An intelligent routing adaptive optimization method and system based on artificial intelligence

By employing an AI-based intelligent routing adaptive optimization method, the performance issues of traditional routing mechanisms in high-concurrency, large-scale, and dynamically changing network environments are resolved. This enables intelligent and efficient network optimization, improving network reliability, stability, and security.

CN122293570APending Publication Date: 2026-06-26SHENZHEN FANGYUANBAO INFORMATION TECH SERVICE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-31
Publication Date
2026-06-26

Smart Images

  • Figure CN122293570A_ABST
    Figure CN122293570A_ABST
Patent Text Reader

Abstract

This invention relates to the field of routing optimization technology, and more particularly to an intelligent adaptive routing optimization method and system based on artificial intelligence. The method includes the following steps: identifying multi-device interconnection information in the routing network; performing topology interconnection analysis between multiple devices and performing temporal topology modeling to construct a network topology spatiotemporal evolution model; performing real-time link monitoring of the network topology spatiotemporal evolution model based on a distributed probe agent and performing dynamic link quality mapping to construct a topology link quality mapping model; identifying data packets of each service flow in the network topology spatiotemporal evolution model, performing dynamic perception of traffic behavior and traffic situation prediction to generate future time window traffic prediction trends; acquiring traffic mirror feedback data, performing abnormal access traffic detection and network risk situation perception to generate a network security intelligent perception map. This invention performs adaptive routing optimization based on the real-time status of the links, avoiding network congestion and improving traffic transmission efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of routing optimization technology, and in particular to an intelligent routing adaptive optimization method and system based on artificial intelligence. Background Technology

[0002] In modern communication network systems, with the rapid increase in data traffic and the increasing complexity of network structures, traditional routing mechanisms face severe challenges in coping with high-concurrency, large-scale, and dynamically changing network environments. Traditional routing protocols typically select paths based on static or semi-dynamic rules, making it difficult to respond promptly to rapid changes in network conditions. This can easily lead to problems such as routing congestion, increased transmission latency, and low link utilization, and in severe cases, may even cause network service interruptions and a decline in overall performance.

[0003] Meanwhile, network operation faces various external uncertainties, such as sudden traffic surges, link failures, node migrations, and malicious attacks, making traditional fixed-policy routing optimization methods difficult to achieve true flexibility and robustness. Furthermore, existing adaptive routing mechanisms mostly rely on preset algorithm parameters and human policy adjustments, lacking a deep understanding of complex network behavior and real-time decision-making capabilities. They fail to fully exploit the patterns and characteristics hidden in network operation data, resulting in limited network optimization efficiency and failing to meet the high-efficiency transmission requirements of intelligent network environments. Against this backdrop, to achieve highly intelligent, dynamic, adaptive, and optimized network path selection, it is urgently necessary to introduce artificial intelligence technology to construct an intelligent routing optimization method with real-time perception, accurate prediction, and autonomous decision-making capabilities. Summary of the Invention

[0004] To address the aforementioned technical problems, this invention proposes an intelligent routing adaptive optimization method and system based on artificial intelligence, thereby resolving at least one of the aforementioned technical problems.

[0005] To achieve the above objectives, this invention provides an intelligent routing adaptive optimization method based on artificial intelligence, comprising the following steps: Step S1: Identify the interconnection information of multiple devices in the routing network; perform topology interconnection analysis between multiple devices, and perform temporal topology modeling to construct a network topology spatiotemporal evolution model; Step S2: Based on the distributed probe agent, perform real-time link monitoring on the network topology spatiotemporal evolution model, and perform dynamic link quality mapping to construct a topology link quality mapping model; Step S3: Identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and prediction of traffic situation, so as to generate the traffic prediction situation of future time windows; Step S4: Obtain traffic mirroring feedback data, perform abnormal access traffic detection and network risk situation awareness, and generate a network security intelligent awareness map; Step S5: Based on the future time window traffic prediction trend, network security intelligent perception map and topology link quality mapping model, perform multi-link capacity planning calculation and real-time stable link adjustment to generate an adaptive routing scheduling strategy. Step S6: Reconfigure traffic distribution based on the adaptive routing scheduling strategy, then perform iterative route optimization to build an intelligent iterative route optimization agent.

[0006] This specification provides an artificial intelligence-based intelligent route adaptive optimization system for executing the artificial intelligence-based intelligent route adaptive optimization method described above, including: The topology interconnection analysis module identifies the interconnection information of multiple devices in the routing network; performs topology interconnection analysis between multiple devices; performs temporal topology modeling; and constructs a network topology spatiotemporal evolution model. The link quality calculation module is used to perform real-time link monitoring on the spatiotemporal evolution model of network topology based on the distributed probe agent, and to perform dynamic link quality mapping to build a topology link quality mapping model. The traffic situation prediction module is used to identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and traffic situation prediction, and generate future time window traffic prediction situation. The risk situation awareness module is used to acquire traffic mirror feedback data, detect abnormal access traffic and network risk situation awareness, and generate a network security intelligent awareness map. The adaptive routing scheduling module is used to perform multi-link capacity planning calculations and real-time stable link adjustments based on future time window traffic prediction trends, network security intelligent perception maps, and topology link quality mapping models, and to generate adaptive routing scheduling strategies. The iterative route optimization module is used to reconfigure traffic distribution based on adaptive route scheduling strategies, and then perform iterative route optimization to build an intelligent iterative route optimization agent.

[0007] The beneficial effects of this invention are specifically as follows: Through in-depth analysis and modeling of network topology, a comprehensive and dynamic view is provided, helping to identify the interconnection relationships between multiple devices. Using temporal topology modeling, changes in network topology at different time points can be tracked, accurately predicting topology change trends and providing a data foundation for subsequent traffic prediction and routing optimization. The spatiotemporal evolution model of the topology reflects the dynamic changes of network devices and links, facilitating timely adjustments and optimizations when network changes occur. Real-time monitoring of links through a distributed probe agent can quickly detect problems when link quality changes, contributing to improved network reliability and stability. The link quality mapping model visually displays the quality of each link, providing a basis for subsequent traffic guidance and routing decisions. Links with better quality can be dynamically selected for traffic forwarding, reducing packet loss and latency and improving network performance. Identifying and analyzing data packets of service flows allows for real-time perception of traffic changes and patterns, helping to determine the current network load status. Traffic situation prediction allows for forecasting traffic demand within future time windows. This not only helps in advance planning of bandwidth requirements but also facilitates dynamic adjustment of traffic guidance strategies. Traffic prediction results can identify potential traffic pressure in advance, providing a basis for load balancing and routing adjustments. Through traffic mirroring feedback data, abnormal traffic can be detected in real time, and potential security threats (such as DDoS attacks and virus propagation) can be identified. This helps to prevent malicious traffic from intruding into the network in advance. Generating a network security intelligent awareness map helps to dynamically understand the network's security status, quickly respond to security incidents, and ensure network security. It can quickly identify abnormal traffic patterns in massive traffic volumes, reducing missed detections and false alarms, and improving the accuracy of security incident response. By integrating traffic prediction, security awareness, and link quality assessment, it can dynamically adjust link capacity and stability, avoiding link congestion or performance degradation. The generated adaptive routing scheduling strategy can make intelligent decisions based on real-time data, ensuring traffic is transmitted on the optimal link and improving the overall network operating efficiency. It can intelligently schedule multiple links according to their status and needs, thereby achieving higher network resource utilization. Based on the adaptive routing scheduling strategy, traffic can be optimized and distributed according to the real-time status of links, avoiding network congestion and improving traffic transmission efficiency. Through iterative route optimization, routing paths can be continuously adjusted, making network routing more intelligent and efficient. This optimization is dynamic and adaptable to changes in network conditions. By constructing an intelligent iterative routing optimization agent, the network can automatically make optimization decisions based on real-time data during operation, reducing human intervention and maintenance costs. Attached Figure Description

[0008] Figure 1 This is a flowchart illustrating the steps of an intelligent routing adaptive optimization method based on artificial intelligence according to the present invention. Figure 2 This is a detailed flowchart illustrating the implementation steps of step S1. Figure 3 This is a detailed flowchart illustrating the implementation steps of step S2; Figure 4 This is a flowchart illustrating the detailed implementation steps of step S3. Detailed Implementation

[0009] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0010] This application provides an artificial intelligence-based intelligent routing adaptive optimization method and system. The executing entities of the artificial intelligence-based intelligent routing adaptive optimization method and system include, but are not limited to, mechanical equipment, data processing platforms, cloud server nodes, network upload devices, etc., which can be considered general computing nodes of this application. The data processing platform includes, but is not limited to, at least one of an audio-visual management system, an information management system, and a cloud data management system.

[0011] Please see Figures 1 to 4 This invention provides an intelligent routing adaptive optimization method based on artificial intelligence, comprising the following steps: Step S1: Identify the interconnection information of multiple devices in the routing network; perform topology interconnection analysis between multiple devices, and perform temporal topology modeling to construct a network topology spatiotemporal evolution model; Step S2: Based on the distributed probe agent, perform real-time link monitoring on the network topology spatiotemporal evolution model, and perform dynamic link quality mapping to construct a topology link quality mapping model; Step S3: Identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and prediction of traffic situation, so as to generate the traffic prediction situation of future time windows; Step S4: Obtain traffic mirroring feedback data, perform abnormal access traffic detection and network risk situation awareness, and generate a network security intelligent awareness map; Step S5: Based on the future time window traffic prediction trend, network security intelligent perception map and topology link quality mapping model, perform multi-link capacity planning calculation and real-time stable link adjustment to generate an adaptive routing scheduling strategy. Step S6: Reconfigure traffic distribution based on the adaptive routing scheduling strategy, then perform iterative route optimization to build an intelligent iterative route optimization agent.

[0012] In the embodiments of the present invention, see Figure 1 The diagram below illustrates the steps of an artificial intelligence-based intelligent routing adaptive optimization method according to the present invention. In this example, the steps of the artificial intelligence-based intelligent routing adaptive optimization method include: Step S1: Identify the interconnection information of multiple devices in the routing network; perform topology interconnection analysis between multiple devices, and perform temporal topology modeling to construct a network topology spatiotemporal evolution model; In this embodiment, interconnection information between devices in a routing network is identified. The core of this process is collecting the connection status of all devices in the network, as well as the interconnection relationships of network nodes such as switches and routers. By using network protocols (such as SNMP, ICMP, ARP, etc.) and device exchange data records, the system can identify the connections and interactions between devices in the network. This interconnection information includes physical and logical connections between devices, such as which devices are connected to each other via which links, and performance indicators such as device ports, bandwidth, and latency. The key to the identification process is extracting interconnection data through network topology probing and interaction with device communication protocols. In experiments, packet capture tools (such as Wireshark) and routing protocols (such as OSPF, BGP) are typically used to obtain device interconnection data. For larger networks, the identification frequency can be set to update every 30 seconds to ensure that the acquired interconnection information reflects the actual connection status of devices in a timely manner. This is achieved by constructing a topology graph, where network devices are nodes and the links between devices are edges. During the analysis, the system uses graph theory algorithms (such as Dijkstra's algorithm and Bellman-Ford algorithm) to analyze key indicators such as shortest paths and load balancing between devices based on their physical or logical addresses. In addition, it analyzes performance data such as link bandwidth, latency, and packet loss rate to determine the optimal communication path between devices. To ensure the accuracy of the analysis, the system collects device status information, such as link bandwidth (in Mbps) and latency (in ms), and uses traffic monitoring tools (such as NetFlow and sFlow) to continuously track link status changes, adjusting the topology analysis model based on this data.

[0013] Temporal topology modeling incorporates the evolution of network topology into the model to adapt to dynamic changes in the network environment. Network topology is not static; the addition and removal of devices and changes in link states over time all affect it. To accurately describe this evolution, the system needs to use time-series analysis techniques (such as time series forecasting and sliding window analysis) to correlate the states of devices and links with time series, generating a temporal topology model. In practice, the system analyzes the access time of each device, changes in link bandwidth utilization, etc., to construct the topology state of devices at different points in time. Temporal topology modeling typically employs methods such as Markov processes and state transition matrices to predict future changes in the connection states between devices, considering factors such as device and link lifecycles, traffic load, and link failures. Through temporal topology modeling, the system constructs a complete spatiotemporal evolution model of the network topology. This model is a comprehensive representation of the network topology in both time and space dimensions, capable of describing the states of each device and link in the network over time. The goal of this model is to accurately predict possible changes in the network topology over future time periods, thereby providing support for intelligent routing optimization. The spatiotemporal evolution model not only focuses on the static structure of the network topology but also considers dynamic factors such as link bandwidth, latency, and faults. Specifically, the system utilizes spatiotemporal analysis algorithms in machine learning (such as spatiotemporal graph convolutional networks and LSTM) to spatiotemporally model the connection status and link performance between devices to predict the future state of the network. This model can optimize routing strategies and predict potential network bottlenecks based on changes in the network topology at different time points, thereby adjusting network configurations to ensure efficient network operation. In experiments, the model construction requires a large amount of historical data and relies on a high-precision prediction model. In practical applications, the accuracy of the network topology spatiotemporal evolution model should reach over 85% to ensure its effectiveness and practicality.

[0014] Step S2: Based on the distributed probe agent, perform real-time link monitoring on the network topology spatiotemporal evolution model, and perform dynamic link quality mapping to construct a topology link quality mapping model; In this embodiment, distributed probing agents are deployed. These agents are typically composed of lightweight network probing modules and are deployed on key routers, switches, or core terminal device nodes to achieve comprehensive sampling of critical links across the entire network. Each agent node obtains the actual transmission performance parameters of the link by periodically sending probe packets (such as ICMP, UDP, TCP SYN Probe, or custom NetFlow sampling packets) to other network nodes. To ensure sampling efficiency and coverage balance, a node-centric strategy was adopted in the experiment to select deployment points (the top 15% of Betweenness Centrality), with a total of 64 probing agents deployed and a sampling period of 10 seconds.

[0015] During the sampling process, each probe agent records the following key metrics: average round-trip time (RTT), one-way latency, packet loss ratio, jitter, available bandwidth, and throughput. These raw metrics undergo local preprocessing (such as outlier removal and smoothing filtering) within each sampling period and are uploaded to the central monitoring system via MQTT or Kafka message middleware to support unified link quality modeling. The system constructs a topology-based link quality mapping model based on a dynamic weighted graph modeling framework. This model is essentially a time-series graph, with each edge carrying a quality vector that evolves over time to describe the link's transformation from normal, high-load, to potential failure. This model further incorporates anomaly detection mechanisms (such as an LSTM-based sequence prediction residual detector) to issue early warnings for link mutations or abnormal fluctuations, such as automatically marking a link as high-risk if the predicted packet loss rate is greater than 20% in the next 5 minutes. To enhance model visualization and interactivity, the system maps link quality data onto a visualized topology map, providing real-time feedback on the current network operating status through color gradients, edge thickness variations, and flashing effects. For example, in the simulation environment, the system successfully detected severe latency spikes on three core links during peak data periods and promptly alerted operations and maintenance personnel through the visual interface.

[0016] Step S3: Identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and prediction of traffic situation, so as to generate the traffic prediction situation of future time windows; In this embodiment, a deep packet inspection and protocol identification module is used to identify each service data packet passing through the network in real time. In practical applications, standard traffic acquisition protocols such as NetFlow, sFlow, or IPFIX are used to obtain basic metadata of the data flow, including the five-tuple (source IP, destination IP, source port, destination port, protocol type), packet size, timestamp, duration, and other fields. Based on this, a deep protocol parser (such as open-source engines like nDPI or JOY) is introduced to perform application layer protocol reconstruction and behavior identification of the traffic. Using this method, approximately 30 major application types (such as HTTPS, VoIP, SSH, DNS, video conferencing streams, etc.) can be stably identified in an enterprise-level network environment, with a daily peak service traffic of 2.3Tbps. Dynamic perception modeling of traffic behavior is then performed. This process uses a sliding time window technique (such as a three-layer structure of 5 seconds, 30 seconds, and 5 minutes) to construct hierarchical service flow behavior features. Each flow is extracted within a specified time window using the following feature vectors: flow duration, average packet interval, direction change frequency, packet size variation coefficient, bandwidth utilization mutation value, etc. By utilizing these characteristics, clustering algorithms (such as DBSCAN and K-Means++) can be used to classify typical flow behavior patterns, such as stable and continuous flows, high burst control flows, large download flows, and latent abnormal flows, thereby gaining an overall understanding of the current network traffic structure.

[0017] After completing the perception modeling, the system enters the traffic situation prediction stage. The core of this stage is to predict the temporal behavior of different traffic categories, generating traffic trend maps for several future time windows (e.g., the next 10 minutes, 30 minutes, and 1 hour). The prediction employs a multi-model fusion mechanism, using LSTM (Long Short-Term Memory) as the base model, combined with ARIMA (Autoregressive Integral Moving Average), Prophet (Decomposition-based Time Series Modeling), and Transformer-based time series models to predict and model different types of business flows. In the experiment, a large government network was selected as a sample, and the top 10 types of business flows were trained over a historical 72-hour window. The average error of each model predicting the next 30 minutes was between 8.2% and 11.7%, demonstrating good generalization ability. To achieve a visual modeling of the overall future network load distribution, the system weighted and superimposed the predicted trends of each flow type, mapping them back to each node and link based on the network topology, thereby constructing a traffic prediction situation map for the future time window. This graph uses various visual elements such as node popularity, link thickness, and dynamic changes in flow arrows to provide visual warnings of upcoming high-pressure areas, sudden hotspot nodes, and potential congestion paths. For example, in a corporate security drill in 2025, the prediction module identified 45 minutes in advance that an outbound link was about to reach 90% bandwidth saturation and successfully avoided it by adjusting service routes.

[0018] Step S4: Obtain traffic mirroring feedback data, perform abnormal access traffic detection and network risk situation awareness, and generate a network security intelligent awareness map; In this embodiment, relying on SPAN (Switched Port Analyzer) ports or TAP (Test Access Point) devices deployed on network switching equipment (such as core switches, firewalls, and traffic mirroring servers), the entire data flow of a specified link or device is mirrored end-to-end. To reduce processing latency, the mirrored data needs to adopt a distributed caching access architecture, such as a Kafka-based streaming data queue system, which can receive approximately 300,000 to 500,000 mirrored data packets per second (depending on bandwidth configuration). This raw data then enters the security analysis engine, proceeding to the abnormal access traffic detection phase. In this process, the system first performs multi-dimensional feature extraction on the mirrored traffic data, including but not limited to: IP address distribution characteristics, access frequency, port scanning behavior, packet size variability, protocol layer interaction paths, and other features. For example, for a potential DDoS attack, the system can perform feature matching by analyzing the source IP distribution entropy (Shannon entropy), burst rate, ACK / RST ratio, etc. Using machine learning methods, the system will collaboratively determine whether there is abnormal access behavior based on supervised classification models (such as RandomForest and LightGBM) and unsupervised clustering methods (such as Isolation Forest and DBSCAN).

[0019] Specifically, the system embeds a behavior association modeling framework based on Graph Neural Network (GNN). By establishing a graph structure between IP and traffic behavior and introducing node embedding and edge weight learning mechanisms, the system can mine potential collaborative relationships between attack sources, thereby identifying highly concealed APT attacks and lateral penetration behaviors. In actual testing, when conducting a week-long traffic capture and analysis of an enterprise's intranet environment, the module successfully identified a reverse shell connection disguised through a legitimate port (443), with an accuracy rate of 93.6% and a false negative rate of 4.1%. After completing the abnormal flow detection, the system enters the network risk situation awareness modeling stage. The system normalizes and fuses multi-dimensional indicators such as abnormal flow behavior within a time window, triggered attack feature rules (such as those based on the Snort / YARA rule engine), link occupancy rate change trends, and attack path propagation to generate a network security risk situation matrix. This matrix unfolds along a node-time dimension, reflecting the risk level of each device within the current time period (categorized into four levels: secure, low-risk, medium-risk, and high-risk), and assigning path sensitivity scores to the affected paths of critical resources. The system constructs a network security intelligent perception map. This map expresses the source, flow path, affected devices, behavioral characteristics, and predicted trends of each type of security event in the network in a visual structure. Nodes in the map represent source / destination IPs, servers, gateway devices, etc.; edges represent network flow and risk propagation channels; and the color and thickness of the edges map to attack intensity and frequency. Interactive and dynamic visualization of the map is achieved by integrating a WebGL graphics engine or a Three.js 3D visualization component. The system also supports security map heatmap overlays, reflecting the security "temperature" of the entire network environment in real time through color changes.

[0020] Step S5: Based on the future time window traffic prediction trend, network security intelligent perception map and topology link quality mapping model, perform multi-link capacity planning calculation and real-time stable link adjustment to generate an adaptive routing scheduling strategy. In this embodiment, based on future time window traffic prediction data, the upcoming peak and off-peak periods of network load are determined. During this stage, the system uses an LSTM (Long Short-Term Memory) recurrent neural network model to perform sliding window prediction of service traffic (typically with a window width of 30 to 300 seconds), outputting the bandwidth demand change trend of each link in the future time period (in bps). Combined with statistical parameters such as the maximum, average, and volatility of traffic distribution, a link capacity utilization prediction model is established. Taking an experimental environment as an example, in the prediction module deployed in a medium-sized enterprise campus network, the model's Mean Absolute Error (MAE) for traffic changes in the next 10 minutes remains below 4.7 Mbps, with prediction accuracy fluctuating within ±8%.

[0021] Simultaneously, the system calls upon the network security intelligent perception map generated in the previous step to identify potential risky links or attacked nodes. By setting risk level thresholds (e.g., nodes with "medium risk and above" will be marked as routing avoidance targets), the system dynamically adjusts the set of available links, eliminating link areas with potential security vulnerabilities to ensure security redundancy in the path selection process.

[0022] Next, based on the topology link quality mapping model, the system evaluates key performance indicators such as available bandwidth, latency, packet loss rate, and jitter for each link, and calculates the "availability weight coefficient" for each link accordingly. In the specific implementation, each link is assigned a comprehensive evaluation weight value, and the formula typically includes the following weighted dimensions: Real-time bandwidth utilization (30% weight) Delay mean and variance (25% weight) Packet loss rate (20% weight) Safety risk coefficient (15% weight, taken from the graph) Fluctuation stability (10% weight, derived from the QoS change trend of the previous 10 minutes) After normalization, the above parameters are input into the optimization module to perform multi-link capacity planning and path reconstruction calculations. This step uses graph search and heuristic algorithms (such as the A* algorithm and the K-shortest path algorithm optimized by genetic algorithms) to calculate the optimal path under constraints. The optimization objective is to maximize overall bandwidth utilization, minimize path hop count, and avoid high-risk nodes and low-quality links. In the scheduling experiment, the system generates a set of path recommendation strategies (Top-N path suggestions) every second for subsequent strategy distribution and verification. Based on the above calculation results, combined with the current network traffic status and historical behavior patterns, the system performs real-time stable link adjustments. Through the interface with the SDN (Software-Defined Networking) controller (such as the OpenFlow protocol), the system dynamically distributes path change policies to the corresponding switches and routers to achieve data flow rerouting. This process must ensure uninterrupted service during the adjustment process; therefore, the system introduces a hot path switching mechanism and the principle of minimum traffic disturbance, switching only the path with the highest congestion risk, and setting a minimum interval threshold (generally 10 to 30 seconds) for each path reassignment to prevent frequent jitter. Finally, the system summarizes all link status, predicted load, path adjustment and policy issuance actions to generate a structured adaptive routing scheduling policy report. This policy not only includes the optimized path settings for the current time period, but also provides dynamic routing suggestions for multiple future time windows (such as 5 minutes, 15 minutes, and 30 minutes), which facilitates the network management system to plan resources in advance.

[0023] Step S6: Reconfigure traffic distribution based on the adaptive routing scheduling strategy, then perform iterative route optimization to build an intelligent iterative route optimization agent.

[0024] In this embodiment, after receiving the adaptive routing scheduling policy, the system calls the routing control module (such as an SDN controller) to reallocate some critical service flows (especially high-bandwidth, low-latency, or high-priority flows) in the current network to the new paths recommended by the policy. This process requires real-time querying of the current network topology, link load, and service priorities. Taking an enterprise backbone network as an experimental scenario, the system uses static priority classification (VoIP > database > video stream > file transfer) combined with dynamic traffic stress test results to allocate bandwidth and paths according to the ratio of service importance and timeliness (such as 30:40:20:10). This stage must also ensure the "seamlessness" of traffic migration; therefore, MPTCP (Multipath TCP) and load balancing scheduling algorithms (such as Weighted Round Robin, WRR) are used for parallel forwarding to ensure uninterrupted switching. After traffic redistribution, the path configuration status of the entire network is globally re-optimized. In this phase, the system introduces an intelligent routing policy optimization method based on reinforcement learning (RL), with the core algorithms being Deep Q-Network (DQN) or Proximal Policy Optimization (PPO). Network states (such as link bandwidth utilization, latency, jitter, and packet loss rate) are encoded as state vectors and input into the agent model. The optimization objective is to maximize the overall routing reward function (typically defined as a weighted combination of maximizing network throughput, minimizing latency, and optimizing security). After each path adjustment, the system obtains a new round of state reward signals through a feedback mechanism, thereby guiding the evolution of the next routing policy.

[0025] Using continuous 24-hour real-world network traffic simulation (average 85 network nodes, average 312 links, and traffic fluctuations ranging from 150Mbps to 1.6Gbps), the agent updates its policy every 5 minutes, with each training iteration consisting of 300 rounds. The overall optimization convergence time is controlled within 30 minutes. Compared to the initial static policy, the agent's optimized path scheme reduces average service flow latency by 14.2%, packet loss rate by 8.7%, and path hop count by 1.1 hops, achieving significant benefits from intelligent iteration. To prevent network instability caused by frequent agent updates in actual deployment, the system employs an adaptive learning rate and policy solidification mechanism. When the fluctuation in routing optimization performance falls below a preset threshold (e.g., optimization performance fluctuation less than 2% over three consecutive evaluation periods), the current policy is solidified as the interim optimal policy and stored in the policy pool for version management. Simultaneously, a policy memory module with a forgetting mechanism is introduced, retaining only the top-N best-performing policies for rapid rollback and comparison reference during future routing scheduling. Through the continuous execution of this step, the system successfully constructed an intelligent iterative routing optimization agent that can perceive changes in network status, make autonomous routing decisions, and self-evolve and optimize in a dynamic real-world traffic environment. This agent becomes the core scheduling mechanism of the entire intelligent routing architecture, realizing a fundamental leap from a passive response-oriented to an active intelligent network, and providing solid technical support and a model foundation for traffic scheduling, bandwidth resource allocation, and security protection in large-scale complex network environments.

[0026] In this embodiment, see Figure 2 The diagram below illustrates the detailed implementation steps of step S1. In this embodiment, the detailed implementation steps of step S1 include: Identify interconnection information of multiple devices in a routing network; The device node is identified from the multi-device interconnection information, and the topology interconnection between the multiple devices is analyzed to extract the topology interconnection path between the multiple devices. Based on the topology interconnection path, a global device connection fit is performed to construct a multi-device topology interconnection network; Node importance assessment and edge weight calculation are performed based on multi-device topology interconnection networks to generate topological semantic features; Based on multi-device interconnection information, real-time establishment and exit detection of device links are performed to generate real-time network connectivity trends of devices. Based on the real-time networking trends and topological semantic features, a temporal topology model is performed on the multi-device interconnection network to construct a spatiotemporal evolution model of the network topology.

[0027] In this embodiment, by capturing data packets in the network and analyzing information such as source and destination addresses, protocol types, and port numbers, preliminary connection information between devices can be inferred. Using packet analysis tools such as Wireshark and Tcpdump, combined with network management protocols such as SNMP (Simple Network Management Protocol) and LLDP (Link Layer Discovery Protocol), the interconnection status between devices can be monitored in real time. ARP (Address Resolution Protocol) and MAC address table lookups can further confirm the physical connection status of devices. The multi-device interconnection information obtained through these methods will form the basis for subsequent topology analysis and optimization, providing real-time feedback on dynamic links and changes between devices. Graph theory is used to model the connections between devices, treating devices as nodes in a graph and connections as edges. By employing traditional shortest path algorithms (such as Dijkstra's and Bellman-Ford's algorithms) or link-state-based algorithms (such as OSPF and IS-IS protocols), paths between devices are analyzed and optimal routes are obtained. To further optimize the topology, for loops or redundant paths in complex networks, minimum spanning tree (MST) algorithms, such as Kruskal's or Prim's algorithms, are used to eliminate unnecessary redundant connections, ensuring the efficiency and stability of the network topology. Simultaneously, network topology discovery technologies, such as the OpenFlow protocol in SDN (Software-Defined Networking), are employed to update the network topology in real time, providing efficient path planning and routing decisions. Optimization algorithms (such as genetic algorithms and simulated annealing) are used for global topology optimization. First, a preliminary device connection graph is established using the minimum spanning tree algorithm. Then, simulated annealing or genetic algorithms are introduced to optimize the connection paths between devices in the network, ensuring the selection of paths with high bandwidth, low latency, and strong stability. This optimization process reduces data transmission latency between devices in the network and avoids excessively congested links. Furthermore, load balancing algorithms are used to distribute traffic, ensuring a reasonable distribution of transmission load among different devices and preventing network bottlenecks.

[0028] By calculating the "centrality" metrics of device nodes (such as degree centrality, betweenness centrality, and proximity centrality), the importance of each node in the network can be assessed. Nodes with high betweenness centrality are usually located in the core area of ​​data traffic and are key points for network transmission, while nodes with high degree centrality connect more devices and act as bridges. In edge weight calculation, weights are assigned to each link based on parameters such as bandwidth, latency, and packet loss rate. In this process, the shortest path algorithm can be used to weight the paths in the network, prioritizing links with lower latency and higher bandwidth, and dynamically adjusting the weights based on link stability and real-time load to achieve effective optimization of the network topology. Through BGP (Border Gateway Protocol) or OSPF protocols, in conjunction with network traffic monitoring systems (such as NetFlow, sFlow, etc.), the establishment, termination, and failure information of device links can be detected in real time. Based on this data, combined with reinforcement learning algorithms (such as Q-learning, Deep Q-Networks), the system can adjust routing paths in real time to reduce network performance degradation caused by device failures or link changes. Furthermore, the system can utilize temporal analysis methods (such as deep learning models like LSTM and GRU) to predict the changing trends of device links and make advance routing adjustments to ensure the network is always in optimal operating condition. By using temporal deep learning models such as LSTM (Long Short-Term Memory) or GRU (Gated Recurrent Unit), the system can model the temporal changes in connections between devices and predict future trends in device links. These models can capture periodic or sudden changes in network topology based on historical data, thus providing predictive capabilities. Combined with network topology semantic features (such as topology density, average path length, node centrality, etc.), the system can automatically optimize the network topology in time and space, adjusting the connection paths between devices in real time. In this process, the spatiotemporal evolution model can automatically adjust routing strategies according to the predicted network change trends to ensure adaptive optimization of the network and achieve optimal performance.

[0029] In this embodiment, see Figure 3 The diagram below illustrates the detailed implementation steps of step S2. In this embodiment, the detailed implementation steps of step S2 include: Based on a distributed probe agent, real-time link monitoring is performed on the spatiotemporal evolution model of network topology to extract round-trip delay, bandwidth utilization, bit error rate and availability status of multiple network links. The round-trip time, bandwidth utilization, bit error rate, and availability status are evaluated to assess the link network quality and generate a real-time quality assessment value for each link. The time-series quality change trend is calculated based on the real-time quality assessment value to obtain the time-series quality trend curve for each link; Based on the time-series quality trend curve, link reliability is predicted, and a reliability index for each link is generated. Based on the aforementioned reliability indicators, a dynamic link quality mapping is performed on the network topology spatiotemporal evolution model to construct a topology link quality mapping model.

[0030] In this embodiment, distributed probing agents are deployed to monitor the performance metrics of each link in the network in real time. Each probing agent is placed on a key node in the network (such as between routers, switches, and terminal devices) and periodically performs network performance probing tasks. Through active probing methods (such as ICMP echo requests, TCP three-way handshakes, UDP packet transmission, etc.), the probing agents can collect link round-trip time (RTT), bandwidth utilization, bit error rate (BER), and link availability status (whether the link is disconnected or faulty). This data is transmitted to the central node through the probing agents, and after aggregation, a real-time performance view of the network is generated. The monitoring cycle is typically set to 1 to 5 seconds to ensure data real-time performance. In the experiment, it is assumed that the monitoring data of 100 links is sampled every 3 seconds, the interval between each data packet transmission is 10ms, and the data transmission latency is less than 50ms to ensure efficient link monitoring. The system comprehensively evaluates the quality of each link based on the collected data. The link quality evaluation is based on multiple key performance indicators, such as round-trip time, bandwidth utilization, bit error rate, and availability. Each metric is normalized. For example, the maximum tolerable round-trip latency is 50ms, bandwidth utilization is optimally set between 60% and 80%, a bit error rate below 10^-6 is acceptable, and link availability must be above 99%. Based on these standards, a weighted average method is used to calculate the quality score for each link. The evaluation formula can be: Where w1, w2, w3, and w4 are the weights of each performance metric. In this way, a comprehensive quality score for the link is generated to determine its performance within the entire network. The evaluation weights set in the experiment were: RTT 40%, bandwidth utilization 30%, bit error rate 20%, and availability 10%.

[0031] The system employs sliding window techniques or time-series models (such as LSTM and ARIMA) to model and analyze the changing trends of link quality over time. The sliding window algorithm smooths the quality assessment value of each link, eliminating the impact of short-term fluctuations and capturing long-term trends. By training an LSTM model, the system can predict future link quality trends based on historical quality data and plot a time-series quality trend curve. This curve effectively reflects changes in link quality at different points in time, providing a basis for subsequent fault prediction and network optimization decisions. In the experiment, the sliding window time range was set to 30 minutes, the LSTM model training cycle was 10 rounds, and retraining was performed every hour. Deep learning models such as LSTM (Long Short-Term Memory) or GRU (Gated Recurrent Unit) are used to train on historical link quality data to predict future link quality changes. The goal of this process is to determine whether a link will experience performance degradation or failure. By inputting the time-series link quality data into the trained prediction model, the system can output a reliability index for each link, representing the probability that the link will maintain good performance over a future period. The link reliability score is used to determine whether the link is worth continuing to undertake data transmission tasks. For fault prediction, a fault probability threshold of 50% is set. This means that when the predicted link reliability falls below 50%, the system automatically triggers path reselection or activates a backup link. The routing strategy in the network topology is dynamically adjusted based on the real-time reliability and quality assessment values ​​of each link. High-reliability links will prioritize carrying more data traffic, while low-reliability links will be temporarily removed from the main path or have traffic carried via backup paths. The system uses a link quality mapping model based on reliability metrics and dynamically adjusts link selection through optimization algorithms (such as shortest path first, load balancing, etc.) to ensure the overall stability of network performance. In the experiment, links with reliability values ​​below 0.5 were automatically removed, and the network topology adjustment cycle was 5 minutes to ensure rapid response to changes in link quality.

[0032] In this embodiment, reference Figure 4 The above is a detailed implementation flowchart of step S3. In this embodiment, the detailed implementation steps of step S3 include: Identify data packets of various service flows in the spatiotemporal evolution model of network topology; The packet traffic size of each service flow data packet is calculated, and the link distribution is analyzed to obtain network link traffic distribution data; Perform protocol stack layer parsing and business application identification on data packets of each business flow, and mark data packet attributes; Dynamically perceive traffic behavior based on network link traffic distribution data and data packet attributes, and construct a panoramic perception map of traffic behavior. Predict future traffic patterns based on a panoramic perception map of traffic behavior, in order to generate a predicted traffic pattern for future time windows.

[0033] In this embodiment, the identification of service flow data packets relies on network layer and transport layer protocols, such as IP addresses and port numbers. First, the system captures all data packets in the network in real time through a distributed probing agent and performs deep analysis of the packets using network packet capture tools (such as Wireshark and Tcpdump). Each captured data packet contains information such as source IP, destination IP, protocol type (such as TCP or UDP), and port number. This information allows the data packets to be categorized into different service flows. For example, a data packet on TCP port 80 can be classified as HTTP traffic, while a data packet on TCP port 443 is HTTPS traffic. Through these service flow characteristics, the system can accurately identify each service flow in the network topology, thus providing data support for subsequent traffic analysis and routing optimization. In the experiment, the number of captured data packets reached thousands per second, and the identification time accuracy of each data packet was at the microsecond level. The system statistically analyzes the size of each data packet to obtain the traffic information for each service flow. The calculation of traffic size depends on the number of bytes in the data packet. Combined with the arrival timestamp of the data packet, the bandwidth usage of each service flow on the link can be calculated. Furthermore, the system aggregates traffic based on the time series of data packets to analyze the distribution of link load. Link distribution analysis displays the traffic density, transmission rate, and load of each link. By statistically analyzing link traffic distribution data, the system can identify high-load and low-load links in the network, providing a basis for subsequent load balancing and routing optimization. In the experiment, the number of links in the network can reach 100, and the timestamp accuracy of data packets is at the nanosecond level, enabling precise calculation of the instantaneous traffic of each link. Protocol stack parsing refers to identifying the specific protocol type of the data packet and the application layer data it transmits by analyzing the protocol fields of the data packet layer by layer (such as Ethernet header, IP header, TCP / UDP header, etc.). Application identification relies on Deep Packet Inspection (DPI) technology, which identifies the specific business application to which the data packet belongs by analyzing the content of the data packet (such as the URI of an HTTP request, DNS query content, etc.), such as web browsing, video streaming, file transfer, etc. During the parsing process, the system marks each data packet with attributes such as its protocol type, business application type, and data packet size, thereby constructing a full business flow data model. Through this process, the system can perform fine-grained management and optimization of various business flows in the network. In the experiment, the protocol stack parsing time of the data packets was controlled within 1 millisecond to ensure rapid processing of large-scale data packet traffic.

[0034] The system employs machine learning algorithms to perform deep learning on the packet characteristics of various service flows, identifying traffic behavior patterns within the network. By analyzing information such as temporal changes in link traffic, protocol distribution, and service traffic share, the system can detect abnormal traffic fluctuations and sudden traffic spikes. Dynamic perception goes beyond real-time monitoring; it also includes trend prediction and anomaly detection. In this process, the system constructs a panoramic perception map of traffic behavior, vividly displaying the traffic distribution and behavioral characteristics of different service flows on various links. Through this panoramic perception map, the system can identify traffic bottlenecks, overloaded areas, and potential network attacks (such as DDoS attacks). This map combines multi-dimensional information such as link load, traffic fluctuations, and service traffic share, providing a comprehensive view for network optimization. In the experiment, the traffic perception map is updated once per second, supporting multi-dimensional dynamic data visualization. Temporal prediction models, such as LSTM (Long Short-Term Memory) and ARIMA (Autoregressive Integral Moving Average), are trained on historical network traffic data to predict traffic change trends within future time windows. Traffic prediction goes beyond predicting a single link or a single service flow; it considers overall network traffic changes and generates a traffic situation map for future time windows through a multi-dimensional prediction model. This prediction helps network administrators identify potential congestion points in advance, enabling traffic scheduling and path optimization to prevent network overload and performance degradation. The prediction model is trained for several hours, with each update window lasting 30 minutes to ensure the network can dynamically adapt to load changes. In experiments, the model's prediction accuracy is required to reach over 90% to ensure the accuracy of traffic prediction. In this embodiment, the specific steps for generating future time window traffic situation prediction based on a panoramic traffic behavior perception map are as follows: Based on the data packets of each business flow, user access patterns are analyzed to obtain user access patterns. Calculate the application call frequency based on the data packets of each service flow; Data transmission volume change analysis is performed on the data packets of each service flow to obtain the data transmission volume change values ​​at multiple time points; Periodic variation mining is performed based on the changes in transmission volume at multiple time points to obtain the pattern of data transmission volume changes; Analyze user access needs based on user access patterns, application call frequency, and data transmission volume changes to generate real-time user access requirements. Based on the panoramic perception map of traffic behavior and real-time user access demand, future time window traffic trends are predicted to generate future time window traffic prediction trends.

[0035] In this embodiment, the access behavior of each user is identified by analyzing the source IP, destination IP, and protocol type of each data packet. The construction of user access patterns is based on time series analysis and behavioral clustering methods to identify behavioral characteristics such as the periodicity, frequency, and time period of user access. For example, by analyzing the frequency and time interval of HTTP requests, the active periods and access frequency of users can be determined. The system uses clustering algorithms such as K-means or DBSCAN to cluster users based on attributes such as access time and frequency, thereby obtaining access patterns for different user groups. Using this information, the system can identify common user behavior patterns, such as concentrated access during peak hours and scattered access during off-peak hours. In the experiment, user access data included at least 1000 data packets per second, with each data packet's timestamp accuracy at the millisecond level. The time complexity of the clustering process was controlled within O(n log n). Protocol stack analysis was performed on each data packet to identify the specific application layer protocol (such as HTTP, FTP, DNS, etc.) and the number of calls to each application was counted. The system identifies the call patterns of different applications by extracting application-layer features from data packets, such as HTTP request URIs and DNS query domain names. Subsequently, based on time series analysis, the system calculates the call frequency of each application within different time periods. These frequencies reflect the activity level and volatility of different applications on the network. For example, some applications (such as video streaming applications) may see a significant increase in call frequency during peak hours, while some low-frequency applications are used more frequently during off-peak hours. The system uses a sliding window technique to statistically analyze call frequency on an hourly basis and outputs the call frequency change trend for each application. In the experiment, the application call frequency calculation accuracy was updated once per minute, the frequency statistics window was one hour, and the data acquisition time accuracy was at the second level.

[0036] Based on the timestamps of data packets, the system calculates data traffic (in bytes) for each time period. This allows the system to calculate traffic fluctuations for each link and each service flow in the network at different points in time. To obtain traffic change trends, the system uses a sliding window method, setting the time window to 1 minute or 5 minutes to analyze traffic changes within that time period. Calculating multi-time-point transmission volume changes helps the system identify sudden changes in traffic, load peaks, and troughs. The system uses the transmission volume change value at each time point as a key indicator for traffic trend prediction and anomaly detection. In the experiment, the system collects and calculates the transmission volume of data packets every second and performs traffic aggregation every minute, with the unit of transmission volume change being bytes. Periodic analysis algorithms (such as Fourier transform, waveform analysis, Haar wavelet transform, etc.) are used to analyze the fluctuation patterns of data transmission volume at different time points. By modeling the time series of multi-time-point transmission volume changes, the system can extract periodic traffic patterns, such as daily peak periods and weekly traffic changes. Periodic change mining helps the system identify regular traffic patterns and the underlying regularities behind certain sudden traffic spikes. During this process, the system decomposes the seasonality, trend, and periodicity of traffic and displays these patterns in the form of charts or models to provide a basis for subsequent traffic prediction and resource scheduling. In the experiment, the detection accuracy of periodic changes was required to be above 95%, and the period range of the periodic model ranged from minutes to hours.

[0037] The system predicts user access demands in future time periods and uses these demands to inform network resource scheduling and routing optimization. It trains historical data using machine learning models (such as random forests, support vector machines, and neural networks) and combines this with real-time access patterns, call frequencies, and traffic variation patterns to predict user access demands in future time periods. Predicted user demands include bandwidth requirements for each application, the number of access requests, and traffic transmission rates. These predictions allow the system to adjust network resource allocation in advance, avoiding traffic bottlenecks or congestion. In the experiment, the user access demand analysis time window was 30 minutes, and the prediction accuracy was required to reach over 90% to ensure the effectiveness of network resource scheduling. The system uses a comprehensive traffic prediction model, combining real-time link load data from the traffic behavior perception map with user access demands, to predict traffic trends in future time windows. This model can predict traffic fluctuations, bandwidth demands, and potential congestion points within future time windows. The system models historical data using time-series analysis (such as deep learning models like LSTM and GRU) to generate a traffic trend prediction map for future time periods. This forecast graph displays information such as changes in network traffic demand, application call trends, and traffic peaks, providing network administrators with an intuitive view of the traffic situation. Based on this forecast, the system can perform load balancing, routing optimization, and resource scheduling in advance to ensure the network can cope with changing traffic demands in the future. In the experiment, the traffic forecast was updated every minute, and the accuracy rate was over 95%.

[0038] In this embodiment, step S4 includes the following steps: Full-link data collection is performed based on network traffic mirroring technology to obtain traffic mirroring feedback data; Detect abnormal access traffic based on traffic mirroring feedback data and mark abnormal access traffic data. The system identifies attack behaviors in abnormal access traffic data and assesses the security threat level to determine the threat level of the abnormal behavior. Obtain real-time operating status data of all devices in the routing network; Identify network status fluctuations in real-time device operating status data and mark status fluctuation points; Calculate the amplitude and duration of the state fluctuation at the aforementioned state fluctuation point; Based on the amplitude and duration of the state fluctuations, the real-time device security performance bottleneck is estimated, thereby obtaining the real-time device security performance bottleneck. Based on the threat level of abnormal behavior and the real-time security performance bottlenecks of equipment, network risk situation awareness is conducted, and a network security intelligent awareness map is generated.

[0039] In this embodiment, network traffic mirroring technology is used for end-to-end data acquisition. Traffic mirroring technology replicates all network traffic flowing through key nodes in the network (such as routers and switches) and transmits these replicated data to a traffic analysis device for further processing. Traffic mirroring can efficiently capture all data packets passing through the device, including packets from protocols such as TCP, UDP, and ICMP, ensuring the system can comprehensively analyze network traffic behavior. By configuring the mirroring port of the network device, the system can acquire network data for each link in real time, ensuring data integrity and timeliness. The data acquisition frequency of traffic mirroring can be set to 1 second, with the data packet acquisition timestamp accuracy at the microsecond level to ensure real-time tracking of every data packet in the network. In the experiment, the number of traffic acquisition ports in the network can reach 50, with each port processing at least 100,000 data packets per second, ensuring traffic monitoring capabilities under high load. Abnormal access traffic refers to traffic behavior that does not conform to normal traffic patterns, which may be caused by malicious attacks (such as DDoS attacks, port scanning, etc.) or configuration errors. To detect this abnormal traffic, the system uses machine learning-based anomaly detection algorithms, such as Isolation Forest and One-Class SVM, combined with statistical characteristics of the traffic (e.g., traffic fluctuations, packet size, access frequency). The system models normal traffic patterns to identify abnormal packets that deviate from them. Abnormal traffic typically manifests as high-frequency access, unusually concentrated traffic, or persistent bandwidth peaks. By comparing traffic in real-time with known traffic patterns, the system can promptly flag abnormal traffic data and provide data support for subsequent attack behavior identification.

[0040] By analyzing tagged abnormal traffic, the system determines whether it constitutes an attack and assigns a security threat level to each attack. The system first uses a rule-based intrusion detection system (IDS) and a behavior-based intrusion prevention system (IPS) for comprehensive analysis to identify attack patterns (such as DDoS, SQL injection, cross-site scripting, etc.). The identification of each attack relies on a pre-defined attack signature database or dynamically learned attack patterns; the system makes its judgment by comparing traffic characteristics with those of known attack behaviors in real time. Based on the attack type, severity, and potential impact on the network, the system assigns a security threat level (e.g., low, medium, high) to each attack. The threat level can be comprehensively assessed based on factors such as traffic intensity, attack duration, and scope of impact. For example, a large-scale DDoS attack might be assessed as a high threat level, while a small-scale scanning attack might be assessed as a low threat level. Device operating status includes key performance indicators such as CPU utilization, memory usage, network interface traffic load, device temperature, and error logs. This data helps the system understand the current health status of the devices and provides a basis for subsequent network security assessments and troubleshooting. To monitor device status in real time, the system extracts operational data from the devices using protocols such as SNMP (Simple Network Management Protocol), NetFlow, and sFlow. In addition, the system periodically collects health check data from the devices and performs periodic analysis to promptly identify potential hardware failures or performance bottlenecks. Device status data is typically collected every 10 seconds, ensuring real-time data transmission and prompt action when problems occur. In experiments, the system can monitor up to 1000 devices, ensuring data acquisition capabilities in high-density device environments.

[0041] Network status fluctuations typically manifest as drastic changes in device performance, such as sharp fluctuations in CPU utilization within a short period, excessive memory usage, and instantaneous network bandwidth overload. The system analyzes time-series data of device operating status to identify abnormal fluctuation points. These fluctuation points may be caused by factors such as network congestion, hardware failure, or malicious attacks. The system uses statistical analysis methods (such as standard deviation, rate of change, and moving average) to analyze the fluctuations in device performance indicators and identify state changes that exceed the normal fluctuation range. When a fluctuation point is detected, the system marks it as an abnormal state and triggers an alarm. Fluctuation point detection requires a response time of less than 1 second to ensure rapid response to any abnormal states in the network. Once a status fluctuation point is marked, the system further analyzes these points to calculate the amplitude and duration of the fluctuation. The fluctuation amplitude represents the maximum change in the device performance indicator, while the duration is the length of time the fluctuation persists within a certain threshold range. This data helps the system determine whether the fluctuation may have a long-term impact on the network. The calculation method includes comparing performance data before and after the fluctuation point to determine the amplitude and duration of the fluctuation. For example, when a device's CPU usage spikes from 20% to 90%, the system records the 90% fluctuation and calculates the time from the start of the fluctuation to its recovery. Fluctuation amplitude and duration are important indicators for assessing whether a device is in a dangerous state. For high-amplitude, high-duration fluctuations, the system will consider that the device may have potential safety hazards or hardware malfunctions.

[0042] Device performance bottlenecks refer to the points where devices cannot continue to provide normal services, typically caused by resource overload, hardware failure, or network attacks. The system uses the obtained fluctuation amplitude and duration information, combined with device performance indicators, to calculate the device's resource bottlenecks. For example, if a device's CPU utilization consistently exceeds 80% for a short period and the recovery time is long, the system will consider the device to have a CPU performance bottleneck. Bottleneck estimation helps network administrators understand which devices or services may be affected and take timely load balancing, resource expansion, or optimization measures. The system combines the threat level of abnormal behavior with the device's security performance bottlenecks to perform network risk situational awareness. By integrating data from multiple dimensions such as abnormal traffic detection, attack behavior identification, and device performance analysis, the system generates a comprehensive network security situational map. The security situational map displays the risk status of various devices in the network, potential security threats, and device security bottlenecks. This map helps network administrators monitor network security status in real time, discovering potential attack paths, performance bottlenecks, and security vulnerabilities. The system uses deep learning models and visualization technology to classify, label, and display risk information for rapid response to security threats.

[0043] In this embodiment, the specific steps of step S5 are as follows: Based on the future time window traffic forecast, multi-link capacity planning calculations are performed to obtain the multi-link capacity allocation benchmark; Security link gradient analysis is performed based on network security intelligent perception map to generate security link gradient sequences in the network; Adaptive routing scheduling decisions are made based on the gradient sequence of secure links in the network and the multi-link capacity allocation benchmark. Real-time stable link adjustments are performed based on the topology link quality mapping model to generate an adaptive routing scheduling strategy.

[0044] In this embodiment, to cope with future traffic growth and dynamic changes, the system first performs multi-link capacity planning calculations based on the predicted traffic situation within future time windows. Traffic prediction is achieved by analyzing historical traffic data and time-series trend models (such as ARIMA models and Long Short-Term Memory networks LSTM) to derive the trend of future traffic changes. Based on this, the system calculates the capacity requirements of each network link to meet the potential traffic load within the future time window. To ensure that links do not become congested under high load conditions, the system considers the bandwidth utilization, peak traffic, and fluctuation range of the links, optimizing the link capacity configuration. Based on these calculation results, the system generates a multi-link capacity allocation benchmark, i.e., the capacity requirement that each link should meet within the future time window. In the experiment, the expected traffic change range in the network can reach 30-50%, and a peak traffic capacity upper limit is set for each link to ensure that the link can still carry normally even when traffic changes drastically. The calculation accuracy requirement is 95%, and the traffic prediction time window is typically 10 minutes to 1 hour. The security link gradient describes the security changes of the link, thus providing a basis for routing decisions. By analyzing the security status of each link in the network (such as attack detection, traffic anomalies, and device health status), the system performs a security risk assessment on each link and calculates the security gradient of the link. The gradient value reflects the degree of change of a link from secure to insecure. The system sorts all links by gradient, generating a link gradient sequence to identify which links may become security bottlenecks and which links exhibit high risk at specific times. In the experiment, the calculation of the link security gradient relies on multiple dimensions of security indicators, such as attack frequency, traffic anomaly degree, and device load. The system dynamically adjusts the link gradient according to set thresholds. In the experiment, the security gradient assessment time for each link is required to be less than 2 seconds to ensure rapid response to potential security threats.

[0045] Based on the previously calculated multi-link capacity allocation benchmark and security link gradient sequence, the system will make adaptive routing scheduling decisions. The goal of this stage is to dynamically adjust routing strategies according to the current network traffic demand, security status, and link capacity, optimizing network performance and security. The system will prioritize traffic carrying on links with higher security and sufficient capacity based on the security link gradient sequence, thereby reducing the risk of attacks or abnormal traffic. Simultaneously, the system will adjust link load according to the multi-link capacity allocation benchmark to avoid overloading certain links and ensure balanced traffic distribution. The key to adaptive routing scheduling is real-time adjustment of routing paths based on network topology changes, traffic load changes, and link security status. Building upon adaptive routing scheduling decisions, the system will perform real-time stable link adjustments based on the topology link quality mapping model. The topology link quality mapping model dynamically models the quality (including latency, bandwidth, bit error rate, etc.) of each link in the network topology, enabling spatiotemporal analysis of link quality changes. When the quality of some links significantly deteriorates, the system will promptly adjust routes, switching traffic from unstable or poor-quality links to more stable, higher-quality links, thereby ensuring network performance stability and security. At this point, the system intelligently selects and adjusts links based on their real-time status (such as link quality, load, latency, etc.) and traffic demand. Through continuous optimization of routing strategies using machine learning algorithms (such as reinforcement learning and Q-learning), the system can adaptively select the best link for traffic transmission. In experiments, the response time for link adjustments typically does not exceed 3 seconds, ensuring rapid network recovery in the event of link failures or performance degradation, minimizing network downtime.

[0046] In this embodiment, step S6 is as follows: Traffic distribution is reconfigured based on an adaptive routing scheduling strategy, real-time routing scheduling is executed, and real-time network device interaction information flow is collected. The device interaction delay is calculated on the real-time network device interaction information stream to obtain device interaction delay data; Identify network congestion nodes and traffic overload nodes based on the real-time network device interaction information flow; Overloaded links are marked based on network congestion nodes and traffic overload nodes; Based on device interaction latency data and the overloaded links, iterative route optimization is performed, and deep learning modeling is used to construct an intelligent iterative route optimization agent.

[0047] In this embodiment, an already generated adaptive routing scheduling strategy is used to intelligently distribute traffic to the optimal routing path based on the current network topology, traffic demand, and link status. The core of this process lies in dynamically adjusting the traffic distribution in the network to maximize bandwidth utilization and reduce network latency. During traffic distribution, the system first monitors the performance indicators of each link in real time, such as bandwidth, latency, and bit error rate, and then determines which links the traffic should take based on this data. Based on the acquired topology information, network traffic model, real-time traffic, and link quality data, the system adjusts the traffic distribution path in real time using techniques such as dynamic programming, shortest path algorithms, or reinforcement learning, and continuously optimizes it through regularly updated routing strategies. In the experiment, the response time for traffic distribution reconfiguration is typically controlled within 2 seconds to ensure that the network can adapt to traffic fluctuations in real time. During each traffic reconfiguration, the system collects real-time network device interaction information streams, including data packet exchange, signal strength, and latency information between devices. The collection of these information streams helps the system comprehensively understand the interaction process between devices, providing basic data for subsequent analysis. Interaction latency refers to the time it takes for data packets to be transmitted between devices, including delays in sending, receiving, processing, and queuing. To perform accurate latency calculations, the system records the timestamp of each data packet. From the moment a data packet is sent to the moment it is received, the system calculates the transmission delay on each link and performs statistical analysis. The latency calculation methods used by the system include timestamp-based calculations, network traffic model derivation, and end-to-end latency analysis. Latency calculations consider not only the latency of a single link but also the overall latency of multi-hop paths in the network. Specifically, the system estimates the interaction latency between devices by analyzing factors such as queue length, processing time, and transmission time for each device. In the experiment, the latency calculation time accuracy is required to reach the microsecond level to ensure accurate reflection of the interaction latency of each link. Through accurate calculations, the system can identify potential latency bottleneck links, providing an important basis for subsequent optimization.

[0048] A congested node refers to a network device or node whose excessive traffic degrades link quality, while an overloaded node is one whose traffic exceeds its processing capacity, causing its resources (such as CPU, memory, and bandwidth) to reach their limits. The system monitors the traffic of each node, calculates the rate of change of network traffic, network load, and bandwidth utilization, and combines this with latency data to identify potential bottleneck nodes. In this process, the system uses traffic analysis-based congestion detection algorithms, such as threshold-based traffic monitoring, time-series analysis-based anomaly detection, and dynamic adaptive analysis. Through statistical analysis of traffic and multi-dimensional data monitoring, the system can capture overloaded nodes in real time and mark these nodes and links. In the experiment, the system set the congestion threshold to 80% of the link bandwidth; once the traffic of a node exceeds this threshold, it is marked as a congested node. The experiment aimed for an accuracy rate of over 90% to ensure accurate identification under high load conditions. Overloaded links typically refer to links connected to congested or overloaded nodes. Due to the influence of these overloaded nodes, traffic cannot pass smoothly through these links, leading to increased latency, higher data loss rates, and potentially even network outages. To identify overloaded links, the system combines node traffic monitoring data with link performance metrics, calculating link bandwidth utilization, peak traffic, and bit error rate to assess link load. Based on this, the system models the network topology using graph theory, calculates the load of each link, and marks links carrying high traffic and experiencing performance degradation. The process of marking overloaded links typically combines traffic prediction and historical performance data. The system updates the quality of each link in real time and marks overloaded links to facilitate subsequent optimization decisions. In experiments, the accuracy of overloaded link marking is required to reach over 95% to ensure the real-time response capability of the network management system. Through deep learning models and iterative optimization algorithms, routing decisions are continuously optimized to improve the overall network performance. The system first implements adaptive routing adjustments in the network using deep learning models (such as reinforcement learning and Q-learning). Each device dynamically adjusts its routing selection based on its own load, interaction latency, and link quality, thereby reducing network congestion and optimizing traffic distribution. The core of the intelligent iterative routing optimization agent is to continuously learn and optimize, determining the optimal routing path and adjusting based on real-time feedback. The agent continuously updates its strategy based on real-time collected device interaction latency data and overloaded link markers, learning how to most effectively distribute traffic in the network environment. Through repeated learning and optimization, the system can achieve dynamic routing decisions and optimization, ensuring network stability and efficiency under different loads.

[0049] In this embodiment, an artificial intelligence-based intelligent routing adaptive optimization system is provided for executing the artificial intelligence-based intelligent routing adaptive optimization method described above, including: The topology interconnection analysis module identifies the interconnection information of multiple devices in the routing network; performs topology interconnection analysis between multiple devices; performs temporal topology modeling; and constructs a network topology spatiotemporal evolution model. The link quality calculation module is used to perform real-time link monitoring on the spatiotemporal evolution model of network topology based on the distributed probe agent, and to perform dynamic link quality mapping to build a topology link quality mapping model. The traffic situation prediction module is used to identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and traffic situation prediction, and generate future time window traffic prediction situation. The risk situation awareness module is used to acquire traffic mirror feedback data, detect abnormal access traffic and network risk situation awareness, and generate a network security intelligent awareness map. The adaptive routing scheduling module is used to perform multi-link capacity planning calculations and real-time stable link adjustments based on future time window traffic prediction trends, network security intelligent perception maps, and topology link quality mapping models, and to generate adaptive routing scheduling strategies. The iterative route optimization module is used to reconfigure traffic distribution based on adaptive route scheduling strategies, and then perform iterative route optimization to build an intelligent iterative route optimization agent.

[0050] The beneficial effects of this invention are specifically as follows: Through in-depth analysis and modeling of network topology, a comprehensive and dynamic view is provided, helping to identify the interconnection relationships between multiple devices. Using temporal topology modeling, changes in network topology at different time points can be tracked, accurately predicting topology change trends and providing a data foundation for subsequent traffic prediction and routing optimization. The spatiotemporal evolution model of the topology reflects the dynamic changes of network devices and links, facilitating timely adjustments and optimizations when network changes occur. Real-time monitoring of links through a distributed probe agent can quickly detect problems when link quality changes, contributing to improved network reliability and stability. The link quality mapping model visually displays the quality of each link, providing a basis for subsequent traffic guidance and routing decisions. Links with better quality can be dynamically selected for traffic forwarding, reducing packet loss and latency and improving network performance. Identifying and analyzing data packets of service flows allows for real-time perception of traffic changes and patterns, helping to determine the current network load status. Traffic situation prediction allows for forecasting traffic demand within future time windows. This not only helps in advance planning of bandwidth requirements but also facilitates dynamic adjustment of traffic guidance strategies. Traffic prediction results can identify potential traffic pressure in advance, providing a basis for load balancing and routing adjustments. Through traffic mirroring feedback data, abnormal traffic can be detected in real time, and potential security threats (such as DDoS attacks and virus propagation) can be identified. This helps to prevent malicious traffic from intruding into the network in advance. Generating a network security intelligent awareness map helps to dynamically understand the network's security status, quickly respond to security incidents, and ensure network security. It can quickly identify abnormal traffic patterns in massive traffic volumes, reducing missed detections and false alarms, and improving the accuracy of security incident response. By integrating traffic prediction, security awareness, and link quality assessment, it can dynamically adjust link capacity and stability, avoiding link congestion or performance degradation. The generated adaptive routing scheduling strategy can make intelligent decisions based on real-time data, ensuring traffic is transmitted on the optimal link and improving the overall network operating efficiency. It can intelligently schedule multiple links according to their status and needs, thereby achieving higher network resource utilization. Based on the adaptive routing scheduling strategy, traffic can be optimized and distributed according to the real-time status of links, avoiding network congestion and improving traffic transmission efficiency. Through iterative route optimization, routing paths can be continuously adjusted, making network routing more intelligent and efficient. This optimization is dynamic and adaptable to changes in network conditions. By constructing an intelligent iterative routing optimization agent, the network can automatically make optimization decisions based on real-time data during operation, reducing human intervention and maintenance costs.

[0051] Therefore, the embodiments should be considered as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of the equivalents of the application are intended to be included within the invention.

[0052] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein are implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.

Claims

1. An intelligent routing adaptive optimization method based on artificial intelligence, characterized in that, Includes the following steps: Step S1: Identify the interconnection information of multiple devices in the routing network; Perform topology interconnection analysis between multiple devices, and perform temporal topology modeling to construct a spatiotemporal evolution model of network topology; Step S2: Based on the distributed probe agent, perform real-time link monitoring on the network topology spatiotemporal evolution model, and perform dynamic link quality mapping to construct a topology link quality mapping model; Step S3: Identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and prediction of traffic situation, so as to generate the traffic prediction situation of future time windows; Step S4: Obtain traffic mirroring feedback data, perform abnormal access traffic detection and network risk situation awareness, and generate a network security intelligent awareness map; Step S5: Based on the future time window traffic prediction trend, network security intelligent perception map and topology link quality mapping model, perform multi-link capacity planning calculation and real-time stable link adjustment to generate an adaptive routing scheduling strategy. Step S6: Reconfigure traffic distribution based on the adaptive routing scheduling strategy, then perform iterative route optimization to build an intelligent iterative route optimization agent.

2. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, The specific steps of step S1 are as follows: Identify interconnection information of multiple devices in a routing network; The device node is identified from the multi-device interconnection information, and the topology interconnection between the multiple devices is analyzed to extract the topology interconnection path between the multiple devices. Based on the topology interconnection path, a global device connection fit is performed to construct a multi-device topology interconnection network; Node importance assessment and edge weight calculation are performed based on multi-device topology interconnection networks to generate topological semantic features; Based on multi-device interconnection information, real-time establishment and exit detection of device links are performed to generate real-time network connectivity trends of devices. Based on the real-time networking trends and topological semantic features, a temporal topology model is performed on the multi-device interconnection network to construct a spatiotemporal evolution model of the network topology.

3. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, The specific steps of step S2 are as follows: Based on a distributed probe agent, real-time link monitoring is performed on the spatiotemporal evolution model of network topology to extract round-trip delay, bandwidth utilization, bit error rate and availability status of multiple network links. The round-trip time, bandwidth utilization, bit error rate, and availability status are evaluated to assess the link network quality and generate a real-time quality assessment value for each link. The time-series quality change trend is calculated based on the real-time quality assessment value to obtain the time-series quality trend curve for each link; Based on the time-series quality trend curve, link reliability is predicted, and a reliability index for each link is generated. Based on the aforementioned reliability indicators, a dynamic link quality mapping is performed on the network topology spatiotemporal evolution model to construct a topology link quality mapping model.

4. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, Step S3 is as follows: Identify data packets of various service flows in the spatiotemporal evolution model of network topology; The packet traffic size of each service flow data packet is calculated, and the link distribution is analyzed to obtain network link traffic distribution data; Perform protocol stack layer parsing and business application identification on data packets of each business flow, and mark data packet attributes; Dynamically perceive traffic behavior based on network link traffic distribution data and data packet attributes, and construct a panoramic perception map of traffic behavior. Predict future traffic patterns based on a panoramic perception map of traffic behavior, in order to generate a predicted traffic pattern for future time windows.

5. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 4, characterized in that, The specific steps for predicting future traffic patterns based on a panoramic perception map of traffic behavior to generate future traffic prediction patterns are as follows: Based on the data packets of each business flow, user access patterns are analyzed to obtain user access patterns. Calculate the application call frequency based on the data packets of each service flow; Data transmission volume change analysis is performed on the data packets of each service flow to obtain the data transmission volume change values ​​at multiple time points; Periodic variation mining is performed based on the changes in transmission volume at multiple time points to obtain the pattern of data transmission volume changes; Analyze user access needs based on user access patterns, application call frequency, and data transmission volume changes to generate real-time user access requirements. Based on the panoramic perception map of traffic behavior and real-time user access demand, future time window traffic trends are predicted to generate future time window traffic prediction trends.

6. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, The specific steps of step S4 are as follows: Full-link data collection is performed based on network traffic mirroring technology to obtain traffic mirroring feedback data; Detect abnormal access traffic based on traffic mirroring feedback data and mark abnormal access traffic data. The system identifies attack behaviors in abnormal access traffic data and assesses the security threat level to determine the threat level of the abnormal behavior. Obtain real-time operating status data of all devices in the routing network; Identify network status fluctuations in real-time device operating status data and mark status fluctuation points; Calculate the amplitude and duration of the state fluctuation at the aforementioned state fluctuation point; Based on the amplitude and duration of the state fluctuations, the real-time device security performance bottleneck is estimated, thereby obtaining the real-time device security performance bottleneck. Based on the threat level of abnormal behavior and the real-time security performance bottlenecks of equipment, network risk situation awareness is conducted, and a network security intelligent awareness map is generated.

7. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, The specific steps of step S5 are as follows: Based on the future time window traffic forecast, multi-link capacity planning calculations are performed to obtain the multi-link capacity allocation benchmark; Security link gradient analysis is performed based on network security intelligent perception map to generate security link gradient sequences in the network; Adaptive routing scheduling decisions are made based on the gradient sequence of secure links in the network and the multi-link capacity allocation benchmark. Real-time stable link adjustments are performed based on the topology link quality mapping model to generate an adaptive routing scheduling strategy.

8. The intelligent routing adaptive optimization method based on artificial intelligence according to claim 1, characterized in that, The specific steps of step S6 are as follows: Traffic distribution is reconfigured based on an adaptive routing scheduling strategy, real-time routing scheduling is executed, and real-time network device interaction information flow is collected. The device interaction delay is calculated on the real-time network device interaction information stream to obtain device interaction delay data; Identify network congestion nodes and traffic overload nodes based on the real-time network device interaction information flow; Overloaded links are marked based on network congestion nodes and traffic overload nodes; Based on device interaction latency data and the overloaded links, iterative route optimization is performed, and deep learning modeling is used to construct an intelligent iterative route optimization agent.

9. An intelligent routing adaptive optimization system based on artificial intelligence, characterized in that, The method for executing the AI-based intelligent routing adaptive optimization method as described in claim 1 includes: The topology interconnection analysis module identifies the interconnection information of multiple devices in the routing network; performs topology interconnection analysis between multiple devices; performs temporal topology modeling; and constructs a network topology spatiotemporal evolution model. The link quality calculation module is used to perform real-time link monitoring on the spatiotemporal evolution model of network topology based on the distributed probe agent, and to perform dynamic link quality mapping to build a topology link quality mapping model. The traffic situation prediction module is used to identify the data packets of each service flow in the network topology spatiotemporal evolution model, perform dynamic perception of traffic behavior and traffic situation prediction, and generate future time window traffic prediction situation. The risk situation awareness module is used to acquire traffic mirror feedback data, detect abnormal access traffic and network risk situation awareness, and generate a network security intelligent awareness map. The adaptive routing scheduling module is used to perform multi-link capacity planning calculations and real-time stable link adjustments based on future time window traffic prediction trends, network security intelligent perception maps, and topology link quality mapping models, and to generate adaptive routing scheduling strategies. The iterative route optimization module is used to reconfigure traffic distribution based on adaptive route scheduling strategies, and then perform iterative route optimization to build an intelligent iterative route optimization agent.