to integrate decoupled control laws with independent control laws to form a distributed control strategy, and calculate the control adjustment quantities of each network security device based on the distributed control strategy. The control execution and evaluation module is used to perform control adjustments on each network security device according to the control adjustment amount, collect the operating status quantities after control adjustment, calculate the dynamic performance index of the control system, and adaptively adjust the control parameters of the decoupled controller and the distributed controller based on the dynamic performance index.
[0005] The technical effects and advantages of the distributed monitoring and automatic response control system for network security devices of this invention are as follows: This invention enhances the collaborative combat capabilities and operational stability of enterprise-level network security protection systems. When facing complex and ever-changing network attacks, it can accurately identify potential bottlenecks in the protection chain, intelligently adjust resource allocation strategies, prevent cascading failures caused by security incidents, and ensure the overall resilience of the protection system. Especially in high-pressure network environments, this invention enables security devices to seamlessly collaborate based on the threat landscape, maintaining consistency in global defense strategies while responding quickly to specific local threats. This collaborative operation mode reduces the operational burden on security teams, shifting daily resource allocation from manual decision-making to intelligent automatic response, allowing security experts to focus on higher-level threat analysis and defense strategy development. The predictive control capabilities of this invention ensure the continuous availability of critical business operations, maintaining stable output of detection and protection capabilities even during large-scale DDoS attacks or zero-day exploits, avoiding the precipitous drop in protection quality common in traditional architectures. Attached Figure Description
[0006] Figure 1 This is a schematic diagram of the distributed monitoring and automatic response control system of the network security device of the present invention. Detailed Implementation
[0007] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0008] This application provides a distributed monitoring and automatic response control system for network security devices. The system's execution entities include, but are not limited to, entities such as a security operations center, a distributed network protection system, a multi-layered security defense platform, and an adaptive security architecture, which can be considered general control nodes in this application. The automatic response control system includes, but is not limited to, at least one of a cloud-based status monitoring engine, a distributed controller coordination system, and an intelligent load balancer.
[0009] Please see Figure 1 In this embodiment of the invention, the distributed monitoring and automatic response control system for network security devices includes: The data acquisition module is used to obtain real-time operational status data from multiple distributed network security devices. These operational status data include key indicators such as device processing load, response latency, and resource utilization, acquired in real-time through multi-channel data acquisition interfaces. Device processing load reflects the utilization level of the device's current processing capacity, response latency records the time delay in the device's response to requests, and resource utilization indicates the usage of the device's computing, storage, and network resources. This data provides comprehensive raw material for subsequent analysis, ensuring the accuracy and real-time performance of monitoring and control.
[0010] The deviation analysis module compares the operating state variables with the preset system target operating state to calculate the state deviation vector of each network security device. The state deviation vector includes dimensions such as load rate deviation, response latency deviation, and resource utilization deviation, formed through normalization and dynamic weighting. Load rate deviation reflects the difference between the actual load and the expected load of the device; response latency deviation quantifies the difference between the device's response time and the target response time; and resource utilization deviation indicates the degree of deviation in resource utilization. These multi-dimensional deviations collectively constitute the device's "state deviation fingerprint," providing a foundation for subsequent control system design.
[0011] The function modeling module is used to construct the control deviation transfer function for each network security device based on the state deviation vector. This module extracts the dynamic characteristics of device state deviations through time-domain sampling and frequency-domain analysis, constructing an accurate mathematical model. The control deviation transfer function describes the evolution of device state deviations over time, including the convergence rate, steady-state characteristics, and dynamic response modes, providing crucial single-device dynamic characteristics for system model construction.
[0012] The coupling analysis module identifies control coupling channels between devices and calculates the coupling transfer coefficient and coupling time constant of these channels. Through excitation-response experiments and correlation analysis, this module accurately identifies the interactive effects between devices and establishes a coupling relationship model. The coupling transfer coefficient quantifies the intensity of the influence between devices, and the coupling time constant reflects the time delay characteristics of the influence; together, they describe the complex interactions in a distributed device network, providing a basis for multi-device coordinated control.
[0013] The system modeling module is used to construct a multi-input multi-output control system model for distributed network security devices based on the control deviation transfer function, coupling transfer coefficient, and coupling time constant. This model integrates the dynamic characteristics of individual devices and the coupling relationships between devices to form a complete system state-space equation and coupling matrix, accurately describing the dynamic behavior of the entire distributed system and providing a mathematical foundation for subsequent control strategy design.
[0014] The controllability analysis module is used to perform controllability analysis on the control system model, identifying strongly coupled and weakly coupled device groups within the system. Through matrix factorization and eigenvector analysis, it evaluates the controllability of the system and the coupling strength between devices, providing a scientific basis for selecting differentiated control strategies and ensuring the relevance and effectiveness of the control scheme.
[0015] The controller design module is used to design decoupling controllers for strongly coupled device groups and distributed controllers for weakly coupled device groups. The decoupling controller cancels the coupling effect between devices by constructing a decoupling compensation network, realizing coordinated control of strongly coupled devices; the distributed controller configures feedback controllers for each independent device, realizing individual optimization of weakly coupled devices, forming a complete hierarchical control strategy system.
[0016] The strategy integration module integrates decoupled control laws with independent control laws to form a distributed control strategy. Based on this strategy, it calculates the control adjustment quantities for each network security device. This module comprehensively considers the scope and priority of different control laws, coordinates the outputs of each controller, and generates unified control adjustment quantities to ensure the consistency and coordination of the overall control strategy.
[0017] The control execution and evaluation module is used to perform control adjustments on each network security device according to the control adjustment amount, collect the operating status quantities after control adjustment, calculate the dynamic performance index of the control system, and adaptively adjust the control parameters of the decoupled controller and distributed controller based on the dynamic performance index. This module evaluates the control effect and forms a closed-loop feedback mechanism to ensure the adaptability and stability of the control system.
[0018] The modules are connected via wired and / or wireless means to enable data transmission between them.
[0019] In this embodiment of the invention, the detailed implementation steps for comparing the operating state quantity with the preset system target operating state and calculating the state deviation vector of each network security device include: The device processing load rate, response latency, and resource utilization rate of each network security device at the current sampling moment are extracted to form a device operating status vector. This vector is the foundational data for deviation analysis, reflecting the current actual operating status of the devices. The extraction process employs multi-source data acquisition technology, obtaining accurate data from device monitoring interfaces, log systems, and performance counters. Device processing load rate is typically expressed as the ratio of the number of tasks processed to the device's rated processing capacity; response latency is recorded in milliseconds as the request response time; and resource utilization includes dimensions such as CPU utilization, memory utilization, and network bandwidth utilization. After preprocessing, this data forms a standard-format operating status vector, providing real-time and accurate current values for status comparison.
[0020] The system obtains preset target operating state vectors for each network security device. These vectors are determined based on the device's rated performance parameters and the system's load balancing strategy. The target state vector represents the optimal operating state the system expects the device to achieve and serves as a reference benchmark for deviation calculation. The determination process first establishes basic target values based on the device's rated performance parameters, including maximum processing capacity, standard response time, and resource capacity. Then, considering the system's load balancing strategy and the device's role and position within the current network topology and traffic flow, the target values are dynamically adjusted. For example, devices in core locations may be assigned lower target load rates to maintain sufficient redundancy, while edge devices can handle higher loads. The resulting preset target operating state vectors consider both the inherent capabilities of the devices and the overall system load balancing strategy, providing a reasonable target reference for deviation calculation.
[0021] The difference between the device's operating state vector and the preset target operating state vector is calculated to obtain the initial state deviation vector. The initial deviation vector is the most primitive representation of the difference, directly reflecting the absolute gap between the device's current state and the target state. The calculation process uses vector subtraction, subtracting corresponding dimensions to obtain an initial vector containing load rate deviation, response latency deviation, and resource utilization deviation. This step preserves all information from the original data, providing the foundation for subsequent normalization and weighted processing.
[0022] The components of the initial state deviation vector are normalized, with the normalization benchmark value being the allowable deviation range for each state quantity. Normalization is a crucial step in making deviations of different dimensions comparable, mapping various deviations to a unified standard scale. The process first determines the allowable deviation range for each state quantity, typically based on equipment performance specifications and business requirements; then, using the max-min normalization method, the initial deviation is divided by the corresponding allowable deviation range to obtain the normalized deviation value. The normalization calculation formula is: ; in, This is the normalized deviation value. This is the initial deviation value. This represents the maximum permissible deviation for the corresponding state variable. After normalization, the values of each component are typically within the range of [-1, 1]. Values closer to 0 indicate smaller deviations, while values closer to ±1 indicate deviations closer to or exceeding the permissible range. This unified metric allows for direct comparison and comprehensive analysis of different types of deviations, providing standardized data for subsequent dynamic deviation analysis.
[0023] The rate of change of the normalized state deviation vector within a preset time window is calculated and denoted as the dynamic component of the state deviation. The dynamic component is a key indicator for capturing the evolution trend of deviations, reflecting the speed and direction of changes in equipment state. The calculation process uses the finite difference method, comparing the current deviation with historical deviations within the time window to obtain the rate of change. The window size is typically set to 5-10 sampling periods, reflecting both recent trends and filtering short-term fluctuations. The calculation of the dynamic component enables the system to predict the development trend of deviations, take control measures in advance, and improve the system's predictability and responsiveness.
[0024] The normalized state deviation vector is weighted and combined with the dynamic components of the state deviation. The weighting coefficients are determined based on the system's requirements for steady-state accuracy and dynamic response speed, resulting in the final state deviation vector. The final state deviation vector comprehensively considers both the current deviation value and the deviation trend, reflecting both the degree of static deviation and dynamic change information. A linear weighting method is used for the weighting combination. The weighting coefficients are adjusted according to the system's control objectives; systems with high steady-state accuracy requirements have increased weight for static deviation, while systems with high dynamic response requirements have increased weight for dynamic components. The weighting combination formula is: ; in, This is the final state deviation vector. For the normalized bias vector, For the dynamic component of the deviation, and These are weighting coefficients, and A reasonable weighting strategy enables the system to balance static accuracy and dynamic response capability, improve the overall performance of the control system, and provide a comprehensive description of deviation characteristics for subsequent control deviation transfer function modeling.
[0025] In this embodiment of the invention, the detailed implementation steps for constructing the control deviation transfer function of each network security device based on the state deviation vector include: The historical state deviation vectors of each network security device are sampled in the time domain to obtain a discrete-time series of state deviations. Time-domain sampling is a fundamental data acquisition step in function modeling, forming time-series data by periodically recording device state deviations. The sampling process employs an equal-interval sampling strategy, with the sampling period determined based on the device's dynamic characteristics, typically 1 / 5 to 1 / 10 of the device's characteristic time constant. For fast-responding devices, such as load balancers, the sampling period may be on the order of seconds; while for slowly changing devices, such as storage systems, the sampling period may be on the order of minutes. The sampling duration must at least cover the complete transition process from a stable state to a new stable state, ensuring that all dynamic characteristics are captured. The resulting discrete-time series directly reflects the changing pattern of device state deviations over time and serves as the foundational data for subsequent Z-transform.
[0026] The Z-transform is applied to a discrete-time series to obtain a representation of the state deviation in the Z-domain. The Z-transform is an important mathematical tool for converting discrete-time signals into frequency-domain representations, revealing the frequency characteristics of the signal and the dynamics of the system. The transformation process uses the standard Z-transform formula to map the time series to the Z-plane, facilitating the analysis of the system's characteristic poles and zeros. For long sequences, a fast Z-transform algorithm is used to improve computational efficiency. The result of the Z-transform is a complex function, and its pole and zero distribution directly reflects the system's stability and response characteristics. The Z-domain representation allows complex time series to be expressed using a concise mathematical model, providing convenience for subsequent system characteristic analysis.
[0027] Identifying the characteristic poles and zeros in the Z-domain representation is crucial, as the characteristic poles reflect the system's inherent oscillation modes. These poles and zeros are core characteristics of the system's dynamic properties, determining its response mode and stability. The identification process employs polynomial root solving and factorization techniques to accurately locate the poles and zeros of the Z-domain function. The position of the characteristic poles in the Z-plane directly reflects the system's oscillation characteristics and decay rate: poles closer to the unit circle indicate slow decay, while poles farther from the unit circle indicate rapid decay; the angle of the poles determines the oscillation frequency. By analyzing the pole distribution, it is possible to determine whether the system is underdamped, critically damped, or overdamped, providing key parameters for subsequent transfer function construction.
[0028] Based on the location of the characteristic poles, the state deviation convergence characteristics of each network security device are determined, and the deviation decay time constant is calculated. Deviation convergence characteristics are a crucial consideration in control system design, directly affecting the system's response speed and stability. The determination process is based on the pole's position in the Z-plane, calculating the corresponding time constant and decay rate. The closer the pole is to the origin of the Z-plane, the faster the decay and the quicker the system response; the closer the pole is to the unit circle, the slower the decay and the slower the system response. The time constant is typically defined as the time required for the deviation to decay to 36.8% of its initial value, calculated using the pole's magnitude. The decay time constant directly reflects the speed of the device's control response, is a core parameter of the transfer function, and a crucial basis for subsequent controller design.
[0029] A rational fractional function with characteristic poles and zeros as parameters is constructed as the Z-domain transfer function. The Z-domain transfer function is a mathematical expression of the system's dynamic characteristics, describing the relationship between input and output in a concise form. The construction process uses rational fractions, based on characteristic poles and zeros, to form a standard transfer function expression. For the case with multiple poles and zeros, the complete numerator and denominator polynomials are obtained by factoring. The general form of the Z-domain transfer function is: ; in, It is the gain constant. , ,..., Zero point , ,..., The poles are defined by the order of the function (usually the maximum value between n and m). The order of the function reflects the complexity of the system; a higher order indicates a more complex dynamic system. The constructed Z-domain transfer function is an accurate mathematical model of the system characteristics, providing a foundation for subsequent inverse transform and time-domain analysis.
[0030] The inverse Z-transform of the Z-domain transfer function yields the time-domain control deviation transfer function, which characterizes the dynamic relationship between the control input and the state deviation. The time-domain transfer function is a more intuitive form of system description, directly representing the influence of the input signal on the output. The inverse transform process uses partial fraction expansion and table lookup to convert the Z-domain function into a difference equation or a discrete-time function. For complex transfer functions, numerical calculation methods are used to assist in the transformation. The final time-domain control deviation transfer function may be a composite expression including time delay, damping coefficient, and gain, fully describing the influence mechanism and time process of the control input on the equipment state deviation, providing a directly usable mathematical model for system modeling and controller design.
[0031] In this embodiment of the invention, the detailed implementation steps for identifying control coupling channels between devices based on the control deviation transfer function and calculating the coupling transfer coefficient and coupling time constant of the coupling channel include: Using any one network security device as the first network security device, a step control input is applied to it while keeping the control inputs of other devices unchanged. Step response testing is a fundamental experimental method for identifying coupling relationships between devices, revealing coupling channels by observing the impact of a single device's disturbance on other devices. The test process first selects a device in the network as the test subject, then applies a standard step signal to it, such as a sudden change in the processing load rate adjustment value to a preset percentage, while ensuring that the control inputs of other devices remain unchanged. The amplitude of the step signal is typically set to 10%-30% of the device's rated adjustment range, which is sufficient to elicit a significant response without causing the system to deviate excessively from its normal operating point. The test duration must cover the entire dynamic response process of the system until all devices return to a steady state. This controlled single-variable experimental design ensures that the observed cross-effects accurately reflect the coupling relationships between devices, providing reliable raw data for subsequent coupling analysis.
[0032] The system collects the operational state response curves of the first network security device and its adjacent devices. Response curve acquisition is a crucial step in obtaining coupling effect data, revealing coupling dynamics by recording the time response of each device to disturbances. High-precision synchronous sampling technology is used to ensure temporal consistency of data from multiple devices, with the sampling frequency set to 2-5 times the expected highest response frequency to meet the Nyquist sampling theorem requirements. For each device, three key indicators—load rate, response latency, and resource utilization—are recorded simultaneously to form a multi-dimensional response curve. Filtering and outlier detection techniques are employed during data acquisition to improve signal quality. The acquired response curves visually demonstrate the trajectory of each device's state variables over time. The curve of the first device reflects the direct response, while the curves of adjacent devices reflect the coupling effect, providing fundamental data for coupling measurement.
[0033] The ratio of the change in the operating state variables of adjacent devices to that of the first network security device is denoted as the direct coupling degree. Direct coupling degree is a fundamental indicator for quantifying the strength of mutual influence between devices, and it intuitively reflects the coupling strength through a comparison of response amplitudes. The calculation process first determines the steady-state change amplitude of each device's response, i.e., the difference between the steady state before and after the disturbance; then, it calculates the ratio of the amplitudes of adjacent devices to that of the first device to obtain the direct coupling degree. To ensure the reliability of the results, the average value of multiple experimental data is taken, and the standard deviation is calculated to assess consistency. Coupling degree is usually expressed as a percentage, reflecting the degree of attenuation or amplification of the coupled signal. By analyzing the distribution of coupling degrees among different indicators, the main coupling paths and sensitive parameters can be identified, providing a quantitative basis for determining the coupling channel.
[0034] The process involves determining whether the direct coupling degree exceeds a preset coupling threshold. If it does, a control coupling channel is confirmed to exist between the first network security device and its adjacent device. Coupling channel determination is a crucial step in screening significant coupling relationships from numerous device connections, identifying important control interactions through threshold screening. An appropriate coupling threshold is set during the determination process, typically between 5% and 15%, taking into account the system's noise level and control accuracy requirements. Only device pairs with a direct coupling degree exceeding this threshold are considered to have a significant control coupling channel, requiring special consideration in subsequent control design. This threshold-based screening method avoids overly complex fully connected models while ensuring that important coupling relationships are not ignored, resulting in a reasonably simplified system coupling topology and providing a clear research object for subsequent coupling parameter extraction.
[0035] For device pairs with control coupling channels, the steady-state gain of the operational state response curves of adjacent devices is extracted and denoted as the coupling transfer coefficient. The coupling transfer coefficient is a precise parameter quantifying the coupling strength, reflecting the signal transmission ratio under steady-state conditions. The extraction process first smooths the response curves to filter out noise and fluctuations; then, it identifies the steady-state segment of the curve, typically taking the average of the last 10%-20% of data points; finally, it calculates the steady-state gain, which is the ratio of the steady-state change value of the adjacent device to the control input value of the first device. The coupling transfer coefficient can be positive (positive feedback) or negative (negative feedback), and its absolute value directly reflects the coupling strength. These coefficients constitute the elements of the system coupling matrix and are key parameters for multi-device coordinated control, providing a quantitative description of the coupling strength for system modeling.
[0036] The time required for the response curves of adjacent devices to reach a predetermined percentage of their steady-state values is denoted as the coupling time constant. The coupling time constant is a key parameter describing the dynamic characteristics of coupling, reflecting the time delay and response speed of the coupling effect. The identification process first determines the rise characteristics of the response curve and calculates the time required to reach a specific percentage (typically 63.2% or 95%) of the steady-state value from the initial change. For complex response curves, a parametric fitting method is used to approximate the curve as a standard first- or second-order system response, extracting the time constant. The coupling time constant is measured in seconds or minutes and directly reflects the propagation speed of the coupling effect, serving as an important basis for system dynamic modeling and control timing design. A smaller time constant indicates a faster coupling response, requiring a higher reaction speed from the control system; a larger time constant indicates a slower coupling response, allowing the control system to employ a more conservative control strategy.
[0037] Repeat the above steps, traversing all network security devices, to construct a complete topology diagram of inter-device coupling channels. Topology diagram construction is the final comprehensive step in coupling analysis, forming a complete network coupling relationship diagram through systematic experiments. During the construction process, each device is tested in turn as the first device, comprehensively capturing the coupling relationships of N×N device pairs, ultimately forming a topology diagram containing nodes (devices) and directed edges (coupling channels). The weight of the edge is the coupling transmission coefficient, and the edge attributes include the coupling time constant. For large-scale systems, group testing and parallel experimentation methods can be used to improve efficiency. The final constructed coupling channel topology diagram visually displays the coupling relationship network in the system, including characteristic structures such as strongly coupled paths, weakly coupled regions, and isolated devices, providing a topological foundation for system modeling and control partitioning, and serving as an important basis for subsequent design of differentiated control strategies.
[0038] In this embodiment of the invention, the detailed implementation steps for constructing a multi-input multi-output control system model for a distributed network security device include:
[0039] The operational state vectors of each network security device are defined as system state variables, and the control and adjustment quantities of each device are defined as system control inputs. System definition is a fundamental step in model building, establishing a unified mathematical description framework by clearly defining the variable system. The definition process first determines the dimension of the state space. For n devices, each device's state vector contains m indicators (such as load rate, response latency, and resource utilization), then the system state variables are n×m dimensional vectors; the control inputs correspond to the control and adjustment quantities of the n devices, such as task allocation adjustments and resource allocation adjustments. The precise definition of state variables and control inputs ensures the integrity and consistency of the model, providing a standardized variable system for subsequent state equation construction. This physically-based variable definition establishes a clear correspondence between the model and the actual system, facilitating engineering implementation and result interpretation.
[0040] Based on the control deviation transfer function, differential or difference equations for the state variables of each device are established. Establishing single-device equations is a fundamental step in system modeling, involving converting the transfer function into time-domain equations to describe the dynamics of a single device. The conversion process uses the inverse Laplace transform for continuous systems and the inverse Z-transform for discrete systems, transforming the frequency-domain expression into time-domain differential or difference equations. For complex high-order systems, state-space decomposition is used to convert the high-order equations into a system of first-order equations. Single-device equations typically take the standard form: or ,in For state variables, To control the input, or These are functions that describe the dynamics of the system. These equations accurately describe the dynamic response characteristics of a single device under isolated conditions and are the basic building blocks for constructing a complete system model.
[0041] Based on the coupling transfer coefficients, a coupling matrix is constructed between devices. The elements of the coupling matrix represent the influence coefficients of the control input of device i on the state variables of device j. The coupling matrix is the core data structure describing device interactions, quantifying the cross-influence of control signals. The construction process maps the previously identified coupling transfer coefficients to matrix positions according to device pairs, forming an n×n square matrix (for multi-index systems, this may be a block matrix). The diagonal elements of the matrix represent the control effects of the devices themselves, while the off-diagonal elements represent cross-coupling effects. For device pairs with no significant coupling, the corresponding matrix elements are set to zero, forming a sparse matrix structure that reflects the actual coupling relationships while improving computational efficiency. The coupling matrix is a complete mathematical expression of the system's coupling characteristics, providing quantitative parameters for the cross-influence terms in the state-space equations.
[0042] Based on the coupling time constant, the delay element in the coupling dynamics is determined, and this delay element can be represented as a first-order inertial element or a pure delay element. Modeling the delay element is a crucial step in capturing the time dynamics, expressing the time characteristics of signal propagation through a mathematical model. The modeling process selects an appropriate delay model based on the characteristics of the actual response curve: for a gradually changing response, a first-order inertial element is used, in the form of... For systems that only begin responding after a significant delay, a pure delay element is used, such as... Delay parameters The coupling time constant is directly taken from the previously identified coupling time constant. For discrete systems, the corresponding Z-domain expression is used. The introduction of the delay element enables the model to accurately reflect the dynamic timing characteristics of the system, especially the signal propagation delay common in distributed network environments, thus improving the model's time-domain accuracy.
[0043] By integrating the differential equations and coupling matrices of each device, a state-space expression for the system is established. The form of the state-space expression is as follows: ; ,in For state vectors, To control the input vector, For the output vector, For the system matrix, For the input matrix, This is the output matrix. State-space integration is the core step in forming a complete system model, expressing the dynamic behavior and interactions of multiple devices in a unified mathematical form. The integration process first constructs the system matrix. This includes the dynamic characteristics of each device and the coupling relationships between devices; then, an input matrix is constructed. Describe the path of influence of control inputs on state variables; finally, determine the output matrix. State-space equations define the combination of observed states of the system. For systems with delays, it may be necessary to introduce extended state variables or use modified state equation forms. The complete state-space expression is the standard mathematical description of system dynamics, directly supporting analysis and design methods in modern control theory, and providing a unified mathematical framework for subsequent controllability analysis and controller design.
[0044] Based on the state-space expression, a multi-input multi-output (MIMO) control system model is constructed. The MIMO model is the final mathematical representation describing the overall system behavior, integrating all information about individual device characteristics and coupling relationships. The construction process can employ a modular approach, converting the state-space expression into a structured block diagram or matrix transfer function form for easier analysis and visualization. For large-scale systems, a hierarchical or modular structure may be used to highlight core coupling relationships and key dynamic characteristics. The final MIMO control system model is a comprehensive mathematical description capable of accurately predicting the system's dynamic response under arbitrary control inputs. It provides a reliable theoretical foundation for control strategy design and performance evaluation, and is also a core tool for system simulation and verification.
[0045] In this embodiment of the invention, the detailed implementation steps for performing controllability analysis on the control system model and identifying strongly coupled and weakly coupled device groups in the system include: Extracting the system matrix from a multi-input multi-output control system model With input matrix Matrix extraction is a fundamental preparatory step in controllability analysis, ensuring that subsequent calculations use an accurate system description. The extraction process isolates key matrices from the complete system model, preserving their mathematical structure and parameter values. (System matrix) It describes the internal relationships and natural evolution laws among state variables, and its elements include the device's own characteristic parameters and the coupling coefficients between devices; input matrix These matrices describe the path and intensity of the influence of control inputs on state variables, reflecting the distribution of the system's control effectiveness. Together, they determine the system's controllability and dynamic characteristics, forming the core data foundation for subsequent analysis.
[0046] Construct a controllability matrix, which has the following form: ,in Let be the dimension of the system state variables. Constructing a controllability matrix is a standard method for analyzing system controllability, generating controllability criteria through matrix operations. The construction process first calculates the matrix... and The products of each order, from Begin by calculating sequentially. , ...until These matrices are then horizontally concatenated in sequence to form a complete controllability matrix. For high-dimensional systems, numerically stable algorithms such as the Krylov subspace method can be used to improve computational efficiency and accuracy. Each column of the controllability matrix represents the ability of the control input to influence the system state through different time paths. The structure of the matrix directly reflects the controllability characteristics of the system and is the theoretical basis for judging the controllability of the system.
[0047] Calculating the rank of the controllability matrix is crucial for determining the controllability of a system. Rank calculation is a core step in quantitatively assessing controllability, determining the controllable dimension of the system through linear algebraic operations. The calculation process employs numerically stable matrix decomposition methods such as Singular Value Decomposition (SVD) or QR decomposition to accurately calculate the rank of the controllability matrix. According to modern control theory, the rank of the controllability matrix equals the dimension of the system's state vector. When the rank is less than 1, the system is completely controllable; if the rank is less than 1... If the condition number of the controllability matrix is not explicitly defined, then the system is partially controllable, and there exists a state subspace unaffected by control. For large-scale systems, it is also necessary to analyze the condition number of the controllability matrix and evaluate the robustness and sensitivity of controllability. The results of controllability analysis directly affect the selection of control strategies and the design direction, and are a key transitional step from system modeling to control design.
[0048] For system matrix Eigenvalue decomposition is performed to obtain the system's eigenvalues and corresponding eigenvectors. Eigenvalue decomposition is the fundamental analysis for identifying the system's intrinsic modes, revealing the system's inherent dynamic structure through algebraic calculations. The decomposition process involves solving the characteristic equation. Calculate the matrix All eigenvalues and the corresponding feature vector For complex high-dimensional matrices, efficient numerical methods such as the QR algorithm or power iteration method are employed. Eigenvalues reflect the inherent frequencies and decay characteristics of each mode of the system, while eigenvectors represent the distribution direction of these modes in the state space. By analyzing the distribution of eigenvalues, the stability, oscillation, and response speed of the system can be determined; by examining the structure of eigenvectors, the intrinsic relationships between state variables can be identified, providing a mathematical basis for device grouping.
[0049] Based on the element distribution of eigenvectors, devices that significantly contribute to the same eigenvalue are identified and grouped into the same coupled device group. Modal grouping is a key step in system decomposition based on mathematical features, identifying naturally coupled device clusters through eigenvector analysis. The grouping process first analyzes the element distribution of each eigenvector; the positions with larger absolute values correspond to state variables and devices that significantly contribute to that eigenmode. Then, based on the mapping relationship between state variables and devices, sets of devices closely related in the same eigenmode are identified and grouped into a coupled device group. For complex systems, a device may belong to multiple eigenmodes simultaneously; in this case, the primary affiliation needs to be determined based on the magnitude of contribution. This eigenvalue-based grouping method has a solid mathematical foundation, revealing the natural clustering structure in the system and providing a reasonable partitioning basis for subsequent differentiated control strategies.
[0050] The average coupling transfer coefficient within each coupled device group is calculated and denoted as the intra-group coupling strength. Intra-group coupling strength is a key indicator for quantifying the degree of interdependence within a device group, reflecting the level of mutual influence among devices within the group through statistical calculation. The calculation process first extracts the coupling transfer coefficients between all device pairs within the group, forming a dataset; then, the average or weighted average of these coefficients (possibly weighted according to the contribution of eigenvectors) is calculated to obtain the intra-group coupling strength. For large device groups, the distribution characteristics of the coupling coefficients, such as variance and kurtosis, can also be calculated to assess the uniformity and concentration of intra-group coupling. Intra-group coupling strength directly reflects the tightness of the internal interdependence of the device group, serving as a fundamental indicator for judging strong and weak coupling and an important reference for differentiated design of control strategies.
[0051] The average coupling transfer coefficient between each coupled device group is calculated and denoted as the inter-group coupling strength. Inter-group coupling strength is a fundamental indicator for evaluating the mutual influence of device groups, quantifying the interaction level between different functional units through cross-group coefficient statistics. The calculation process is similar to intra-group strength calculation, but focuses on the coupling coefficients crossing the boundaries of different device groups. For two device groups A and B, all coupling transfer coefficients from devices in group A to devices in group B are extracted, and their average value is calculated as the inter-group coupling strength from A to B; similarly, the inter-group coupling strength from B to A is calculated. Inter-group coupling may be asymmetric, reflecting the directionality and imbalance of influence between device groups. Inter-group coupling strength is a key indicator for evaluating the modularity of the system and the feasibility of zonal control, directly affecting the selection and design of control strategies.
[0052] Groups of coupled devices whose intra-group coupling strength to inter-group coupling strength ratio exceeds a preset strong coupling criterion are marked as strongly coupled device groups. Strong coupling determination is a decision-making step in control strategy classification, identifying clusters of devices requiring coordinated control through quantitative comparison. The determination process calculates the intra-group coupling ratio for each device group, i.e., the intra-group coupling strength divided by the average inter-group coupling strength of that group and all other groups. When the ratio exceeds a preset criterion (typically 2-5, depending on system characteristics and control requirements), the group is marked as a strongly coupled device group. These device groups exhibit significantly stronger internal correlations than external correlations; changes in the state of member devices closely affect other devices within the group, requiring a unified and coordinated decoupling control strategy. The setting of the strong coupling criterion needs to balance the granularity of system segmentation and control complexity; a higher criterion value results in fewer strongly coupled groups and a larger scope of decentralized control.
[0053] Groups of coupled devices whose intra-group coupling strength to inter-group coupling strength ratio is less than a preset strong coupling criterion are labeled as weakly coupled device groups. Weak coupling determination is a supplementary step in control strategy classification, identifying clusters of devices that can be controlled relatively independently. The criterion is that the intra-group coupling ratio is less than a preset criterion, indicating that the intra-group correlation strength is equal to or weaker than the inter-group correlation, that changes in the state of group members may have a significant impact on devices outside the group, or that the mutual influence between devices within the group is relatively weak. These device groups are suitable for distributed control strategies, requiring independent controller design for each device, simplifying the control structure and implementation. Identifying weakly coupled groups provides the possibility of divide-and-conquer in system control, reducing the complexity and computational burden of the control system without significantly sacrificing control performance, and improving implementation efficiency and maintainability. The division of strongly and weakly coupled device groups is the foundation for differentiated control strategies, providing clear technical guidance for subsequent controller design.
[0054] In this embodiment of the invention, for a group of strongly coupled devices, a decoupling controller is designed. The detailed implementation steps for generating decoupling control laws for each device by constructing a decoupling compensation network to counteract the coupling effect between devices include:
[0055] Extracting the coupling matrix sub-blocks corresponding to the strongly coupled device groups, denoted as the strongly coupled matrix, is a fundamental preparatory step in decoupling controller design. It involves obtaining a precise coupling description of the target subsystem through data segmentation. The extraction process separates the corresponding sub-matrices from the complete system coupling matrix based on the member identifiers of the strongly coupled device groups, preserving the original parameter values and structural relationships. For a strongly coupled group containing m devices, the extracted strongly coupled matrix is an m×m square matrix, accurately describing the interaction relationships between the devices within the group. Matrix extraction ensures that subsequent decoupling design targets accurate coupling relationships and is essential data preparation for controller design.
[0056] The inverse or pseudo-inverse of the strongly coupled matrix is calculated and denoted as the decoupling compensation matrix. Matrix inversion is the core mathematical operation in designing decoupling compensation, constructing a mathematical mapping to cancel coupling through algebraic operations. The calculation process involves inverting the strongly coupled matrix. For full-rank square matrices, the standard inverse is calculated directly; for non-full-rank or non-square matrices, the Moore-Penrose pseudo-inverse is calculated. To improve numerical stability, methods such as SVD decomposition or QR decomposition are used to implement the inversion operation. The elements of the decoupling compensation matrix represent the compensation coefficients required to cancel the corresponding coupling effects, and its structure reflects the connection topology of the decoupling network. Matrix inversion is the theoretical foundation of decoupling control. By using the inverse mapping to cancel the cross-coupling of the original system, the input and output are decoupled and independent, providing an effective means for multivariable coordinated control.
[0057] Design a diagonally dominant target transfer function matrix, where the diagonal elements represent the desired single-device closed-loop transfer function, and the off-diagonal elements are zero or close to zero. Target matrix design is a crucial step in defining the control objective, mathematically defining the desired system response characteristics. The design process first determines the desired closed-loop response characteristics for each device, including performance indicators such as response speed, damping ratio, and steady-state accuracy; then, these characteristics are transformed into standard transfer functions, such as those for a first-order system. or second-order system ;in, The system gain is the magnitude scaling factor of the system's steady-state response, which determines the ratio of the system's final output to its input. The time constant represents the system response speed and is defined as the time required for the output to reach 63.2% of its final change, usually expressed in seconds. For complex variables that are Laplace transforms, this is used to transform time-domain analysis to the frequency domain; The natural frequency represents the inherent oscillation frequency of the system and determines the oscillation velocity of the system when it is undamped. The damping ratio represents the degree to which the system oscillations are attenuated. Finally, the target transfer function matrix is constructed, with the diagonal elements filled with the desired transfer function of the device and the off-diagonal elements set to zero, representing the desired fully decoupled control. The design of the target matrix must meet performance requirements while considering the physical constraints and feasibility of the system, serving as a guiding principle and evaluation benchmark for the design of decoupled controllers.
[0058] Based on the decoupling compensation matrix and the target transfer function matrix, a feedforward decoupling compensation network is constructed. The transfer function matrix of the feedforward decoupling compensation network is equal to the product of the decoupling compensation matrix and the target transfer function matrix. The construction of the compensation network is the core step in realizing decoupling control, generating the actual control structure through mathematical combination. The construction process multiplies the decoupling compensation matrix with the target transfer function matrix to obtain the transfer function matrix of the feedforward decoupling compensation network. This network acts on the original control signal, generating a modified control input, and cancels the inherent coupling effect of the system by introducing carefully designed cross-paths. Feedforward compensation is usually implemented in parallel, applying matrix transformations to each control input signal to form a linear combination of multiple control signals, ultimately generating a decoupled control signal set. The construction of the compensation network transforms mathematical decoupling theory into an implementable control structure and is the core component of the decoupling controller.
[0059] Feedback controllers are designed for each device in a tightly coupled equipment group. These controllers employ either PID control or state feedback control. Feedback controller design is a fundamental step in ensuring the performance of individual devices, achieving stability and performance requirements through classical or modern control methods. The design process begins by selecting a suitable controller type: PID controllers are used for simple systems, leveraging their simplicity and practicality; state feedback control is employed for complex or demanding systems, utilizing its flexibility and precision. Then, based on the control deviation transfer function of each device, controller parameters are designed: PID parameters are typically tuned using the Ziegler-Nichols method or internal model control, while the state feedback gain is designed using pole placement or LQR optimization methods. The feedback controller ensures the closed-loop performance of each device, including stability, speed, and accuracy, and is a fundamental component guaranteeing the decoupled control system.
[0060] A feedforward decoupling compensation network is connected in series with the feedback controller to form a decoupled controller for each device. Controller integration is the final step in forming a complete control scheme, achieving both decoupling and performance goals through structural combination. The integration process adopts a cascaded structure, sending the basic control signal generated by the feedback controller into the feedforward decoupling compensation network to generate the final decoupled control signal. This structure not only leverages the performance guarantee function of feedback control but also utilizes feedforward compensation to achieve system decoupling, thus achieving the goal of control coordination. In engineering implementation, it may be necessary to add smoothing filters or amplitude limiting protection to ensure the stability and safety of the control signal. The final decoupled controller has a clear structure and complete functions, solving the coupling interference problem while ensuring the performance goals of individual devices, making it an effective solution for controlling strongly coupled systems.
[0061] Based on the state deviation vectors of each device and the decoupled controller, the control output of each device is calculated as the decoupled control law. Control law calculation is the final step in transforming the design scheme into actual control decisions, generating executable control commands through mathematical operations. The calculation process first obtains the current state deviation vectors of each device, then calculates the basic control signals according to the feedback control algorithm, and finally converts them into the final control output through the decoupled compensation network. The control calculation adopts a real-time processing method, continuously updating according to the system sampling period. The decoupled control law, while suppressing coupling interference, ensures the coordination and consistency of control response and performance optimization, making it an effective technical path for solving the control problems of strongly coupled systems. The final generated control commands are directly transmitted to the actuators, enabling precise adjustment of network security devices and ensuring the optimization of overall system performance.
[0062] In this embodiment of the invention, for a loosely coupled group of devices, a distributed controller is designed, and a feedback controller is independently configured for each device to generate an independent control law for each device. The detailed implementation steps include: For each device in a weakly coupled device group, its coupling with other devices is ignored, and a single-device independent control model is established. Establishing an independent model is a fundamental step in distributed control design, obtaining a concise description of the single-device control problem through simplifying assumptions. The modeling process treats each device as an independent system, retaining only its own dynamic characteristics and ignoring cross-influences from other devices. This simplification is based on the characteristics of weakly coupled device groups, where mutual influence between devices within the group is minimal, allowing independent control to achieve near-optimal results. The single-device model typically uses a transfer function or state-space form, directly extracted from the previously established control deviation transfer function. This simplified model significantly reduces the complexity of control design, allowing for the direct application of classical control theory and mature design methods, improving design efficiency while ensuring control stability and reliability.
[0063] Based on the control deviation transfer function of the single-device independent control model, the dynamic characteristic parameters of the device are determined, including gain, time constant, and lag time. Parameter determination is a prerequisite for controller design, extracting key dynamic characteristics of the system through model analysis. The determination process involves analyzing the structure and parameters of the transfer function to identify the basic dynamic type of the system (such as a first-order, second-order, or higher-order system) and extracting key dynamic parameters. For the case of an approximate first-order system with a time delay, the steady-state gain K (the steady-state ratio of output to input), time constant T (the time required for the response to reach 63.2%), and lag time L (the delay time from input change to output response) are determined. These parameters directly reflect the system's response speed, stability, and control difficulty, serving as fundamental data for controller parameter design and reference indicators for evaluating control performance.
[0064] Independent feedback controller parameters are designed for each device using engineering tuning methods or optimal control methods. These parameters include proportional gain, integral time, and derivative time. Controller design is the core of distributed control, determining the optimal controller parameters using classical or modern methods. Various mature methods can be employed in the design process: for simple systems, engineering tuning formulas such as Ziegler-Nichols or Cohen-Coon are used to directly calculate PID parameters based on the system's dynamic characteristics; for complex systems or high-performance requirements, internal model control (IMC), ITAE criterion optimization, or multi-objective optimization methods are used to find the optimal balance between stability, speed, and steady-state accuracy. PID parameter design is based on classical control engineering theory: the proportional term provides the basic response speed, the integral term eliminates steady-state error, and the derivative term improves dynamic performance and stability. Parameter design must consider both theoretical optimality and engineering practicality and robustness to ensure reliable operation of the control system in real-world environments.
[0065] The stability of the designed feedback controller is verified by calculating the phase margin and gain margin of the closed-loop system. Stability verification is a necessary step in control design, ensuring the stability and reliability of the control system through quantitative analysis. The verification process employs frequency domain analysis methods from classical control theory to calculate the phase-frequency characteristics of the open-loop transfer function, determining the phase margin (the angle by which the phase exceeds -180° when the open-loop gain is 1) and gain margin (the dB value by which the gain is less than 1 when the phase is -180°). For digital control systems, the influence of the sampling period must also be considered to analyze the stability of the discrete system. Margin analysis not only verifies the system's stability but also quantifies the system's resistance to parameter variations and external disturbances, serving as an important indicator of control robustness. The phase margin should typically be greater than 30-45 degrees, and the gain margin should be greater than 6-12 dB to ensure the system has sufficient stability margin to cope with parameter fluctuations and external disturbances in practical operation.
[0066] If the phase margin and gain margin meet the stability requirements, the feedback controller parameters are adopted; otherwise, the controller parameters are adjusted until the stability requirements are met. Parameter tuning is a crucial step in ensuring control safety, achieving a balance between stability and performance through iterative optimization. The tuning process employs a systematic approach: if the margin is insufficient, the proportional gain is typically reduced or the integral time increased to improve system stability; if the margin is excessive, the proportional gain can be appropriately increased or the integral time decreased to improve system response speed. During tuning, tools such as root locus, Bode plots, or Nyquist plots are used to visually analyze the impact of parameter changes on system characteristics, guiding the tuning direction. Parameter tuning not only focuses on stability margin but also needs to balance various performance indicators such as response speed, overshoot, and steady-state error, ultimately finding a parameter combination that meets all requirements. This verification-based tuning method ensures the safety, reliability, and performance optimization of the control system, serving as a vital safeguard in engineering practice.
[0067] Based on the state deviation vectors of each device and the designed feedback controller, the control output of each device is calculated as an independent control law. Control law calculation is the execution stage that transforms theoretical design into actual control action, generating specific control commands through mathematical operations. The calculation process first obtains the current state deviation vector of the device, and then calculates the corresponding control output according to PID or other feedback control algorithms. For a standard PID controller, the control law calculation formula is: ; in, To control the output, This is a state deviation. , , These are proportional, integral, and differential gains, respectively.
[0068] In digital implementation, discrete PID algorithms, such as positional or incremental PID, are employed. Control law calculations are typically performed periodically in real-time control systems, updating the control output according to the sampling period. Distributed control, with its independent control laws, fully leverages the characteristics of weakly coupled systems, achieving near-global optimal control effects through simplified independent control while maintaining system simplicity and computational efficiency. This makes it an ideal strategy for controlling weakly coupled systems.
[0069] In this embodiment of the invention, the decoupled control law and the independent control law are integrated to form a distributed control strategy. The detailed implementation steps for calculating the control adjustment quantities of each network security device based on the distributed control strategy include: Extract the decoupling control law output values of each network security device in the strongly coupled device group and the independent control law output values of each network security device in the weakly coupled device group. This step obtains the basic data for policy integration. The decoupling control law output values come from the aforementioned decoupling controller design module and are represented as vectors. The output values of the independent control law come from the distributed controller design module and are represented as vectors. The extraction process includes data normalization and time synchronization to ensure the comparability of outputs from different controllers at the same time. The system employs a buffer mechanism to handle computational delays from different controllers, ensuring that the integration operation is based on the latest and most valid control output.
[0070] Identify boundary devices that are coupled to both strongly coupled and weakly coupled device groups. This step determines transitional region devices requiring special handling. Boundary devices are special nodes in the system's internal coupling structure, simultaneously affected by both strong and weak coupling dynamics. The identification process is based on the coupled topology graph constructed by the aforementioned controllability analysis module, employing graph theory analysis methods. Specifically, it determines the boundary device by calculating the connectivity degree between the device and the two types of device groups. The connectivity degree is defined as the sum of the absolute values of the coupling transfer coefficients between the device and all devices within the target group. If the ratio of the connectivity degree between the device and the two device groups is within a threshold range (typically 0.3-3), it is marked as a boundary device. This topology-based identification method ensures an accurate grasp of the system's coupling characteristics, providing precise object location for subsequent strategy fusion.
[0071] For boundary devices, the coupling influence from strongly coupled device groups and weakly coupled device groups is calculated, and the control law fusion weights are determined based on the ratio of these coupling influences. This step quantitatively assesses the coupling characteristics of boundary devices, providing a weighting basis for strategy fusion. The calculation of coupling influence is based on the results of the aforementioned coupling analysis module, considering both the coupling transfer coefficient and the device state. The calculation process comprehensively considers the magnitude of the coupling transfer coefficient and the degree of influence of the current device state, thus obtaining a quantitative coupling influence assessment value. The control law fusion weights are obtained through a smooth mapping of the coupling influence ratio, ensuring that the weight values are between 0 and 1, and that the sum of the weights of the two control strategies is 1. This weight calculation method based on actual coupling physical characteristics makes the fusion of control strategies more consistent with the actual dynamic characteristics of the system.
[0072] The decoupled control law output values and independent control law output values of the boundary devices are weighted and summed according to the control law fusion weights to obtain the fused control output value of the boundary devices. This step performs the actual control strategy fusion calculation. For each boundary device... The fusion control output value is calculated as follows: ; in, and These represent the weights of the decoupled control law and the independent control law, respectively. This linear weighting method is simple and effective, ensuring a smooth transition of the control output. The fusion process considers the physical meaning and constraints of the control input, ensuring the interpretability and feasibility of the fusion result.
[0073] The decoupling control law outputs of each strongly coupled device, the independent control law outputs of each weakly coupled device, and the fused control outputs of the boundary devices are integrated to construct a global control output vector. This step organizes the distributed control outputs into a unified system-level control vector. Global Control Output Vector The devices are ordered by device ID or network location to ensure consistency with system state variables and control structures. The integration operation fills the corresponding positions with the control outputs of the three types of devices, forming a complete global control vector. After the global vector is built, a consistency check is performed to ensure that all devices have corresponding valid control outputs without omissions or conflicts, providing a complete data foundation for subsequent clipping processing.
[0074] A distributed control strategy is generated by applying amplitude saturation limiting and rate-of-change limiting to the global control output vector. This step ensures the safety and smoothness of the control output. Amplitude saturation limiting constrains the absolute value of the control output, ensuring it does not exceed the physical limitations of the equipment; that is, control values exceeding the upper and lower limits are truncated to the allowable range. Rate-of-change limiting constrains the temporal rate of change of the control output, preventing sudden changes from impacting the system. This is achieved by comparing the difference between the current calculated value and the actual output value at the previous moment, limiting the change amplitude to no more than a preset maximum rate of change. This dual limiting process ensures the physical feasibility and dynamic smoothness of the control signal, effectively preventing control oscillations and system damage, and improving the robustness and reliability of the control system.
[0075] Based on the distributed control strategy, the control output values corresponding to each network security device are extracted as control adjustment quantities for each device. This step maps the system-level control strategy to the execution instructions of specific devices. Control adjustment quantities include three basic adjustment parameters: task allocation ratio, processing priority, and resource quota. The extraction process first locates the corresponding control output sub-vector from the global limiting control vector based on the device ID, and then converts the abstract control values into specific adjustment parameters through predefined mapping relationships. For example, for the task allocation ratio, normalization ensures that the sum of the allocation ratios of all devices in the system is 100%; for the processing priority, continuous values are converted into discrete priority levels through sorting mapping; and for the resource quota, scaling is used to map it to the actual system resource configuration value. The final control adjustment quantities adopt a standardized format, facilitating actual adjustments through the device management interface and completing the final stage of the control loop.
[0076] Through the above steps, the strategy integration module achieves fine integration of different control laws, especially the precise handling of critical boundary devices in the system. It constructs a distributed control strategy that comprehensively considers the coupling characteristics of devices, providing network security devices with control and adjustment schemes that are both coordinated and unified yet tailored to each device, ensuring the efficient and stable operation of the system in complex network environments.
[0077] In this embodiment of the invention, the detailed implementation steps for performing control adjustments on each network security device according to the control adjustment amount, collecting the operating status quantities after control adjustment, and calculating the dynamic performance indicators of the control system include: Based on the control adjustment quantities, control commands are issued to each network security device. These commands include adjustments to task allocation ratios, settings of processing priorities, and modifications to resource quotas. Command issuance is the initial step in control execution, transmitting control decisions to the actual devices through standard interfaces. The issuance process first converts mathematical control adjustment quantities into specific instructions recognizable by the devices. For example, load adjustments are converted into percentage changes in task allocation ratios, response requirements into level settings for processing priorities, and resource optimizations into modifications to memory, CPU, or bandwidth quotas. Then, the control commands are transmitted to the target devices through device management interfaces, such as API calls, configuration file modifications, or command-line instructions. Command issuance employs secure and reliable communication mechanisms to ensure the integrity and timeliness of commands, potentially including acknowledgment mechanisms and failure retry strategies to guarantee the reliability of the control link. This step transforms theoretical control into practical operation, is a crucial link in the closed-loop control system, and is the direct means of achieving control effects.
[0078] Real-time acquisition of the time series of operational status variables of each network security device after control and adjustment is performed. Status acquisition is the data foundation for evaluating control effectiveness, and dynamic response data of the system is obtained through continuous monitoring. The acquisition process uses the same techniques as the initial data acquisition, obtaining real-time operational status variables from the device monitoring interface, including device processing load rate, response latency, and resource utilization. The sampling frequency is typically set to 2-5 times the control system bandwidth to ensure that all dynamic characteristics of the system are captured. The acquisition duration needs to cover the entire control response process, from the start of control command execution until the system reaches a new steady state. The acquired time series data undergoes preprocessing, including noise filtering, outlier handling, and time synchronization, forming a standard format dynamic response record to provide accurate raw data for subsequent performance index calculations.
[0079] The settling time required for each device's operating state variable to reach the target value from its initial deviation is denoted as the system settling time. Settling time is a key indicator for evaluating the speed of control response, quantifying the system's response speed through time measurement. The calculation process first determines the starting point of the response curve (the control start time) and the termination condition (the state variable entering a specified range of the target value, typically ±2% or ±5% of the target value); then, the time interval from the starting point to the first satisfaction of the termination condition is measured and denoted as the system settling time. For multi-indicator systems, it may be necessary to calculate the settling time for each indicator separately, or take the maximum value as the overall system settling time. Settling time directly reflects the response speed of the control system, is an important dimension of performance evaluation, and is one of the key objectives for controller parameter optimization, especially for safety protection systems requiring rapid response.
[0080] The overshoot is calculated as the ratio of the maximum deviation of each device's operating status variable from the target value during the adjustment process to the target value. Overshoot is a key indicator for evaluating control stability, quantifying the degree of overshoot through amplitude measurement. The calculation process analyzes the entire response curve to identify the point of maximum deviation from the target value, calculating its ratio to the target value, and recording it as the overshoot. Overshoot is usually expressed as a percentage, reflecting the smoothness of system control. Large overshoot may cause the system to temporarily enter an unsafe state, such as excessive resource consumption or insufficient processing capacity, and should be controlled in the control design. The ideal range of overshoot is determined based on the system nature and application scenario, generally within 5%-20%, ensuring the smoothness of the system response and a safe boundary.
[0081] The time required for each device's operating status variable to enter and remain within the target tolerance range is recorded as the settling time. Settling time is a supplementary indicator for evaluating control stability, quantifying the system's stabilization process through continuous monitoring. The calculation process first defines the tolerance range of the target value, typically ±2% or ±5% of the target value; then, it determines the point in time when the status variable finally enters the tolerance range and remains there without exceeding it; finally, it calculates the time interval from the start of control to this point in time, recording it as the settling time. Settling time differs from settling time; it emphasizes the system's ability to reach and maintain a stable state, excluding situations where the system temporarily enters the tolerance range and then fluctuates beyond it. Settling time comprehensively reflects the overall stability of the system and is an important indicator for evaluating control quality, particularly suitable for network security systems requiring continuous stable operation.
[0082] The deviation between the operating state variables of each device after reaching steady state and the target value is calculated and denoted as steady-state error. Steady-state error is a fundamental indicator for evaluating control accuracy, quantifying the system's control precision through final value deviation. The calculation process involves calculating the difference between the average value of the state variables and the target value after the system reaches a steady state (typically the last 10%-20% of the control process), denoted as steady-state error. Error can be expressed as an absolute value or a percentage relative to the target value, reflecting the static accuracy of the control system. Steady-state error is affected by the controller type and system characteristics. Integral controllers can theoretically eliminate steady-state error, but in practical systems, small steady-state errors may exist due to model errors, noise interference, or quantization effects. The acceptable range of steady-state error is determined based on application requirements; for systems with high precision requirements, it may be necessary to control the error within 1%.
[0083] By integrating settling time, overshoot, settling time, and steady-state error, a dynamic performance index is formed. Performance integration is a comprehensive step in evaluating control effectiveness, reflecting system performance comprehensively through the integration of multi-dimensional indicators. The integration process first standardizes each indicator to ensure that indicators with different dimensions and ranges can be reasonably compared and combined; then, weights are assigned to each indicator according to the system's control priorities and application requirements, reflecting their relative importance; finally, a weighted combination is calculated to form a comprehensive performance index. This comprehensive index can be used to compare different control strategies, evaluate control effectiveness, and automatically optimize control parameters. Performance integration provides a comprehensive evaluation perspective for control systems, considering both the speed of dynamic response and the stability and accuracy, serving as an important reference for control system optimization.
[0084] In this embodiment of the invention, the detailed implementation steps for adaptively adjusting the control parameters of the decoupled controller and the distributed controller based on dynamic performance indicators include: Define the comprehensive performance evaluation function of the control system. This function is a weighted sum of settling time, overshoot, and steady-state error. The weighting coefficients are determined based on the system's requirements for speed, stability, and accuracy. Defining the evaluation function is a step in setting the objectives for parameter optimization, quantifying the system's comprehensive performance requirements mathematically. The definition process begins by selecting key performance indicators, typically including settling time. (Reflection speed), overshoot (Reflecting stability) and steady-state error (Reflecting accuracy); then determine the weight coefficients of each indicator to reflect the performance emphasis of the system design; finally, construct a weighted sum evaluation function. The general form of the evaluation function is: ; in, The value of the comprehensive performance evaluation function. , , These are the weighting coefficients, and .
[0085] Weight settings reflect the application characteristics of the system: systems with high real-time requirements increase weights. Weighting; systems with strict security boundaries increase Weighting; systems requiring high precision control increase The weights are determined by the performance evaluation function. A well-defined performance evaluation function provides a quantitative basis for the optimization of control parameters, giving the optimization process a clear objective.
[0086] Calculate the comprehensive performance evaluation function value under the current control parameters. Performance evaluation is a baseline measurement step before optimization, establishing a reference point for the current state through performance calculation. The evaluation process is based on the actual operating data of the system or control model simulation, using the current control parameters to calculate the dynamic response of the system under standard inputs (such as step changes), extracting key indicators such as settling time, overshoot, and steady-state error, and substituting them into the evaluation function to calculate the current performance value. This step provides a starting point reference for parameter optimization, enabling the optimization process to quantify the degree of improvement, and serves as a baseline for judging the success of optimization, ensuring that the new parameters truly bring performance improvement rather than degradation.
[0087] The system determines whether the comprehensive performance evaluation function value meets the preset performance index requirements. This performance judgment is the decision-making step triggered by optimization, using threshold comparisons to determine whether control parameters need adjustment. The judgment process compares the current evaluation function value with the preset performance index requirements, which are typically determined based on system design specifications and actual operational needs. If the current performance value exceeds the preset index (indicating performance failure), the parameter optimization process is triggered; if the performance meets the requirements, the current parameters remain unchanged, and monitoring continues. This performance-triggered optimization mechanism avoids unnecessary parameter adjustments, reduces system disturbances, and ensures that the system can adapt promptly to performance degradation, maintaining optimal operating conditions.
[0088] If these conditions are not met, gradient descent or genetic algorithms are used to optimize the control parameters. These parameters include the decoupling compensation matrix elements of the decoupled controller and the PID parameters of the distributed controller. Parameter optimization is the core computational step in adaptive adjustment, using numerical algorithms to find the optimal combination of control parameters. Various algorithms can be employed in the optimization process: for simple systems with smooth performance surfaces, gradient descent is used, determining the optimization direction by calculating the partial derivatives of the performance function with respect to the parameters, quickly approximating local optima; for complex nonlinear systems or systems with multiple local optima, global optimization methods such as genetic algorithms and particle swarm optimization are used, simulating biological evolution or swarm intelligence principles to search for the global optimum in a broader parameter space. The optimization process requires setting a reasonable search range and step size to ensure the search space contains the optimal solution while controlling computational complexity; appropriate termination conditions must also be set, such as reaching a predetermined number of iterations, performance improvement less than a threshold, or reaching the target performance value. Parameter optimization is a key manifestation of the adaptive capability of the control system, enabling the system to automatically adjust its control strategy according to performance requirements and environmental changes, maintaining optimal performance.
[0089] In the process of control parameter optimization, a multi-input multi-output (MIMO) control system model is simulated to predict the dynamic performance indices corresponding to the adjusted control parameters. Simulation prediction is the evaluation stage of the optimization iteration, verifying the effect of the parameters in advance through model calculation. The simulation process uses the previously established MIMO control system model, applies candidate control parameters to the model, and simulates the dynamic response of the system under standard input conditions. The simulation uses numerical integration methods to solve the system equations, obtains the evolution trajectory of state variables over time, extracts dynamic performance indices, and calculates evaluation function values. Simulation prediction provides a rapid evaluation method for parameter optimization, avoiding the risks and costs of repeatedly trying parameters on the actual system, and greatly improving optimization efficiency and safety. For complex systems, parallel computing technology can be used to evaluate multiple sets of parameters simultaneously, further accelerating the optimization process. Predictive evaluation through model simulation ensures the scientific nature and reliability of parameter optimization, which is an important technical guarantee for adaptive control.
[0090] The control parameters that minimize the overall performance evaluation function value are selected as the updated control parameters. Parameter selection is the decision-making stage of the optimization result; the final parameter combination is determined through comparative analysis. The selection process compares the performance evaluation function values corresponding to all candidate parameter groups during the optimization process, and selects the parameter group that minimizes the function value as the optimal result. To increase the robustness of the selection, it may also be necessary to consider the sensitivity and robustness of the parameters, avoiding the selection of parameter groups with large performance fluctuations under small perturbations. The determination of the optimal parameters marks the completion of this round of optimization, and the system will use the new parameters for subsequent control, expecting to achieve better overall performance. This parameter selection method based on quantitative evaluation ensures the objectivity of the optimization results and the continuous improvement of system performance.
[0091] The updated control parameters are applied to the decoupled controller and distributed controllers, updating the decoupled control law and independent control law. Parameter application is the final step in optimizing the closed loop, translating theoretical optimization into practical control actions through system updates. The application process first configures the selected optimal parameters into the corresponding controllers, updating the decoupling compensation matrix elements of the decoupled controller and the PID parameters of the distributed controller; then, the control law is recalculated based on the new parameters, generating updated decoupled and independent control laws; finally, the new control laws are put into actual operation, initiating a new round of control execution. The parameter update process employs a smooth transition strategy to avoid control instability caused by sudden parameter changes, possibly using parameter interpolation or gradual transition methods. Parameter application completes the full closed loop of adaptive control, enabling the system to continuously optimize the control strategy based on performance feedback, adapt to environmental changes and performance requirements, and maintain optimal operating conditions. This adaptive mechanism greatly improves the intelligence level and long-term stability of the control system, a crucial characteristic of modern control systems.
[0092] This invention achieves real-time monitoring and precise control of distributed network security devices by comprehensively monitoring device operating status, accurately analyzing status deviations, scientifically modeling device characteristics, identifying coupling relationships between devices, constructing a multi-input multi-output control system model, designing differentiated control strategies, and adjusting adaptive control parameters. It possesses adaptability and robustness, enabling coordinated control and optimized management of multiple devices in complex network environments, effectively improving overall system performance and responsiveness.
[0093] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
[0094] It should be noted that all formulas in this manual are calculated by removing dimensions and taking their numerical values. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters and thresholds in the formulas are set by those skilled in the art according to the actual situation.
[0095] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
Claims
1. A distributed monitoring and automatic response control system for network security devices, characterized in that, include: The data acquisition module is used to acquire real-time operating status data of multiple network security devices deployed in a distributed manner. The operating status data includes device processing load rate, response latency, and resource utilization rate. The deviation analysis module is used to compare the operating state quantity with the preset system target operating state and calculate the state deviation vector of each network security device. The function modeling module is used to construct the control deviation transfer function for each network security device based on the state deviation vector, including: The historical state deviation vectors of each network security device are sampled in the time domain to obtain the discrete time series of the state deviation. The discrete-time series is subjected to Z-transform to obtain the representation of the state deviation in the Z-domain; Identify the characteristic poles and characteristic zeros in the Z-domain representation; Based on the location of the characteristic poles, determine the convergence characteristics of the state deviation of each network security device and calculate the deviation decay time constant; Construct a rational fractional function with the characteristic poles and the characteristic zeros as parameters, as the Z-domain transfer function; Performing an inverse Z-transform on the Z-domain transfer function yields the control deviation transfer function in the time domain; The coupling analysis module is used to identify control coupling channels between devices and calculate the coupling transfer coefficient and coupling time constant of the coupling channels. The system modeling module is used to construct a control system model based on the control deviation transfer function, the coupling transfer coefficient, and the coupling time constant. The controllability analysis module is used to perform controllability analysis on the control system model, identifying strongly coupled and weakly coupled device groups in the system, including: Extract the system matrix A and input matrix B from the multi-input multi-output control system model; Construct a controllability matrix, calculate the rank of the controllability matrix, and determine the controllability of the system; Perform eigenvalue decomposition on the system matrix A to obtain the system's eigenvalues and corresponding eigenvectors; Based on the element distribution of the feature vector, identify devices that make significant contributions to the same feature value and group these devices into the same coupled device group; analyze the element distribution of each feature vector, and the positions with larger absolute values of the elements correspond to the state variables and devices that make significant contributions to the feature mode; Calculate the average coupling transfer coefficient within each group of coupling devices, and denot it as the coupling strength within the group; Calculate the average coupling transfer coefficient between each group of coupled devices, and denote it as the inter-group coupling strength; A group of coupling devices whose ratio of intra-group coupling strength to inter-group coupling strength is greater than a preset strong coupling criterion is marked as the strong coupling device group; The coupling device group whose ratio is less than the preset strong coupling criterion is marked as the weak coupling device group; The controller design module is used to design a decoupling controller for the strongly coupled device group, and to generate a decoupling control law for each device by constructing a decoupling compensation network to cancel the coupling effect between devices. For the aforementioned weakly coupled device group, a distributed controller is designed, with each device independently configured with a feedback controller to generate an independent control law for each device; The strategy integration module is used to integrate the decoupled control law with the independent control law to form a distributed control strategy, including: Extract the decoupling control law output values of each network security device in a strongly coupled device group and the independent control law output values of each network security device in a weakly coupled device group; Identify boundary devices that are coupled to both strongly coupled device groups and weakly coupled device groups; For boundary devices, calculate the coupling influence from the strongly coupled device group and the coupling influence from the weakly coupled device group, and determine the control law fusion weight based on the ratio of the coupling influence. The decoupled control law output value and the independent control law output value of the boundary device are weighted and summed according to the control law fusion weight to obtain the fused control output value of the boundary device. The global control output vector is subjected to amplitude saturation limiting and rate of change limiting to generate a distributed control strategy. Calculate the control adjustment amount of each network security device according to the distributed control strategy; The control execution and evaluation module is used to perform control adjustments on each network security device according to the control adjustment amount, collect the operating status quantity after control adjustment, calculate the dynamic performance index of the control system, and adaptively adjust the control parameters of the decoupled controller and the distributed controller based on the dynamic performance index.
2. The system according to claim 1, characterized in that, The step of comparing the operational state quantity with the preset system target operational state and calculating the state deviation vector of each network security device includes: Extract the device processing load rate, response latency, and resource utilization rate of each network security device at the current sampling time to form a device operating status vector; Obtain the preset target operating state vectors of each network security device; Calculate the difference between the device operating state vector and the preset target operating state vector to obtain the initial state deviation vector; The components of the initial state deviation vector are normalized, and the normalization reference value is the allowable deviation range of each state quantity. Calculate the rate of change of the normalized state deviation vector within a preset time window, and denote it as the dynamic component of the state deviation. The normalized state deviation vector is combined with the dynamic components of the state deviation by weighting to obtain the state deviation vector.
3. The system according to claim 1, characterized in that, The step of identifying control coupling channels between devices based on the control deviation transfer function and calculating the coupling transfer coefficient and coupling time constant of the coupling channels includes: Take any network security device as the first network security device, apply a step control input to the first network security device, and keep the control inputs of other devices unchanged; Collect the operational status response curves of the first network security device and its adjacent devices; The ratio of the change in the operating state of the adjacent device to the change in the operating state of the first network security device is calculated and denoted as the direct coupling degree. Determine whether the direct coupling degree is greater than a preset coupling threshold. If it is greater, confirm that there is a control coupling channel between the first network security device and the adjacent device. For a pair of devices with a control coupling channel, the steady-state gain of the operating state response curves of the adjacent devices is extracted and denoted as the coupling transfer coefficient. The time required for the response curves of the operating status variables of adjacent devices to reach a preset proportion of steady-state values is denoted as the coupling time constant. Repeat the above steps to explore all network security devices and build a complete topology diagram of the coupling channels between devices.
4. The system according to claim 1, characterized in that, The construction of the control system model includes: Define the operating state vector of each network security device as the system state variable, and the control adjustment quantity of each device as the system control input; Based on the control deviation transfer function, establish differential equations or difference equations for the state variables of each device; Based on the coupling transfer coefficients, construct the coupling matrix between devices; Based on the coupling time constant, determine the delay element of the coupling dynamics; The differential equations of each device are integrated with the coupling matrix to establish the state-space expression of the system; The control system model is constructed based on the state-space expression.
5. The system according to claim 1, characterized in that, For the strongly coupled device group, a decoupling controller is designed. This controller cancels the coupling effect between devices by constructing a decoupling compensation network, generating decoupling control laws for each device, including: Extract the coupling matrix sub-blocks corresponding to the strongly coupled device group, and denote them as the strongly coupled matrix; Calculate the inverse or pseudo-inverse of the strongly coupled matrix, and denote it as the decoupling compensation matrix; Design a diagonally dominant target transfer function matrix, wherein the diagonal elements of the target transfer function matrix are the desired single-device closed-loop transfer functions, and the off-diagonal elements are zero; Construct a feedforward decoupling compensation network based on the decoupling compensation matrix and the target transfer function matrix; A feedback controller is designed for each device in the strongly coupled device group, and the feedback controller adopts a PID control law or a state feedback control law. The feedforward decoupling compensation network is connected in series with the feedback controller to form a decoupling controller for each device. Based on the state deviation vector of each device and the decoupling controller, the control output of each device is calculated as the decoupling control law.
6. The system according to claim 1, characterized in that, The design of a distributed controller for the loosely coupled device group involves configuring an independent feedback controller for each device and generating an independent control law for each device, including: For each device in the weakly coupled device group, its coupling with other devices is ignored, and a single-device independent control model is established. Based on the control deviation transfer function of the single-device independent control model, the dynamic characteristic parameters of the device are determined; Use engineering tuning methods or optimal control methods to design independent feedback controller parameters for each device; The stability of the designed feedback controller is verified, and the phase margin and gain margin of the closed-loop system are calculated. If the phase margin and the amplitude margin meet the stability requirements, then the feedback controller parameters are used; otherwise, the controller parameters are adjusted until the stability requirements are met. Based on the state deviation vector of each device and the designed feedback controller, the control output of each device is calculated as the independent control law.
7. The system according to claim 1, characterized in that, The process of performing control adjustments on each network security device according to the control adjustment amount, collecting the operating status quantities after control adjustment, and calculating the dynamic performance indicators of the control system includes: Based on the control adjustment amount, control instructions are issued to each network security device, including task allocation ratio adjustment, processing priority setting and resource quota modification; Real-time acquisition of the time series of operational status variables of each network security device after control and adjustment; Calculate the adjustment time required for each device's operating status variable to reach the target value from the initial deviation, and record it as the system adjustment time; Calculate the ratio of the maximum extent by which the operating status variables of each device exceed the target value during the adjustment process to the target value, and record it as the overshoot. The time required for each device's operating status value to enter and remain within the target value tolerance band is recorded as the settling time. The deviation between the operating state variables of each device and the target value after reaching steady state is calculated and denoted as steady-state error. The settling time, overshoot, settling time, and steady-state error are integrated to form the dynamic performance index.
8. The system according to claim 1, characterized in that, The adaptive adjustment of the control parameters of the decoupled controller and the distributed controller based on the dynamic performance index includes: Define the comprehensive performance evaluation function of the control system; Calculate the value of the comprehensive performance evaluation function under the current control parameters; Determine whether the value of the comprehensive performance evaluation function meets the preset performance index requirements; If the conditions are not met, the gradient descent method or genetic algorithm is used to optimize the control parameters, which include the decoupling compensation matrix elements of the decoupling controller and the PID parameters of the distributed controller. During the control parameter optimization process, the multi-input multi-output control system model is simulated to predict the dynamic performance index corresponding to the adjusted control parameters. Select the control parameter that minimizes the value of the comprehensive performance evaluation function as the updated control parameter; The updated control parameters are applied to the decoupled controller and the distributed controller, thereby updating the decoupled control law and the independent control law.
Citation Information
Patent Citations
Decoupling control method for weak power grid inverter system
CN118554519A
Power plant load intelligent adjustment method and system
CN120582128A